Thank you again.
Here the logs in order: Combofix, MB and ESET.
ComboFix 11-06-04.02 - pita 04/06/2011 20:36:54.3.1 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2015.1690 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\pita\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
file zipped: c:\windows\system32\drivers\zefnkzgi.sys
file zipped: c:\windows\system32\msnat711f.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\common.data
c:\documents and settings\pita\Application Data\xculptxmsunsrab1vlrpfhtok3szgflf2
c:\windows\system32\drivers\zefnkzgi.sys
c:\windows\system32\msnat711f.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_BLACKBOX
——-\Legacy_MSUNATSERVICE
——-\Legacy_ZEFNKZGI
——-\Service_BlackBox
——-\Service_MSUNatService
——-\Service_zefnkzgi
.
.
((((((((((((((((((((((((( Files Created from 2011-05-05 to 2011-06-05 )))))))))))))))))))))))))))))))
.
.
2011-06-05 01:24 . 2011-06-05 01:24 ——– d—–w- c:\documents and settings\LocalService\Application Data\Avira
2011-05-31 19:24 . 2011-05-31 19:24 ——– d—–w- c:\documents and settings\pita\Application Data\Avira
2011-05-28 03:52 . 2011-04-01 23:07 137656 —-a-w- c:\windows\system32\drivers\avipbb.sys
2011-05-28 03:52 . 2010-06-17 21:27 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2011-05-28 03:52 . 2009-02-13 18:17 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2011-05-28 03:52 . 2011-05-28 03:52 ——– d—–w- c:\program files\Avira
2011-05-28 03:52 . 2011-05-28 03:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2011-05-28 03:36 . 2011-05-28 03:36 ——– d—–w- c:\windows\system32\wbem\Repository
2011-05-28 03:36 . 2011-05-28 03:36 ——– d—–w- c:\program files\Common Files\xing shared
2011-05-18 17:49 . 2011-05-18 17:49 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-12 07:10 . 2011-05-12 07:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype Extras
2011-05-12 07:10 . 2011-05-12 07:10 ——– d—–w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-01 23:07 . 2009-10-04 18:01 61960 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2011-03-07 05:33 . 2004-06-07 15:24 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-14 16:43 . 2011-06-03 05:27 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 —-a-w- c:\documents and settings\pita\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 —-a-w- c:\documents and settings\pita\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 —-a-w- c:\documents and settings\pita\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 —-a-w- c:\documents and settings\pita\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-31 68856]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"="c:\windows\System32\\NeroCheck.exe" [2001-07-09 155648]
"PCTVOICE"="pctspk.exe" [2003-09-24 180224]
"SMSERIAL"="sm56hlpr.exe" [2003-10-07 548864]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-01 202256]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-02-22 72192]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-16 932288]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-03-28 281768]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\pita\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\pita\Application Data\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Recorte de pantalla e Inicio r pido de OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Shortcut to Adobe Gamma Loader.lnk - c:\qoobox\Quarantine\C\WINDOWS\system32\Adobe Gamma Loader.exe.vir [N/A]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2011-4-15 610120]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Documents and Settings\\pita\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [25/09/2009 0:04 721904]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [27/05/2011 21:52 136360]
S2 gupdate;Servicio Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [13/10/2009 21:14 133104]
S3 gupdatem;Servicio de Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [13/10/2009 21:14 133104]
S3 Normandy;Normandy SR2; [x]
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-14 03:14]
.
2011-06-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-14 03:14]
.
2011-06-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-2139871995-839522115-1003Core.job
- c:\documents and settings\pita\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-03 04:59]
.
2011-06-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-2139871995-839522115-1003UA.job
- c:\documents and settings\pita\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-03 04:59]
.
2011-06-05 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-861567501-2139871995-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 04:09]
.
2011-06-03 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-861567501-2139871995-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 04:09]
.
.
——- Supplementary Scan ——-
.
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportar a Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\pita\Application Data\Mozilla\Firefox\Profiles\i91sg5lh.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?ref=hp
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-06-04 21:08
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(536)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
- - - - - - - > 'explorer.exe'(2324)
c:\windows\system32\WININET.dll
c:\documents and settings\pita\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wscntfy.exe
c:\windows\sm56hlpr.exe
c:\progra~1\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2011-06-04 21:15:43 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-05 03:15
ComboFix2.txt 2011-06-04 20:03
.
Pre-Run: 15,980,195,840 bytes free
Post-Run: 15,899,115,520 bytes free
.
- - End Of File - - 743D4B2910F982E655659EFFBC3C0CFA
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Versión de la Base de Datos: 6773
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
04/06/2011 21:25:53
mbam-log-2011-06-04 (21-25-53).txt
Tipos de Análisis: Análisis Rápido
Objetos examinados: 152113
Tiempo transcurrido: 4 minuto(s), 49 segundo(s)
Procesos en Memoria Infectados: 0
Módulos de Memoria Infectados: 0
Claves del Registro Infectadas: 0
Valores del Registro Infectados: 0
Elementos de Datos del Registro Infectados: 0
Carpetas Infectadas: 0
Archivos Infectados: 0
Procesos en Memoria Infectados:
(No se han detectado elementos maliciosos)
Módulos de Memoria Infectados:
(No se han detectado elementos maliciosos)
Claves del Registro Infectadas:
(No se han detectado elementos maliciosos)
Valores del Registro Infectados:
(No se han detectado elementos maliciosos)
Elementos de Datos del Registro Infectados:
(No se han detectado elementos maliciosos)
Carpetas Infectadas:
(No se han detectado elementos maliciosos)
Archivos Infectados:
(No se han detectado elementos maliciosos)
C:\Documents and Settings\pita\My Documents\My Pictures\pc vieja-varias rafa teatro mias- prime foto\autorun.inf Win32/Peerfrag.BA worm
C:\Qoobox\Quarantine\C\win-update\win-update.exe.vir a variant of Win32/Injector.GTT trojan
C:\System Volume Information\_restore{2812C836-3D93-42D3-A8BF-60A7B21E6271}\RP1\A0001121.exe a variant of Win32/Injector.GTT trojan
D:\INSTALADORES\skipcreen\SkipScreen-Setup.exe Win32/Toolbar.Zugo application
D:\INSTALADORES\vegas pro 8.0\S_V80a179Esp.part1.rar a variant of Win32/Keygen.AR application