This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ping.exe consume 100% CPU [Solved]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

DDS.txt
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_24
Run by [removed] at 19:28:47 on 2012-01-17
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.34.3082.18.3328.2302 [GMT 0:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\nHancer\nHancerService.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
C:\Windows\System32\ping.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [NVIDIA nTune] "c:\program files\nvidia corporation\ntune\nTuneCmd.exe" clear
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [amd_dc_opt] c:\program files\amd\dual-core optimizer\amd_dc_opt.exe
mRun: [PlusService] c:\program files\yuna software\messenger plus!\PlusService.exe
dRun: [NVIDIA nTune] "c:\program files\nvidia corporation\ntune\nTuneCmd.exe" clear
mPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xportar; a Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: Interfaces\{A733C2F9-0BF0-429B-BE05-780883D0D889} : DhcpNameServer = [removed] [removed]
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\eros\appdata\roaming\mozilla\firefox\profiles\lbyuiugg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.es
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\users\eros\appdata\local\google\update\1.3.21.79\npGoogleUpdate3.dll
.
============= SERVICES / DRIVERS ===============
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2011-8-15 1361288]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-9-23 2253120]
R2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2011-10-15 381248]
R3 3xHybrid;Philips SAA713x PCI Card;c:\windows\system32\drivers\3xHybrid.sys [2006-11-22 1121536]
R3 hxctlflt;hxctlflt;c:\windows\system32\drivers\hxctlflt.sys [2011-11-18 99968]
R3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM108.sys [2007-6-28 1310720]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-11-17 15872]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-11-17 52224]
S4 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-13 20992]
.
=============== Created Last 30 ================
.
2012-01-17 00:55:21 356352 —-a-w- c:\windows\system32\nvusmb.exe
2012-01-17 00:55:06 356352 —-a-w- c:\windows\system32\NVUNINST.EXE
2012-01-15 22:12:36 ——– d—–w- c:\users\eros\appdata\local\MooExt
2012-01-15 21:33:31 ——– d—–w- c:\users\eros\appdata\local\ElevatedDiagnostics
2012-01-15 17:50:26 ——– d—–w- c:\users\eros\appdata\roaming\QuickScan
2012-01-15 17:32:36 3967856 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-01-15 17:32:36 3912560 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-01-15 17:32:31 534528 —-a-w- c:\windows\system32\EncDec.dll
2012-01-15 17:32:30 38912 —-a-w- c:\windows\system32\csrsrv.dll
2012-01-15 16:54:40 ——– d—–w- c:\users\eros\appdata\roaming\Malwarebytes
2012-01-15 16:54:33 ——– d—–w- c:\programdata\Malwarebytes
2012-01-15 16:54:32 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-01-15 16:54:32 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-01-15 02:28:08 ——– d-sh–w- C:\$RECYCLE.BIN
2012-01-15 02:25:13 ——– d—–w- c:\users\eros\appdata\local\temp
2012-01-15 02:20:43 98816 —-a-w- c:\windows\sed.exe
2012-01-15 02:20:43 518144 —-a-w- c:\windows\SWREG.exe
2012-01-15 02:20:43 256000 —-a-w- c:\windows\PEV.exe
2012-01-15 02:20:43 208896 —-a-w- c:\windows\MBR.exe
2012-01-15 02:19:53 ——– d—–w- C:\ComboFix
2012-01-14 19:55:25 ——– d—–w- c:\users\eros\appdata\roaming\NationRed
2012-01-12 12:16:09 ——– d—–w- c:\programdata\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
2012-01-12 00:31:43 ——– d—–w- c:\program files\rFactor2
2012-01-12 00:23:59 ——– d—–w- c:\users\eros\appdata\roaming\F8F6B
2012-01-11 00:52:01 ——– d—–w- c:\users\eros\appdata\local\SanctionedMedia
2012-01-10 23:01:02 ——– d—–w- c:\users\eros\DoctorWeb
2012-01-08 19:32:57 ——– d—–w- c:\program files\uTorrent
2012-01-08 19:32:01 ——– d—–w- c:\users\eros\appdata\roaming\uTorrent
2012-01-07 16:15:14 ——– d—–w- c:\windows\system32\RTCOM
2012-01-07 16:04:56 17488 —-a-w- c:\windows\gdrv.sys
2012-01-07 16:04:54 753664 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iKernel.dll
2012-01-07 16:04:54 69714 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\ctor.dll
2012-01-07 16:04:54 5632 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\DotNetInstaller.exe
2012-01-07 16:04:54 331908 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\setup.dll
2012-01-07 16:04:54 32768 —-a-w- c:\program files\common files\installshield\professional\runtime\Objectps.dll
2012-01-07 16:04:54 274432 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iscript.dll
2012-01-07 16:04:54 200836 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iGdi.dll
2012-01-07 16:04:54 184320 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iuser.dll
2012-01-06 21:19:52 327168 —-a-w- c:\windows\IsUninst.exe
2012-01-02 20:34:28 ——– d—–w- c:\programdata\Electronic Arts
2012-01-02 20:34:28 ——– d—–w- c:\programdata\EA Core
2012-01-02 20:33:04 ——– d–h–w- c:\program files\common files\EAInstaller
2011-12-31 19:09:46 ——– d—–w- C:\$AVG
2011-12-31 18:26:03 ——– d—–w- c:\program files\EA
2011-12-31 18:25:57 ——– d—–w- c:\program files\AVG
2011-12-31 13:32:08 ——– d—–w- c:\users\eros\appdata\local\LogMeIn Hamachi
2011-12-31 13:31:46 ——– d—–w- c:\program files\LogMeIn Hamachi
2011-12-30 20:13:53 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll
2011-12-30 20:13:53 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll
2011-12-30 20:13:53 43992 —-a-w- c:\program files\mozilla firefox\mozutils.dll
2011-12-30 20:13:52 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll
2011-12-27 20:21:48 ——– d—–w- C:\Down
2011-12-27 20:21:31 ——– d—–w- C:\Perfect World Entertainment
.
==================== Find3M ====================
.
2011-11-24 04:25:27 2342912 —-a-w- c:\windows\system32\win32k.sys
2011-11-22 21:01:28 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-19 14:01:00 67072 —-a-w- c:\windows\system32\packager.dll
2011-11-17 17:53:42 152576 —-a-w- c:\windows\system32\msclmd.dll
2011-11-17 05:41:52 67440 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2011-11-17 05:41:51 134000 —-a-w- c:\windows\system32\drivers\ksecpkg.sys
2011-11-17 05:39:24 369352 —-a-w- c:\windows\system32\drivers\cng.sys
2011-11-17 05:38:39 1288472 —-a-w- c:\windows\system32\ntdll.dll
2011-11-17 05:35:02 314880 —-a-w- c:\windows\system32\webio.dll
2011-11-17 05:34:55 15872 —-a-w- c:\windows\system32\sspisrv.dll
2011-11-17 05:34:55 100352 —-a-w- c:\windows\system32\sspicli.dll
2011-11-17 05:34:52 224768 —-a-w- c:\windows\system32\schannel.dll
2011-11-17 05:34:52 22016 —-a-w- c:\windows\system32\secur32.dll
2011-11-17 05:32:51 1038848 —-a-w- c:\windows\system32\lsasrv.dll
2011-11-17 05:29:50 22528 —-a-w- c:\windows\system32\lsass.exe
2011-11-05 04:35:00 981504 —-a-w- c:\windows\system32\wininet.dll
2011-11-05 04:26:03 2048 —-a-w- c:\windows\system32\tzres.dll
2011-11-05 02:48:51 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2011-10-31 15:53:36 939368 —-a-w- c:\windows\system32\flash.ocx
2011-10-26 04:32:11 514560 —-a-w- c:\windows\system32\qdvd.dll
2011-10-26 04:32:11 1328128 —-a-w- c:\windows\system32\quartz.dll
.
============= FINISH: 19:29:30,48 ===============


Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows 7 Ultimate
Boot Device: \Device\HarddiskVolume3
Install Date: 29/09/2010 21:01:07
System Uptime: 17/01/2012 19:20:45 (0 hours ago)
.
Motherboard: Gigabyte Technology Co., Ltd. | | M57SLI-S4
Processor: AMD Athlon™ 64 X2 Dual Core Processor 4200+ | Socket M2 | 2200/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 233 GiB total, 41,682 GiB free.
D: is FIXED (NTFS) - 149 GiB total, 86,64 GiB free.
E: is CDROM ()
F: is FIXED (NTFS) - 932 GiB total, 724,238 GiB free.
G: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP186: 14/01/2012 19:53:51 - Se ha instalado DirectX
RP187: 14/01/2012 22:11:17 - Installed LOST PLANET 2.
RP188: 14/01/2012 22:35:10 - Installed LOST PLANET 2
RP189: 15/01/2012 2:18:57 - Removed AVG 2012
RP191: 15/01/2012 2:20:43 - Removed AVG 2012
RP192: 15/01/2012 17:33:50 - Windows Update
RP194: 17/01/2012 0:52:00 - Configurado NVIDIA nTune
RP196: 17/01/2012 0:59:58 - Configurado NVIDIA nTune
.
==== Installed Programs ======================
.
@BIOS
Actualización de NVIDIA 1.5.20
Adobe AIR
Adobe Community Help
Adobe Digital Editions
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 7.0.8 - Español
AdobeColorCommonSetRGB
AdWare SpyWare SE
Akamai NetSession Interface
Anti-reCAPTCHA v2.07 JD
Apple Application Support
Apple Software Update
ArcaniA – Gothic 4
µTorrent
AviSynth 2.5
Battlefield 3™
BMW M3 Challenge
CCleaner
CDBurnerXP
Cheat Engine 5.6.1
Compresor WinRAR
Counter-Strike: Source
Darksiders
DarksidersInstaller
Diablo II
DiRT 3
Dual-Core Optimizer
Endurance Series by EnduRacers - v1 SP1 FULL
F1 2004 RH FINAL
F1 2010 WCP
F1 2011
Ferrari Virtual Academy version 1.3
Fraps
FreeArc 0.666
Gigabyte PCI TV Card
Google Chrome
Gtk# for .Net 2.12.10
GTR Evolution
Hercules Classic Link
Hercules Webcam Station Evolution SE
Herramienta de carga de Windows Live
Java Auto Updater
Java™ 6 Update 24
JDownloader
JDownloader 0.9
K-Lite Codec Pack 6.6.0 (Full)
K!TV
Killing Floor
Legend: Hand of God
Logitech Gaming Software 5.08
LogMeIn Hamachi
LOST PLANET 2
Magicka
Malwarebytes Anti-Malware versión 1.60.0.1800
Messenger Plus! 5
Microsoft .NET Compact Framework 2.0 SP2
Microsoft .NET Compact Framework 3.5
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile ESN Language Pack
Microsoft .NET Framework 4 Extended
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft Application Error Reporting
Microsoft ASP.NET MVC 2
Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
Microsoft Choice Guard
Microsoft Device Emulator, versión 3.0 - ESN
Microsoft Document Explorer 2008
Microsoft Document Explorer 2008 Language Pack - ESN
Microsoft Expression Blend 3 SDK
Microsoft Expression Blend SDK for .NET 4
Microsoft Expression Blend SDK for Silverlight 4
Microsoft Games for Windows - LIVE Redistributable
Microsoft Games for Windows Marketplace
Microsoft Help Viewer 1.0
Microsoft Office 2003 Web Components
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft Sync Framework Runtime v1.0 SP1 (x86)
Microsoft Sync Framework SDK v1.0 SP1
Microsoft Sync Framework Services v1.0 SP1 (x86)
Microsoft Team Foundation Server 2010 Object Model - ENU
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319
Microsoft Visual F# 2.0 Runtime
Microsoft Visual Studio 2005 Tools for Office Runtime
Microsoft XNA Framework Redistributable 3.1
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mozilla Firefox 9.0.1 (x86 es-ES)
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
nHancer
NVIDIA 3D Vision Controller Driver
NVIDIA Controlador de 3D Vision 285.62
NVIDIA Controlador de gráficos 285.62
NVIDIA Controlador de la controladora 3D Vision 285.62
NVIDIA Drivers
NVIDIA Install Application
NVIDIA nTune
NVIDIA PhysX
NVIDIA Software del sistema PhysX 9.11.0621
NVIDIA Stereoscopic 3D Driver
NVIDIA Update Components
OpenAL
Panel de control de NVIDIA 285.62
Paquete de compatibilidad para 2007 Office system
Paquete de idioma de Microsoft .NET Framework 4 Client Profile ESN
Paquete de idioma de Microsoft Document Explorer 2008 - ESN
Paquete de idioma de Visual Studio Tools para Office system 3.0 Runtime - ESN
Pirates, Vikings, & Knights II
PSP Video 9 6
QuickTime
RACE 07
RACE 07 - Andy Priaulx Crowne Plaza Expansion
RACE 07 - Formula RaceRoom Add-On
Rapture3D 2.4.8 Game
Real Alternative 1.8.2
Realtek High Definition Audio Driver
Remove Empty Directories 2.1
rFactor2
Rusty Hearts
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Paquete de idioma de Microsoft .NET Framework 4 Client Profile ESN (KB2478663)
Security Update for Paquete de idioma de Microsoft .NET Framework 4 Client Profile ESN (KB2518870)
Skype Click to Call
Skype™ 5.5
Skyrim
Star Wars: Knights of the Old Republic
STCC II
Steam
Team Fortress 2
TeamSpeak 3 Client
The Scourge Project: Episode 1 and 2
Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
Visual Studio 2005 Tools for Office Second Edition Runtime
Visual Studio Tools for the Office system 3.0 Runtime
Visual Studio Tools for the Office system 3.0 Runtime Language Pack - ESN
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live ID Sign-in Assistant
Windows Live Messenger
Windows Media Player Firefox Plugin
World of Warcraft
.
==== Event Viewer Messages From Past Week ========
.
17/01/2012 19:23:18, Error: Microsoft-Windows-DNS-Client [1012] - Error al intentar leer el archivo local de hosts.
17/01/2012 19:21:40, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
17/01/2012 19:21:23, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
17/01/2012 19:21:20, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
17/01/2012 19:21:19, Error: Service Control Manager [7000] - El servicio SupportSoft RemoteAssist no pudo iniciarse debido al siguiente error: El sistema no puede encontrar la ruta especificada.
17/01/2012 17:55:57, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
17/01/2012 17:55:38, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
17/01/2012 17:55:34, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
17/01/2012 15:57:32, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
17/01/2012 15:57:18, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
17/01/2012 15:57:15, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
17/01/2012 13:35:55, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
17/01/2012 13:35:39, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
17/01/2012 13:35:36, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
17/01/2012 12:10:33, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
17/01/2012 12:10:23, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
17/01/2012 0:58:18, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
17/01/2012 0:58:02, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
16/01/2012 19:43:26, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
16/01/2012 19:43:17, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
16/01/2012 19:43:14, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
16/01/2012 14:46:51, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
16/01/2012 14:46:43, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
16/01/2012 14:46:39, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
16/01/2012 12:55:33, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
16/01/2012 12:55:16, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
16/01/2012 12:55:08, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 20:44:10, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
15/01/2012 20:43:56, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 20:43:49, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 2:33:00, Error: Microsoft-Windows-WindowsUpdateClient [20] - Error de instalación: error de Windows al instalar la siguiente actualización, error 0x80242016: Actualización de seguridad para Windows 7 (KB979688).
15/01/2012 2:28:14, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
15/01/2012 2:27:44, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 2:27:19, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 2:17:17, Error: Service Control Manager [7031] - El servicio WatchDog de AVG terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 0 milisegundos: Reiniciar el servicio.
15/01/2012 2:16:58, Error: Service Control Manager [7031] - El servicio WatchDog de AVG terminó inesperadamente. Esto se ha repetido 1 veces. Se realizará la siguiente acción correctora en 0 milisegundos: Reiniciar el servicio.
15/01/2012 17:48:35, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
15/01/2012 17:48:10, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 17:16:03, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
15/01/2012 17:15:46, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 17:15:43, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 15:54:57, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
15/01/2012 15:54:44, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 15:54:41, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 15:54:36, Error: Service Control Manager [7000] - El servicio MySQL no pudo iniciarse debido al siguiente error: El sistema no puede encontrar el archivo especificado.
15/01/2012 15:21:13, Error: VDS Basic Provider [1] - Error inesperado. Código de error: 490@01010004
15/01/2012 13:28:48, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
15/01/2012 13:28:30, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 13:28:27, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 1:19:46, Error: Service Control Manager [7034] - El servicio LogMeIn Hamachi Tunneling Engine se terminó de manera inesperada. Esto ha sucedido 1 veces.
15/01/2012 0:23:36, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
15/01/2012 0:23:18, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
15/01/2012 0:23:13, Error: Service Control Manager [7003] - El servicio Módulos de creación de claves de IPsec para IKE y AuthIP depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
15/01/2012 0:23:13, Error: Service Control Manager [7003] - El servicio Agente de directiva IPsec depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
14/01/2012 5:30:39, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
14/01/2012 5:30:11, Error: Service Control Manager [7003] - El servicio Agente de directiva IPsec depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
14/01/2012 5:30:03, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
14/01/2012 5:29:58, Error: Service Control Manager [7003] - El servicio Módulos de creación de claves de IPsec para IKE y AuthIP depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
14/01/2012 16:42:10, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
14/01/2012 16:41:52, Error: Service Control Manager [7003] - El servicio Agente de directiva IPsec depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
14/01/2012 16:41:49, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
14/01/2012 16:41:45, Error: Service Control Manager [7003] - El servicio Módulos de creación de claves de IPsec para IKE y AuthIP depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
13/01/2012 22:46:19, Error: Service Control Manager [7024] - El servicio Superfetch se cerró con el error específico de servicio La operación se completó correctamente..
13/01/2012 22:46:03, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
13/01/2012 22:45:33, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
13/01/2012 22:45:33, Error: Service Control Manager [7003] - El servicio Agente de directiva IPsec depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
13/01/2012 22:45:26, Error: Service Control Manager [7003] - El servicio Módulos de creación de claves de IPsec para IKE y AuthIP depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
13/01/2012 16:38:28, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
13/01/2012 16:38:10, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
13/01/2012 16:38:10, Error: Service Control Manager [7003] - El servicio Agente de directiva IPsec depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
13/01/2012 16:38:05, Error: Service Control Manager [7003] - El servicio Módulos de creación de claves de IPsec para IKE y AuthIP depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
12/01/2012 19:53:49, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
12/01/2012 19:53:06, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
12/01/2012 19:53:05, Error: Service Control Manager [7003] - El servicio Agente de directiva IPsec depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
12/01/2012 19:53:00, Error: Service Control Manager [7003] - El servicio Módulos de creación de claves de IPsec para IKE y AuthIP depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
12/01/2012 17:18:34, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
12/01/2012 17:17:44, Error: Service Control Manager [7003] - El servicio Agente de directiva IPsec depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
12/01/2012 17:17:43, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
12/01/2012 17:17:36, Error: Service Control Manager [7003] - El servicio Módulos de creación de claves de IPsec para IKE y AuthIP depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
12/01/2012 17:17:22, Error: Microsoft-Windows-WER-SystemErrorReporting [1001] - El equipo se reinició después de una comprobación de errores. La comprobación de errores fue: 0x0000000a (0xa95e56c0, 0x00000002, 0x00000000, 0x832bbee5). Se guardó un volcado en: C:\Windows\MEMORY.DMP. Id. de informe: 011212-61328-01.
11/01/2012 7:18:29, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
11/01/2012 7:17:49, Error: Service Control Manager [7003] - El servicio Agente de directiva IPsec depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
11/01/2012 7:17:35, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
11/01/2012 7:17:29, Error: Service Control Manager [7003] - El servicio Módulos de creación de claves de IPsec para IKE y AuthIP depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
11/01/2012 22:14:25, Error: Service Control Manager [7024] - El servicio Escucha de Grupo Hogar se cerró con el error específico de servicio %%-2147023143.
11/01/2012 22:14:08, Error: Service Control Manager [7003] - El servicio Agente de directiva IPsec depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
11/01/2012 22:13:59, Error: Service Control Manager [7023] - El servicio Examinador de equipos se cerró con el siguiente error: El servicio especificado no existe como servicio instalado.
11/01/2012 22:13:53, Error: Service Control Manager [7003] - El servicio Módulos de creación de claves de IPsec para IKE y AuthIP depende del siguiente servicio: BFE. Este servicio podría no estar instalado.
10/01/2012 23:35:23, Error: Disk [11] - El controlador detectó un error de controladora en \Device\Harddisk3\DR3.
.
==== End Of File ===========================



GMER.EXE SCAN

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-17 19:42:57
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\00000067 HDT72252 rev.V44O
Running: gmer.exe; Driver: C:\Users\Eros\AppData\Local\Temp\kxldapoc.sys


—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwSaveKey + 13D1 83047369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 83080D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? System32\Drivers\spig.sys El sistema no puede encontrar la ruta especificada. !
.text csc.sys 9179B000 69 Bytes [90, 90, 90, 90, 90, 8B, FF, …]
.text csc.sys 9179B046 52 Bytes [D0, 7B, 91, 81, F9, 00, D0, …]
.text csc.sys 9179B07C 170 Bytes [80, 7D, FF, 00, 0F, 85, 5D, …]
.text csc.sys 9179B127 50 Bytes [4D, D8, 8D, 0C, 59, 89, 4D, …]
.text csc.sys 9179B15A 64 Bytes [FF, 15, 18, A0, 7B, 91, 84, …]
.text …
? C:\Windows\system32\drivers\csc.sys suspicious PE modification
.text USBPORT.SYS!DllUnload 91A42D81 5 Bytes JMP 8732A1D8
.text acpzev0o.SYS 92443000 12 Bytes [44, 08, 42, 83, EE, 06, 42, …]
.text acpzev0o.SYS 9244300D 9 Bytes [E7, 41, 83, 48, 0B, 42, 83, …] {OUT 0x41, EAX; OR DWORD [EAX+0xb], 0x42; ADD DWORD [EAX], 0x0}
.text acpzev0o.SYS 92443017 170 Bytes [00, DE, D7, 11, 8C, E6, D5, …]
.text acpzev0o.SYS 924430C3 8 Bytes [00, 00, 00, 00, 00, 00, 00, …] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
.text acpzev0o.SYS 924430CE 4 Bytes [00, 00, 00, 00] {ADD [EAX], AL; ADD [EAX], AL}
.text …
.text apm7lcrb.SYS 9247A000 12 Bytes [44, 08, 42, 83, EE, 06, 42, …]
.text apm7lcrb.SYS 9247A00D 9 Bytes [E7, 41, 83, 48, 0B, 42, 83, …] {OUT 0x41, EAX; OR DWORD [EAX+0xb], 0x42; ADD DWORD [EAX], 0x0}
.text apm7lcrb.SYS 9247A017 170 Bytes [00, DE, D7, 11, 8C, E6, D5, …]
.text apm7lcrb.SYS 9247A0C3 8 Bytes [00, 00, 00, 00, 00, 00, 00, …] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
.text apm7lcrb.SYS 9247A0CE 4 Bytes [00, 00, 00, 00] {ADD [EAX], AL; ADD [EAX], AL}
.text …
PAGE peauth.sys A333B02C 102 Bytes JMP 8577158A
? C:\Users\Eros\AppData\Local\Temp\mbr.sys El sistema no puede encontrar el archivo especificado. !

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\system32\svchost.exe[988] ntdll.dll!NtProtectVirtualMemory 77905F18 5 Bytes JMP 0063000A
.text C:\Windows\system32\svchost.exe[988] ntdll.dll!NtWriteVirtualMemory 77906A98 5 Bytes JMP 0068000A
.text C:\Windows\system32\svchost.exe[988] ntdll.dll!KiUserExceptionDispatcher 77906FE8 5 Bytes JMP 0062000A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] kernel32.dll!LockResource 76F402D9 5 Bytes JMP 280A7AF0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] kernel32.dll!CreateEventA 76F41662 5 Bytes JMP 280A6FF0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] kernel32.dll!FindResourceExW 76F443B2 5 Bytes JMP 280A7830 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] kernel32.dll!FindResourceW 76F454CF 5 Bytes JMP 280A77B0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] kernel32.dll!SizeofResource 76F454ED 5 Bytes JMP 280A7A80 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] kernel32.dll!LoadResource 76F49C72 5 Bytes JMP 280A79D0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] kernel32.dll!FindResourceExA 76F4A3AD 7 Bytes JMP 280A7940 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] kernel32.dll!FindResourceA 76F4A475 5 Bytes JMP 280A78B0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] ADVAPI32.dll!CryptDecrypt 77223178 5 Bytes JMP 280A6B50 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] ADVAPI32.dll!CryptDeriveKey 77223188 5 Bytes JMP 280A6AF0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] USER32.dll!SetWindowPlacement 77467F78 5 Bytes JMP 280AD520 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] USER32.dll!SetWindowRgn 774699EC 7 Bytes JMP 280AD5C0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] USER32.dll!CreateWindowExW 7746EC7C 5 Bytes JMP 280A93D0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] USER32.dll!LoadIconW 7746F142 5 Bytes JMP 280ADE40 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] USER32.dll!LoadImageW 774712EB 5 Bytes JMP 280ADCC0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] USER32.dll!GetWindowLongW 774761B8 7 Bytes JMP 280ADF70 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] USER32.dll!PeekMessageW 7747634A 5 Bytes JMP 280AA150 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] USER32.dll!TrackPopupMenuEx 77494832 5 Bytes JMP 280AA870 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] USER32.dll!CreateDialogParamW 77495630 5 Bytes JMP 280AD670 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] USER32.dll!MessageBoxIndirectW 774BE963 5 Bytes JMP 280AD8A0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] WS2_32.dll!closesocket 77063918 5 Bytes JMP 280B5910 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] WS2_32.dll!WSASend 77064406 5 Bytes JMP 280B5740 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] WS2_32.dll!recv 77066B0E 5 Bytes JMP 280B52F0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] WS2_32.dll!send 77066F01 5 Bytes JMP 280B55D0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] WS2_32.dll!WSARecv 77067089 5 Bytes JMP 280B5420 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] SHELL32.dll!Shell_NotifyIconW 75F801C1 5 Bytes JMP 280A87C0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] ole32.dll!CoRegisterClassObject 76DB21E1 5 Bytes JMP 280A7E50 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] ole32.dll!CoInitializeEx 76DE09AD 5 Bytes JMP 280A7D50 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] ole32.dll!CoCreateInstance 76DE9D0B 5 Bytes JMP 280A80D0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] WININET.dll!InternetCloseHandle 777DAB41 5 Bytes JMP 280B4600 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] WININET.dll!InternetReadFile 777DB3FE 5 Bytes JMP 280B44C0 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] WININET.dll!HttpOpenRequestA 777E4C7E 5 Bytes JMP 280B4360 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[2484] WININET.dll!HttpSendRequestA 77851A48 5 Bytes JMP 280B4560 C:\Program Files\Yuna Software\Messenger Plus!\MsgPlusLive.dll (Messenger Plus! 5 Add-On/Yuna Software)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3500] ntdll.dll!NtProtectVirtualMemory 77905F18 5 Bytes JMP 0083000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3500] ntdll.dll!NtWriteVirtualMemory 77906A98 5 Bytes JMP 0084000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3500] ntdll.dll!KiUserExceptionDispatcher 77906FE8 5 Bytes JMP 0067000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3500] USER32.dll!GetWindowInfo 77474B5E 5 Bytes JMP 659F36FB C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4020] USER32.dll!SetWindowLongA 77468BA3 5 Bytes JMP 65C43A89 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4020] USER32.dll!SetWindowLongW 77474449 5 Bytes JMP 65C43A1B C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4020] USER32.dll!GetWindowInfo 77474B5E 5 Bytes JMP 659EC909 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[4020] USER32.dll!TrackPopupMenu 77482228 5 Bytes JMP 659ECEBD C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 86A021F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{A733C2F9-0BF0-429B-BE05-780883D0D889} 872241F8
Device \Driver\volmgr \Device\VolMgrControl 85D431F8
Device \Driver\ACPI_HAL \Device\00000050 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\NetBT \Device\NetBT_Tcpip_{405743EA-8C96-4059-8098-4E0D0A3D8F61} 872241F8
Device \Driver\usbohci \Device\USBPDO-0 873671F8
Device \Driver\usbehci \Device\USBPDO-1 8736E1F8
Device \Driver\volmgr \Device\HarddiskVolume1 85D431F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\PCI_PNP0160 \Device\00000058 spig.sys
Device \Driver\volmgr \Device\HarddiskVolume2 85D431F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\cdrom \Device\CdRom0 8722E1F8
Device \Driver\sptd \Device\498275160 spig.sys
Device \Driver\PCI_PNP0160 \Device\00000059 spig.sys
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 85D451F8
Device \Driver\atapi \Device\Ide\IdePort0 85D451F8
Device \Driver\atapi \Device\Ide\IdePort1 85D451F8
Device \Driver\volmgr \Device\HarddiskVolume3 85D431F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\cdrom \Device\CdRom1 8722E1F8
Device \Driver\nvstor32 \Device\00000067 85D471F8
Device \Driver\volmgr \Device\HarddiskVolume4 85D431F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\nvstor32 \Device\00000068 85D471F8
Device \Driver\nvstor32 \Device\00000069 85D471F8
Device \Driver\sptd \Device\498118910 spig.sys
Device \Driver\NetBT \Device\NetBt_Wins_Export 872241F8
Device \Driver\nvstor32 \Device\RaidPort0 85D471F8
Device \Driver\nvstor32 \Device\RaidPort1 85D471F8
Device \Driver\nvstor32 \Device\RaidPort2 85D471F8
Device \Driver\usbohci \Device\USBFDO-0 873671F8
Device \Driver\usbehci \Device\USBFDO-1 8736E1F8
Device \Driver\apm7lcrb \Device\Scsi\apm7lcrb1Port6Path0Target0Lun0 876351F8
Device \Driver\apm7lcrb \Device\Scsi\apm7lcrb1 876351F8
Device \Driver\acpzev0o \Device\Scsi\acpzev0o1 873661F8

—- Modules - GMER 1.0.15 —-

Module (noname) (*** hidden *** ) 91788000-9179A000 (73728 bytes)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xCC 0xB5 0x4A 0x66 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x89 0x30 0xC6 0xC4 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD0 0x77 0xFB 0xB0 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7F 0x0A 0xB3 0xE9 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x77 0x16 0x08 0x01 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xCC 0xB5 0x4A 0x66 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x89 0x30 0xC6 0xC4 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD0 0x77 0xFB 0xB0 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7F 0x0A 0xB3 0xE9 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x77 0x16 0x08 0x01 …
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Program Files\EA\Battlefield 3\x2122\__Installer\vc\vc2008sp1\redist\vcredist_x86.exe 1

—- EOF - GMER 1.0.15 —-

OTL.txt


OTL logfile created on: 17/01/2012 19:46:15 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Eros\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000c0a | Country: España | Language: ESN | Date Format: dd/MM/yyyy

3,25 Gb Total Physical Memory | 2,13 Gb Available Physical Memory | 65,68% Memory free
6,50 Gb Paging File | 5,36 Gb Available in Paging File | 82,52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,88 Gb Total Space | 41,69 Gb Free Space | 17,90% Space Free | Partition Type: NTFS
Drive D: | 148,95 Gb Total Space | 86,64 Gb Free Space | 58,17% Space Free | Partition Type: NTFS
Drive F: | 931,51 Gb Total Space | 724,24 Gb Free Space | 77,75% Space Free | Partition Type: NTFS

Computer Name: EROS- | User Name: Eros | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/01/17 19:44:21 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Eros\Downloads\OTL.exe
PRC - [2011/12/30 20:13:52 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Archivos de programa\Mozilla Firefox\firefox.exe
PRC - [2011/10/24 16:51:19 | 000,801,792 | —- | M] (Yuna Software) – C:\Archivos de programa\Yuna Software\Messenger Plus!\PlusService.exe
PRC - [2011/10/15 08:53:00 | 002,253,120 | —- | M] (NVIDIA Corporation) – C:\Archivos de programa\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/10/15 08:53:00 | 001,820,480 | —- | M] (NVIDIA Corporation) – C:\Archivos de programa\NVIDIA Corporation\Display\nvtray.exe
PRC - [2011/10/15 08:53:00 | 001,328,960 | —- | M] (NVIDIA Corporation) – C:\Archivos de programa\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2011/10/15 00:54:40 | 000,381,248 | —- | M] (NVIDIA Corporation) – C:\Archivos de programa\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/08/15 16:18:10 | 001,361,288 | —- | M] (LogMeIn Inc.) – C:\Archivos de programa\LogMeIn Hamachi\hamachi-2.exe
PRC - [2011/07/16 22:21:04 | 000,302,592 | —- | M] () – C:\Users\Eros\Downloads\gmer\gmer.exe
PRC - [2011/06/24 04:22:20 | 000,271,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\conhost.exe
PRC - [2010/11/20 12:17:56 | 001,121,792 | —- | M] (Microsoft Corporation) – C:\Archivos de programa\Windows Media Player\wmpnetwk.exe
PRC - [2010/11/20 12:17:47 | 000,049,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe
PRC - [2010/11/20 12:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2010/09/30 15:36:00 | 003,872,080 | —- | M] (Microsoft Corporation) – C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe
PRC - [2010/05/02 17:29:34 | 000,039,936 | —- | M] (KSE - Korndörfer Software Engineering) – C:\Archivos de programa\nHancer\nHancerService.exe
PRC - [2010/04/16 17:36:42 | 000,026,480 | —- | M] (Microsoft Corporation) – C:\Archivos de programa\Windows Live\Contacts\wlcomm.exe
PRC - [2009/08/18 11:29:22 | 001,529,728 | —- | M] (Microsoft Corporation) – C:\Archivos de programa\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2009/08/18 11:29:22 | 000,183,152 | —- | M] (Microsoft Corporation) – C:\Archivos de programa\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009/07/14 01:14:28 | 000,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\PING.EXE
PRC - [2007/09/04 19:25:44 | 000,131,072 | —- | M] (NVIDIA) – C:\Archivos de programa\NVIDIA Corporation\nTune\nTuneService.exe
PRC - [2007/05/28 16:57:54 | 000,275,968 | —- | M] (Rocket Division Software) – C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe


========== Modules (No Company Name) ==========

MOD - [2011/12/30 20:13:52 | 002,124,760 | —- | M] () – C:\Archivos de programa\Mozilla Firefox\mozjs.dll
MOD - [2011/11/22 18:43:16 | 008,527,008 | —- | M] () – C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2011/10/15 00:54:26 | 000,265,536 | —- | M] () – C:\Archivos de programa\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
MOD - [2011/08/07 14:54:16 | 000,004,096 | —- | M] () – C:\Archivos de programa\Yuna Software\Messenger Plus!\Detour32.dll
MOD - [2011/07/16 22:21:04 | 000,302,592 | —- | M] () – C:\Users\Eros\Downloads\gmer\gmer.exe
MOD - [2010/11/20 12:19:56 | 000,232,448 | —- | M] () – \\?\globalroot\systemroot\system32\mswsock.DLL
MOD - [2010/11/20 12:19:56 | 000,232,448 | —- | M] () – \\.\globalroot\systemroot\system32\mswsock.dll
MOD - [2009/12/08 13:44:12 | 000,042,280 | —- | M] () – C:\Archivos de programa\Hercules\Classic Link\WebCamKSProxyPlugin.ax
MOD - [2006/12/04 16:00:00 | 000,126,464 | —- | M] () – C:\Archivos de programa\WinRAR\RarExt.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] – – (SupportSoft RemoteAssist)
SRV - [2011/12/09 00:09:34 | 000,419,624 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2011/10/15 08:53:00 | 002,253,120 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Archivos de programa\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe – (nvUpdatusService)
SRV - [2011/10/15 00:54:40 | 000,381,248 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Archivos de programa\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2011/08/15 16:18:10 | 001,361,288 | —- | M] (LogMeIn Inc.) [Auto | Running] – C:\Program Files\LogMeIn Hamachi\hamachi-2.exe – (Hamachi2Svc)
SRV - [2011/03/18 00:18:06 | 003,229,784 | —- | M] () [Disabled | Stopped] – c:\Archivos de programa\Common Files\Akamai\netsession_win_d76cf65.dll – (Akamai)
SRV - [2010/05/02 17:29:34 | 000,039,936 | —- | M] (KSE - Korndörfer Software Engineering) [Auto | Running] – C:\Program Files\nHancer\nHancerService.exe – (nHancer)
SRV - [2009/07/14 01:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/14 01:16:12 | 001,004,544 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\PeerDistSvc.dll – (PeerDistSvc)
SRV - [2007/09/04 19:25:44 | 000,131,072 | —- | M] (NVIDIA) [Auto | Running] – C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe – (nTuneService)
SRV - [2007/05/28 16:57:54 | 000,275,968 | —- | M] (Rocket Division Software) [Auto | Running] – C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe – (StarWindServiceAE)


========== Driver Services (SafeList) ==========

DRV - [2012/01/07 16:23:58 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\gdrv.sys – (gdrv)
DRV - [2011/10/15 08:53:00 | 010,327,360 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2010/11/20 12:30:15 | 000,175,360 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmbus.sys – (vmbus)
DRV - [2010/11/20 12:30:15 | 000,040,704 | —- | M] (Microsoft Corporation) [Kernel | Boot | Running] – C:\Windows\system32\drivers\vmstorfl.sys – (storflt)
DRV - [2010/11/20 12:30:15 | 000,028,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\storvsc.sys – (storvsc)
DRV - [2010/11/20 10:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 10:21:14 | 000,015,872 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\rdpvideominiport.sys – (RdpVideoMiniport)
DRV - [2010/11/20 09:14:45 | 000,017,920 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\VMBusHID.sys – (VMBusHID)
DRV - [2010/11/20 09:14:41 | 000,005,632 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\system32\drivers\vms3cap.sys – (s3cap)
DRV - [2010/09/29 20:39:38 | 000,691,696 | —- | M] () [Kernel | Boot | Running] – C:\Windows\System32\Drivers\sptd.sys – (sptd)
DRV - [2009/09/11 11:48:04 | 000,066,056 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\WmXlCore.sys – (WmXlCore)
DRV - [2009/09/11 11:47:54 | 000,014,984 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\WmVirHid.sys – (WmVirHid)
DRV - [2009/09/11 11:47:42 | 000,031,752 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\WmHidLo.sys – (WmHidLo)
DRV - [2009/09/11 11:47:32 | 000,035,592 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\WmFilter.sys – (WmFilter)
DRV - [2009/09/11 11:47:22 | 000,022,792 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\WmBEnum.sys – (WmBEnum)
DRV - [2009/03/18 17:35:40 | 000,026,176 | -H– | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\hamachi.sys – (hamachi)
DRV - [2009/02/09 09:42:42 | 000,099,968 | —- | M] (Guillemot Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\hxctlflt.sys – (hxctlflt)
DRV - [2007/09/10 08:50:56 | 000,457,984 | —- | M] (PixArt Imaging Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\PAC7302.SYS – (PAC7302)
DRV - [2007/09/04 19:26:32 | 000,029,696 | —- | M] (NVidia Corp.) [Kernel | On_Demand | Running] – C:\Windows\nvoclock.sys – (NVR0Dev)
DRV - [2007/06/29 13:47:34 | 000,034,304 | —- | M] (AMD, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\AmdLLD.sys – (AmdLLD)
DRV - [2007/06/28 06:18:10 | 001,310,720 | —- | M] (C-Media Inc) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\CM108.sys – (USBPNPA)
DRV - [2007/01/15 17:35:18 | 001,032,104 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmfdx32.sys – (NVENETFD)
DRV - [2006/12/22 20:07:10 | 000,093,696 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\system32\DRIVERS\nvstor32.sys – (nvstor32)
DRV - [2006/11/22 00:53:00 | 001,121,536 | —- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\3xHybrid.sys – (3xHybrid)
DRV - [2005/02/14 00:00:00 | 000,007,168 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Archivos de programa\K!TV\Plugins\S_Bt8x8\DSDrv4.sys – (DSDrv4)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = es
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F8 ED 94 39 5A A8 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.es"
FF - prefs.js..network.proxy.type: 0

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2852: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1662: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Eros\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Eros\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/30 20:13:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/16 18:29:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/30 20:13:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/16 18:29:32 | 000,000,000 | —D | M]

[2010/09/29 20:20:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Eros\AppData\Roaming\mozilla\Extensions
[2012/01/15 21:02:01 | 000,000,000 | —D | M] (No name found) – C:\Users\Eros\AppData\Roaming\mozilla\Firefox\Profiles\lbyuiugg.default\extensions
[2010/10/01 17:04:17 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\Eros\AppData\Roaming\mozilla\Firefox\Profiles\lbyuiugg.default\extensions\[removed]
[2011/05/11 18:23:24 | 000,000,000 | —D | M] (Diccionario de Español/España) – C:\Users\Eros\AppData\Roaming\mozilla\Firefox\Profiles\lbyuiugg.default\extensions\[removed]
[2011/11/16 12:30:33 | 000,000,000 | —D | M] (No name found) – C:\Archivos de programa\Mozilla Firefox\extensions
[2011/11/25 19:03:05 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Archivos de programa\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
() (No name found) – C:\USERS\EROS\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\LBYUIUGG.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/12/30 20:13:52 | 000,121,816 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/05 03:32:18 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/05 03:57:33 | 000,003,996 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\drae.xml
[2011/11/05 03:57:33 | 000,001,143 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-es.xml
[2011/12/30 20:13:52 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2011/11/05 03:57:33 | 000,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-es.xml
[2011/11/05 03:57:33 | 000,001,102 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-es.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Eros\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2003 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFFICE.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Eros\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Eros\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\nppdf32.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Eros\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Eros\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: B\u00FAsqueda de Google = C:\Users\Eros\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Skype Click to Call = C:\Users\Eros\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Gmail = C:\Users\Eros\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\

Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O4 - HKLM..\Run: [amd_dc_opt] C:\Archivos de programa\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [PlusService] C:\Archivos de programa\Yuna Software\Messenger Plus!\PlusService.exe (Yuna Software)
O4 - HKCU..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xportar; a Microsoft Excel - C:\Archivos de programa\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Archivos de programa\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Archivos de programa\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Archivos de programa\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - %SystemRoot%\System32\winrnr.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - %SystemRoot%\System32\winrnr.dll File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A733C2F9-0BF0-429B-BE05-780883D0D889}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Archivos de programa\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Archivos de programa\Common Files\microsoft shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Archivos de programa\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Archivos de programa\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Archivos de programa\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 21:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.ac3acm - C:\Windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\System32\ff_vfw.dll ()
Drivers32: VIDC.FPS1 - C:\Windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.LAGS - C:\Windows\System32\lagarith.dll ( )
Drivers32: VIDC.VP70 - C:\Windows\System32\vp7vfw.dll (On2.com)
Drivers32: VIDC.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/01/17 00:55:21 | 000,356,352 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvusmb.exe
[2012/01/17 00:55:06 | 000,356,352 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\NVUNINST.EXE
[2012/01/15 22:12:36 | 000,000,000 | —D | C] – C:\Users\Eros\AppData\Local\MooExt
[2012/01/15 21:33:31 | 000,000,000 | —D | C] – C:\Users\Eros\AppData\Local\ElevatedDiagnostics
[2012/01/15 17:50:26 | 000,000,000 | —D | C] – C:\Users\Eros\AppData\Roaming\QuickScan
[2012/01/15 17:33:39 | 002,342,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/01/15 17:33:37 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2012/01/15 17:33:20 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/01/15 17:33:20 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/01/15 17:33:20 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/01/15 17:33:20 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/01/15 17:33:20 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/01/15 17:33:09 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\packager.dll
[2012/01/15 17:33:08 | 000,314,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\webio.dll
[2012/01/15 17:33:08 | 000,015,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sspisrv.dll
[2012/01/15 17:33:07 | 001,328,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2012/01/15 17:33:07 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\qdvd.dll
[2012/01/15 17:32:36 | 003,967,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2012/01/15 17:32:36 | 003,912,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2012/01/15 17:32:31 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2012/01/15 17:32:30 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2012/01/15 16:54:40 | 000,000,000 | —D | C] – C:\Users\Eros\AppData\Roaming\Malwarebytes
[2012/01/15 16:54:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/15 16:54:33 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/01/15 16:54:32 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/01/15 16:54:32 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/01/15 02:33:00 | 000,000,000 | —D | C] – C:\Windows\TEMP
[2012/01/15 02:28:08 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/01/15 02:25:13 | 000,000,000 | —D | C] – C:\Users\Eros\AppData\Local\temp
[2012/01/15 02:20:43 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/01/15 02:20:43 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/01/15 02:20:43 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/01/15 02:20:01 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/01/15 02:19:53 | 000,000,000 | —D | C] – C:\ComboFix
[2012/01/15 02:15:03 | 000,000,000 | —D | C] – C:\Qoobox
[2012/01/14 22:42:33 | 000,000,000 | —D | C] – C:\Users\Eros\Documents\capcom
[2012/01/14 19:55:25 | 000,000,000 | —D | C] – C:\Users\Eros\AppData\Roaming\NationRed
[2012/01/12 17:17:12 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012/01/12 12:16:09 | 000,000,000 | —D | C] – C:\ProgramData\{83C3B2FD-37EA-4C06-A228-E9B5E32FF0B1}
[2012/01/12 00:32:23 | 000,000,000 | —D | C] – C:\Users\Eros\Documents\rFactor2
[2012/01/12 00:32:23 | 000,000,000 | —D | C] – C:\Users\Eros\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\rFactor 2
[2012/01/12 00:32:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\rFactor 2
[2012/01/12 00:31:43 | 000,000,000 | —D | C] – C:\Program Files\rFactor2
[2012/01/12 00:23:59 | 000,000,000 | —D | C] – C:\Users\Eros\AppData\Roaming\F8F6B
[2012/01/11 00:52:01 | 000,000,000 | —D | C] – C:\Users\Eros\AppData\Local\SanctionedMedia
[2012/01/10 23:01:02 | 000,000,000 | —D | C] – C:\Users\Eros\DoctorWeb
[2012/01/08 19:32:57 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2012/01/08 19:32:01 | 000,000,000 | —D | C] – C:\Users\Eros\AppData\Roaming\uTorrent
[2012/01/07 16:15:14 | 000,000,000 | —D | C] – C:\Windows\System32\RTCOM
[2012/01/07 16:14:41 | 001,783,056 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\WavesLib.dll
[2012/01/07 16:14:41 | 001,725,784 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\WavesGUILib.dll
[2012/01/07 16:14:40 | 001,497,704 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RTSndMgr.cpl
[2012/01/07 16:14:40 | 001,379,760 | —- | C] (TOSHIBA Corporation) – C:\Windows\System32\tosade.dll
[2012/01/07 16:14:40 | 000,345,328 | —- | C] (SRS Labs, Inc.) – C:\Windows\System32\SRSTSXT.dll
[2012/01/07 16:14:40 | 000,214,368 | —- | C] (Synopsys, Inc.) – C:\Windows\System32\SFNHK.dll
[2012/01/07 16:14:40 | 000,185,584 | —- | C] (SRS Labs, Inc.) – C:\Windows\System32\SRSTSHD.dll
[2012/01/07 16:14:40 | 000,178,624 | —- | C] (TOSHIBA Corporation) – C:\Windows\System32\tadefxapo2.dll
[2012/01/07 16:14:40 | 000,173,296 | —- | C] (SRS Labs, Inc.) – C:\Windows\System32\SRSHP360.dll
[2012/01/07 16:14:40 | 000,140,528 | —- | C] (SRS Labs, Inc.) – C:\Windows\System32\SRSWOW.dll
[2012/01/07 16:14:40 | 000,134,584 | —- | C] (TOSHIBA Corporation) – C:\Windows\System32\tadefxapo.dll
[2012/01/07 16:14:40 | 000,074,080 | —- | C] (Synopsys, Inc.) – C:\Windows\System32\SFCOM.dll
[2012/01/07 16:14:40 | 000,068,960 | —- | C] (Synopsys, Inc.) – C:\Windows\System32\SFAPO.dll
[2012/01/07 16:14:39 | 004,229,736 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtkAPO.dll
[2012/01/07 16:14:39 | 002,269,288 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtkPgExt.dll
[2012/01/07 16:14:39 | 001,313,384 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtkApoApi.dll
[2012/01/07 16:14:39 | 000,359,768 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\System32\RTEEP32A.dll
[2012/01/07 16:14:39 | 000,170,840 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\System32\RTEED32A.dll
[2012/01/07 16:14:39 | 000,080,488 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtkCoInst.dll
[2012/01/07 16:14:39 | 000,078,680 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\System32\RTEEL32A.dll
[2012/01/07 16:14:39 | 000,064,856 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\System32\RTEEG32A.dll
[2012/01/07 16:14:38 | 003,327,320 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\MaxxAudioRealtek.dll
[2012/01/07 16:14:38 | 003,296,600 | —- | C] (Dolby Laboratories) – C:\Windows\System32\R4EEP32A.dll
[2012/01/07 16:14:38 | 001,836,376 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\MaxxAudioEQ.dll
[2012/01/07 16:14:38 | 001,501,696 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RCoRes.dat
[2012/01/07 16:14:38 | 000,345,944 | —- | C] (Dolby Laboratories) – C:\Windows\System32\R4EED32A.dll
[2012/01/07 16:14:38 | 000,295,768 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\System32\RP3DHT32.dll
[2012/01/07 16:14:38 | 000,295,768 | —- | C] (Dolby Laboratories, Inc.) – C:\Windows\System32\RP3DAA32.dll
[2012/01/07 16:14:38 | 000,259,928 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\MaxxAudioAPO30.dll
[2012/01/07 16:14:38 | 000,252,760 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\MaxxVolumeSDAPO.dll
[2012/01/07 16:14:38 | 000,232,792 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\MaxxAudioAPO20.dll
[2012/01/07 16:14:38 | 000,132,368 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\MaxxAudioAPO.dll
[2012/01/07 16:14:38 | 000,103,256 | —- | C] (Dolby Laboratories) – C:\Windows\System32\R4EEL32A.dll
[2012/01/07 16:14:38 | 000,088,408 | —- | C] (Dolby Laboratories) – C:\Windows\System32\R4EEA32A.dll
[2012/01/07 16:14:38 | 000,061,272 | —- | C] (Dolby Laboratories) – C:\Windows\System32\R4EEG32A.dll
[2012/01/07 16:14:37 | 000,357,712 | —- | C] (Knowles Acoustics ) – C:\Windows\System32\KAAPORT.dll
[2012/01/07 16:14:36 | 001,740,352 | —- | C] (Fortemedia Corporation) – C:\Windows\System32\FMAPO.dll
[2012/01/07 16:14:35 | 001,509,480 | —- | C] (DTS) – C:\Windows\System32\DTSS2SpeakerDLL.dll
[2012/01/07 16:14:35 | 001,292,904 | —- | C] (DTS) – C:\Windows\System32\DTSS2HeadphoneDLL.dll
[2012/01/07 16:14:35 | 001,220,200 | —- | C] (DTS) – C:\Windows\System32\DTSBoostDLL.dll
[2012/01/07 16:14:35 | 000,654,952 | —- | C] (DTS) – C:\Windows\System32\DTSBassEnhancementDLL.dll
[2012/01/07 16:14:35 | 000,631,400 | —- | C] (DTS) – C:\Windows\System32\DTSSymmetryDLL.dll
[2012/01/07 16:14:35 | 000,601,704 | —- | C] (DTS) – C:\Windows\System32\DTSVoiceClarityDLL.dll
[2012/01/07 16:14:35 | 000,458,344 | —- | C] (DTS) – C:\Windows\System32\DTSNeoPCDLL.dll
[2012/01/07 16:14:35 | 000,413,696 | —- | C] (DTS) – C:\Windows\System32\DTSU2PLFX32.dll
[2012/01/07 16:14:35 | 000,390,656 | —- | C] (DTS) – C:\Windows\System32\DTSU2PGFX32.dll
[2012/01/07 16:14:35 | 000,389,736 | —- | C] (DTS) – C:\Windows\System32\DTSGainCompensatorDLL.dll
[2012/01/07 16:14:35 | 000,375,400 | —- | C] (DTS) – C:\Windows\System32\DTSLimiterDLL.dll
[2012/01/07 16:14:35 | 000,327,168 | —- | C] (DTS) – C:\Windows\System32\DTSU2PREC32.dll
[2012/01/07 16:14:35 | 000,218,728 | —- | C] (DTS) – C:\Windows\System32\DTSGFXAPONS.dll
[2012/01/07 16:14:35 | 000,218,728 | —- | C] (DTS) – C:\Windows\System32\DTSGFXAPO.dll
[2012/01/07 16:14:35 | 000,218,216 | —- | C] (DTS) – C:\Windows\System32\DTSLFXAPO.dll
[2012/01/07 16:14:35 | 000,175,200 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\AERTACap.dll
[2012/01/07 16:14:35 | 000,096,160 | —- | C] (Andrea Electronics Corporation) – C:\Windows\System32\AERTARen.dll
[2012/01/07 16:14:35 | 000,000,000 | —D | C] – C:\Program Files\Realtek
[2012/01/07 16:14:33 | 001,698,408 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\RtlExUpd.dll
[2012/01/07 16:14:33 | 000,000,000 | -H-D | C] – C:\Program Files\Temp
[2012/01/07 16:04:56 | 000,017,488 | —- | C] (Windows ® 2000 DDK provider) – C:\Windows\gdrv.sys
[2012/01/06 21:19:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gigabyte
[2012/01/06 21:19:52 | 000,327,168 | —- | C] (InstallShield Software Corporation) – C:\Windows\IsUninst.exe
[2012/01/02 20:34:28 | 000,000,000 | —D | C] – C:\ProgramData\Electronic Arts
[2012/01/02 20:34:28 | 000,000,000 | —D | C] – C:\ProgramData\EA Core
[2012/01/02 20:33:04 | 000,000,000 | -H-D | C] – C:\Program Files\Common Files\EAInstaller
[2012/01/01 13:28:31 | 000,000,000 | —D | C] – C:\Users\Eros\Documents\Battlefield 3
[2011/12/31 19:09:46 | 000,000,000 | —D | C] – C:\$AVG
[2011/12/31 18:26:03 | 000,000,000 | —D | C] – C:\Program Files\EA
[2011/12/31 18:25:57 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2011/12/31 13:32:08 | 000,000,000 | —D | C] – C:\Users\Eros\AppData\Local\LogMeIn Hamachi
[2011/12/31 13:31:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011/12/31 13:31:46 | 000,000,000 | —D | C] – C:\Program Files\LogMeIn Hamachi
[2011/12/27 20:21:48 | 000,000,000 | —D | C] – C:\Down
[2011/12/27 20:21:31 | 000,000,000 | —D | C] – C:\Perfect World Entertainment
[2011/12/19 12:07:50 | 000,000,000 | —D | C] – C:\Users\Eros\Documents\My Digital Editions
[2010/12/13 16:09:33 | 000,121,344 | —- | C] ( ) – C:\Windows\System32\lagarith.dll
[4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/01/17 19:28:28 | 000,016,624 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/17 19:28:28 | 000,016,624 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/17 19:21:05 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/01/17 19:20:58 | 2616,893,440 | -HS- | M] () – C:\hiberfil.sys
[2012/01/17 18:04:00 | 000,001,106 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1417867071-3267230069-1058266891-1000UA.job
[2012/01/17 18:04:00 | 000,001,054 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1417867071-3267230069-1058266891-1000Core.job
[2012/01/17 01:10:16 | 000,002,050 | —- | M] () – C:\Users\Eros\Desktop\NVIDIA Monitor.lnk
[2012/01/17 01:10:16 | 000,001,864 | —- | M] () – C:\Users\Eros\Desktop\nTune.lnk
[2012/01/17 01:02:56 | 000,749,774 | —- | M] () – C:\Windows\System32\perfh00A.dat
[2012/01/17 01:02:56 | 000,656,476 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/01/17 01:02:56 | 000,159,172 | —- | M] () – C:\Windows\System32\perfc00A.dat
[2012/01/17 01:02:56 | 000,122,306 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/01/17 00:48:03 | 000,001,299 | —- | M] () – C:\Users\Eros\Desktop\teknohelper.exe - Acceso directo.lnk
[2012/01/15 17:47:54 | 000,340,472 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/01/15 16:54:33 | 000,001,071 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/14 22:42:25 | 000,001,590 | —- | M] () – C:\Users\Eros\Desktop\Lost Planet 2.lnk
[2012/01/13 18:44:44 | 000,001,388 | —- | M] () – C:\Users\Eros\Desktop\uTorrent.lnk
[2012/01/12 00:39:22 | 000,001,095 | —- | M] () – C:\Users\Eros\Desktop\rFactor2.lnk
[2012/01/07 16:23:58 | 000,017,488 | —- | M] (Windows ® 2000 DDK provider) – C:\Windows\gdrv.sys
[2012/01/07 14:06:06 | 000,002,395 | —- | M] () – C:\Users\Eros\Desktop\Google Chrome.lnk
[2012/01/01 13:28:05 | 000,001,487 | —- | M] () – C:\Users\Eros\Desktop\Battlefield 3.lnk
[2011/12/31 14:39:50 | 000,000,924 | —- | M] () – C:\Users\Eros\Desktop\LogMeIn Hamachi.lnk
[2011/12/26 02:06:38 | 000,000,069 | —- | M] () – C:\Windows\NeroDigital.ini
[2011/12/26 01:42:40 | 000,029,184 | —- | M] () – C:\Users\Eros\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/19 12:32:09 | 000,001,751 | —- | M] () – C:\Users\Eros\Desktop\eBooks.lnk
[4 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/01/17 01:10:16 | 000,002,050 | —- | C] () – C:\Users\Eros\Desktop\NVIDIA Monitor.lnk
[2012/01/17 01:10:16 | 000,001,864 | —- | C] () – C:\Users\Eros\Desktop\nTune.lnk
[2012/01/17 00:55:28 | 000,003,903 | —- | C] () – C:\Windows\System32\nvnrm.nvu
[2012/01/17 00:55:21 | 000,001,864 | —- | C] () – C:\Windows\System32\nvsmb.nvu
[2012/01/17 00:48:03 | 000,001,299 | —- | C] () – C:\Users\Eros\Desktop\teknohelper.exe - Acceso directo.lnk
[2012/01/15 17:15:16 | 000,340,472 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2012/01/15 16:54:33 | 000,001,071 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/15 02:20:43 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/01/15 02:20:43 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/01/15 02:20:43 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/01/15 02:20:43 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/01/15 02:20:43 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/01/14 22:42:25 | 000,001,590 | —- | C] () – C:\Users\Eros\Desktop\Lost Planet 2.lnk
[2012/01/13 18:44:44 | 000,001,388 | —- | C] () – C:\Users\Eros\Desktop\uTorrent.lnk
[2012/01/12 00:39:22 | 000,001,095 | —- | C] () – C:\Users\Eros\Desktop\rFactor2.lnk
[2012/01/11 00:46:01 | 000,001,922 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2012/01/11 00:46:01 | 000,001,897 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Uninstaller.lnk
[2012/01/11 00:46:01 | 000,001,874 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2012/01/01 01:40:55 | 000,001,487 | —- | C] () – C:\Users\Eros\Desktop\Battlefield 3.lnk
[2011/12/31 14:39:50 | 000,000,924 | —- | C] () – C:\Users\Eros\Desktop\LogMeIn Hamachi.lnk
[2011/12/19 12:32:09 | 000,001,751 | —- | C] () – C:\Users\Eros\Desktop\eBooks.lnk
[2011/11/22 18:41:45 | 000,000,015 | —- | C] () – C:\Windows\ASSE.dat
[2011/11/18 18:27:35 | 000,000,566 | —- | C] () – C:\Windows\System32\SP7302.INI
[2011/11/17 15:55:08 | 000,080,896 | —- | C] () – C:\Windows\System32\RDVGHelper.exe
[2011/11/17 15:53:46 | 000,066,048 | —- | C] () – C:\Windows\System32\PrintBrmUi.exe
[2011/10/15 00:54:52 | 000,321,856 | —- | C] () – C:\Windows\System32\nvStreaming.exe
[2011/09/07 12:23:06 | 000,000,056 | RHS- | C] () – C:\Windows\System32\ECB65442CC.sys
[2011/09/07 12:23:03 | 000,001,056 | -HS- | C] () – C:\Windows\System32\KGyGaAvL.sys
[2011/08/24 18:12:00 | 000,000,069 | —- | C] () – C:\Windows\NeroDigital.ini
[2011/08/11 18:31:10 | 000,000,170 | —- | C] () – C:\Windows\game.ini
[2011/07/07 14:23:01 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
[2011/04/09 17:55:28 | 000,179,261 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2011/03/26 17:26:01 | 000,021,840 | —- | C] () – C:\Windows\System32\SIntfNT.dll
[2011/03/26 17:26:01 | 000,017,212 | —- | C] () – C:\Windows\System32\SIntf32.dll
[2011/03/26 17:26:01 | 000,012,067 | —- | C] () – C:\Windows\System32\SIntf16.dll
[2011/03/26 17:13:36 | 000,035,772 | —- | C] () – C:\Windows\DIIUnin.dat
[2010/12/13 16:09:33 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/12/13 16:09:32 | 000,790,528 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2010/12/13 16:09:32 | 000,134,144 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2010/12/13 16:09:32 | 000,108,032 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/11/06 22:28:42 | 001,970,176 | —- | C] () – C:\Windows\System32\d3dx9.dll
[2010/10/25 15:46:53 | 000,032,768 | —- | C] () – C:\Windows\System32\BCGPOleAcc.dll
[2010/10/21 22:36:38 | 000,165,376 | —- | C] () – C:\Windows\System32\unrar.dll
[2010/10/16 17:38:31 | 000,029,184 | —- | C] () – C:\Users\Eros\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/03 22:51:08 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/09/29 21:08:13 | 000,015,047 | —- | C] () – C:\Windows\System32\Main.ini
[2010/09/29 20:32:33 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/07/14 08:48:37 | 000,749,774 | —- | C] () – C:\Windows\System32\perfh00A.dat
[2009/07/14 08:48:37 | 000,341,432 | —- | C] () – C:\Windows\System32\perfi00A.dat
[2009/07/14 08:48:37 | 000,159,172 | —- | C] () – C:\Windows\System32\perfc00A.dat
[2009/07/14 08:48:37 | 000,041,390 | —- | C] () – C:\Windows\System32\perfd00A.dat
[2009/07/14 04:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 02:05:48 | 000,656,476 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/14 02:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/14 02:05:48 | 000,122,306 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/14 02:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/14 02:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/14 02:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 23:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 23:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 23:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 21:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2007/03/12 12:01:30 | 000,217,088 | —- | C] () – C:\Windows\NVGfxOgl.dll
[2005/08/30 00:00:00 | 000,778,752 | —- | C] () – C:\Windows\System32\RGSS102E.dll
[2003/02/27 01:07:00 | 000,003,072 | —- | C] () – C:\Windows\System32\34CoInstaller.dll

========== LOP Check ==========

[2011/08/11 18:43:26 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\Activision
[2011/03/14 23:24:34 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\AtomZombieDemoData
[2011/11/18 19:22:36 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\BeNaughtyChat
[2010/10/08 21:53:07 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\BlackBean
[2010/11/03 15:19:19 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\Canneverbe Limited
[2012/01/15 17:11:36 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\DAEMON Tools Lite
[2011/10/23 19:14:24 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\DBDesigner4
[2012/01/12 00:23:59 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\F8F6B
[2010/10/10 16:57:02 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\FreeArc
[2011/03/18 23:09:43 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\Kalypso Media
[2011/02/27 21:43:25 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\MySQL
[2012/01/14 22:05:13 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\NationRed
[2012/01/15 18:12:11 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\QuickScan
[2010/10/13 17:37:21 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\Red Kawa
[2010/12/22 16:26:30 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\The Path
[2011/11/22 18:37:02 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\TS3Client
[2012/01/15 17:11:34 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\uTorrent
[2011/11/17 15:28:05 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\vcards
[2011/01/12 22:00:32 | 000,000,000 | —D | M] – C:\Users\Eros\AppData\Roaming\ZombieDriver
[2012/01/17 15:57:07 | 000,032,522 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/12/06 12:35:51 | 000,001,024 | —- | M] () – C:\.rnd
[2009/06/10 21:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2012/01/15 02:31:18 | 000,021,987 | —- | M] () – C:\ComboFix.txt
[2009/06/10 21:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/01/17 19:20:58 | 2616,893,440 | -HS- | M] () – C:\hiberfil.sys
[2011/10/17 19:24:07 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/10/17 19:24:07 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/01/17 19:21:02 | 3489,193,984 | -HS- | M] () – C:\pagefile.sys
[2012/01/15 16:53:21 | 000,000,357 | —- | M] () – C:\rkill.log
[2012/01/02 20:34:51 | 000,003,646 | —- | M] () – C:\shared.log
[2004/08/03 23:56:46 | 000,438,272 | —- | M] (Microsoft Corporation) – C:\shimgvw.dll

< %systemroot%\Fonts\*.com >
[2009/07/14 04:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 04:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 04:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 04:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 21:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 01:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2010/11/20 12:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 04:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/09/29 20:17:07 | 000,000,221 | -HS- | M] () – C:\Users\Eros\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-01-15 17:44:03

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB65372$] -> Error: Cannot create file handle -> Unknown point type

< End of report >


Extras.txt
OTL Extras logfile created on: 17/01/2012 19:46:15 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Eros\Downloads
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000c0a | Country: España | Language: ESN | Date Format: dd/MM/yyyy

3,25 Gb Total Physical Memory | 2,13 Gb Available Physical Memory | 65,68% Memory free
6,50 Gb Paging File | 5,36 Gb Available in Paging File | 82,52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,88 Gb Total Space | 41,69 Gb Free Space | 17,90% Space Free | Partition Type: NTFS
Drive D: | 148,95 Gb Total Space | 86,64 Gb Free Space | 58,17% Space Free | Partition Type: NTFS
Drive F: | 931,51 Gb Total Space | 724,24 Gb Free Space | 77,75% Space Free | Partition Type: NTFS

Computer Name: EROS- | User Name: Eros | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{058E89EF-09E7-4398-8365-246D196766DF}" = Anti-reCAPTCHA v2.07 JD
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0E3CBA63-CF26-336A-8A2E-5ECE3CC4D852}" = Microsoft Document Explorer 2008 Language Pack - ESN
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{1803A630-3C38-4D2B-9B9A-0CB37243539C}" = Microsoft ASP.NET MVC 2
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Herramienta de carga de Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 24
"{2B83A043-BA8C-4164-98AA-29529D0BE756}" = Windows Live Essentials
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{33BC9D7E-E790-495E-A4EA-CFB160C17A91}" = Logitech Gaming Software 5.08
"{37B369BF-FBDF-40C7-8F75-D08BF77C7EBA}" = Microsoft .NET Compact Framework 2.0 SP2
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3EF00220-A9CB-49BC-9A09-D7B5A805D42B}" = Microsoft Expression Blend 3 SDK
"{40416836-56CC-4C0E-A6AF-5C34BADCE483}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools
"{43430808-081A-4C0D-B7CC-601000018301}" = LOST PLANET 2
"{434D0FA0-1558-4D8E-AC3D-BD1000008200}" = DiRT 3
"{434D0FA1-3E0C-4D03-A5D4-5E1000008100}" = F1 2011
"{47C39E4A-28F2-33B1-B9B7-97F24E52D917}" = Microsoft Help Viewer 1.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4EFED687-A8B8-4C85-8D5D-9CE46C8EB277}" = Microsoft .NET Compact Framework 3.5
"{550B72C4-F404-4812-971F-947E835A877E}" = Gtk# for .Net 2.12.10
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008
"{690D4AFA-9857-4220-BED9-CFC420DFD502}" = Gigabyte PCI TV Card
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A86554B-8928-30E4-A53C-D7337689134D}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.30319
"{6ED37A91-7710-3183-BE50-AB043FF6689E}" = Microsoft Team Foundation Server 2010 Object Model - ENU
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{729A3000-BC8A-3B74-BA5D-5068FE12D70C}" = Microsoft Visual F# 2.0 Runtime
"{737369DC-08E8-4787-A78C-F86943247BDF}" = LOST PLANET 2
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{7D66915F-05FF-4F59-B2D3-AA2E58506F72}" = nHancer
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7EA86E10-7D59-44DE-85D5-B4B623ED4686}" = Skyrim
"{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
"{8275A948-DB4C-4315-B697-AAAFDE4686D3}_is1" = Ferrari Virtual Academy version 1.3
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{88397286-3F36-32A0-9AFA-76FFF0676EC6}" = Microsoft Device Emulator, versión 3.0 - ESN
"{8924FD04-AFF1-4387-B08B-6A979485F2BD}" = Windows Live Call
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BBB5E4C-3F5E-4C07-BFBE-33B34600783A}" = LogMeIn Hamachi
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90110C0A-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0C0A-0000-0000000FF1CE}" = Paquete de compatibilidad para 2007 Office system
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95B012AD-3A4A-31D7-9167-5D07D2A71F47}" = Microsoft .NET Framework 4 Client Profile ESN Language Pack
"{97CE8B73-AA5A-4987-A1BE-50DD1A187478}" = Microsoft Sync Framework SDK v1.0 SP1
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1034-7B44-A70800000002}" = Adobe Reader 7.0.8 - Español
"{B1549CC1-EB81-4E7C-9C7C-8B97CD9FD37A}" = Hercules Classic Link
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA Controlador de 3D Vision 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panel de control de NVIDIA 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Controlador de gráficos 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA Controlador de la controladora 3D Vision 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA Software del sistema PhysX 9.11.0621
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = Actualización de NVIDIA 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B62DEA25-1830-433A-BCA0-CFAE392E1081}" = Microsoft Expression Blend SDK for .NET 4
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{B93EEE50-9C8F-45DF-95E4-3D85A6E242F3}" = DarksidersInstaller
"{C3C44248-B8F7-4B20-A5C7-994870B60F55}" = Hercules Webcam Station Evolution SE
"{C4156B59-DD7E-40DF-AF08-E568A27A6409}" = Windows Live Messenger
"{C4CD208D-E3A2-488B-A4F4-FD8DE3DADD25}_is1" = BMW M3 Challenge
"{C6DD625F-4B61-4561-8286-87CA0275CEA1}" = Microsoft Sync Framework Runtime v1.0 SP1 (x86)
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.4.8 Game
"{D4116CF9-58E0-3B22-B30E-215C6EC03D43}" = Visual Studio Tools for the Office system 3.0 Runtime Language Pack - ESN
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{E6E28426-4610-4F83-B95A-727CE8F57EC5}" = Microsoft Expression Blend SDK for Silverlight 4
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F990B526-8F7C-46E0-B1F1-6C893A8B478F}" = Microsoft Sync Framework Services v1.0 SP1 (x86)
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AdWare SpyWare SE_is1" = AdWare SpyWare SE
"Akamai" = Akamai NetSession Interface
"AviSynth" = AviSynth 2.5
"CCleaner" = CCleaner
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Cheat Engine 5.6.1_is1" = Cheat Engine 5.6.1
"Diablo II" = Diablo II
"Digital Editions" = Adobe Digital Editions
"F1 2004 RH FINAL" = F1 2004 RH FINAL
"Fraps" = Fraps
"FreeArc" = FreeArc 0.666
"GFWL_{434D0FA0-1558-4D8E-AC3D-BD1000008200}" = DiRT 3
"GFWL_{434D0FA1-3E0C-4D03-A5D4-5E1000008100}" = F1 2011
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"JDownloader" = JDownloader
"K!TV" = K!TV
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.6.0 (Full)
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware versión 1.60.0.1800
"Messenger Plus!" = Messenger Plus! 5
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile ESN Language Pack" = Paquete de idioma de Microsoft .NET Framework 4 Client Profile ESN
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008
"Microsoft Document Explorer 2008 Language Pack - ESN" = Paquete de idioma de Microsoft Document Explorer 2008 - ESN
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft Team Foundation Server 2010 Object Model - ENU" = Microsoft Team Foundation Server 2010 Object Model - ENU
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Mozilla Firefox 9.0.1 (x86 es-ES)" = Mozilla Firefox 9.0.1 (x86 es-ES)
"nHancer" = nHancer
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"PSP Video 9" = PSP Video 9 6
"RealAlt_is1" = Real Alternative 1.8.2
"Remove Empty Directories" = Remove Empty Directories 2.1
"rFactor2" = rFactor2
"Steam App 1250" = Killing Floor
"Steam App 12630" = Legend: Hand of God
"Steam App 17570" = Pirates, Vikings, & Knights II
"Steam App 240" = Counter-Strike: Source
"Steam App 32370" = Star Wars: Knights of the Old Republic
"Steam App 36630" = Rusty Hearts
"Steam App 36700" = The Scourge Project: Episode 1 and 2
"Steam App 39690" = ArcaniA – Gothic 4
"Steam App 42910" = Magicka
"Steam App 440" = Team Fortress 2
"Steam App 44620" = STCC II
"Steam App 44630" = RACE 07 - Formula RaceRoom Add-On
"Steam App 50620" = Darksiders
"Steam App 8600" = RACE 07
"Steam App 8650" = RACE 07 - Andy Priaulx Crowne Plaza Expansion
"Steam App 8660" = GTR Evolution
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"uTorrent" = µTorrent
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"Visual Studio Tools for the Office system 3.0 Runtime Language Pack - ESN" = Paquete de idioma de Visual Studio Tools para Office system 3.0 Runtime - ESN
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = Compresor WinRAR
"World of Warcraft" = World of Warcraft

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Endurance Series by EnduRacers - v1 SP1 FULL" = Endurance Series by EnduRacers - v1 SP1 FULL
"F1 2010 WCP" = F1 2010 WCP
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 30/07/2011 7:11:05 | Computer Name = Eros- | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Error en la extracción de la lista raíz de terceros del archivo .CAB
actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
con el error: Un certificado requerido no se encuentra dentro del periodo de validez
cuando se ha realizado la comprobación con el reloj de sistema actual o con la
marca de tiempo en el archivo firmado. .

Error - 30/07/2011 7:11:05 | Computer Name = Eros- | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Error en la extracción de la lista raíz de terceros del archivo .CAB
actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
con el error: Un certificado requerido no se encuentra dentro del periodo de validez
cuando se ha realizado la comprobación con el reloj de sistema actual o con la
marca de tiempo en el archivo firmado. .

Error - 30/07/2011 7:11:05 | Computer Name = Eros- | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Error en la extracción de la lista raíz de terceros del archivo .CAB
actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
con el error: Un certificado requerido no se encuentra dentro del periodo de validez
cuando se ha realizado la comprobación con el reloj de sistema actual o con la
marca de tiempo en el archivo firmado. .

Error - 30/07/2011 7:11:05 | Computer Name = Eros- | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Error en la extracción de la lista raíz de terceros del archivo .CAB
actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
con el error: Un certificado requerido no se encuentra dentro del periodo de validez
cuando se ha realizado la comprobación con el reloj de sistema actual o con la
marca de tiempo en el archivo firmado. .

Error - 30/07/2011 7:11:06 | Computer Name = Eros- | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Error en la extracción de la lista raíz de terceros del archivo .CAB
actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
con el error: Un certificado requerido no se encuentra dentro del periodo de validez
cuando se ha realizado la comprobación con el reloj de sistema actual o con la
marca de tiempo en el archivo firmado. .

Error - 30/07/2011 7:11:09 | Computer Name = Eros- | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Error en la extracción de la lista raíz de terceros del archivo .CAB
actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
con el error: Un certificado requerido no se encuentra dentro del periodo de validez
cuando se ha realizado la comprobación con el reloj de sistema actual o con la
marca de tiempo en el archivo firmado. .

Error - 30/07/2011 7:11:09 | Computer Name = Eros- | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Error en la extracción de la lista raíz de terceros del archivo .CAB
actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
con el error: Un certificado requerido no se encuentra dentro del periodo de validez
cuando se ha realizado la comprobación con el reloj de sistema actual o con la
marca de tiempo en el archivo firmado. .

Error - 30/07/2011 9:21:39 | Computer Name = Eros- | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Error en la extracción de la lista raíz de terceros del archivo .CAB
actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
con el error: Un certificado requerido no se encuentra dentro del periodo de validez
cuando se ha realizado la comprobación con el reloj de sistema actual o con la
marca de tiempo en el archivo firmado. .

Error - 30/07/2011 9:21:39 | Computer Name = Eros- | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Error en la extracción de la lista raíz de terceros del archivo .CAB
actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
con el error: Un certificado requerido no se encuentra dentro del periodo de validez
cuando se ha realizado la comprobación con el reloj de sistema actual o con la
marca de tiempo en el archivo firmado. .

Error - 30/07/2011 9:21:39 | Computer Name = Eros- | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Error en la extracción de la lista raíz de terceros del archivo .CAB
actualizado automáticamente: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
con el error: Un certificado requerido no se encuentra dentro del periodo de validez
cuando se ha realizado la comprobación con el reloj de sistema actual o con la
marca de tiempo en el archivo firmado. .

[ Media Center Events ]
Error - 10/08/2011 12:35:49 | Computer Name = Eros- | Source = MCUpdate | ID = 0
Description = 17:35:48 - No se pudo recuperar MCEClientUX (Error: No es posible
conectar con el servidor remoto)

[ System Events ]
Error - 17/01/2012 13:55:57 | Computer Name = Eros- | Source = Service Control Manager | ID = 7024
Description = El servicio Escucha de Grupo Hogar se cerró con el error específico
de servicio %%-2147023143.

Error - 17/01/2012 13:57:32 | Computer Name = Eros- | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Error al intentar leer el archivo local de hosts.

Error - 17/01/2012 15:21:14 | Computer Name = Eros- | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Error al intentar leer el archivo local de hosts.

Error - 17/01/2012 15:21:15 | Computer Name = Eros- | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Error al intentar leer el archivo local de hosts.

Error - 17/01/2012 15:21:19 | Computer Name = Eros- | Source = Service Control Manager | ID = 7000
Description = El servicio SupportSoft RemoteAssist no pudo iniciarse debido al siguiente
error: %%3

Error - 17/01/2012 15:21:19 | Computer Name = Eros- | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Error al intentar leer el archivo local de hosts.

Error - 17/01/2012 15:21:20 | Computer Name = Eros- | Source = Service Control Manager | ID = 7023
Description = El servicio Examinador de equipos se cerró con el siguiente error:
%%1060

Error - 17/01/2012 15:21:23 | Computer Name = Eros- | Source = Service Control Manager | ID = 7023
Description = El servicio Examinador de equipos se cerró con el siguiente error:
%%1060

Error - 17/01/2012 15:21:40 | Computer Name = Eros- | Source = Service Control Manager | ID = 7024
Description = El servicio Escucha de Grupo Hogar se cerró con el error específico
de servicio %%-2147023143.

Error - 17/01/2012 15:23:18 | Computer Name = Eros- | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = Error al intentar leer el archivo local de hosts.


< End of report >


HijackThis

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:55:09, on 17/01/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\taskmgr.exe
C:\Users\Eros\Downloads\OTL.exe
C:\Windows\notepad.exe
C:\Windows\notepad.exe
C:\Users\Eros\Downloads\HiJackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [PlusService] C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-21-1417867071-3267230069-1058266891-1008\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1417867071-3267230069-1058266891-1008\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1417867071-3267230069-1058266891-1008\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1417867071-3267230069-1058266891-1008\..\Run: [Google Update] "C:\Users\Eros\AppData\Local\Google\Update\GoogleUpdate.exe" /c (User 'UpdatusUser')
O4 - HKUS\S-1-5-21-1417867071-3267230069-1058266891-1008\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'UpdatusUser')
O4 - HKUS\S-1-5-18\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (User 'Default user')
O8 - Extra context menu item: E&xportar; a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe
O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @appmgmts.dll,-3250 (AppMgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (Audiosrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\cscsvc.dll,-200 (CscService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe
O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe
O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe
O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: nHancer Support (nHancer) - KSE - Korndörfer Software Engineering - C:\Program Files\nHancer\nHancerService.exe
O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\peerdistsvc.dll,-9000 (PeerDistSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe
O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ipnathlp.dll,-106 (SharedAccess) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe
O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (StiSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe
O23 - Service: @%SystemRoot%\system32\umrdp.dll,-1000 (UmRdpService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe
O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe
O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\wmpnetwk.exe
O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: wscsvc - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe
O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe

–
End of file - 20185 bytes
:welcome:

Your computer is infected with the Zero Access Rootkit


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
:thumbup:

Thanks for letting me know. With the severity of the latest threats sometime a format and reinstall is the way to go, now you know you have a nice clean safe computer.


  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports


Safe Surfn
Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI