OLWHiddenWin message on reboot
8 min read
My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
- I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
- The fixes are specific to your problem and should only be used for the issues on this machine.
- Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
- It's often worth reading through these instructions and printing them for ease of reference.
- If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
- Please reply to this thread. Do not start a new topic.
Hi,
My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
As I'm still in training at What The Tech, all my posts needs to be checked by an expert first. This may cause a delay, but I will do my best to keep it as short as possible.
- I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
- The fixes are specific to your problem and should only be used for the issues on this machine.
- Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
- It's often worth reading through these instructions and printing them for ease of reference.
- If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
- Please reply to this thread. Do not start a new topic.
Hello and many thanks.
I copy and paste the scan log of mi other computer, both in the same home network, as I fear the two of them might suffer the same attack.
I eagerly wait for your answer.
All the best.
María
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=36abbd9db7278b49bd3bff0c2a1764bd
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-10-04 07:24:12
# local_time=2010-10-04 04:24:12 (-0300, Hora estándar de Argentina)
# country="Argentina"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=768 16777215 100 0 6732855 6732855 0 0
# compatibility_mode=5891 16776869 100 100 0 15724710 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=197502
# found=8
# cleaned=0
# scan_time=10536
C:\Documents and Settings\Maria\Configuración local\Datos de programa\Microsoft\Windows Live Mail\Yahoo.com ( b05\Inbox\Ahorro\1B0B09F9-00000470.eml HTML/Phishing.gen trojan 00000000000000000000000000000000 I
C:\Documents and Settings\Maria\Configuración local\Datos de programa\Microsoft\Windows Live Mail\Yahoo.com ( b05\Inbox\Ahorro\32DE7512-00000471.eml HTML/Phishing.gen trojan 00000000000000000000000000000000 I
D:\mis documentos\My Completed Downloads\SmileyCentralFWBInitialSetup1.0.0.15-3.exe Win32/AdInstaller application 00000000000000000000000000000000 I
D:\mis documentos\My Completed Downloads\Nero-6.6.1.15d_wch.exe Win32/Toolbar.AskSBar application 00000000000000000000000000000000 I
D:\mis documentos\Varios viejos\Backup\Carpetas\Outlook Express\Ahorro.dbx HTML/Phishing.gen trojan 00000000000000000000000000000000 I
D:\mis documentos\Varios viejos\Backup\Carpetas\Outlook Express\Dominique.dbx HTML/Phishing.gen trojan 00000000000000000000000000000000 I
D:\mis documentos\Varios viejos\Mis documentos\mail\Mail (Backup-dbx)\Mail\Bandeja de entrada.dbx HTML/Phishing.gen trojan 00000000000000000000000000000000 I
D:\Outlook Express\Ahorro.dbx HTML/Phishing.gen trojan 00000000000000000000000000000000 I
Let's clean your computers one at a time. We will work on the first one first. Please do not follow the same procedure for the second computer because the infection is different.
Download OTL to your Desktop
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- Click on Minimal Output at the top
- Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
- Double click inside the Custom Scan box at the bottom
- A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
- Click the OK button and navigate to the file scan.txt which we just saved to your desktop
- Select scan.txt and click Open. Writing will now appear under the Custom Scan box
- Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
- When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
- If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
[external image: Posted Image]
Click the image to enlarge it
- In the right panel, you will see several boxes that have been checked. Uncheck the following …
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and attach it in your reply.
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi Marianueva,
Let's clean your computers one at a time. We will work on the first one first. Please do not follow the same procedure for the second computer because the infection is different.
Download OTL to your Desktop
Download and Run GMER
- Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
- Click on Minimal Output at the top
- Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
- Double click inside the Custom Scan box at the bottom
- A window will appear saying "Click OK to load a custom scan from a file or Cancel to cancel"
- Click the OK button and navigate to the file scan.txt which we just saved to your desktop
- Select scan.txt and click Open. Writing will now appear under the Custom Scan box
- Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
OTL Extras logfile created on: 05/10/2010 10:06:18 a.m. - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Maria\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00002C0A | Country: Argentina | Language: ESS | Date Format: dd/MM/yyyy
502,00 Mb Total Physical Memory | 182,00 Mb Available Physical Memory | 36,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 63,00% Paging File free
Paging file location(s): D:\pagefile.sys 1024 1024 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 30,53 Gb Total Space | 11,87 Gb Free Space | 38,89% Space Free | Partition Type: FAT32
Drive D: | 21,44 Gb Total Space | 3,07 Gb Free Space | 14,34% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: VIAJERA
Current User Name: Maria
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Acer\Acer Arcade\PCMService.exe" = C:\Program Files\Acer\Acer Arcade\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program – (CyberLink Corp.)
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows – (Ares Development Group)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02A2EE40-723D-4644-A996-E03BB4688E42}" = Microsoft Antimalware Service ES-ES Language Pack
"{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"{1F2C8256-2773-46C7-9ABA-3E39C24ABB51}" = Acer eSettings Management
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Herramienta de carga de Windows Live
"{211E8730-5681-49ED-BC6A-78C9F88E95F5}" = Adobe Shockwave Player
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2EAF7E61-068E-11DF-953C-005056806466}" = Google Earth
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{375943E2-B268-4AD7-B7A4-0FD90E9C2AC7}" = Skype™ 3.8 Lite
"{405C32CF-9C6F-49B3-9436-3F5FDBE7B3CE}" = Microsoft .NET Framework 2.0 Language Pack - ESN
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4AD13F68-CADA-4C6B-9759-C33753F89908}" = Acer eDataSecurity Management
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A28AB0B-22B1-494C-AF61-B386EA1736C0}" = LightScribe 1.4.97.1
"{7057702F-6D71-4F30-8000-9E72BC771887}" = Acer ePerformance Management
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-1437-443D-B06E-79A00FE45110}" = Adobe Stock Photos 1.0
"{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = TIPCI
"{88F560AD-9B38-4273-8450-0C7485830A4B}" = Winamp AudioPlayer
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8FFC924C-ED06-44CB-8867-3CA778ECE903}" = Adobe Help Center 2.0
"{90110C0A-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95120000-0122-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology
"{AC76BA86-7AD7-1034-7B44-A91000000001}" = Adobe Reader 9.1 - Español
"{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}" = Adobe Bridge 1.0
"{B06B842F-2450-494F-BBDE-217CDC151A37}" = NTI Backup NOW! 4.5
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BF839132-BD43-4056-ACBF-4377F4A88E2A}" = Acer ePresentation Management
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D458BBDC-0363-42E0-8FF9-4736E3CB3CA2}" = Acer Screensaver
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Ares" = Ares 2.1.1
"Eset NOD32 v3.0.642 FiX1.2 by TemDono_is1" = NOD32 v3.0.642 FiX1.2 by TemDono (31 days remaining forever up
"ESET Online Scanner" = ESET Online Scanner v3
"GridVista" = Acer GridVista
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"InstallShield_{4AD13F68-CADA-4C6B-9759-C33753F89908}" = Acer eDataSecurity Management 2.0.3077
"InstallShield_{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"KLiteCodecPack_is1" = K-Lite Codec Pack 3.9.0 Standard
"LManager" = Launch Manager
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0 Language Pack - ESN" = Paquete de idioma de Microsoft .NET Framework 2.0 - ESN
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"MyDefrag v4.3.1_is1" = MyDefrag v4.3.1
"Nero8WinuE_is1" = Nero [removed]
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa2" = Picasa 2
"qt7lite_is1" = QT Lite 2.5.1
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Unlocker" = Unlocker 1.8.7
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = Compresor WinRAR
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 04/10/2010 06:26:51 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 04/10/2010 06:26:51 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 28844
Error - 04/10/2010 06:26:51 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 28844
Error - 04/10/2010 06:26:53 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 04/10/2010 06:26:53 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 30907
Error - 04/10/2010 06:26:53 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 30907
Error - 04/10/2010 06:26:55 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 04/10/2010 06:26:55 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 32891
Error - 04/10/2010 06:26:55 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 32891
Error - 04/10/2010 12:19:17 p.m. | Computer Name = VIAJERA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
[ System Events ]
Error - 03/10/2010 03:11:08 p.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 03/10/2010 03:13:00 p.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Eset Nod32 Boot service
to connect.
Error - 03/10/2010 03:13:00 p.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7000
Description = The Eset Nod32 Boot service failed to start due to the following error:
%%1053
Error - 03/10/2010 03:36:31 p.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Eset Nod32 Boot service
to connect.
Error - 03/10/2010 03:36:31 p.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7000
Description = The Eset Nod32 Boot service failed to start due to the following error:
%%1053
Error - 04/10/2010 10:36:20 a.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.
Error - 04/10/2010 11:40:43 a.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Eset Nod32 Boot service
to connect.
Error - 04/10/2010 11:40:43 a.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7000
Description = The Eset Nod32 Boot service failed to start due to the following error:
%%1053
Error - 05/10/2010 07:59:26 a.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Eset Nod32 Boot service
to connect.
Error - 05/10/2010 07:59:26 a.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7000
Description = The Eset Nod32 Boot service failed to start due to the following error:
%%1053
< End of report >
- When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
- Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
**Caution**
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
- If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
[external image: Posted Image]
Click the image to enlarge it
- In the right panel, you will see several boxes that have been checked. Uncheck the following …
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and attach it in your reply.
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
OTL logfile created on: 05/10/2010 12:28:38 p.m. - Run 2
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Maria\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00002C0A | Country: Argentina | Language: ESS | Date Format: dd/MM/yyyy
502,00 Mb Total Physical Memory | 70,00 Mb Available Physical Memory | 14,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 56,00% Paging File free
Paging file location(s): D:\pagefile.sys 1024 1024 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 30,53 Gb Total Space | 11,87 Gb Free Space | 38,88% Space Free | Partition Type: FAT32
Drive D: | 21,44 Gb Total Space | 3,07 Gb Free Space | 14,34% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: VIAJERA
Current User Name: Maria
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/10/05 10:04:46 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Maria\Desktop\OTL.exe
PRC - [2010/06/01 14:53:46 | 001,093,208 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Essentials\msseces.exe
PRC - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/03/25 21:40:44 | 000,017,904 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
PRC - [2008/11/09 17:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/13 21:12:20 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2006/08/01 12:05:42 | 000,507,904 | —- | M] (Realtek Semiconductor Corp.) – C:\Documents and Settings\Maria\Local Settings\Temp\RtkBtMnt.exe
PRC - [2006/07/14 12:13:00 | 000,471,040 | —- | M] (Dritek System Inc.) – C:\Program Files\Launch Manager\QtZgAcer.EXE
PRC - [2006/07/12 15:48:50 | 000,438,272 | —- | M] () – C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
PRC - [2006/06/29 10:45:00 | 000,045,056 | —- | M] (Acer Inc.) – C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
PRC - [2006/06/13 09:57:00 | 000,094,208 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\igfxext.exe
PRC - [2006/06/01 14:40:54 | 000,413,696 | —- | M] (Acer Inc.) – C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
PRC - [2006/05/17 19:04:20 | 000,254,050 | —- | M] () – C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
PRC - [2006/05/17 19:04:20 | 000,114,784 | —- | M] () – C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
PRC - [2006/05/17 19:03:40 | 001,077,376 | —- | M] (Cyberlink) – C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
PRC - [2006/05/17 19:03:40 | 000,061,440 | —- | M] (Cyberlink) – C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
PRC - [2006/03/29 20:53:34 | 000,028,672 | —- | M] (Acer Inc.) – C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
PRC - [2006/03/17 15:00:50 | 000,345,088 | —- | M] (HiTRUST) – C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
========== Modules (SafeList) ==========
MOD - [2010/10/05 10:04:46 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Maria\Desktop\OTL.exe
MOD - [2008/04/13 21:12:02 | 000,413,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcp60.dll
MOD - [2008/04/13 21:11:56 | 001,028,096 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\mfc42.dll
MOD - [2008/04/13 21:10:20 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx
MOD - [2006/03/17 14:59:44 | 000,176,128 | —- | M] (HiTRUST) – C:\WINDOWS\system32\sysenv.dll
MOD - [2006/03/08 17:11:40 | 000,022,016 | —- | M] (HiTRUST) – C:\WINDOWS\system32\MSNChatHook.dll
MOD - [2006/03/06 21:25:40 | 000,199,168 | —- | M] (HiTRUST) – C:\WINDOWS\system32\CryptoAPI.dll
MOD - [2005/10/11 13:18:54 | 000,028,672 | —- | M] () – C:\Acer\Empowering Technology\ePower\SysHook.dll
MOD - [2003/03/18 22:12:12 | 001,047,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\MFC71u.dll
MOD - [2003/03/18 20:14:50 | 000,499,712 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcp71.dll
MOD - [2003/02/21 05:42:20 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msvcr71.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] – C:\WINDOWS\System32\hidserv.dll – (HidServ)
SRV - File not found [On_Demand | Stopped] – C:\WINDOWS\System32\appmgmts.dll – (AppMgmt)
SRV - [2010/04/16 08:33:40 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/03/25 21:40:44 | 000,017,904 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Security Essentials\MsMpEng.exe – (MsMpSvc)
SRV - [2008/11/09 17:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
SRV - [2006/05/17 19:04:20 | 000,254,050 | —- | M] () [Auto | Running] – C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe – (CLCapSvc) CyberLink Background Capture Service (CBCS)
SRV - [2006/05/17 19:04:20 | 000,114,784 | —- | M] () [Auto | Running] – C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe – (CLSched) CyberLink Task Scheduler (CTS)
SRV - [2006/05/17 19:03:40 | 000,061,440 | —- | M] (Cyberlink) [Auto | Running] – C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe – (CyberLink Media Library Service)
SRV - [2006/03/29 20:53:34 | 000,028,672 | —- | M] (Acer Inc.) [Auto | Running] – C:\Acer\Empowering Technology\ePerformance\MemCheck.exe – (AcerMemUsageCheckService)
SRV - [2005/11/14 01:06:04 | 000,069,632 | —- | M] (Macrovision Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe – (IDriverT)
SRV - [2004/08/04 05:00:00 | 000,003,584 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\WINDOWS\System32\regedt32.exe – (NOD32FiXTemDono)
========== Driver Services (SafeList) ==========
DRV - [2010/03/25 21:30:22 | 000,151,216 | —- | M] (Microsoft Corporation) [File_System | System | Running] – C:\WINDOWS\system32\drivers\MpFilter.sys – (MpFilter)
DRV - [2009/06/26 17:21:02 | 001,956,352 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\VX3000.sys – (VX3000)
DRV - [2008/04/13 15:54:36 | 000,028,672 | —- | M] (National Semiconductor Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\nscirda.sys – (NSCIRDA)
DRV - [2008/04/13 15:45:12 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 15:36:40 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/13 15:36:40 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2008/04/13 13:36:06 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\Hdaudbus.sys – (HDAudBus)
DRV - [2006/08/01 16:36:02 | 000,006,144 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\NTIDrvr.sys – (NTIDrvr)
DRV - [2006/07/19 09:42:00 | 004,304,384 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.Sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2006/07/14 12:13:00 | 000,016,896 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\DKbFltr.SYS – (DKbFltr)
DRV - [2006/06/20 03:20:24 | 001,097,728 | —- | M] (Logitech) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\lv321av.sys – (lv321av) Logitech USB PC Camera (VC0321)
DRV - [2006/06/20 03:16:16 | 000,039,424 | —- | M] (Logitech) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\LVUSBSta.sys – (LVUSBSta)
DRV - [2006/06/13 10:18:00 | 000,162,432 | —- | M] (Texas Instruments) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\tifm21.sys – (tifm21)
DRV - [2006/06/13 10:03:00 | 000,424,320 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\BCMWL5.SYS – (BCM43XX)
DRV - [2006/06/02 13:59:54 | 000,014,544 | —- | M] (EnTech Taiwan) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\TVicPort.sys – (tvicport)
DRV - [2006/06/02 13:59:52 | 000,006,080 | —- | M] (Zeal SoftStudio) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\zntport.sys – (zntport)
DRV - [2006/06/02 13:59:50 | 000,069,632 | —- | M] () [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\int15.sys – (int15)
DRV - [2006/06/01 08:55:00 | 000,244,864 | —- | M] (Marvell) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\yk51x86.sys – (yukonwxp)
DRV - [2006/04/29 05:54:52 | 000,193,056 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2006/04/07 20:17:34 | 000,012,288 | —- | M] (HiTRUST) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\psdfilter.sys – (psdfilter)
DRV - [2006/04/04 03:17:24 | 001,429,632 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\w39n51.sys – (w39n51) Intel®
DRV - [2006/03/08 17:10:52 | 000,060,416 | —- | M] (HiTRUST) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\psdvdisk.sys – (psdvdisk)
DRV - [2005/12/13 23:08:44 | 001,124,097 | —- | M] (Agere Systems) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2004/12/17 17:14:44 | 000,013,952 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\System32\drivers\UBHelper.sys – (UBHelper)
DRV - [2004/08/04 05:00:00 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2004/08/04 05:00:00 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2004/08/04 05:00:00 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2004/08/04 05:00:00 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2004/08/04 05:00:00 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2004/08/04 05:00:00 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2004/08/04 05:00:00 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2004/08/04 05:00:00 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2004/08/04 05:00:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2004/08/04 05:00:00 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2004/08/04 05:00:00 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2004/08/04 05:00:00 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2004/08/04 05:00:00 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2004/08/04 05:00:00 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)
DRV - [2004/08/04 05:00:00 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {DCBD1271-D228-4082-9FBC-36D9B7660B03}:1.1.9.1
FF - prefs.js..extensions.enabledItems: [removed]:2.0
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/04/25 02:30:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/04/25 02:30:38 | 000,000,000 | —D | M]
[2010/09/29 21:27:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Maria\Application Data\Mozilla\Extensions
[2009/04/25 11:59:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\isacrv5y.default\extensions
[2010/09/24 19:59:36 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\isacrv5y.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/05 09:59:26 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\isacrv5y.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/09/24 19:59:38 | 000,000,000 | —D | M] () – C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\isacrv5y.default\extensions\{DCBD1271-D228-4082-9FBC-36D9B7660B03}
[2010/09/24 19:59:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\isacrv5y.default\extensions\[removed]
[2010/09/24 19:59:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\isacrv5y.default\extensions\[removed]
[2010/09/29 21:33:08 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/09/14 18:13:14 | 000,003,996 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\drae.xml
[2010/09/14 18:13:14 | 000,000,751 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-es.xml
[2010/09/14 18:13:14 | 000,001,178 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-es.xml
[2010/09/14 18:13:14 | 000,001,102 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-es.xml
O1 HOSTS File: ([2010/10/03 13:28:50 | 000,000,909 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll (HiTRUST)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll (HiTRUST)
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [Boot] C:\Acer\Empowering Technology\ePower\Boot.exe ()
O4 - HKLM..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe (HiTRUST)
O4 - HKLM..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe ()
O4 - HKLM..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe (Acer Inc.)
O4 - HKLM..\Run: [LaunchApp] C:\WINDOWS\Alaunch.exe (Acer Inc.)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [MSSE] C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [SkyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10c.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer Empowering Technology.lnk = C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe (Acer Inc.)
O4 - Startup: C:\Documents and Settings\Maria\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\npjpi160_06.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1240671992671 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Acer.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Acer.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/08/01 16:37:40 | 000,000,100 | —- | M] () - C:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2008/06/10 20:52:36 | 000,000,090 | —- | M] () - D:\AUTORUN.INF – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - File not found
Drivers32: msacm.mkdmp3enc - C:\PROGRA~1\Acer\ACERAR~1\Kernel\Burner\MKDMP3Enc.ACM File not found
Drivers32: msacm.siren - C:\WINDOWS\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
MsConfig - StartUpReg: Acer ePresentation HPD - hkey= - key= - C:\Acer\Empowering Technology\ePresentation\ePresentation.exe (Acer Inc.)
MsConfig - StartUpReg: ares - hkey= - key= - C:\Program Files\Ares\Ares.exe (Ares Development Group)
MsConfig - StartUpReg: BluetoothAuthenticationAgent - hkey= - key= - File not found
MsConfig - StartUpReg: igfxhkcmd - hkey= - key= - File not found
MsConfig - StartUpReg: igfxpers - hkey= - key= - File not found
MsConfig - StartUpReg: igfxtray - hkey= - key= - File not found
MsConfig - StartUpReg: iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg: ntiMUI - hkey= - key= - C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe ()
MsConfig - StartUpReg: Picasa Media Detector - hkey= - key= - C:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.)
MsConfig - StartUpReg: QuickTime Task - hkey= - key= - C:\Program Files\QT Lite\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg: VX3000 - hkey= - key= - C:\WINDOWS\vVX3000.exe (Microsoft Corporation)
MsConfig - State: "system.ini" - 0
MsConfig - State: "win.ini" - 0
MsConfig - State: "bootini" - 0
MsConfig - State: "services" - 0
MsConfig - State: "startup" - 2
SafeBootMin: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: MsMpSvc - C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: MsMpSvc - C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
ActiveX: {0291E591-EA41-4c82-8106-3DC6CE7F7664} - Reg Error: Value error.
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {10072CEC-8CC1-11D1-986E-00A0C955B42F} - Vector Graphics Rendering (VML)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} - NetShow
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 6.4
ActiveX: {233C1507-6A77-46A4-9443-F871F945D258} - Adobe Shockwave Director 11.0
ActiveX: {283807B5-2C60-11D0-A31D-00AA00B92C03} - DirectAnimation
ActiveX: {2A202491-F00D-11cf-87CC-0020AFEECF20} - Adobe Shockwave Director 11.0
ActiveX: {2A3320D6-C805-4280-B423-B665BDE33D8F} - Microsoft .NET Framework 1.1 Security Update (KB979906)
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2CDB8B06-E2D5-9FEF-853D-4E76CC3483E1} - Adobe Shockwave Director 11.0
ActiveX: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - Reg Error: Value error.
ActiveX: {347B0667-C7ED-429B-BDE3-CC8D3BACAA31} - Reg Error: Value error.
ActiveX: {36f8ec70-c29a-11d1-b5c7-0000f8051515} - Dynamic HTML Data Binding for Java
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3bf42070-b3b1-11d1-b5c5-0000f8051515} - Uniscribe
ActiveX: {405C32CF-9C6F-49B3-9436-3F5FDBE7B3CE} - .NET Framework
ActiveX: {411EDCF7-755D-414E-A74B-3DCD6583F589} - Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
ActiveX: {4278c270-a269-11d1-b5bf-0000f8051515} - Advanced Authoring
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
ActiveX: {44BBA842-CC51-11CF-AAFA-00AA00B6015B} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} - DirectShow
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f216970-c90c-11d1-b5c7-0000f8051515} - DirectAnimation Java Classes
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5945c046-1e7d-11d1-bc44-00c04fd912be} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
ActiveX: {5A8D6EE0-3E18-11D0-821E-444553540000} - ICW
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {73FA19D0-2D75-11D2-995D-00C04F98BBC9} - Carpetas Web
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
ActiveX: {83169D43-4660-4347-BC95-E9D6E6BE65CE} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\WINDOWS\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install
ActiveX: {8b15971b-5355-4c82-8c07-7e181ea07608} - rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {94de52c8-2d59-4f1b-883e-79663d2d9a8c} - Fax Provider
ActiveX: {B508B3F1-A24A-32C0-B310-85786919EF28} - .NET Framework
ActiveX: {C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1} - .NET Framework
ActiveX: {CC2A9BA0-3BDD-11D0-821E-444553540000} - Task Scheduler
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11cf-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: <{12d0ed0d-0ee0-4f90-8827-78cefb8f4988} - C:\WINDOWS\system32\ieudinit.exe
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\WINDOWS\inf\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS - RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
ActiveX: >{881dd1c5-3dcf-431b-b061-f3f88e8be88a} - %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)
========== Files/Folders - Created Within 30 Days ==========
[2010/10/05 10:04:31 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Maria\Desktop\OTL.exe
[2010/10/05 09:59:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Maria\Local Settings\Application Data\Yahoo
[2010/10/05 09:59:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Yahoo!
[2010/10/05 09:59:06 | 000,000,000 | —D | C] – C:\Documents and Settings\Maria\Application Data\Yahoo!
[2010/10/03 16:07:59 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/10/03 14:04:48 | 000,221,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/10/03 13:54:17 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/10/03 13:34:11 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Maria\IECompatCache
[2010/10/03 13:26:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/10/03 13:13:50 | 000,088,576 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\AntiXPVSTFix.exe
[2010/10/03 13:13:50 | 000,082,944 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\o4Patch.exe
[2010/10/03 13:13:50 | 000,082,944 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\IEDFix.C.exe
[2010/10/03 13:13:49 | 000,289,144 | —- | C] (S!Ri) – C:\WINDOWS\System32\VCCLSID.exe
[2010/10/03 13:13:49 | 000,086,528 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\VACFix.exe
[2010/10/03 13:13:49 | 000,082,944 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\IEDFix.exe
[2010/10/03 13:13:49 | 000,082,432 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\404Fix.exe
[2010/10/03 13:13:48 | 000,288,417 | —- | C] (S!Ri) – C:\WINDOWS\System32\SrchSTS.exe
[2010/10/03 13:13:48 | 000,079,360 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swxcacls.exe
[2010/10/03 13:13:47 | 000,135,168 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swreg.exe
[2010/10/03 13:13:47 | 000,053,248 | —- | C] (http://www.beyondlogic.org) – C:\WINDOWS\System32\Process.exe
[2010/09/29 20:53:08 | 000,000,000 | —D | C] – D:\MIS DOCUMENTOS\My Received Files
[2010/09/25 15:47:19 | 000,000,000 | —D | C] – D:\MIS DOCUMENTOS\Mis archivos recibidos
[2010/09/25 10:59:21 | 000,000,000 | —D | C] – C:\WINDOWS\pss
[2006/05/25 18:18:48 | 000,053,248 | —- | C] ( ) – C:\WINDOWS\System32\Interop.Shell32.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/05 12:31:32 | 000,000,374 | -H– | M] () – C:\WINDOWS\tasks\MpIdleTask.job
[2010/10/05 10:04:46 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Maria\Desktop\OTL.exe
[2010/10/05 09:04:54 | 000,000,614 | —- | M] () – C:\WINDOWS\win.ini
[2010/10/05 09:04:46 | 000,000,408 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/10/05 08:59:22 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/10/05 08:59:20 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/05 08:59:16 | 526,565,376 | -HS- | M] () – C:\hiberfil.sys
[2010/10/04 16:37:02 | 002,621,440 | -H– | M] () – C:\Documents and Settings\Maria\NTUSER.DAT
[2010/10/04 16:36:40 | 000,000,012 | —- | M] () – C:\WINDOWS\bthservsdp.dat
[2010/10/04 16:36:32 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Maria\ntuser.ini
[2010/10/04 16:00:39 | 000,023,040 | —- | M] () – D:\MIS DOCUMENTOS\Infeccion compus.doc
[2010/10/03 13:54:20 | 000,000,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/10/03 13:54:02 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/03 13:18:12 | 000,003,662 | —- | M] () – C:\WINDOWS\System32\tmp.reg
[2010/09/29 21:33:14 | 000,001,528 | —- | M] () – C:\Documents and Settings\Maria\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/09/29 21:33:12 | 000,001,510 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2010/09/25 11:21:46 | 000,052,516 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/09/25 11:03:48 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/09/25 11:03:48 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/09/24 20:40:16 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/09/24 19:22:08 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/09/10 16:20:02 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/04 16:00:39 | 000,023,040 | —- | C] () – D:\MIS DOCUMENTOS\Infeccion compus.doc
[2010/10/03 14:05:55 | 000,000,374 | -H– | C] () – C:\WINDOWS\tasks\MpIdleTask.job
[2010/10/03 13:59:38 | 000,000,408 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/10/03 13:54:19 | 000,000,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Microsoft Security Essentials.lnk
[2010/10/03 13:14:30 | 000,003,662 | —- | C] () – C:\WINDOWS\System32\tmp.reg
[2010/10/03 13:13:49 | 000,025,600 | —- | C] () – C:\WINDOWS\System32\WS2Fix.exe
[2010/10/03 13:13:48 | 000,051,200 | —- | C] () – C:\WINDOWS\System32\dumphive.exe
[2010/10/03 13:13:48 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\swsc.exe
[2010/09/25 11:21:45 | 000,052,516 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/06/26 17:21:02 | 000,015,498 | —- | C] () – C:\WINDOWS\VX3000.ini
[2009/06/10 22:15:43 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/04/28 05:20:33 | 000,000,181 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/04/25 02:30:03 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/04/25 02:28:05 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OgaCheckControl.dll
[2009/04/25 02:26:24 | 000,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2009/04/25 01:48:38 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\drivers\int15.sys
[2009/04/25 01:48:38 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\drivers\int15_64.sys
[2009/04/25 01:41:48 | 000,000,128 | —- | C] () – C:\Documents and Settings\Maria\Local Settings\Application Data\fusioncache.dat
[2008/04/28 17:58:50 | 000,005,827 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2006/08/01 17:00:52 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/08/01 16:38:54 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIBUN4.dll
[2006/08/01 16:36:04 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIMPEG2.dll
[2006/08/01 16:36:04 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIMP3.dll
[2006/08/01 16:36:04 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTIFCD3.dll
[2006/08/01 16:36:04 | 000,001,024 | RH– | C] () – C:\WINDOWS\System32\NTICDMK7.dll
[2006/07/19 09:42:00 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2006/06/20 02:59:24 | 000,013,227 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2006/06/13 10:18:00 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\tifmicon.dll
[2006/05/25 18:18:48 | 000,331,776 | —- | C] () – C:\WINDOWS\System32\ScrollBarLib.dll
[2006/04/12 14:08:36 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\InstallCheck.dll
[2006/03/10 14:15:44 | 000,036,404 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/03/08 17:19:28 | 001,421,824 | —- | C] () – C:\WINDOWS\System32\UIVCL.dll
[2006/03/08 17:11:30 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\APISlice.dll
[2005/12/14 20:59:52 | 000,000,038 | —- | C] () – C:\WINDOWS\Acer.ini
[2005/11/10 11:27:42 | 000,003,218 | —- | C] () – C:\WINDOWS\System32\drivers\WINIO.sys
[2005/03/28 15:45:26 | 000,000,089 | —- | C] () – C:\WINDOWS\ALaunch.ini
[2004/12/17 17:14:44 | 000,013,952 | —- | C] () – C:\WINDOWS\System32\drivers\UBHelper.sys
[2004/08/04 05:00:00 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2001/12/26 15:12:30 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\multiplex_vcd.dll
[2001/09/03 22:46:38 | 000,110,592 | —- | C] () – C:\WINDOWS\System32\Hmpg12.dll
[2001/07/30 15:33:56 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\HMPV2_ENC.dll
[2001/07/23 21:04:36 | 000,118,784 | —- | C] () – C:\WINDOWS\System32\HMPV2_ENC_MMX.dll
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/04/25 12:28:20 | 000,250,048 | RHS- | M] () – C:\ntldr
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/09/25 11:03:48 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2006/08/01 11:54:18 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/08/01 16:37:40 | 000,000,100 | —- | M] () – C:\AUTOEXEC.BAT
[2006/08/01 11:54:18 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2006/08/01 11:54:18 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/08/01 12:03:44 | 000,000,519 | —- | M] () – C:\RHDSetup.log
[2006/08/01 12:11:36 | 000,000,166 | —- | M] () – C:\Arcade.log
[2006/08/01 17:08:14 | 000,000,076 | RHS- | M] () – C:\Preload.aaa
[2010/08/01 20:37:18 | 000,152,088 | —- | M] () – C:\img2-001.raw
[2010/10/03 13:18:40 | 000,001,481 | —- | M] () – C:\rapport.txt
[2010/10/05 08:59:16 | 526,565,376 | -HS- | M] () – C:\hiberfil.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/08/01 11:54:00 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:50:04 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2008/07/06 09:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2005/12/14 20:56:06 | 000,187,392 | —- | M] () – C:\WINDOWS\Acer.scr
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/08/01 11:48:02 | 000,905,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav
[2006/08/01 11:48:02 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/08/01 11:48:02 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/04/25 12:36:48 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/08/01 12:02:32 | 000,000,079 | —- | M] () – C:\Documents and Settings\Maria\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2009/04/25 12:51:24 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Maria\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/06/10 23:10:22 | 097,547,048 | —- | M] (Apple Inc.) – C:\Documents and Settings\Maria\Desktop\iTunesSetup.exe
[2010/10/05 10:04:46 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Maria\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2009/06/26 17:21:02 | 000,013,023 | —- | M] () – C:\WINDOWS\VX3000.src
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2004/08/04 05:00:00 | 000,000,791 | —- | M] () – C:\WINDOWS\addins\fxsext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2009/04/25 12:51:24 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Maria\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2010/10/05 12:23:22 | 000,032,768 | —- | M] () – C:\Documents and Settings\Maria\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2008/04/13 21:12:38 | 000,208,896 | —- | M] (Microsoft Corporation) – C:\WINDOWS\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
[2005/07/10 23:42:28 | 000,002,560 | —- | M] () – C:\WINDOWS\Installer\msistub.exe
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.exe >
[2008/04/13 21:12:28 | 001,695,232 | —- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
[1998/12/25 08:15:38 | 000,345,983 | —- | M] () – C:\WINDOWS\system\RCDsetup.exe
< %USERPROFILE%\Templates\*.tmp >
< %SYSTEMDRIVE%\explorexxx.exe\*.* >
< %Windir%\Installer\*.tmp >
< %systemroot%\System32\*.xco >
< %ProgramFiles%\system32\*.* >
< %systemroot%\System32\windos\*.* >
< %SystemRoot%\system32\sandbox\*.* >
< %SystemRoot%\system32\*.amo >
< %SystemRoot%\system32\Windows Live\*.* >
< %ProgramFiles%\logs\*.* >
< %ProgramFiles%\Bifrost\*.* >
< %SystemRoot%\system32\*.goo >
< %systemroot%\system32\IME\*.* >
< %systemroot%\BackUp\*.* >
< %systemroot%\system32\*.ico >
< %systemroot%\system\*.dat >
< %systemroot%\system\*.exe >
[1998/12/25 08:15:38 | 000,345,983 | —- | M] () – C:\WINDOWS\system\RCDsetup.exe
< %AppData%\Macromedia\Common\*.* >
< %SYSTEMDRIVE%\dir\*.* /s >
< %systemroot%\system32\ras\*.exe >
< %SYSTEMDRIVE%\MFILES\*.* >
< %SYSTEMDRIVE%\mDNSRespon.exe\*.* >
< %systemroot%\system32\services\*.* >
< %systemroot%\Spooler\*.* >
< %ProgramFiles%\system32\*.* >
< %systemroot%\system32\Setup\*.dll /x >
< %systemroot%\system32\*.mine >
< %SYSTEMDRIVE%\cleansweep.exe\*.* >
< %systemroot%\system32\ras\*.dll >
< %systemroot%\system32\ras\*.drv >
< %systemroot%\*.iq >
< %systemroot%\system32\XP\*.* >
< %SYSTEMDRIVE%\Extracted\*.* >
< %systemroot%\system32\windows\*.* >
< %systemroot%\logs\*.* >
< %SYSTEMDRIVE%\Win.Msi\*.* >
< %systemroot%\regedit\*.* >
< %systemroot%\system32\skype\*.* >
< %AppData%\Adobe\dlluplwin25\*.* >
< %UserProfile%\*.dat >
[2010/10/04 16:37:02 | 002,621,440 | -H– | M] () – C:\Documents and Settings\Maria\NTUSER.DAT
< %UserProfile%\*.dll >
< %systemroot%\system32\*.sxo >
< %SYSTEMDRIVE%\Gazma\*.* /s >
< %systemroot%\system32\spynet\*.* >
< %systemroot%\system32\System\*.* >
< %appdata%\Microsoft\Windows\*.* >
< %systemroot%\system32\WinDir\*.* >
< %systemroot%\_\*.* >
< %systemroot%\system32\windows32\*.* >
< %ProgramFiles%\win\*.* >
< %AppData%\Microsoft\CD Burning\*.* >
< %systemroot%\*.cab >
< %systemroot%\K.Backup\*.* >
< %ProgramFiles%\Massenger\*.* >
< %systemroot%\System32\*.doc >
< %systemroot%\Office12\*.* >
< %systemroot%\System32\Rundl32.exe\*.* >
< %ProgramFiles%\yahoo.net\*.* >
< %systemroot%\system32\*.igo >
< %systemroot%\*.rew >
< %systemroot%\System32\spool\DRIVERS\W32X86\3\*.exe >
[2001/11/15 14:02:20 | 000,245,760 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzcfg04.exe
[2001/11/15 14:02:20 | 000,368,640 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzeng04.exe
[2001/11/15 14:02:22 | 000,286,720 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzpre04.exe
[2001/11/15 14:02:24 | 000,356,352 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzstc04.exe
[2001/11/15 14:02:24 | 000,196,608 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztbu04.exe
[2001/11/15 14:02:24 | 000,405,504 | —- | M] (HP) – C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztbx04.exe
< %USERPROFILE%\.COMMgr\*.* >
< %USERPROFILE%\Desktop\*.bat >
< %PROGRAMFILES%\Common Files\Real\visualizations\*.* >
< %PROGRAMFILES%\Internet Explorer\*.Jmp >
< %PROGRAMFILES%\Windows NT\system\*.dll >
< %systemroot%\system32\*.ext >
< %systemroot%\system32\Com\*.cfg >
< %systemroot%\system32\btz\*.* >
< %systemroot%\system32\EMP\*.* >
< %systemroot%\system32\expo\*.* >
< %systemroot%\system32\inet2\*.* >
< %systemroot%\system32\xrem\*.* >
< %ProgramFiles%\Microsoft\*.* >
< %systemroot%\usgwmt\*.* >
< %ProgramFiles%\B\*.* >
< %SYSTEMDRIVE%\lspp\*.* >
< %systemroot%\Kral\*.* >
< %SYSTEMDRIVE%\windowsdvd.exe\*.* >
< %systemroot%\system32\*.ipo >
< %SYSTEMDRIVE%\usxxxxxxxx.exe\*.* >
< %systemroot%\system32\*.mof >
< %systemroot%\*.atm >
< %systemroot%\system32\svhost\*.* >
< %ProgramFiles%\system32\*.* >
< %ProgramFiles%\Docmentt\*.* >
< %systemroot%\Help\*.vbs >
< %ProgramFiles%\Windows WinSxs\*.* /s >
< %ProgramFiles%\Outlook Express\IDT\*.* /s >
< %ProgramFiles%\Microsoft Office\365\*.* /s >
< %ProgramFiles%\Windows Live\*.* >
< %systemroot%\system32\win32\*.* >
< %SYSTEMDRIVE%\RECYCLER\*.* >
< %systemroot%\Fresh1\*.* >
< %ProgramFiles%\Kekj\*.* /s >
< %systemroot%\GDU\*.* >
< %systemroot%\KA\*.* >
< %systemroot%\R\*.* >
< %systemroot%\system32\*.fyo >
< %USERPROFILE%\System\*.* >
< %systemroot%\Source\*.* >
< %systemroot%\system32\ac\*.* >
< %ProgramFiles%\MSDN\*.* >
< %AppData%\AdobeUM\winvcldll54\*.* /s >
< %ProgramFiles%\Internet Explorer\*.ico >
< %systemroot%\system32\*.ojo >
< %systemroot%\system32\d323s\*.* >
< %systemroot%\system32\re\*.* >
< %UserProfile%\Microsoft\*.dll >
< %UserProfile%\Microsoft\*.log >
< %systemroot%\Bios\*.* >
< %ProgramFiles%\Spool\*.* >
< %ProgramFiles%\promp3\*.* >
< %SYSTEMDRIVE%\Driver\*.* /s >
< %SYSTEMDRIVE%\inetserver.exe\*.* >
< %systemroot%\java\trustlib\*.* >
< %ProgramFiles%\Common Files\designer\*.exe >
< %ProgramFiles%\*. >
[2006/08/01 11:48:56 | 000,000,000 | —D | M] – C:\Program Files\Common Files
[2006/08/01 11:52:06 | 000,000,000 | —D | M] – C:\Program Files\Windows NT
[2006/08/01 11:52:06 | 000,000,000 | —D | M] – C:\Program Files\MSN
[2006/08/01 11:52:12 | 000,000,000 | —D | M] – C:\Program Files\MSN Gaming Zone
[2006/08/01 11:52:14 | 000,000,000 | —D | M] – C:\Program Files\Messenger
[2006/08/01 11:52:20 | 000,000,000 | —D | M] – C:\Program Files\Windows Media Player
[2006/08/01 11:52:20 | 000,000,000 | —D | M] – C:\Program Files\Online Services
[2006/08/01 11:52:46 | 000,000,000 | —D | M] – C:\Program Files\ComPlus Applications
[2006/08/01 11:53:00 | 000,000,000 | —D | M] – C:\Program Files\Internet Explorer
[2006/08/01 11:53:00 | 000,000,000 | —D | M] – C:\Program Files\Outlook Express
[2006/08/01 11:53:02 | 000,000,000 | —D | M] – C:\Program Files\NetMeeting
[2006/08/01 11:53:04 | 000,000,000 | —D | M] – C:\Program Files\Movie Maker
[2006/08/01 11:53:22 | 000,000,000 | -H-D | M] – C:\Program Files\WindowsUpdate
[2006/08/01 11:54:26 | 000,000,000 | —D | M] – C:\Program Files\microsoft frontpage
[2006/08/01 11:54:26 | 000,000,000 | —D | M] – C:\Program Files\xerox
[2006/08/01 11:59:54 | 000,000,000 | —D | M] – C:\Program Files\Intel
[2006/08/01 12:02:24 | 000,000,000 | -H-D | M] – C:\Program Files\Uninstall Information
[2006/08/01 12:02:44 | 000,000,000 | -H-D | M] – C:\Program Files\InstallShield Installation Information
[2006/08/01 12:02:44 | 000,000,000 | —D | M] – C:\Program Files\Realtek
[2006/08/01 12:05:40 | 000,000,000 | —D | M] – C:\Program Files\Synaptics
[2006/08/01 12:08:32 | 000,000,000 | —D | M] – C:\Program Files\Acer Inc
[2006/08/01 12:09:56 | 000,000,000 | —D | M] – C:\Program Files\Adobe
[2006/08/01 12:11:02 | 000,000,000 | —D | M] – C:\Program Files\Acer
[2006/08/01 12:11:08 | 000,000,000 | —D | M] – C:\Program Files\CyberLink
[2006/08/01 12:17:14 | 000,000,000 | —D | M] – C:\Program Files\NewTech Infosystems
[2009/04/25 01:46:16 | 000,000,000 | —D | M] – C:\Program Files\Launch Manager
[2009/04/25 01:49:40 | 000,000,000 | —D | M] – C:\Program Files\Yahoo!
[2009/04/25 02:25:40 | 000,000,000 | —D | M] – C:\Program Files\Java
[2009/04/25 02:26:22 | 000,000,000 | —D | M] – C:\Program Files\K-Lite Codec Pack
[2009/04/25 02:28:22 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Office
[2009/04/25 02:28:22 | 000,000,000 | —D | M] – C:\Program Files\Microsoft.NET
[2009/04/25 02:28:48 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Works
[2009/04/25 02:30:36 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox
[2009/04/25 02:31:02 | 000,000,000 | —D | M] – C:\Program Files\Nero
[2009/04/25 02:31:38 | 000,000,000 | —D | M] – C:\Program Files\ESET
[2009/04/25 02:33:28 | 000,000,000 | —D | M] – C:\Program Files\Picasa2
[2009/04/25 02:33:34 | 000,000,000 | —D | M] – C:\Program Files\Google
[2009/04/25 02:34:04 | 000,000,000 | —D | M] – C:\Program Files\QT Lite
[2009/04/25 02:34:50 | 000,000,000 | —D | M] – C:\Program Files\Skype
[2009/04/25 02:34:58 | 000,000,000 | —D | M] – C:\Program Files\Unlocker
[2009/04/25 02:35:16 | 000,000,000 | —D | M] – C:\Program Files\Winamp
[2009/04/25 02:35:32 | 000,000,000 | —D | M] – C:\Program Files\WinRAR
[2009/04/24 23:59:12 | 000,000,000 | —D | M] – C:\Program Files\Windows Live
[2009/04/24 23:59:34 | 000,000,000 | —D | M] – C:\Program Files\Windows Live SkyDrive
[2009/04/25 13:54:24 | 000,000,000 | —D | M] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2009/04/25 14:31:42 | 000,000,000 | —D | M] – C:\Program Files\MSXML 4.0
[2009/04/25 14:39:20 | 000,000,000 | —D | M] – C:\Program Files\Reference Assemblies
[2009/04/25 14:39:28 | 000,000,000 | —D | M] – C:\Program Files\MSBuild
[2009/04/25 15:58:14 | 000,000,000 | —D | M] – C:\Program Files\iTunes
[2009/04/28 05:23:14 | 000,000,000 | —D | M] – C:\Program Files\shARES
[2009/04/28 05:27:52 | 000,000,000 | —D | M] – C:\Program Files\Ares
[2009/08/18 15:43:42 | 000,000,000 | —D | M] – C:\Program Files\Windows Live Safety Center
[2009/08/20 00:00:14 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Windows OneCare Live
[2009/11/24 18:58:42 | 000,000,000 | —D | M] – C:\Program Files\Microsoft
[2009/11/24 19:02:36 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Office Outlook Connector
[2010/06/10 23:19:24 | 000,000,000 | —D | M] – C:\Program Files\Bonjour
[2010/06/10 23:22:08 | 000,000,000 | —D | M] – C:\Program Files\Apple Software Update
[2010/06/10 23:27:20 | 000,000,000 | —D | M] – C:\Program Files\iPod
[2010/07/15 16:05:22 | 000,000,000 | —D | M] – C:\Program Files\MyDefrag v4.3.1
[2010/10/03 13:54:18 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Security Essentials
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-30 00:27:48
< End of report >
OTL Extras logfile created on: 05/10/2010 10:06:18 a.m. - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Maria\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00002C0A | Country: Argentina | Language: ESS | Date Format: dd/MM/yyyy
502,00 Mb Total Physical Memory | 182,00 Mb Available Physical Memory | 36,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 63,00% Paging File free
Paging file location(s): D:\pagefile.sys 1024 1024 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 30,53 Gb Total Space | 11,87 Gb Free Space | 38,89% Space Free | Partition Type: FAT32
Drive D: | 21,44 Gb Total Space | 3,07 Gb Free Space | 14,34% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: VIAJERA
Current User Name: Maria
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Acer\Acer Arcade\PCMService.exe" = C:\Program Files\Acer\Acer Arcade\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program – (CyberLink Corp.)
"C:\Program Files\Ares\Ares.exe" = C:\Program Files\Ares\Ares.exe:*:Enabled:Ares p2p for windows – (Ares Development Group)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02A2EE40-723D-4644-A996-E03BB4688E42}" = Microsoft Antimalware Service ES-ES Language Pack
"{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"{1F2C8256-2773-46C7-9ABA-3E39C24ABB51}" = Acer eSettings Management
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Herramienta de carga de Windows Live
"{211E8730-5681-49ED-BC6A-78C9F88E95F5}" = Adobe Shockwave Player
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{2637C347-9DAD-11D6-9EA2-00055D0CA761}" = Acer Arcade
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2EAF7E61-068E-11DF-953C-005056806466}" = Google Earth
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{375943E2-B268-4AD7-B7A4-0FD90E9C2AC7}" = Skype™ 3.8 Lite
"{405C32CF-9C6F-49B3-9436-3F5FDBE7B3CE}" = Microsoft .NET Framework 2.0 Language Pack - ESN
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4AD13F68-CADA-4C6B-9759-C33753F89908}" = Acer eDataSecurity Management
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{58E5844B-7CE2-413D-83D1-99294BF6C74F}" = Acer ePower Management
"{5ECB3A3C-980B-4D12-9724-25DCB07A1F47}" = iTunes
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A28AB0B-22B1-494C-AF61-B386EA1736C0}" = LightScribe 1.4.97.1
"{7057702F-6D71-4F30-8000-9E72BC771887}" = Acer ePerformance Management
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-1437-443D-B06E-79A00FE45110}" = Adobe Stock Photos 1.0
"{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = TIPCI
"{88F560AD-9B38-4273-8450-0C7485830A4B}" = Winamp AudioPlayer
"{8A253629-0511-4854-8B4E-46E57E66005C}" = Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8FFC924C-ED06-44CB-8867-3CA778ECE903}" = Adobe Help Center 2.0
"{90110C0A-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{95120000-0122-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9DE1BE03-AFE2-4CDB-BFEB-D06D736CD01A}" = Apple Mobile Device Support
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AB6097D9-D722-4987-BD9E-A076E2848EE2}" = Acer Empowering Technology
"{AC76BA86-7AD7-1034-7B44-A91000000001}" = Adobe Reader 9.1 - Español
"{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}" = Adobe Bridge 1.0
"{B06B842F-2450-494F-BBDE-217CDC151A37}" = NTI Backup NOW! 4.5
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{BF839132-BD43-4056-ACBF-4377F4A88E2A}" = Acer ePresentation Management
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D458BBDC-0363-42E0-8FF9-4736E3CB3CA2}" = Acer Screensaver
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"{EF98A02A-1748-4762-9B7D-5ED1600520D5}" = Microsoft Security Essentials
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"Ares" = Ares 2.1.1
"Eset NOD32 v3.0.642 FiX1.2 by TemDono_is1" = NOD32 v3.0.642 FiX1.2 by TemDono (31 days remaining forever up
"ESET Online Scanner" = ESET Online Scanner v3
"GridVista" = Acer GridVista
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{1577A05B-EE62-4BBC-9DB7-FE748FA44EC2}" = NTI CD & DVD-Maker
"InstallShield_{4AD13F68-CADA-4C6B-9759-C33753F89908}" = Acer eDataSecurity Management 2.0.3077
"InstallShield_{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"KLiteCodecPack_is1" = K-Lite Codec Pack 3.9.0 Standard
"LManager" = Launch Manager
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0 Language Pack - ESN" = Paquete de idioma de Microsoft .NET Framework 2.0 - ESN
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"MyDefrag v4.3.1_is1" = MyDefrag v4.3.1
"Nero8WinuE_is1" = Nero [removed]
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Picasa2" = Picasa 2
"qt7lite_is1" = QT Lite 2.5.1
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Unlocker" = Unlocker 1.8.7
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = Compresor WinRAR
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 04/10/2010 06:26:51 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 04/10/2010 06:26:51 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 28844
Error - 04/10/2010 06:26:51 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 28844
Error - 04/10/2010 06:26:53 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 04/10/2010 06:26:53 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 30907
Error - 04/10/2010 06:26:53 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 30907
Error - 04/10/2010 06:26:55 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 04/10/2010 06:26:55 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 32891
Error - 04/10/2010 06:26:55 a.m. | Computer Name = VIAJERA | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 32891
Error - 04/10/2010 12:19:17 p.m. | Computer Name = VIAJERA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
[ System Events ]
Error - 03/10/2010 03:11:08 p.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 03/10/2010 03:13:00 p.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Eset Nod32 Boot service
to connect.
Error - 03/10/2010 03:13:00 p.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7000
Description = The Eset Nod32 Boot service failed to start due to the following error:
%%1053
Error - 03/10/2010 03:36:31 p.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Eset Nod32 Boot service
to connect.
Error - 03/10/2010 03:36:31 p.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7000
Description = The Eset Nod32 Boot service failed to start due to the following error:
%%1053
Error - 04/10/2010 10:36:20 a.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.
Error - 04/10/2010 11:40:43 a.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Eset Nod32 Boot service
to connect.
Error - 04/10/2010 11:40:43 a.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7000
Description = The Eset Nod32 Boot service failed to start due to the following error:
%%1053
Error - 05/10/2010 07:59:26 a.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Eset Nod32 Boot service
to connect.
Error - 05/10/2010 07:59:26 a.m. | Computer Name = VIAJERA | Source = Service Control Manager | ID = 7000
Description = The Eset Nod32 Boot service failed to start due to the following error:
%%1053
< End of report >
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Malwarebytes' Anti-Malware 1.46Please download Malwarebytes' Anti-Malware to your desktop.
Also please describe how your computer behaves at the moment.
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
www.malwarebytes.org
Database version: 4764
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
07/10/2010 02:52:57 a.m.
mbam-log-2010-10-07 (02-52-57).txt
Scan type: Quick scan
Objects scanned: 163091
Time elapsed: 20 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Many thanks!
Before this, I pasted last report, showing no infections…, it s weird…
After unsuccessfully trying 3 times I was absolutely not at all able to run GMER on ACER laptop VIAJERA. System froze each time.
Having two computers at home, I m not aware which one has been the source for the hacker to steal my passwords…
Just in case it would be useful, I run Malwarebytes' Anti-Malware 1.46 in both computers, DELL and ACER with same result: no infection.
After procedure, both seam quite the same as usual: extremely slow.
Im very grateful and remain ready to try whatever necessary in order to turn both as safe and fast as possible.
Please tell me what to do next…
Thanks a lot,
Maria
Malwarebytes' Anti-Malware 1.46Please download Malwarebytes' Anti-Malware to your desktop.
Also please describe how your computer behaves at the moment.
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, and click Remove Selected.
- When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
www.malwarebytes.org
Database version: 4764
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
07/10/2010 02:52:57 a.m.
mbam-log-2010-10-07 (02-52-57).txt
Scan type: Quick scan
Objects scanned: 163091
Time elapsed: 20 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Many thanks!
Before this, I pasted last report, showing no infections…, it s weird…
After unsuccessfully trying 3 times I was absolutely not at all able to run GMER on ACER laptop VIAJERA. System froze each time.
Having two computers at home, I m not aware which one has been the source for the hacker to steal my passwords…
Just in case it would be useful, I run Malwarebytes' Anti-Malware 1.46 in both computers, DELL and ACER with same result: no infection.
After procedure, both seam quite the same as usual: extremely slow.
Im very grateful and remain ready to try whatever necessary in order to turn both as safe and fast as possible.
Please tell me what to do next…
Thanks a lot,
Maria
Nexte, I m also pasting log from my Dell's scan
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4764
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
07/10/2010 02:53:38 a.m.
mbam-log-2010-10-07 (02-53-38).txt
Scan type: Quick scan
Objects scanned: 151118
Time elapsed: 18 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Thanks for the logs. I notice that you are running a cracked version of ESET Antivirus. This is a very bad idea because you cannot trust the program to protect you properly. Please go to Add/Remove programs and remove ESET NOD32.
Let's see if we can run GMER in safe mode.
To boot into safe mode follow these steps:
- Turn on or restart your computer
- As the computer is booting, press and hold your F8 Key
- This should bring up the Windows Advanced Options Menu
- Use your arrow keys to move to Safe Mode and press your Enter Key
Post the log when the scan finishes.
If you need help please start a new thread.
New members follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI