This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My HijackThis Slow PC [Closed]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:12:21, on 08/12/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Archivos de programa\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Archivos de programa\Bonjour\mDNSResponder.exe
C:\Archivos de programa\Archivos comunes\Digital Rapids\hypersonic-service.exe
C:\Archivos de programa\Archivos comunes\Digital Rapids\rmi-registry-service.exe
C:\Archivos de programa\Archivos comunes\Digital Rapids\jre1.6.0_06\bin\java.exe
C:\Archivos de programa\Archivos comunes\Digital Rapids\jre1.6.0_06\bin\java.exe
C:\Archivos de programa\Java\jre6\bin\jqs.exe
C:\Archivos de programa\LogMeIn\x86\LMIGuardianSvc.exe
C:\Archivos de programa\LogMeIn\x86\RaMaint.exe
C:\Archivos de programa\LogMeIn\x86\LogMeIn.exe
C:\Archivos de programa\Mediafour\MacDrive 8\MacDrive8Service.exe
C:\Archivos de programa\NDAS\System\ndassvc.exe
C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Archivos de programa\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\UMonit.exe
C:\Archivos de programa\LogMeIn\x86\LogMeInSystray.exe
C:\Archivos de programa\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Archivos de programa\Mediafour\MacDrive 8\MacDrive.exe
C:\Archivos de programa\Archivos comunes\Nokia\MPlatform\NokiaMServer.exe
C:\Archivos de programa\DivX\DivX Update\DivXUpdate.exe
C:\Archivos de programa\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\algsrvs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE
C:\Archivos de programa\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
C:\Archivos de programa\FinePixViewerS\QuickDCF2.exe
C:\Archivos de programa\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Archivos de programa\iPod\bin\iPodService.exe
C:\Archivos de programa\PC Connectivity Solution\ServiceLayer.exe
C:\Archivos de programa\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Archivos de programa\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Archivos de programa\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Archivos de programa\PC Connectivity Solution\Transports\NclMSBTSrv.exe
C:\Archivos de programa\Lavasoft\Ad-Aware\AAWTray.exe
C:\Archivos de programa\Mozilla Firefox\firefox.exe
C:\Archivos de programa\Mozilla Firefox\plugin-container.exe
C:\Archivos de programa\Mozilla Firefox\plugin-container.exe
C:\Archivos de programa\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Mario\Mis documentos\Descargas\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.es/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
R3 - URLSearchHook: myBabylon EnglishBB Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Archivos de programa\myBabylon_English\prxtbmyB0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Archivos de programa\ConduitEngine\prxConduitEngine.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Archivos de programa\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Archivos de programa\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
O2 - BHO: myBabylon EnglishBB - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Archivos de programa\myBabylon_English\prxtbmyB0.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Archivos de programa\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Archivos de programa\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PDF de Adobe - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: myBabylon EnglishBB Toolbar - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - C:\Archivos de programa\myBabylon_English\prxtbmyB0.dll
O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Archivos de programa\ConduitEngine\prxConduitEngine.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Archivos de programa\Archivos comunes\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Archivos de programa\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Archivos de programa\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Archivos de programa\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Archivos de programa\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\jre6\bin\jusched.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Archivos de programa\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Archivos de programa\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [UMonit] C:\WINDOWS\system32\UMonit.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Archivos de programa\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MacDrive 8 application] "C:\Archivos de programa\Mediafour\MacDrive 8\MacDrive.exe"
O4 - HKLM\..\Run: [Getting started with MacDrive 8] "C:\Archivos de programa\Mediafour\MacDrive 8\MDGetStarted.exe" /auto
O4 - HKLM\..\Run: [IMJPMIG8.2] msime82.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [NokiaMServer] C:\Archivos de programa\Archivos comunes\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [Google Updater] "C:\Archivos de programa\Google\Google Updater\GoogleUpdater.exe" -check_deprecation
O4 - HKLM\..\Run: [APSDaemon] "C:\Archivos de programa\Archivos comunes\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Archivos de programa\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [iTunesHelper] "C:\Archivos de programa\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Mario\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [NokiaOviSuite2] C:\Archivos de programa\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe -tray
O4 - HKCU\..\Run: [Samsung_AppInst] J:\SamsungSoftware\AppInst.exe
O4 - HKCU\..\Run: [MsServer] msfun80.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Herramienta de búsqueda de soportes de PMB.lnk = C:\Archivos de programa\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Convertir a PDF de Adobe - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir a PDF existente - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir destino de vínculo a PDF existente - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir destino de vínculo en archivo PDF de Adobe - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir selección a archivo PDF existente - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir selección a PDF de Adobe - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir vínculos seleccionados a PDF de Adobe - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir vínculos seleccionados a PDF existente - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Crear un favorito móvil - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Archivos de programa\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Archivos de programa\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Crear un favorito móvil… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Archivos de programa\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {2D0CBE69-DAFC-11D3-96D2-0020182E2E27} - http://194.140.3.43/comun/download/wcf-pc-25_0_0_2.cab
O16 - DPF: {983A9C21-8207-4B58-BBB8-0EBC3D7C5505} (Domino Web Access 8 Control) - http://194.224.244.52/dwa8W.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O22 - SharedTaskScheduler: Precargador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Demonio de caché de las categorías de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Archivos de programa\Archivos comunes\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Servicio Bonjour (Bonjour Service) - Apple Inc. - C:\Archivos de programa\Bonjour\mDNSResponder.exe
O23 - Service: Servicio del administrador de discos lógicos (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: DRC Hypersonic (DRCHypersonic) - Unknown owner - C:\Archivos de programa\Archivos comunes\Digital Rapids\hypersonic-service.exe
O23 - Service: DRC RMI Registry (DRCRMIRegistry) - Unknown owner - C:\Archivos de programa\Archivos comunes\Digital Rapids\rmi-registry-service.exe
O23 - Service: DRC Stream Server (DRCStreamServer) - Unknown owner - C:\Archivos de programa\Digital Rapids\Stream\stream-server-service.exe
O23 - Service: Registro de sucesos (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - Unknown owner - C:\Archivos de programa\MAGIX\Common\Database\bin\fbserver.exe (file missing)
O23 - Service: Servicio Google Update (gupdate) (gupdate) - Unknown owner - C:\Archivos de programa\Google\Update\GoogleUpdate.exe
O23 - Service: Servicio de Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Archivos de programa\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Servicio COM de grabación de CD de IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Servicio del iPod (iPod Service) - Apple Inc. - C:\Archivos de programa\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Archivos de programa\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Archivos de programa\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Archivos de programa\LogMeIn\x86\LMIGuardianSvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Archivos de programa\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Archivos de programa\LogMeIn\x86\LogMeIn.exe
O23 - Service: MacDrive 8 service (MacDrive8Service) - Mediafour Corporation - C:\Archivos de programa\Mediafour\MacDrive 8\MacDrive8Service.exe
O23 - Service: Escritorio remoto compartido de NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: NDAS Service (ndassvc) - XIMETA, Inc. - C:\Archivos de programa\NDAS\System\ndassvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Archivos de programa\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Administrador de sesión de Ayuda de escritorio remoto (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Tarjeta inteligente (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: ServiceLayer - Nokia - C:\Archivos de programa\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Registros y alertas de rendimiento (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Instantáneas de volumen (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Adaptador de rendimiento de WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe

–
End of file - 17107 bytes
:welcome:

Looks like you have a worm on your system, you got this by inserting a removable drive that was infected.


Open HJT to do a System Scan Only, put a checkmark by these entries and click on Fix Checked


O4 - HKLM\..\Run: [IMJPMIG8.2] msime82.exe
O4 - HKCU\..\Run: [MsServer] msfun80.exe



  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.


Then boot to Safemode

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode


Delete these files by right clicking on them and select delete

C:\WINDOWS\system32\algsrvs.exe
C:\WINDOWS\system32\msime82.exe
C:\WINDOWS\system32\msfun80.exe



Reboot your computer and run these programs and post the logs please


Please download Flash_Disinfector.exe by sUBs and save it to your desktop:

  • Double-click Flash_Disinfector.exe to run it.
  • Follow any prompts that may appear.
  • Wait until the program has finished scanning, then please exit the program.
The tool may ask you to insert your flash drive, or other removable drives. Please do so and allow the tool to clean it up as well.


Please restart your computer.








Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)





Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
Thank you very much. My dds . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20 Run by [removed] at 2:14:42 on 2011-12-16 Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.2047.1438 [GMT 1:00] . AV: Lavasoft Ad-Watch Live! Antivirus *Disabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Archivos de programa\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Archivos de programa\Bonjour\mDNSResponder.exe C:\Archivos de programa\Archivos comunes\Digital Rapids\hypersonic-service.exe C:\Archivos de programa\Archivos comunes\Digital Rapids\rmi-registry-service.exe C:\Archivos de programa\Archivos comunes\Digital Rapids\jre1.6.0_06\bin\java.exe C:\Archivos de programa\Archivos comunes\Digital Rapids\jre1.6.0_06\bin\java.exe C:\Archivos de programa\Java\jre6\bin\jqs.exe C:\Archivos de programa\LogMeIn\x86\LMIGuardianSvc.exe C:\Archivos de programa\LogMeIn\x86\RaMaint.exe C:\Archivos de programa\LogMeIn\x86\LogMeIn.exe C:\Archivos de programa\Mediafour\MacDrive 8\MacDrive8Service.exe C:\Archivos de programa\NDAS\System\ndassvc.exe C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe C:\Archivos de programa\ScanSoft\PaperPort\pptd40nt.exe C:\Archivos de programa\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\WINDOWS\system32\UMonit.exe C:\Archivos de programa\LogMeIn\x86\LogMeInSystray.exe C:\WINDOWS\SOUNDMAN.EXE C:\Archivos de programa\Mediafour\MacDrive 8\MacDrive.exe C:\Archivos de programa\Archivos comunes\Nokia\MPlatform\NokiaMServer.exe C:\Archivos de programa\DivX\DivX Update\DivXUpdate.exe C:\Archivos de programa\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE C:\Archivos de programa\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe C:\Archivos de programa\FinePixViewerS\QuickDCF2.exe C:\Archivos de programa\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe C:\Archivos de programa\iPod\bin\iPodService.exe C:\Archivos de programa\PC Connectivity Solution\ServiceLayer.exe C:\Archivos de programa\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Archivos de programa\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Archivos de programa\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\WINDOWS\system32\wuauclt.exe C:\Archivos de programa\PC Connectivity Solution\Transports\NclMSBTSrv.exe C:\WINDOWS\explorer.exe C:\WINDOWS\explorer.exe C:\Archivos de programa\Lavasoft\Ad-Aware\AAWTray.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.es/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: myBabylon EnglishBB Toolbar: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\archivos de programa\mybabylon_english\prxtbmyB0.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\archivos de programa\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - c:\archivos de programa\conduitengine\prxConduitEngine.dll BHO: DivX Plus Web Player HTML5 : {326e768d-4182-46fd-9c16-1449a49795f4} - c:\archivos de programa\divx\divx plus web player\ie\divxhtml5\DivXHTML5.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\archivos de programa\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\archivos de programa\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\archivos de programa\google\googletoolbarnotifier\5.3.4501.1418\swg.dll BHO: myBabylon EnglishBB Toolbar: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\archivos de programa\mybabylon_english\prxtbmyB0.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\archivos de programa\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\archivos de programa\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: PDF de Adobe: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\archivos de programa\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll TB: myBabylon EnglishBB Toolbar: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - c:\archivos de programa\mybabylon_english\prxtbmyB0.dll TB: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - c:\archivos de programa\conduitengine\prxConduitEngine.dll TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\archivos de programa\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [H/PC Connection Agent] "c:\archivos de programa\microsoft activesync\WCESCOMM.EXE" uRun: [Google Update] "c:\documents and settings\mario\configuración local\datos de programa\google\update\GoogleUpdate.exe" /c uRun: [NokiaOviSuite2] c:\archivos de programa\nokia\nokia ovi suite\NokiaOviSuite.exe -tray uRun: [Samsung_AppInst] j:\samsungsoftware\AppInst.exe uRun: [] uRun: [MsServer] msfun80.exe mRun: [ATIPTA] "c:\archivos de programa\ati technologies\ati control panel\atiptaxx.exe" mRun: [Acrobat Assistant 7.0] "c:\archivos de programa\adobe\acrobat 7.0\distillr\Acrotray.exe" mRun: [SSBkgdUpdate] "c:\archivos de programa\archivos comunes\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [PaperPort PTD] c:\archivos de programa\scansoft\paperport\pptd40nt.exe mRun: [IndexSearch] c:\archivos de programa\scansoft\paperport\IndexSearch.exe mRun: [BrMfcWnd] c:\archivos de programa\brother\brmfcmon\BrMfcWnd.exe /AUTORUN mRun: [ControlCenter3] c:\archivos de programa\brother\controlcenter3\brctrcen.exe /autorun mRun: [SunJavaUpdateSched] c:\archivos de programa\java\jre6\bin\jusched.exe mRun: [PRONoMgr.exe] c:\archivos de programa\intel\ncs\proset\PRONoMgr.exe mRun: [StartCCC] "c:\archivos de programa\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [UMonit] c:\windows\system32\UMonit.exe mRun: [LogMeIn GUI] "c:\archivos de programa\logmein\x86\LogMeInSystray.exe" mRun: [SoundMan] SOUNDMAN.EXE mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [MacDrive 8 application] "c:\archivos de programa\mediafour\macdrive 8\MacDrive.exe" mRun: [Getting started with MacDrive 8] "c:\archivos de programa\mediafour\macdrive 8\MDGetStarted.exe" /auto mRun: [AppleSyncNotifier] c:\archivos de programa\archivos comunes\apple\mobile device support\AppleSyncNotifier.exe mRun: [NokiaMServer] c:\archivos de programa\archivos comunes\nokia\mplatform\NokiaMServer /watchfiles startup mRun: [Google Updater] "c:\archivos de programa\google\google updater\GoogleUpdater.exe" -check_deprecation mRun: [APSDaemon] "c:\archivos de programa\archivos comunes\apple\apple application support\APSDaemon.exe" mRun: [DivXUpdate] "c:\archivos de programa\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [iTunesHelper] "c:\archivos de programa\itunes\iTunesHelper.exe" mRun: [QuickTime Task] "c:\archivos de programa\quicktime\QTTask.exe" -atboottime mRun: [IMJPMIG8.2] msime82.exe dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\mario\menini~1\progra~1\inicio\herram~1.lnk - c:\archivos de programa\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe StartupFolder: c:\docume~1\alluse~1\menini~1\progra~1\inicio\exifla~1.lnk - c:\archivos de programa\finepixviewers\QuickDCF2.exe StartupFolder: c:\docume~1\alluse~1\menini~1\progra~1\inicio\micros~1.lnk - c:\archivos de programa\microsoft office\office10\OSA.EXE IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Convertir a PDF de Adobe - c:\archivos de programa\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convertir a PDF existente - c:\archivos de programa\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convertir destino de vínculo a PDF existente - c:\archivos de programa\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convertir destino de vínculo en archivo PDF de Adobe - c:\archivos de programa\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convertir selección a archivo PDF existente - c:\archivos de programa\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convertir selección a PDF de Adobe - c:\archivos de programa\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convertir vínculos seleccionados a PDF de Adobe - c:\archivos de programa\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convertir vínculos seleccionados a PDF existente - c:\archivos de programa\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: E&xportar a Microsoft Excel - c:\archiv~1\micros~2\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\archivos de programa\messenger\msmsgs.exe IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\archivos de programa\microsoft activesync\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\archivos de programa\microsoft activesync\INetRepl.dll IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\archivos de programa\skype\toolbars\internet explorer\skypeieplugin.dll DPF: {2D0CBE69-DAFC-11D3-96D2-0020182E2E27} - hxxp://194.140.3.43/comun/download/wcf-pc-25_0_0_2.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {983A9C21-8207-4B58-BBB8-0EBC3D7C5505} - hxxp://194.224.244.52/dwa8W.cab DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{D3211E6A-1AE7-44E6-81E7-83BAB6F90D77} : DhcpNameServer = [removed] [removed] Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\archivos de programa\archivos comunes\microsoft shared\web folders\PKMCDO.DLL Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - c:\archivos de programa\microsoft activesync\aatp.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\archivos de programa\skype\toolbars\internet explorer\skypeieplugin.dll WinCE Filter: image/bmp - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\archivos de programa\microsoft activesync\CENetFlt.dll WinCE Filter: image/gif - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\archivos de programa\microsoft activesync\CENetFlt.dll WinCE Filter: image/jpeg - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\archivos de programa\microsoft activesync\CENetFlt.dll WinCE Filter: image/xbm - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\archivos de programa\microsoft activesync\CENetFlt.dll WinCE Filter: text/asp - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\archivos de programa\microsoft activesync\CENetFlt.dll WinCE Filter: text/html - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\archivos de programa\microsoft activesync\CENetFlt.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: LMIinit - LMIinit.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\mario\datos de programa\mozilla\firefox\profiles\12tcnlfq.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=14542 FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.es/search?q= FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties FF - component: c:\archivos de programa\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll FF - component: c:\archivos de programa\nokia\nokia ovi suite\connectors\bookmarks connector\firefoxextension\components\FirefoxExtension.dll FF - component: c:\documents and settings\mario\datos de programa\mozilla\firefox\profiles\12tcnlfq.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\components\FFExternalAlert.dll FF - component: c:\documents and settings\mario\datos de programa\mozilla\firefox\profiles\12tcnlfq.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\components\RadioWMPCore.dll FF - plugin: c:\archivos de programa\divx\divx ovs helper\npovshelper.dll FF - plugin: c:\archivos de programa\divx\divx plus web player\npdivx32.dll FF - plugin: c:\archivos de programa\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\archivos de programa\google\google updater\2.4.2432.1652\npCIDetect14.dll FF - plugin: c:\archivos de programa\google\picasa3\npPicasa3.dll FF - plugin: c:\archivos de programa\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\archivos de programa\google\update\1.2.183.17\npGoogleOneClick8.dll FF - plugin: c:\archivos de programa\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\archivos de programa\google\update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\archivos de programa\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\archivos de programa\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\archivos de programa\google\update\1.3.21.53\npGoogleUpdate3.dll FF - plugin: c:\archivos de programa\google\update\1.3.21.57\npGoogleUpdate3.dll FF - plugin: c:\archivos de programa\google\update\1.3.21.65\npGoogleUpdate3.dll FF - plugin: c:\archivos de programa\google\update\1.3.21.69\npGoogleUpdate3.dll FF - plugin: c:\archivos de programa\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\archivos de programa\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\archivos de programa\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\documents and settings\mario\configuraciã³n local\datos de programa\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\documents and settings\mario\datos de programa\facebook\npfbplugin_1_0_3.dll . ============= SERVICES / DRIVERS =============== . R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-11-13 64288] R0 lfsfilt;Lean File Sharing;c:\windows\system32\drivers\lfsfilt.sys [2008-12-8 140160] R0 lpx;LPX Protocol;c:\windows\system32\drivers\lpx.sys [2006-3-20 44288] R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [2009-9-28 259176] R0 MDPMGRNT;MacDrive partition driver;c:\windows\system32\drivers\MDPMGRNT.SYS [2009-7-31 27488] R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [2007-8-16 19200] R2 BT848;AVerMedia, AVerTV WDM Video Capture;c:\windows\system32\drivers\BT848.sys [2009-11-30 261696] R2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;c:\windows\system32\drivers\bttuner.sys [2009-11-30 22016] R2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;c:\windows\system32\drivers\btxbar.sys [2009-12-1 13312] R2 DRCHypersonic;DRC Hypersonic;c:\archivos de programa\archivos comunes\digital rapids\hypersonic-service.exe [2009-1-20 135168] R2 DRCRMIRegistry;DRC RMI Registry;c:\archivos de programa\archivos comunes\digital rapids\rmi-registry-service.exe [2009-1-20 135168] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\archivos de programa\lavasoft\ad-aware\AAWService.exe [2009-9-24 1184912] R2 LMIGuardianSvc;LMIGuardianSvc;c:\archivos de programa\logmein\x86\LMIGuardianSvc.exe [2010-9-29 374152] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\archivos de programa\logmein\x86\rainfo.sys [2008-8-11 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2010-4-26 47640] R2 MacDrive8Service;MacDrive 8 service;c:\archivos de programa\mediafour\macdrive 8\MacDrive8Service.exe [2009-9-23 150528] R2 StarWindServiceAE;StarWind AE Service;c:\archivos de programa\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968] R3 ndasbus;NDAS Bus Driver;c:\windows\system32\drivers\ndasbus.sys [2006-3-20 59136] R3 RSUSBCCID;Realtek Smartcard Reader Driver;c:\windows\system32\drivers\RtsUCcid.sys [2010-11-9 44032] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Servicio Google Update (gupdate);c:\archivos de programa\google\update\GoogleUpdate.exe [2009-9-17 133104] S3 AVPsys;AVPsys;\??\c:\windows\system32\drivers\cdaudio.sys –> c:\windows\system32\drivers\cdaudio.sys [?] S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [2010-4-26 223232] S3 CTL511Plus;Video Blaster WebCam 3/WebCam Plus (WDM);c:\windows\system32\drivers\webc3vid.sys [2000-9-14 159867] S3 DRCStreamServer;DRC Stream Server;c:\archivos de programa\digital rapids\stream\stream-server-service.exe [2009-1-20 135168] S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\archivos de programa\magix\common\database\bin\fbserver.exe –> c:\archivos de programa\magix\common\database\bin\fbserver.exe [?] S3 gupdatem;Servicio de Google Update (gupdatem);c:\archivos de programa\google\update\GoogleUpdate.exe [2009-9-17 133104] S3 ndasscsi;NDAS SCSI Miniport Driver;c:\windows\system32\drivers\ndasscsi.sys [2006-3-20 115584] S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2011-7-21 137600] S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2011-7-21 8576] S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [2007-12-17 11776] S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [2007-10-12 99200] S3 NWVSCR;Novatel Wireless USB SmartCardReader Driver;c:\windows\system32\drivers\NWVSCR.sys [2007-9-19 24448] S3 RtsUIr;Realtek IR Driver;c:\windows\system32\drivers\RtsUIr.sys [2010-11-9 17536] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 LMIRfsClientNP;LMIRfsClientNP; [x] . =============== Created Last 30 ================ . 2011-12-16 00:40:35 ——– d–h–w- c:\windows\PIF 2011-12-03 16:51:49 ——– d—–w- c:\archivos de programa\iPod 2011-12-03 16:51:44 ——– d—–w- c:\archivos de programa\iTunes 2011-11-19 20:57:51 ——– d—–w- c:\documents and settings\mario\datos de programa\DDMSettings . ==================== Find3M ==================== . 2011-12-16 00:42:38 0 —-a-w- c:\windows\system32\algsrvs.exe 2011-11-17 17:49:32 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-24 13:29:02 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2011-10-24 13:29:02 69632 —-a-w- c:\windows\system32\QuickTime.qts 2011-10-20 23:26:22 94208 —-a-w- c:\windows\system32\dpl100.dll 2011-10-09 20:14:16 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll 2011-10-09 20:14:16 52096 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\LMIproc.dll 2011-10-09 20:14:15 30592 —-a-w- c:\windows\system32\LMIport.dll 2011-10-09 20:14:14 87424 —-a-w- c:\windows\system32\LMIinit.dll 2001-03-30 12:17:20 32768 –sha-r- c:\windows\system32\systna.dll . ============= FINISH: 2:14:58,54 ===============
My aswMBR log aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-16 02:19:27 —————————– 02:19:27.453 OS Version: Windows 5.1.2600 Service Pack 3 02:19:27.453 Number of processors: 2 586 0x40A 02:19:27.453 ComputerName: ALEMANIA-INVESP UserName: Mario 02:19:30.468 Initialize success 02:20:25.296 AVAST engine defs: 11121502 02:20:31.062 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 02:20:31.062 Disk 0 Vendor: Maxtor_6Y120L0 YAR41BW0 Size: 117245MB BusType: 3 02:20:33.062 Disk 0 MBR read successfully 02:20:33.062 Disk 0 MBR scan 02:20:33.093 Disk 0 Windows XP default MBR code 02:20:33.109 Disk 0 scanning sectors +240107490 02:20:33.171 Disk 0 scanning C:\WINDOWS\system32\drivers 02:20:44.953 Service scanning 02:20:45.484 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32 02:20:46.031 Modules scanning 02:21:01.046 Disk 0 trace - called modules: 02:21:01.046 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spbe.sys >>UNKNOWN [0x8a945938]<< 02:21:01.046 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a893ab8] 02:21:01.062 3 CLASSPNP.SYS[ba0f8fd7] -> nt!IofCallDriver -> \Device\0000006e[0x8a8d5510] 02:21:01.062 5 ACPI.sys[b9e65620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a8de940] 02:21:02.109 AVAST engine scan C:\WINDOWS 02:21:08.250 AVAST engine scan C:\WINDOWS\system32 02:21:09.671 File: C:\WINDOWS\system32\algvs.exe **INFECTED** Win32:VB-CWW [Wrm] 02:22:48.046 File: C:\WINDOWS\system32\systna.dll **INFECTED** Win32:Adware-gen [Adw] 02:23:19.968 AVAST engine scan C:\WINDOWS\system32\drivers 02:23:33.906 AVAST engine scan C:\Documents and Settings\Mario 03:09:00.171 AVAST engine scan C:\Documents and Settings\All Users 03:19:46.359 Scan finished successfully 08:12:41.093 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Mario\Mis documentos\INFORMATICA\20111216HTT\MBR.dat" 08:12:41.093 The log file has been saved successfully to "C:\Documents and Settings\Mario\Mis documentos\INFORMATICA\20111216HTT\aswMBR.txt" Thank you
Good Morning,



Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Hi: Thank you. Here my Combofixlog
📎ComboFix.txt



ComboFix 11-12-18.01 - Mario 18/12/2011 22:31:15.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.2047.989 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Escritorio\ComboFix.exe
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\archivos de programa\OfferBox
c:\archivos de programa\OfferBox\[removed]\components\OfferBoxXpCom.dll
C:\AUTORUN.INF
c:\documents and settings\All Users\Datos de programa\TEMP
c:\documents and settings\Mario\Datos de programa\JuniperExtXP.exe
c:\documents and settings\Mario\Datos de programa\JuniperSetup.exe
c:\documents and settings\Mario\Datos de programa\OfferBox
c:\documents and settings\Mario\Datos de programa\OfferBox\config.dat
c:\documents and settings\Mario\Datos de programa\OfferBox\config.xml
c:\documents and settings\Mario\Mis documentos\DPE.DUS
c:\documents and settings\Mario\WINDOWS
C:\fun.xls.exe
c:\windows\setupapi.log
c:\windows\system32\algsrvs.exe
c:\windows\system32\algvs.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_KAVSYS
——-\Legacy_NPF
——-\Service_AVPsys
.
.
((((((((((((((((((((((((( Files Created from 2011-11-18 to 2011-12-18 )))))))))))))))))))))))))))))))
.
.
2011-12-16 00:40 . 2011-12-16 00:40 ——– d–h–w- c:\windows\PIF
2011-12-16 00:24 . 2011-12-16 00:24 ——– d—–w- c:\documents and settings\Administrador\Configuración local\Datos de programa\Mozilla
2011-12-16 00:23 . 2011-12-16 00:23 ——– d-sh–w- c:\documents and settings\Administrador\IETldCache
2011-12-03 16:51 . 2011-12-03 16:51 ——– d—–w- c:\archivos de programa\iPod
2011-12-03 16:51 . 2011-12-03 16:52 ——– d—–w- c:\archivos de programa\iTunes
2011-11-19 20:57 . 2011-11-19 20:57 ——– d—–w- c:\documents and settings\Mario\Datos de programa\DDMSettings
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-17 17:49 . 2011-05-14 11:38 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 13:29 . 2011-10-24 13:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-20 23:26 . 2011-10-20 23:26 94208 —-a-w- c:\windows\system32\dpl100.dll
2011-10-09 20:14 . 2010-04-26 14:26 52096 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2011-10-09 20:14 . 2010-04-26 14:26 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-10-09 20:14 . 2010-04-26 14:26 30592 —-a-w- c:\windows\system32\LMIport.dll
2011-10-09 20:14 . 2010-04-26 14:26 87424 —-a-w- c:\windows\system32\LMIinit.dll
2011-11-09 21:04 . 2011-04-30 09:48 134104 —-a-w- c:\archivos de programa\mozilla firefox\components\browsercomps.dll
2001-03-30 12:17 32768 –sha-r- c:\windows\system32\systna.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\archivos de programa\myBabylon_English\prxtbmyB0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 —-a-w- c:\archivos de programa\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
2011-01-17 14:54 175912 —-a-w- c:\archivos de programa\myBabylon_English\prxtbmyB0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\archivos de programa\myBabylon_English\prxtbmyB0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\archivos de programa\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7}"= "c:\archivos de programa\myBabylon_English\prxtbmyB0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\archivos de programa\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-24 401491]
"NokiaOviSuite2"="c:\archivos de programa\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2011-07-13 966712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\archivos de programa\Archivos comunes\Nokia\MPlatform\NokiaMServer" [X]
"ATIPTA"="c:\archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-30 344064]
"Acrobat Assistant 7.0"="c:\archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"SSBkgdUpdate"="c:\archivos de programa\Archivos comunes\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\archivos de programa\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-18 57393]
"IndexSearch"="c:\archivos de programa\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-18 40960]
"BrMfcWnd"="c:\archivos de programa\Brother\Brmfcmon\BrMfcWnd.exe" [2006-06-28 622592]
"ControlCenter3"="c:\archivos de programa\Brother\ControlCenter3\brctrcen.exe" [2006-06-29 77824]
"PRONoMgr.exe"="c:\archivos de programa\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"StartCCC"="c:\archivos de programa\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-29 61440]
"UMonit"="c:\windows\system32\UMonit.exe" [2007-06-18 200704]
"LogMeIn GUI"="c:\archivos de programa\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"MacDrive 8 application"="c:\archivos de programa\Mediafour\MacDrive 8\MacDrive.exe" [2009-06-15 202328]
"Getting started with MacDrive 8"="c:\archivos de programa\Mediafour\MacDrive 8\MDGetStarted.exe" [2009-03-31 141312]
"AppleSyncNotifier"="c:\archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"Google Updater"="c:\archivos de programa\Google\Google Updater\GoogleUpdater.exe" [2011-09-24 161336]
"APSDaemon"="c:\archivos de programa\Archivos comunes\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"DivXUpdate"="c:\archivos de programa\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"iTunesHelper"="c:\archivos de programa\iTunes\iTunesHelper.exe" [2011-11-12 421736]
"QuickTime Task"="c:\archivos de programa\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Mario\Menú Inicio\Programas\Inicio\
Herramienta de búsqueda de soportes de PMB.lnk - c:\archivos de programa\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2010-7-13 333088]
.
c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\
Exif Launcher S.lnk - c:\archivos de programa\FinePixViewerS\QuickDCF2.exe [2009-7-16 303104]
Microsoft Office.lnk - c:\archivos de programa\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2011-10-09 20:14 87424 —-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menú Inicio^Programas^Inicio^Inicio rápido de Adobe Acrobat.lnk]
path=c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\Inicio rápido de Adobe Acrobat.lnk
backup=c:\windows\pss\Inicio rápido de Adobe Acrobat.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Mario^Menú Inicio^Programas^Inicio^Adobe Gamma.lnk]
path=c:\documents and settings\Mario\Menú Inicio\Programas\Inicio\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2007-11-17 15:51 221056 —-a-w- c:\archivos de programa\Alcohol Soft\Alcohol 120\AxCmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-11-11 09:57 1451520 —-a-w- c:\archivos de programa\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-10-13 07:27 17351304 —-a-r- c:\archivos de programa\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-01-03 02:40 39408 —-a-w- c:\archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Archivos de programa\\Microsoft ActiveSync\\wcescomm.exe"=
"c:\\Archivos de programa\\Microsoft ActiveSync\\WcesMgr.exe"=
"c:\\Archivos de programa\\Digital Rapids\\Stream\\DRBatchServer.exe"=
"c:\\Archivos de programa\\UltraVNC\\vncviewer.exe"=
"c:\\Archivos de programa\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Archivos de programa\\Archivos comunes\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Archivos de programa\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Documents and Settings\\Mario\\Mis documentos\\Descargas\\VideoConverter_Setup.exe"=
"c:\\Archivos de programa\\IRISnotes\\Easy note taker.exe"=
"c:\\Archivos de programa\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Archivos de programa\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Archivos de programa\\Bonjour\\mDNSResponder.exe"=
"c:\\Archivos de programa\\Skype\\Phone\\Skype.exe"=
"c:\\Archivos de programa\\iTunes\\iTunes.exe"=
"c:\\Archivos de programa\\Archivos comunes\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
.
R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [28/09/2009 14:02 259176]
R0 MDPMGRNT;MacDrive partition driver;c:\windows\system32\drivers\MDPMGRNT.SYS [31/07/2009 16:07 27488]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [07/12/2008 19:02 721904]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [16/08/2007 9:19 19200]
R2 BT848;AVerMedia, AVerTV WDM Video Capture;c:\windows\system32\drivers\BT848.sys [30/11/2009 16:29 261696]
R2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;c:\windows\system32\drivers\bttuner.sys [30/11/2009 16:29 22016]
R2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;c:\windows\system32\drivers\btxbar.sys [01/12/2009 23:24 13312]
R2 DRCHypersonic;DRC Hypersonic;c:\archivos de programa\Archivos comunes\Digital Rapids\hypersonic-service.exe [20/01/2009 11:52 135168]
R2 DRCRMIRegistry;DRC RMI Registry;c:\archivos de programa\Archivos comunes\Digital Rapids\rmi-registry-service.exe [20/01/2009 11:52 135168]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\archivos de programa\LogMeIn\x86\LMIGuardianSvc.exe [29/09/2010 21:50 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\archivos de programa\LogMeIn\x86\rainfo.sys [11/08/2008 11:41 12856]
R2 MacDrive8Service;MacDrive 8 service;c:\archivos de programa\Mediafour\MacDrive 8\MacDrive8Service.exe [23/09/2009 13:13 150528]
R3 RSUSBCCID;Realtek Smartcard Reader Driver;c:\windows\system32\drivers\RtsUCcid.sys [09/11/2010 11:56 44032]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 12:16 130384]
S2 gupdate;Servicio Google Update (gupdate);c:\archivos de programa\Google\Update\GoogleUpdate.exe [17/09/2009 23:57 133104]
S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [26/04/2010 22:30 223232]
S3 CTL511Plus;Video Blaster WebCam 3/WebCam Plus (WDM);c:\windows\system32\drivers\webc3vid.sys [14/09/2000 13:00 159867]
S3 DRCStreamServer;DRC Stream Server;c:\archivos de programa\Digital Rapids\Stream\stream-server-service.exe [20/01/2009 11:52 135168]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\archivos de programa\MAGIX\Common\Database\bin\fbserver.exe –> c:\archivos de programa\MAGIX\Common\Database\bin\fbserver.exe [?]
S3 gupdatem;Servicio de Google Update (gupdatem);c:\archivos de programa\Google\Update\GoogleUpdate.exe [17/09/2009 23:57 133104]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [21/07/2011 23:49 137600]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [21/07/2011 23:49 8576]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [17/12/2007 20:00 11776]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [12/10/2007 15:04 99200]
S3 NWVSCR;Novatel Wireless USB SmartCardReader Driver;c:\windows\system32\drivers\NWVSCR.sys [19/09/2007 10:42 24448]
S3 RtsUIr;Realtek IR Driver;c:\windows\system32\drivers\RtsUIr.sys [09/11/2010 11:56 17536]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 12:16 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\archivos de programa\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2011-12-06 c:\windows\Tasks\Google Software Updater.job
- c:\archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-03 05:37]
.
2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\archivos de programa\Google\Update\GoogleUpdate.exe [2009-09-17 22:56]
.
2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\archivos de programa\Google\Update\GoogleUpdate.exe [2009-09-17 22:56]
.
2011-07-12 c:\windows\Tasks\{61AE66C1-58C9-4CA0-8F29-A02BDEF5C95E}_ALEMANIA-INVESP_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-09-02 c:\windows\Tasks\{715A563D-A2B3-42D0-956F-C0C1603ECC71}_ALEMANIA-INVESP_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-07-12 c:\windows\Tasks\{AC43BDB6-0D30-4A95-9388-F0720DBF55EE}_ALEMANIA-2E60C7_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-12-07 c:\windows\Tasks\{C94FF516-9C6F-44DA-9583-7F16FE139A37}_ALEMANIA-2E60C7_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-09-02 c:\windows\Tasks\{DF04A656-9CC6-4A35-A7D3-010DADB305A0}_ALEMANIA-2E60C7_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-12-07 c:\windows\Tasks\{E0886217-9102-4854-BD85-D523D16A21A8}_ALEMANIA-INVESP_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.es/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Convertir a PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir a PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir destino de vínculo a PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir destino de vínculo en archivo PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir selección a archivo PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir selección a PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir vínculos seleccionados a PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir vínculos seleccionados a PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xportar a Microsoft Excel - c:\archiv~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: {2D0CBE69-DAFC-11D3-96D2-0020182E2E27} - hxxp://194.140.3.43/comun/download/wcf-pc-25_0_0_2.cab
FF - ProfilePath - c:\documents and settings\Mario\Datos de programa\Mozilla\Firefox\Profiles\12tcnlfq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=14542
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.es/search?q=
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellIconOverlayIdentifiers-MacDrive volume icons - (no file)
HKCU-Run-Samsung_AppInst - j:\samsungsoftware\AppInst.exe
HKLM-Run-SunJavaUpdateSched - c:\archivos de programa\Java\jre6\bin\jusched.exe
HKLM-Run-IMJPMIG8.2 - msime82.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-kamsoft - c:\windows\system32\kamsoft.exe
AddRemove-3971-4815-1971-1205 - c:\aeat\Renta2009\uninstall.exe
AddRemove-WebCam Plus - c:\windows\ctdrvins.exe -uninstall usb\vid_05a9&pid_a511 -plugin webc3pin.dll
AddRemove-Firebird SQL Server UK - c:\archivos de programa\MAGIX\Common\Database\unwise.exe
AddRemove-MAGIX 3D Maker UK - c:\archivos de programa\MAGIX\Common\3D_Maker_embeded\unwise.exe
AddRemove-MAGIX Speed 2 UK - c:\archivos de programa\MAGIX\Speed2_burnR_mxcdr\unwise.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\archivos de programa\DivX\DivXCodecUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-18 22:43
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
UMonit = c:\windows\system32\UMonit.exe?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
IMJPMIG8.2 = msime82.exe???.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Samsung_AppInst = j:\samsungsoftware\AppInst.exe?????????????????????????????????????????????????????? ????????????????????????????????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-507921405-1897051121-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8E44A2F0-1EE3-3E9B-D9F3-4230BDC8BFF9}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaelcbokiiegnoclmj"=hex:6b,61,62,63,62,6c,64,70,70,6b,63,6f,69,6b,69,6d,6c,66,
6e,68,6d,70,00,00
"hagliobijbilclfn"=hex:6b,61,62,63,62,6c,64,70,70,6b,63,6f,69,6b,69,6d,6c,66,
6e,68,6d,70,00,00
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(340)
c:\windows\system32\WININET.dll
c:\archivos de programa\Mediafour\MacDrive 8\MDVolumeIcons.dll
c:\archivos de programa\Mediafour\MacDrive 8\MACDRAPI.DLL
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\archivos de programa\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\archivos de programa\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\archivos de programa\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_spa.nlr
c:\archivos de programa\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
- - - - - - - > 'explorer.exe'(2212)
c:\windows\system32\WININET.dll
c:\archivos de programa\Mediafour\MacDrive 8\MDVolumeIcons.dll
c:\archivos de programa\Mediafour\MacDrive 8\MACDRAPI.DLL
c:\archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
c:\windows\system32\LMIRfsClientNP.dll
c:\windows\system32\PortableDeviceApi.dll
c:\archivos de programa\Archivos comunes\Mediafour\MACFPROP.DLL
c:\archivos de programa\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
c:\archivos de programa\Adobe\Acrobat 7.0\ActiveX\PDFShell.ESP
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\SCardSvr.exe
c:\archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\archivos de programa\Bonjour\mDNSResponder.exe
c:\archivos de programa\Archivos comunes\Digital Rapids\jre1.6.0_06\bin\java.exe
c:\archivos de programa\Archivos comunes\Digital Rapids\jre1.6.0_06\bin\java.exe
c:\archivos de programa\Java\jre6\bin\jqs.exe
c:\archivos de programa\LogMeIn\x86\RaMaint.exe
c:\archivos de programa\LogMeIn\x86\LogMeIn.exe
c:\archivos de programa\NDAS\System\ndassvc.exe
c:\archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\SOUNDMAN.EXE
c:\archivos de programa\Archivos comunes\Nokia\MPlatform\NokiaMServer.exe
c:\archivos de programa\iPod\bin\iPodService.exe
c:\archivos de programa\PC Connectivity Solution\ServiceLayer.exe
c:\archivos de programa\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\archivos de programa\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\archivos de programa\PC Connectivity Solution\Transports\NclMSBTSrv.exe
.
**************************************************************************
.
Completion time: 2011-12-19 00:03:34 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-18 23:03
.
Pre-Run: 28.719.304.704 bytes libres
Post-Run: 29.349.302.272 bytes libres
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
.
- - End Of File - - E2320AD19A22081114BF88C082584BEB
Hi,

Just copy and paste the logs into this thread in lew of attaching them, its easier for us to analyse.


You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see. If the site says this file has been checked before, have them check it again

c:\windows\system32\systna.dll <–This file

If the site is busy you can try this one
http://virusscan.jotti.org/en



Go ahead and run aswMBR again and post the new log please
Sorry!!

ComboFix 11-12-18.01 - Mario 18/12/2011 22:31:15.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.2047.989 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Escritorio\ComboFix.exe
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\archivos de programa\OfferBox
c:\archivos de programa\OfferBox\[removed]\components\OfferBoxXpCom.dll
C:\AUTORUN.INF
c:\documents and settings\All Users\Datos de programa\TEMP
c:\documents and settings\Mario\Datos de programa\JuniperExtXP.exe
c:\documents and settings\Mario\Datos de programa\JuniperSetup.exe
c:\documents and settings\Mario\Datos de programa\OfferBox
c:\documents and settings\Mario\Datos de programa\OfferBox\config.dat
c:\documents and settings\Mario\Datos de programa\OfferBox\config.xml
c:\documents and settings\Mario\Mis documentos\DPE.DUS
c:\documents and settings\Mario\WINDOWS
C:\fun.xls.exe
c:\windows\setupapi.log
c:\windows\system32\algsrvs.exe
c:\windows\system32\algvs.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_KAVSYS
——-\Legacy_NPF
——-\Service_AVPsys
.
.
((((((((((((((((((((((((( Files Created from 2011-11-18 to 2011-12-18 )))))))))))))))))))))))))))))))
.
.
2011-12-16 00:40 . 2011-12-16 00:40 ——– d–h–w- c:\windows\PIF
2011-12-16 00:24 . 2011-12-16 00:24 ——– d—–w- c:\documents and settings\Administrador\Configuración local\Datos de programa\Mozilla
2011-12-16 00:23 . 2011-12-16 00:23 ——– d-sh–w- c:\documents and settings\Administrador\IETldCache
2011-12-03 16:51 . 2011-12-03 16:51 ——– d—–w- c:\archivos de programa\iPod
2011-12-03 16:51 . 2011-12-03 16:52 ——– d—–w- c:\archivos de programa\iTunes
2011-11-19 20:57 . 2011-11-19 20:57 ——– d—–w- c:\documents and settings\Mario\Datos de programa\DDMSettings
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-17 17:49 . 2011-05-14 11:38 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 13:29 . 2011-10-24 13:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-20 23:26 . 2011-10-20 23:26 94208 —-a-w- c:\windows\system32\dpl100.dll
2011-10-09 20:14 . 2010-04-26 14:26 52096 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2011-10-09 20:14 . 2010-04-26 14:26 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-10-09 20:14 . 2010-04-26 14:26 30592 —-a-w- c:\windows\system32\LMIport.dll
2011-10-09 20:14 . 2010-04-26 14:26 87424 —-a-w- c:\windows\system32\LMIinit.dll
2011-11-09 21:04 . 2011-04-30 09:48 134104 —-a-w- c:\archivos de programa\mozilla firefox\components\browsercomps.dll
2001-03-30 12:17 32768 –sha-r- c:\windows\system32\systna.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\archivos de programa\myBabylon_English\prxtbmyB0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 —-a-w- c:\archivos de programa\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
2011-01-17 14:54 175912 —-a-w- c:\archivos de programa\myBabylon_English\prxtbmyB0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\archivos de programa\myBabylon_English\prxtbmyB0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\archivos de programa\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7}"= "c:\archivos de programa\myBabylon_English\prxtbmyB0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\archivos de programa\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-24 401491]
"NokiaOviSuite2"="c:\archivos de programa\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2011-07-13 966712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\archivos de programa\Archivos comunes\Nokia\MPlatform\NokiaMServer" [X]
"ATIPTA"="c:\archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-30 344064]
"Acrobat Assistant 7.0"="c:\archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"SSBkgdUpdate"="c:\archivos de programa\Archivos comunes\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\archivos de programa\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-18 57393]
"IndexSearch"="c:\archivos de programa\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-18 40960]
"BrMfcWnd"="c:\archivos de programa\Brother\Brmfcmon\BrMfcWnd.exe" [2006-06-28 622592]
"ControlCenter3"="c:\archivos de programa\Brother\ControlCenter3\brctrcen.exe" [2006-06-29 77824]
"PRONoMgr.exe"="c:\archivos de programa\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"StartCCC"="c:\archivos de programa\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-29 61440]
"UMonit"="c:\windows\system32\UMonit.exe" [2007-06-18 200704]
"LogMeIn GUI"="c:\archivos de programa\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"MacDrive 8 application"="c:\archivos de programa\Mediafour\MacDrive 8\MacDrive.exe" [2009-06-15 202328]
"Getting started with MacDrive 8"="c:\archivos de programa\Mediafour\MacDrive 8\MDGetStarted.exe" [2009-03-31 141312]
"AppleSyncNotifier"="c:\archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"Google Updater"="c:\archivos de programa\Google\Google Updater\GoogleUpdater.exe" [2011-09-24 161336]
"APSDaemon"="c:\archivos de programa\Archivos comunes\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"DivXUpdate"="c:\archivos de programa\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"iTunesHelper"="c:\archivos de programa\iTunes\iTunesHelper.exe" [2011-11-12 421736]
"QuickTime Task"="c:\archivos de programa\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Mario\Menú Inicio\Programas\Inicio\
Herramienta de búsqueda de soportes de PMB.lnk - c:\archivos de programa\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2010-7-13 333088]
.
c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\
Exif Launcher S.lnk - c:\archivos de programa\FinePixViewerS\QuickDCF2.exe [2009-7-16 303104]
Microsoft Office.lnk - c:\archivos de programa\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2011-10-09 20:14 87424 —-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menú Inicio^Programas^Inicio^Inicio rápido de Adobe Acrobat.lnk]
path=c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\Inicio rápido de Adobe Acrobat.lnk
backup=c:\windows\pss\Inicio rápido de Adobe Acrobat.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Mario^Menú Inicio^Programas^Inicio^Adobe Gamma.lnk]
path=c:\documents and settings\Mario\Menú Inicio\Programas\Inicio\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2007-11-17 15:51 221056 —-a-w- c:\archivos de programa\Alcohol Soft\Alcohol 120\AxCmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-11-11 09:57 1451520 —-a-w- c:\archivos de programa\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-10-13 07:27 17351304 —-a-r- c:\archivos de programa\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-01-03 02:40 39408 —-a-w- c:\archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Archivos de programa\\Microsoft ActiveSync\\wcescomm.exe"=
"c:\\Archivos de programa\\Microsoft ActiveSync\\WcesMgr.exe"=
"c:\\Archivos de programa\\Digital Rapids\\Stream\\DRBatchServer.exe"=
"c:\\Archivos de programa\\UltraVNC\\vncviewer.exe"=
"c:\\Archivos de programa\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Archivos de programa\\Archivos comunes\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Archivos de programa\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Documents and Settings\\Mario\\Mis documentos\\Descargas\\VideoConverter_Setup.exe"=
"c:\\Archivos de programa\\IRISnotes\\Easy note taker.exe"=
"c:\\Archivos de programa\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Archivos de programa\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Archivos de programa\\Bonjour\\mDNSResponder.exe"=
"c:\\Archivos de programa\\Skype\\Phone\\Skype.exe"=
"c:\\Archivos de programa\\iTunes\\iTunes.exe"=
"c:\\Archivos de programa\\Archivos comunes\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
.
R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [28/09/2009 14:02 259176]
R0 MDPMGRNT;MacDrive partition driver;c:\windows\system32\drivers\MDPMGRNT.SYS [31/07/2009 16:07 27488]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [07/12/2008 19:02 721904]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [16/08/2007 9:19 19200]
R2 BT848;AVerMedia, AVerTV WDM Video Capture;c:\windows\system32\drivers\BT848.sys [30/11/2009 16:29 261696]
R2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;c:\windows\system32\drivers\bttuner.sys [30/11/2009 16:29 22016]
R2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;c:\windows\system32\drivers\btxbar.sys [01/12/2009 23:24 13312]
R2 DRCHypersonic;DRC Hypersonic;c:\archivos de programa\Archivos comunes\Digital Rapids\hypersonic-service.exe [20/01/2009 11:52 135168]
R2 DRCRMIRegistry;DRC RMI Registry;c:\archivos de programa\Archivos comunes\Digital Rapids\rmi-registry-service.exe [20/01/2009 11:52 135168]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\archivos de programa\LogMeIn\x86\LMIGuardianSvc.exe [29/09/2010 21:50 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\archivos de programa\LogMeIn\x86\rainfo.sys [11/08/2008 11:41 12856]
R2 MacDrive8Service;MacDrive 8 service;c:\archivos de programa\Mediafour\MacDrive 8\MacDrive8Service.exe [23/09/2009 13:13 150528]
R3 RSUSBCCID;Realtek Smartcard Reader Driver;c:\windows\system32\drivers\RtsUCcid.sys [09/11/2010 11:56 44032]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 12:16 130384]
S2 gupdate;Servicio Google Update (gupdate);c:\archivos de programa\Google\Update\GoogleUpdate.exe [17/09/2009 23:57 133104]
S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [26/04/2010 22:30 223232]
S3 CTL511Plus;Video Blaster WebCam 3/WebCam Plus (WDM);c:\windows\system32\drivers\webc3vid.sys [14/09/2000 13:00 159867]
S3 DRCStreamServer;DRC Stream Server;c:\archivos de programa\Digital Rapids\Stream\stream-server-service.exe [20/01/2009 11:52 135168]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\archivos de programa\MAGIX\Common\Database\bin\fbserver.exe –> c:\archivos de programa\MAGIX\Common\Database\bin\fbserver.exe [?]
S3 gupdatem;Servicio de Google Update (gupdatem);c:\archivos de programa\Google\Update\GoogleUpdate.exe [17/09/2009 23:57 133104]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [21/07/2011 23:49 137600]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [21/07/2011 23:49 8576]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [17/12/2007 20:00 11776]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [12/10/2007 15:04 99200]
S3 NWVSCR;Novatel Wireless USB SmartCardReader Driver;c:\windows\system32\drivers\NWVSCR.sys [19/09/2007 10:42 24448]
S3 RtsUIr;Realtek IR Driver;c:\windows\system32\drivers\RtsUIr.sys [09/11/2010 11:56 17536]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 12:16 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\archivos de programa\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2011-12-06 c:\windows\Tasks\Google Software Updater.job
- c:\archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-03 05:37]
.
2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\archivos de programa\Google\Update\GoogleUpdate.exe [2009-09-17 22:56]
.
2011-12-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\archivos de programa\Google\Update\GoogleUpdate.exe [2009-09-17 22:56]
.
2011-07-12 c:\windows\Tasks\{61AE66C1-58C9-4CA0-8F29-A02BDEF5C95E}_ALEMANIA-INVESP_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-09-02 c:\windows\Tasks\{715A563D-A2B3-42D0-956F-C0C1603ECC71}_ALEMANIA-INVESP_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-07-12 c:\windows\Tasks\{AC43BDB6-0D30-4A95-9388-F0720DBF55EE}_ALEMANIA-2E60C7_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-12-07 c:\windows\Tasks\{C94FF516-9C6F-44DA-9583-7F16FE139A37}_ALEMANIA-2E60C7_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-09-02 c:\windows\Tasks\{DF04A656-9CC6-4A35-A7D3-010DADB305A0}_ALEMANIA-2E60C7_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-12-07 c:\windows\Tasks\{E0886217-9102-4854-BD85-D523D16A21A8}_ALEMANIA-INVESP_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.es/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Convertir a PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir a PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir destino de vínculo a PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir destino de vínculo en archivo PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir selección a archivo PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir selección a PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir vínculos seleccionados a PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir vínculos seleccionados a PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xportar a Microsoft Excel - c:\archiv~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: {2D0CBE69-DAFC-11D3-96D2-0020182E2E27} - hxxp://194.140.3.43/comun/download/wcf-pc-25_0_0_2.cab
FF - ProfilePath - c:\documents and settings\Mario\Datos de programa\Mozilla\Firefox\Profiles\12tcnlfq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=14542
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.es/search?q=
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellIconOverlayIdentifiers-MacDrive volume icons - (no file)
HKCU-Run-Samsung_AppInst - j:\samsungsoftware\AppInst.exe
HKLM-Run-SunJavaUpdateSched - c:\archivos de programa\Java\jre6\bin\jusched.exe
HKLM-Run-IMJPMIG8.2 - msime82.exe
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-kamsoft - c:\windows\system32\kamsoft.exe
AddRemove-3971-4815-1971-1205 - c:\aeat\Renta2009\uninstall.exe
AddRemove-WebCam Plus - c:\windows\ctdrvins.exe -uninstall usb\vid_05a9&pid_a511 -plugin webc3pin.dll
AddRemove-Firebird SQL Server UK - c:\archivos de programa\MAGIX\Common\Database\unwise.exe
AddRemove-MAGIX 3D Maker UK - c:\archivos de programa\MAGIX\Common\3D_Maker_embeded\unwise.exe
AddRemove-MAGIX Speed 2 UK - c:\archivos de programa\MAGIX\Speed2_burnR_mxcdr\unwise.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\archivos de programa\DivX\DivXCodecUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-18 22:43
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
UMonit = c:\windows\system32\UMonit.exe?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
IMJPMIG8.2 = msime82.exe???.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Samsung_AppInst = j:\samsungsoftware\AppInst.exe?????????????????????????????????????????????????????? ????????????????????????????????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-507921405-1897051121-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8E44A2F0-1EE3-3E9B-D9F3-4230BDC8BFF9}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaelcbokiiegnoclmj"=hex:6b,61,62,63,62,6c,64,70,70,6b,63,6f,69,6b,69,6d,6c,66,
6e,68,6d,70,00,00
"hagliobijbilclfn"=hex:6b,61,62,63,62,6c,64,70,70,6b,63,6f,69,6b,69,6d,6c,66,
6e,68,6d,70,00,00
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(340)
c:\windows\system32\WININET.dll
c:\archivos de programa\Mediafour\MacDrive 8\MDVolumeIcons.dll
c:\archivos de programa\Mediafour\MacDrive 8\MACDRAPI.DLL
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\archivos de programa\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\archivos de programa\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\archivos de programa\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_spa.nlr
c:\archivos de programa\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
- - - - - - - > 'explorer.exe'(2212)
c:\windows\system32\WININET.dll
c:\archivos de programa\Mediafour\MacDrive 8\MDVolumeIcons.dll
c:\archivos de programa\Mediafour\MacDrive 8\MACDRAPI.DLL
c:\archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
c:\windows\system32\LMIRfsClientNP.dll
c:\windows\system32\PortableDeviceApi.dll
c:\archivos de programa\Archivos comunes\Mediafour\MACFPROP.DLL
c:\archivos de programa\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
c:\archivos de programa\Adobe\Acrobat 7.0\ActiveX\PDFShell.ESP
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\SCardSvr.exe
c:\archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\archivos de programa\Bonjour\mDNSResponder.exe
c:\archivos de programa\Archivos comunes\Digital Rapids\jre1.6.0_06\bin\java.exe
c:\archivos de programa\Archivos comunes\Digital Rapids\jre1.6.0_06\bin\java.exe
c:\archivos de programa\Java\jre6\bin\jqs.exe
c:\archivos de programa\LogMeIn\x86\RaMaint.exe
c:\archivos de programa\LogMeIn\x86\LogMeIn.exe
c:\archivos de programa\NDAS\System\ndassvc.exe
c:\archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\SOUNDMAN.EXE
c:\archivos de programa\Archivos comunes\Nokia\MPlatform\NokiaMServer.exe
c:\archivos de programa\iPod\bin\iPodService.exe
c:\archivos de programa\PC Connectivity Solution\ServiceLayer.exe
c:\archivos de programa\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\archivos de programa\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\archivos de programa\PC Connectivity Solution\Transports\NclMSBTSrv.exe
.
**************************************************************************
.
Completion time: 2011-12-19 00:03:34 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-18 23:03
.
Pre-Run: 28.719.304.704 bytes libres
Post-Run: 29.349.302.272 bytes libres
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware. File name: systna.dll Submission date: 2011-12-18 23:56:51 (UTC) Current status: finished Result: 31/ 43 (72.1%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.12.18.00 2011.12.18 Adware/Win32.WebHancer AntiVir 7.11.19.155 2011.12.18 Adware/Agent.32768.59 Antiy-AVL 2.0.3.7 2011.12.18 - Avast 6.0.1289.0 2011.12.18 Win32:Adware-gen [Adw] AVG 10.0.0.1190 2011.12.18 Adload_r.AMZ BitDefender 7.2 2011.12.19 Adware.Generic.142682 ByteHero 1.0.0.1 2011.12.07 - CAT-QuickHeal 12.00 2011.12.18 - ClamAV 0.97.3.0 2011.12.18 - Commtouch 5.3.2.6 2011.12.17 W32/MalwareS.BIYG Comodo 11004 2011.12.18 Application.Win32.Adware.WebHancer.~F DrWeb 5.0.2.03300 2011.12.18 Adware.WebHancer.105 Emsisoft 5.1.0.11 2011.12.18 Riskware.AdWare.Win32.WebHancer!IK eSafe 7.0.17.0 2011.12.18 - eTrust-Vet 37.0.9628 2011.12.16 - F-Prot 4.6.5.141 2011.12.17 W32/MalwareS.BIYG F-Secure 9.0.16440.0 2011.12.18 Adware.Generic.142682 Fortinet 4.3.388.0 2011.12.18 - GData 22 2011.12.18 Adware.Generic.142682 Ikarus T3.1.1.109.0 2011.12.18 not-a-virus:AdWare.Win32.WebHancer Jiangmin 13.0.900 2011.12.18 Adware/WebHancer.h K7AntiVirus 9.119.5696 2011.12.15 Riskware Kaspersky 9.0.0.837 2011.12.18 not-a-virus:AdWare.Win32.WebHancer.ck McAfee 5.400.0.1158 2011.12.18 Generic PUP.x!hb McAfee-GW-Edition 2010.1E 2011.12.19 Generic PUP.x!hb Microsoft 1.7903 2011.12.18 - NOD32 6722 2011.12.19 Win32/BHO.NWT Norman 6.07.13 2011.12.18 W32/Suspicious_Gen3.OVJS nProtect 2011-12-18.01 2011.12.18 Trojan-Clicker/W32.WebHancer.32768.C Panda 10.0.3.5 2011.12.18 Trj/CI.A PCTools 8.0.0.5 2011.12.19 Adware.Gen!rem Prevx 3.0 2011.12.19 - Rising 23.88.03.02 2011.12.16 - Sophos 4.72.0 2011.12.18 - SUPERAntiSpyware 4.40.0.1006 2011.12.17 Trojan.Agent/Gen-ModuleR[N] Symantec 20111.2.0.82 2011.12.19 Adware.Gen TheHacker 6.7.0.1.361 2011.12.18 Trojan/BHO.nwt TrendMicro 9.500.0.1008 2011.12.18 TROJ_GEN.R21C3AV TrendMicro-HouseCall 9.500.0.1008 2011.12.19 TROJ_GEN.R21C3AV VBA32 3.12.16.4 2011.12.14 AdWare.Win32.WebHancer.w VIPRE 11272 2011.12.18 webHancer ViRobot 2011.12.17.4831 2011.12.18 - VirusBuster 14.1.122.1 2011.12.18 Adware.WebHancer!RZAvPbwXj8Y Additional information MD5 : cdf0b846cfaf87eec319ffe4b1e3bed3 SHA1 : 0c9d9e2d709b53b5010b5491ca81d41a7e93a2bb SHA256: 817a74ce1d300e35bdfac06d72343a2d409544b7c2882a2ec4de321f2b1db399 ssdeep: 192:a5+BuGgLWXFo3LltCr0dQy6knvBGC5+vhAsBlBTvY4qS5qEv2O+ed8V7RI:a4wDLWXFmtCr EQyRcTf5WSbv18V7R File size : 32768 bytes First seen: 2009-12-04 21:47:41 Last seen : 2011-12-18 23:56:51 TrID: DirectShow filter (58.3%) Windows OCX File (35.7%) Win32 Executable Generic (2.4%) Win32 Dynamic Link Library (generic) (2.1%) Generic Win/DOS Executable (0.5%) sigcheck: publisher….: copyright….: Copyright 2006 product……: SystNa Module description..: original name: systna.dll internal name: SystNa file version.: 6, 2, 6001, 788 comments…..: signers……: - signing date.: - verified…..: Unsigned PEInfo: PE structure information [[ basic data ]] entrypointaddress: 0x20F7 timedatestamp….: 0x3AC45D2E (Fri Mar 30 10:17:18 2001) machinetype……: 0x14c (I386) [[ 5 section(s) ]] name, viradd, virsiz, rawdsiz, ntropy, md5 .text, 0x1000, 0x15F5, 0x2000, 4.92, ba6cf9211a78c535264a3902a110a573 .rdata, 0x3000, 0x9A3, 0x1000, 3.47, 5f06ad84109d3ae26d638cbce28b2ade .data, 0x4000, 0x164, 0x1000, 0.22, 55a84dadbf7452c39b7860acdd39869c .rsrc, 0x5000, 0x14F0, 0x2000, 3.31, 8a2e1711fad292e72ae1e32dee16b742 .reloc, 0x7000, 0x26C, 0x1000, 1.28, 2015e48bb0c2d1f116d1a0b4863d10ad [[ 4 import(s) ]] KERNEL32.dll: HeapCreate, lstrlenW, DebugBreak, GetVersionExA, HeapFree, DisableThreadLibraryCalls, GetSystemInfo, HeapAlloc, InterlockedDecrement, EnterCriticalSection, InterlockedIncrement, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSection USER32.dll: MessageBoxA OLEAUT32.dll: -, -, - ATL.DLL: -, -, -, -, -, -, -, -, - [[ 4 export(s) ]] DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer ExifTool: file metadata CharacterSet: Unicode CodeSize: 8192 Comments: CompanyName: EntryPoint: 0x20f7 FileDescription: FileFlagsMask: 0x003f FileOS: Win32 FileSize: 32 kB FileSubtype: 0 FileType: Win32 DLL FileVersion: 6, 2, 6001, 788 FileVersionNumber: 6.2.6001.788 ImageVersion: 0.0 InitializedDataSize: 20480 InternalName: SystNa LanguageCode: English (U.S.) LegalCopyright: Copyright 2006 LegalTrademarks: LinkerVersion: 6.0 MIMEType: application/octet-stream MachineType: Intel 386 or later, and compatibles OLESelfRegister: OSVersion: 4.0 ObjectFileType: Dynamic link library OriginalFilename: systna.dll PEType: PE32 PrivateBuild: ProductName: SystNa Module ProductVersion: 6, 2, 6001, 788 ProductVersionNumber: 6.2.6001.788 SpecialBuild: Subsystem: Windows GUI SubsystemVersion: 4.0 TimeStamp: 2001:03:30 12:17:18+02:00 UninitializedDataSize: 0
Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::


File::
c:\windows\system32\systna.dll

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.
ComboFix 11-12-19.03 - Mario 20/12/2011 0:33.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.2047.1446 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Escritorio\ComboFix.exe
Command switches used :: c:\documents and settings\Mario\Escritorio\CFScript.txt
* Created a new restore point
.
FILE ::
"c:\windows\system32\systna.dll"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Thumbs.db
c:\windows\alcrmv.exe
c:\windows\system32\systna.dll
c:\windows\ufdata2000.log
.
.
((((((((((((((((((((((((( Files Created from 2011-11-19 to 2011-12-19 )))))))))))))))))))))))))))))))
.
.
2011-12-16 00:40 . 2011-12-16 00:40 ——– d–h–w- c:\windows\PIF
2011-12-16 00:24 . 2011-12-16 00:24 ——– d—–w- c:\documents and settings\Administrador\Configuración local\Datos de programa\Mozilla
2011-12-16 00:23 . 2011-12-16 00:23 ——– d-sh–w- c:\documents and settings\Administrador\IETldCache
2011-12-03 16:51 . 2011-12-03 16:51 ——– d—–w- c:\archivos de programa\iPod
2011-12-03 16:51 . 2011-12-03 16:52 ——– d—–w- c:\archivos de programa\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-17 17:49 . 2011-05-14 11:38 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 13:29 . 2011-10-24 13:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-20 23:26 . 2011-10-20 23:26 94208 —-a-w- c:\windows\system32\dpl100.dll
2011-10-09 20:14 . 2010-04-26 14:26 52096 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2011-10-09 20:14 . 2010-04-26 14:26 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-10-09 20:14 . 2010-04-26 14:26 30592 —-a-w- c:\windows\system32\LMIport.dll
2011-10-09 20:14 . 2010-04-26 14:26 87424 —-a-w- c:\windows\system32\LMIinit.dll
2011-11-09 21:04 . 2011-04-30 09:48 134104 —-a-w- c:\archivos de programa\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-18_21.43.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-19 22:01 . 2011-12-19 22:01 16384 c:\windows\Temp\Perflib_Perfdata_148.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\archivos de programa\myBabylon_English\prxtbmyB0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 —-a-w- c:\archivos de programa\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
2011-01-17 14:54 175912 —-a-w- c:\archivos de programa\myBabylon_English\prxtbmyB0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\archivos de programa\myBabylon_English\prxtbmyB0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\archivos de programa\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7}"= "c:\archivos de programa\myBabylon_English\prxtbmyB0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\archivos de programa\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-24 401491]
"NokiaOviSuite2"="c:\archivos de programa\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2011-07-13 966712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\archivos de programa\Archivos comunes\Nokia\MPlatform\NokiaMServer" [X]
"ATIPTA"="c:\archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-30 344064]
"Acrobat Assistant 7.0"="c:\archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"SSBkgdUpdate"="c:\archivos de programa\Archivos comunes\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\archivos de programa\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-18 57393]
"IndexSearch"="c:\archivos de programa\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-18 40960]
"BrMfcWnd"="c:\archivos de programa\Brother\Brmfcmon\BrMfcWnd.exe" [2006-06-28 622592]
"ControlCenter3"="c:\archivos de programa\Brother\ControlCenter3\brctrcen.exe" [2006-06-29 77824]
"PRONoMgr.exe"="c:\archivos de programa\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"StartCCC"="c:\archivos de programa\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-29 61440]
"UMonit"="c:\windows\system32\UMonit.exe" [2007-06-18 200704]
"LogMeIn GUI"="c:\archivos de programa\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"MacDrive 8 application"="c:\archivos de programa\Mediafour\MacDrive 8\MacDrive.exe" [2009-06-15 202328]
"Getting started with MacDrive 8"="c:\archivos de programa\Mediafour\MacDrive 8\MDGetStarted.exe" [2009-03-31 141312]
"AppleSyncNotifier"="c:\archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"Google Updater"="c:\archivos de programa\Google\Google Updater\GoogleUpdater.exe" [2011-09-24 161336]
"APSDaemon"="c:\archivos de programa\Archivos comunes\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"DivXUpdate"="c:\archivos de programa\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"iTunesHelper"="c:\archivos de programa\iTunes\iTunesHelper.exe" [2011-11-12 421736]
"QuickTime Task"="c:\archivos de programa\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Mario\Menú Inicio\Programas\Inicio\
Herramienta de búsqueda de soportes de PMB.lnk - c:\archivos de programa\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2010-7-13 333088]
.
c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\
Exif Launcher S.lnk - c:\archivos de programa\FinePixViewerS\QuickDCF2.exe [2009-7-16 303104]
Microsoft Office.lnk - c:\archivos de programa\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2011-10-09 20:14 87424 —-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menú Inicio^Programas^Inicio^Inicio rápido de Adobe Acrobat.lnk]
path=c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\Inicio rápido de Adobe Acrobat.lnk
backup=c:\windows\pss\Inicio rápido de Adobe Acrobat.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Mario^Menú Inicio^Programas^Inicio^Adobe Gamma.lnk]
path=c:\documents and settings\Mario\Menú Inicio\Programas\Inicio\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2007-11-17 15:51 221056 —-a-w- c:\archivos de programa\Alcohol Soft\Alcohol 120\AxCmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-11-11 09:57 1451520 —-a-w- c:\archivos de programa\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-10-13 07:27 17351304 —-a-r- c:\archivos de programa\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-01-03 02:40 39408 —-a-w- c:\archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Archivos de programa\\Microsoft ActiveSync\\wcescomm.exe"=
"c:\\Archivos de programa\\Microsoft ActiveSync\\WcesMgr.exe"=
"c:\\Archivos de programa\\Digital Rapids\\Stream\\DRBatchServer.exe"=
"c:\\Archivos de programa\\UltraVNC\\vncviewer.exe"=
"c:\\Archivos de programa\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Archivos de programa\\Archivos comunes\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Archivos de programa\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Documents and Settings\\Mario\\Mis documentos\\Descargas\\VideoConverter_Setup.exe"=
"c:\\Archivos de programa\\IRISnotes\\Easy note taker.exe"=
"c:\\Archivos de programa\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Archivos de programa\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Archivos de programa\\Bonjour\\mDNSResponder.exe"=
"c:\\Archivos de programa\\Skype\\Phone\\Skype.exe"=
"c:\\Archivos de programa\\iTunes\\iTunes.exe"=
"c:\\Archivos de programa\\Archivos comunes\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
.
R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [28/09/2009 14:02 259176]
R0 MDPMGRNT;MacDrive partition driver;c:\windows\system32\drivers\MDPMGRNT.SYS [31/07/2009 16:07 27488]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [07/12/2008 19:02 721904]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [16/08/2007 9:19 19200]
R2 BT848;AVerMedia, AVerTV WDM Video Capture;c:\windows\system32\drivers\BT848.sys [30/11/2009 16:29 261696]
R2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;c:\windows\system32\drivers\bttuner.sys [30/11/2009 16:29 22016]
R2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;c:\windows\system32\drivers\btxbar.sys [01/12/2009 23:24 13312]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\archivos de programa\LogMeIn\x86\LMIGuardianSvc.exe [29/09/2010 21:50 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\archivos de programa\LogMeIn\x86\rainfo.sys [11/08/2008 11:41 12856]
R2 MacDrive8Service;MacDrive 8 service;c:\archivos de programa\Mediafour\MacDrive 8\MacDrive8Service.exe [23/09/2009 13:13 150528]
R3 RSUSBCCID;Realtek Smartcard Reader Driver;c:\windows\system32\drivers\RtsUCcid.sys [09/11/2010 11:56 44032]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 12:16 130384]
S2 DRCHypersonic;DRC Hypersonic;c:\archivos de programa\Archivos comunes\Digital Rapids\hypersonic-service.exe [20/01/2009 11:52 135168]
S2 DRCRMIRegistry;DRC RMI Registry;c:\archivos de programa\Archivos comunes\Digital Rapids\rmi-registry-service.exe [20/01/2009 11:52 135168]
S2 gupdate;Servicio Google Update (gupdate);c:\archivos de programa\Google\Update\GoogleUpdate.exe [17/09/2009 23:57 133104]
S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [26/04/2010 22:30 223232]
S3 CTL511Plus;Video Blaster WebCam 3/WebCam Plus (WDM);c:\windows\system32\drivers\webc3vid.sys [14/09/2000 13:00 159867]
S3 DRCStreamServer;DRC Stream Server;c:\archivos de programa\Digital Rapids\Stream\stream-server-service.exe [20/01/2009 11:52 135168]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\archivos de programa\MAGIX\Common\Database\bin\fbserver.exe –> c:\archivos de programa\MAGIX\Common\Database\bin\fbserver.exe [?]
S3 gupdatem;Servicio de Google Update (gupdatem);c:\archivos de programa\Google\Update\GoogleUpdate.exe [17/09/2009 23:57 133104]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [21/07/2011 23:49 137600]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [21/07/2011 23:49 8576]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [17/12/2007 20:00 11776]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [12/10/2007 15:04 99200]
S3 NWVSCR;Novatel Wireless USB SmartCardReader Driver;c:\windows\system32\drivers\NWVSCR.sys [19/09/2007 10:42 24448]
S3 RtsUIr;Realtek IR Driver;c:\windows\system32\drivers\RtsUIr.sys [09/11/2010 11:56 17536]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 12:16 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\archivos de programa\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2011-12-06 c:\windows\Tasks\Google Software Updater.job
- c:\archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-03 05:37]
.
2011-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\archivos de programa\Google\Update\GoogleUpdate.exe [2009-09-17 22:56]
.
2011-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\archivos de programa\Google\Update\GoogleUpdate.exe [2009-09-17 22:56]
.
2011-07-12 c:\windows\Tasks\{61AE66C1-58C9-4CA0-8F29-A02BDEF5C95E}_ALEMANIA-INVESP_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-09-02 c:\windows\Tasks\{715A563D-A2B3-42D0-956F-C0C1603ECC71}_ALEMANIA-INVESP_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-07-12 c:\windows\Tasks\{AC43BDB6-0D30-4A95-9388-F0720DBF55EE}_ALEMANIA-2E60C7_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-12-19 c:\windows\Tasks\{C94FF516-9C6F-44DA-9583-7F16FE139A37}_ALEMANIA-2E60C7_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-09-02 c:\windows\Tasks\{DF04A656-9CC6-4A35-A7D3-010DADB305A0}_ALEMANIA-2E60C7_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-12-19 c:\windows\Tasks\{E0886217-9102-4854-BD85-D523D16A21A8}_ALEMANIA-INVESP_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.es/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Convertir a PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir a PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir destino de vínculo a PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir destino de vínculo en archivo PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir selección a archivo PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir selección a PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir vínculos seleccionados a PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir vínculos seleccionados a PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xportar a Microsoft Excel - c:\archiv~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: {2D0CBE69-DAFC-11D3-96D2-0020182E2E27} - hxxp://194.140.3.43/comun/download/wcf-pc-25_0_0_2.cab
FF - ProfilePath - c:\documents and settings\Mario\Datos de programa\Mozilla\Firefox\Profiles\12tcnlfq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=14542
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.es/search?q=
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-20 00:40
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
UMonit = c:\windows\system32\UMonit.exe?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-507921405-1897051121-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8E44A2F0-1EE3-3E9B-D9F3-4230BDC8BFF9}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaelcbokiiegnoclmj"=hex:6b,61,62,63,62,6c,64,70,70,6b,63,6f,69,6b,69,6d,6c,66,
6e,68,6d,70,00,00
"hagliobijbilclfn"=hex:6b,61,62,63,62,6c,64,70,70,6b,63,6f,69,6b,69,6d,6c,66,
6e,68,6d,70,00,00
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(888)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2011-12-20 00:43:43
ComboFix-quarantined-files.txt 2011-12-19 23:43
ComboFix2.txt 2011-12-18 23:03
.
Pre-Run: 29.189.902.336 bytes libres
Post-Run: 29.219.123.200 bytes libres
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[Boot Loader]
Timeout=2
Default=c:\$win_nt$.~bt\BOOTSECT.DAT
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
c:\$win_nt$.~bt\BOOTSECT.DAT="Instalar Microsoft Windows XP Professional"
.
- - End Of File - - 032058C85374647AC6C0DD22E9E56BC6
:thumbup:

Things any better ?




Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please






OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Thank you. A hard work!!! I´ll send a donation!!!

ComboFix 11-12-19.03 - Mario 20/12/2011 0:33.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.2047.1446 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Escritorio\ComboFix.exe
Command switches used :: c:\documents and settings\Mario\Escritorio\CFScript.txt
* Created a new restore point
.
FILE ::
"c:\windows\system32\systna.dll"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Thumbs.db
c:\windows\alcrmv.exe
c:\windows\system32\systna.dll
c:\windows\ufdata2000.log
.
.
((((((((((((((((((((((((( Files Created from 2011-11-19 to 2011-12-19 )))))))))))))))))))))))))))))))
.
.
2011-12-16 00:40 . 2011-12-16 00:40 ——– d–h–w- c:\windows\PIF
2011-12-16 00:24 . 2011-12-16 00:24 ——– d—–w- c:\documents and settings\Administrador\Configuración local\Datos de programa\Mozilla
2011-12-16 00:23 . 2011-12-16 00:23 ——– d-sh–w- c:\documents and settings\Administrador\IETldCache
2011-12-03 16:51 . 2011-12-03 16:51 ——– d—–w- c:\archivos de programa\iPod
2011-12-03 16:51 . 2011-12-03 16:52 ——– d—–w- c:\archivos de programa\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-17 17:49 . 2011-05-14 11:38 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 13:29 . 2011-10-24 13:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 13:29 . 2011-10-24 13:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-20 23:26 . 2011-10-20 23:26 94208 —-a-w- c:\windows\system32\dpl100.dll
2011-10-09 20:14 . 2010-04-26 14:26 52096 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2011-10-09 20:14 . 2010-04-26 14:26 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-10-09 20:14 . 2010-04-26 14:26 30592 —-a-w- c:\windows\system32\LMIport.dll
2011-10-09 20:14 . 2010-04-26 14:26 87424 —-a-w- c:\windows\system32\LMIinit.dll
2011-11-09 21:04 . 2011-04-30 09:48 134104 —-a-w- c:\archivos de programa\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-18_21.43.05 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-19 22:01 . 2011-12-19 22:01 16384 c:\windows\Temp\Perflib_Perfdata_148.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\archivos de programa\myBabylon_English\prxtbmyB0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 —-a-w- c:\archivos de programa\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
2011-01-17 14:54 175912 —-a-w- c:\archivos de programa\myBabylon_English\prxtbmyB0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}"= "c:\archivos de programa\myBabylon_English\prxtbmyB0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\archivos de programa\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7}"= "c:\archivos de programa\myBabylon_English\prxtbmyB0.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\archivos de programa\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-24 401491]
"NokiaOviSuite2"="c:\archivos de programa\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2011-07-13 966712]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\archivos de programa\Archivos comunes\Nokia\MPlatform\NokiaMServer" [X]
"ATIPTA"="c:\archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-11-30 344064]
"Acrobat Assistant 7.0"="c:\archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"SSBkgdUpdate"="c:\archivos de programa\Archivos comunes\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\archivos de programa\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-18 57393]
"IndexSearch"="c:\archivos de programa\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-18 40960]
"BrMfcWnd"="c:\archivos de programa\Brother\Brmfcmon\BrMfcWnd.exe" [2006-06-28 622592]
"ControlCenter3"="c:\archivos de programa\Brother\ControlCenter3\brctrcen.exe" [2006-06-29 77824]
"PRONoMgr.exe"="c:\archivos de programa\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"StartCCC"="c:\archivos de programa\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-29 61440]
"UMonit"="c:\windows\system32\UMonit.exe" [2007-06-18 200704]
"LogMeIn GUI"="c:\archivos de programa\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"MacDrive 8 application"="c:\archivos de programa\Mediafour\MacDrive 8\MacDrive.exe" [2009-06-15 202328]
"Getting started with MacDrive 8"="c:\archivos de programa\Mediafour\MacDrive 8\MDGetStarted.exe" [2009-03-31 141312]
"AppleSyncNotifier"="c:\archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"Google Updater"="c:\archivos de programa\Google\Google Updater\GoogleUpdater.exe" [2011-09-24 161336]
"APSDaemon"="c:\archivos de programa\Archivos comunes\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"DivXUpdate"="c:\archivos de programa\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376]
"iTunesHelper"="c:\archivos de programa\iTunes\iTunesHelper.exe" [2011-11-12 421736]
"QuickTime Task"="c:\archivos de programa\QuickTime\QTTask.exe" [2011-10-24 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Mario\Menú Inicio\Programas\Inicio\
Herramienta de búsqueda de soportes de PMB.lnk - c:\archivos de programa\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2010-7-13 333088]
.
c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\
Exif Launcher S.lnk - c:\archivos de programa\FinePixViewerS\QuickDCF2.exe [2009-7-16 303104]
Microsoft Office.lnk - c:\archivos de programa\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2011-10-09 20:14 87424 —-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menú Inicio^Programas^Inicio^Inicio rápido de Adobe Acrobat.lnk]
path=c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\Inicio rápido de Adobe Acrobat.lnk
backup=c:\windows\pss\Inicio rápido de Adobe Acrobat.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Mario^Menú Inicio^Programas^Inicio^Adobe Gamma.lnk]
path=c:\documents and settings\Mario\Menú Inicio\Programas\Inicio\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
2007-11-17 15:51 221056 —-a-w- c:\archivos de programa\Alcohol Soft\Alcohol 120\AxCmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-11-11 09:57 1451520 —-a-w- c:\archivos de programa\Nokia\Nokia PC Suite 7\PCSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-10-13 07:27 17351304 —-a-r- c:\archivos de programa\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-01-03 02:40 39408 —-a-w- c:\archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Archivos de programa\\Microsoft ActiveSync\\wcescomm.exe"=
"c:\\Archivos de programa\\Microsoft ActiveSync\\WcesMgr.exe"=
"c:\\Archivos de programa\\Digital Rapids\\Stream\\DRBatchServer.exe"=
"c:\\Archivos de programa\\UltraVNC\\vncviewer.exe"=
"c:\\Archivos de programa\\Nokia\\Nokia Ovi Suite\\NokiaOviSuite.exe"=
"c:\\Archivos de programa\\Archivos comunes\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Archivos de programa\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Documents and Settings\\Mario\\Mis documentos\\Descargas\\VideoConverter_Setup.exe"=
"c:\\Archivos de programa\\IRISnotes\\Easy note taker.exe"=
"c:\\Archivos de programa\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Archivos de programa\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Archivos de programa\\Bonjour\\mDNSResponder.exe"=
"c:\\Archivos de programa\\Skype\\Phone\\Skype.exe"=
"c:\\Archivos de programa\\iTunes\\iTunes.exe"=
"c:\\Archivos de programa\\Archivos comunes\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
.
R0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [28/09/2009 14:02 259176]
R0 MDPMGRNT;MacDrive partition driver;c:\windows\system32\drivers\MDPMGRNT.SYS [31/07/2009 16:07 27488]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [07/12/2008 19:02 721904]
R1 tidnet;TID NDIS Protocol Driver;c:\windows\system32\drivers\tidnet.sys [16/08/2007 9:19 19200]
R2 BT848;AVerMedia, AVerTV WDM Video Capture;c:\windows\system32\drivers\BT848.sys [30/11/2009 16:29 261696]
R2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;c:\windows\system32\drivers\bttuner.sys [30/11/2009 16:29 22016]
R2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;c:\windows\system32\drivers\btxbar.sys [01/12/2009 23:24 13312]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\archivos de programa\LogMeIn\x86\LMIGuardianSvc.exe [29/09/2010 21:50 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\archivos de programa\LogMeIn\x86\rainfo.sys [11/08/2008 11:41 12856]
R2 MacDrive8Service;MacDrive 8 service;c:\archivos de programa\Mediafour\MacDrive 8\MacDrive8Service.exe [23/09/2009 13:13 150528]
R3 RSUSBCCID;Realtek Smartcard Reader Driver;c:\windows\system32\drivers\RtsUCcid.sys [09/11/2010 11:56 44032]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 12:16 130384]
S2 DRCHypersonic;DRC Hypersonic;c:\archivos de programa\Archivos comunes\Digital Rapids\hypersonic-service.exe [20/01/2009 11:52 135168]
S2 DRCRMIRegistry;DRC RMI Registry;c:\archivos de programa\Archivos comunes\Digital Rapids\rmi-registry-service.exe [20/01/2009 11:52 135168]
S2 gupdate;Servicio Google Update (gupdate);c:\archivos de programa\Google\Update\GoogleUpdate.exe [17/09/2009 23:57 133104]
S3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [26/04/2010 22:30 223232]
S3 CTL511Plus;Video Blaster WebCam 3/WebCam Plus (WDM);c:\windows\system32\drivers\webc3vid.sys [14/09/2000 13:00 159867]
S3 DRCStreamServer;DRC Stream Server;c:\archivos de programa\Digital Rapids\Stream\stream-server-service.exe [20/01/2009 11:52 135168]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\archivos de programa\MAGIX\Common\Database\bin\fbserver.exe –> c:\archivos de programa\MAGIX\Common\Database\bin\fbserver.exe [?]
S3 gupdatem;Servicio de Google Update (gupdatem);c:\archivos de programa\Google\Update\GoogleUpdate.exe [17/09/2009 23:57 133104]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [21/07/2011 23:49 137600]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [21/07/2011 23:49 8576]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [17/12/2007 20:00 11776]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [12/10/2007 15:04 99200]
S3 NWVSCR;Novatel Wireless USB SmartCardReader Driver;c:\windows\system32\drivers\NWVSCR.sys [19/09/2007 10:42 24448]
S3 RtsUIr;Realtek IR Driver;c:\windows\system32\drivers\RtsUIr.sys [09/11/2010 11:56 17536]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 12:16 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\archivos de programa\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2011-12-06 c:\windows\Tasks\Google Software Updater.job
- c:\archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-03 05:37]
.
2011-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\archivos de programa\Google\Update\GoogleUpdate.exe [2009-09-17 22:56]
.
2011-12-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\archivos de programa\Google\Update\GoogleUpdate.exe [2009-09-17 22:56]
.
2011-07-12 c:\windows\Tasks\{61AE66C1-58C9-4CA0-8F29-A02BDEF5C95E}_ALEMANIA-INVESP_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-09-02 c:\windows\Tasks\{715A563D-A2B3-42D0-956F-C0C1603ECC71}_ALEMANIA-INVESP_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-07-12 c:\windows\Tasks\{AC43BDB6-0D30-4A95-9388-F0720DBF55EE}_ALEMANIA-2E60C7_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-12-19 c:\windows\Tasks\{C94FF516-9C6F-44DA-9583-7F16FE139A37}_ALEMANIA-2E60C7_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-09-02 c:\windows\Tasks\{DF04A656-9CC6-4A35-A7D3-010DADB305A0}_ALEMANIA-2E60C7_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
2011-12-19 c:\windows\Tasks\{E0886217-9102-4854-BD85-D523D16A21A8}_ALEMANIA-INVESP_Mario.job
- c:\windows\system32\mobsync.exe [2008-04-14 12:00]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.es/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Convertir a PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir a PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir destino de vínculo a PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir destino de vínculo en archivo PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir selección a archivo PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir selección a PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir vínculos seleccionados a PDF de Adobe - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir vínculos seleccionados a PDF existente - c:\archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xportar a Microsoft Excel - c:\archiv~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
DPF: {2D0CBE69-DAFC-11D3-96D2-0020182E2E27} - hxxp://194.140.3.43/comun/download/wcf-pc-25_0_0_2.cab
FF - ProfilePath - c:\documents and settings\Mario\Datos de programa\Mozilla\Firefox\Profiles\12tcnlfq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=14542
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.es/search?q=
FF - prefs.js: keyword.URL - chrome://browser-region/locale/region.properties
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-20 00:40
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
UMonit = c:\windows\system32\UMonit.exe?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-507921405-1897051121-1177238915-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8E44A2F0-1EE3-3E9B-D9F3-4230BDC8BFF9}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaelcbokiiegnoclmj"=hex:6b,61,62,63,62,6c,64,70,70,6b,63,6f,69,6b,69,6d,6c,66,
6e,68,6d,70,00,00
"hagliobijbilclfn"=hex:6b,61,62,63,62,6c,64,70,70,6b,63,6f,69,6b,69,6d,6c,66,
6e,68,6d,70,00,00
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(888)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2011-12-20 00:43:43
ComboFix-quarantined-files.txt 2011-12-19 23:43
ComboFix2.txt 2011-12-18 23:03
.
Pre-Run: 29.189.902.336 bytes libres
Post-Run: 29.219.123.200 bytes libres
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[Boot Loader]
Timeout=2
Default=c:\$win_nt$.~bt\BOOTSECT.DAT
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
c:\$win_nt$.~bt\BOOTSECT.DAT="Instalar Microsoft Windows XP Professional"
.
- - End Of File - - 032058C85374647AC6C0DD22E9E56BC6

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI