This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

abnow.com trojan [Closed]

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi.

This afternoon when I was surfing the web I suddenly got my browser freezed and had this issue. I were redirected to abnow.com every time I tryed to make a search in google. I tryed with other pages like yahoo and I couldn't also find anything and were redirected again.
I don't know how to solve this. I send de OTL.txt and the extra.txt
Thakyou in advance



OTL logfile created on: 07/03/2012 23:01:19 - Run 2
OTL by OldTimer - Version 3.2.35.1 Folder = C:\Users\Mario\Desktop\20120309 VIRUS
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000C0A | Country: España | Language: ESN | Date Format: dd/MM/yyyy

2,97 Gb Total Physical Memory | 1,83 Gb Available Physical Memory | 61,52% Memory free
5,93 Gb Paging File | 4,64 Gb Available in Paging File | 78,14% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288,22 Gb Total Space | 133,50 Gb Free Space | 46,32% Space Free | Partition Type: NTFS

Computer Name: MARIETE | User Name: Mario | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Mario\Desktop\20120309 VIRUS\OTL.exe (OldTimer Tools)
PRC - C:\Archivos de programa\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Archivos de programa\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Archivos de programa\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Archivos de programa\Ask.com\Updater\Updater.exe (Ask)
PRC - C:\Archivos de programa\sony\Marketing Tools\MarketingTools.exe (Sony Corporation)
PRC - C:\Archivos de programa\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\Archivos de programa\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Archivos de programa\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Archivos de programa\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Archivos de programa\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
PRC - c:\Archivos de programa\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Archivos de programa\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\lpksetup.exe (Microsoft Corporation)
PRC - C:\Archivos de programa\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
PRC - C:\Archivos de programa\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
PRC - C:\Archivos de programa\sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
PRC - C:\Archivos de programa\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation)
PRC - C:\Archivos de programa\sony\Network Utility\LANUtil.exe (Sony Corporation)
PRC - C:\Archivos de programa\sony\Network Utility\NSUService.exe (Sony Corporation)
PRC - C:\Archivos de programa\sony\VAIO Power Management\SPMgr.exe (Sony Corporation)
PRC - C:\Archivos de programa\sony\VAIO Power Management\SPMService.exe (Sony Corporation)
PRC - C:\Archivos de programa\sony\VAIO Update 4\VAIOUpdt.exe (Sony Corporation)
PRC - C:\Archivos de programa\sony\ISB Utility\ISBMgr.exe (Sony Corporation)
PRC - C:\Archivos de programa\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.)
PRC - c:\Archivos de programa\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\e5a4bc827a371428406fbc0a743bdbfe\System.IdentityModel.Selectors.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\44d15a5bcd3143d53fd67b871c728616\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\a221123a83601a4a964218b3bd3f4fa6\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\eb46ff3a7098925dd3f0552901668735\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\3623247db0c19cd14589e6f4d6cfb290\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\5ca17001998a75ca774d2b80eead5579\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\2df79ab909c782d3796e4107d040327d\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ff30db6905f8ec024fc808ed8779c0f3\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\a09ee392fa90849f2e9313a1ebbe0279\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d49f4cb0755ccc34cd35ff96dc2ef9e3\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\15742b3597258ce67cbe219005c197e5\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\1f14b3e1ee0847f8662f513e67f92547\System.ni.dll ()
MOD - C:\Archivos de programa\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll ()
MOD - C:\Archivos de programa\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Archivos de programa\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\SPMCommon\3.1.0.6020__e3c7096ba83f9295\SPMCommon.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\SPMDam\3.1.0.6020__1b3c579b6925895f\SPMDam.dll ()
MOD - C:\Archivos de programa\WinRAR\RarExt.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.ServiceModel.resources\3.0.0.0_es_b77a5c561934e089\System.ServiceModel.resources.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_es_b77a5c561934e089\mscorlib.resources.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.DLL ()


========== Win32 Services (SafeList) ==========

SRV - (unlockerdriver5) – File not found
SRV - (tandpl) – File not found
SRV - (protectionservice) – File not found
SRV - (nimcdlbk) – File not found
SRV - (mqdmbus) – File not found
SRV - (hpzius12) – File not found
SRV - (DumaNT) – File not found
SRV - (CdaC15BA) – File not found
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Sony Ericsson PCCompanion) – C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe (Avanquest Software)
SRV - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Archivos de programa\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Archivos de programa\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (VAIO Entertainment TV Device Arbitration Service) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzHardwareResourceManager\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)
SRV - (Vcsw) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)
SRV - (VzCdbSvc) – C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)
SRV - (SOHCImp) – C:\Program Files\Common Files\Sony Shared\SOHLib\SOHCImp.exe (Sony Corporation)
SRV - (SOHPlMgr) – C:\Program Files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe (Sony Corporation)
SRV - (SOHDs) – C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDs.exe (Sony Corporation)
SRV - (SOHDms) – C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDms.exe (Sony Corporation)
SRV - (SOHDBSvr) – C:\Program Files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe (Sony Corporation)
SRV - (VcmIAlzMgr) – C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe (Sony Corporation)
SRV - (VAIO Event Service) – C:\Program Files\sony\VAIO Event Service\VESMgr.exe (Sony Corporation)
SRV - (VcmXmlIfHelper) – C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe (Sony Corporation)
SRV - (VCFw) – C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (NSUService) – C:\Program Files\sony\Network Utility\NSUService.exe (Sony Corporation)
SRV - (VAIO Power Management) – C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation)
SRV - (uCamMonitor) – C:\Archivos de programa\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ArcSoft, Inc.)
SRV - (IviRegMgr) – c:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)


========== Driver Services (SafeList) ==========

DRV - (catchme) – File not found
DRV - (tmhxnbbn) – C:\Windows\System32\drivers\tmhxnbbn.sys (Microsoft Corporation)
DRV - (quzddyui) – C:\Windows\System32\drivers\quzddyui.sys (Microsoft Corporation)
DRV - (ycfucsbk) – C:\Windows\System32\drivers\ycfucsbk.sys (Microsoft Corporation)
DRV - (ugrxcnxh) – C:\Windows\System32\drivers\ugrxcnxh.sys (Microsoft Corporation)
DRV - (fchjjxky) – C:\Windows\System32\drivers\fchjjxky.sys (Microsoft Corporation)
DRV - (ggsemc) – C:\Windows\System32\drivers\ggsemc.sys (Sony Ericsson Mobile Communications)
DRV - (ggflt) – C:\Windows\System32\drivers\ggflt.sys (Sony Ericsson Mobile Communications)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (dtsoftbus01) – C:\Windows\System32\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV - (NisDrv) – C:\Windows\System32\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (yukonw7) – C:\Windows\System32\drivers\yk62x86.sys (Marvell)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (DMICall) – C:\Windows\System32\drivers\DMICall.sys (Sony Corporation)
DRV - (SFEP) – C:\Windows\System32\drivers\SFEP.sys (Sony Corporation)
DRV - (risdptsk) – C:\Windows\System32\drivers\risdptsk.sys (REDC)
DRV - (rimsptsk) – C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (WimFltr) – C:\Windows\System32\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (ArcSoftKsUFilter) – C:\Windows\System32\drivers\ArcSoftKsUFilter.sys (ArcSoft, Inc.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (regi) – C:\Windows\System32\drivers\regi.sys (InterVideo)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…T&bmod=EU01
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…T&bmod=SNYT
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s=…hTerms}&f=4
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{24C0CC4F-D77A-417F-86F9-DC7FA1F74748}: "URL" = http://www.google.es/search?hl=es&q={s…erms}&meta=
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7SNYT
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2851619

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…T&bmod=EU01
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.es/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Archivos de programa\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {db131c55-60c8-4adc-84dc-9e76ab06e2dc} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=ddrnw&s=…hTerms}&f=4
IE - HKCU\..\SearchScopes\{24C0CC4F-D77A-417F-86F9-DC7FA1F74748}: "URL" = http://www.google.es/search?hl=es&q={s…erms}&meta=
IE - HKCU\..\SearchScopes\{26865DD9-649F-4CA1-8E26-2F3ABB0A21EB}: "URL" = http://websearch.ask.com/redirect?client=i…5E-4A6A42B36205
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7SNYT
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2851619
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar_ES Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2851619&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "www.google.es"

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@fxinteractive.com/fxplanet: C:\ProgramData\FXWebPlayer\npfxplanet.dll (FX Interactive)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/24 20:48:55 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/07 16:27:27 | 000,000,000 | —D | M]

[2011/09/25 19:47:19 | 000,000,000 | —D | M] (No name found) – C:\Users\Mario\AppData\Roaming\mozilla\Extensions
[2012/03/07 15:48:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Mario\AppData\Roaming\mozilla\Firefox\Profiles\cdf5drti.default\extensions
[2012/03/01 20:34:14 | 000,000,000 | —D | M] (Greasemonkey) – C:\Users\Mario\AppData\Roaming\mozilla\Firefox\Profiles\cdf5drti.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012/01/03 16:27:44 | 000,002,333 | —- | M] () – C:\Users\Mario\AppData\Roaming\Mozilla\Firefox\Profiles\cdf5drti.default\searchplugins\askcom.xml
[2012/01/11 17:52:24 | 000,000,931 | —- | M] () – C:\Users\Mario\AppData\Roaming\Mozilla\Firefox\Profiles\cdf5drti.default\searchplugins\conduit.xml
[2012/01/01 04:26:23 | 000,000,000 | —D | M] (No name found) – C:\Archivos de programa\Mozilla Firefox\extensions
[2012/02/24 20:48:55 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/12/11 13:53:36 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/07/11 22:48:12 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2011/09/03 01:13:56 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/09/03 01:38:24 | 000,003,996 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\drae.xml
[2011/09/03 01:38:24 | 000,001,143 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-es.xml
[2011/09/25 20:04:26 | 000,002,048 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml
[2012/01/01 04:26:20 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2011/09/03 01:38:24 | 000,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia-es.xml
[2011/09/03 01:38:24 | 000,001,102 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-es.xml

========== Chrome ==========

CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url = http://search.conduit.com/Results.aspx?q={…;ctid=CT2851619
CHR - default_search_provider: suggest_url = http://search.conduit.com/
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Mario\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\17.0.963.66\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Plugin de juegos de FX Interactive (Enabled) = C:\ProgramData\FXWebPlayer\npfxplanet.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Mario\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: B\u00FAsqueda de Google = C:\Users\Mario\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Gmail = C:\Users\Mario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2011/12/09 19:52:21 | 000,000,789 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 74.208.10.249 gs.apple.com
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Aplicación auxiliar de inicio de sesión) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (aTube Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Archivos de programa\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (aTube Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Archivos de programa\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (aTube Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Archivos de programa\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MarketingTools] C:\Archivos de programa\sony\Marketing Tools\MarketingTools.exe (Sony Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Archivos de programa\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [Skytel] C:\Archivos de programa\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [NSUFloatingUI] C:\Program Files\Sony\Network Utility\LANUtil.exe (Sony Corporation)
O4 - HKCU..\Run: [Sony Ericsson PC Companion] C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe (Sony Ericsson)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: E&xportar a Microsoft Excel - C:\Archivos de programa\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Archivos de programa\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Archivos de programa\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F03E6F02-FF7F-4899-B373-BC554DCA5949}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F74F27D3-BBA3-4884-909C-ACA5308F9B53}: DhcpNameServer = 192.168.42.129
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Archivos de programa\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Archivos de programa\Common Files\microsoft shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\VESWinlogon: DllName - (VESWinlogon.dll) - C:\Windows\System32\VESWinlogon.dll (Sony Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\VAIO 08 img5 Wallpaper 1280x800.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\VAIO 08 img5 Wallpaper 1280x800.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{23f3a2aa-f7d9-11e0-9206-001dbaf073a1}\Shell - "" = AutoRun
O33 - MountPoints2\{23f3a2aa-f7d9-11e0-9206-001dbaf073a1}\Shell\AutoRun\command - "" = G:\Install.exe
O33 - MountPoints2\{b484f36b-24e5-11e1-bedb-001dbaf073a1}\Shell - "" = AutoRun
O33 - MountPoints2\{b484f36b-24e5-11e1-bedb-001dbaf073a1}\Shell\AutoRun\command - "" = H:\Startme.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/03/07 22:29:21 | 000,041,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\tmhxnbbn.sys
[2012/03/07 22:23:17 | 000,041,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\quzddyui.sys
[2012/03/07 21:59:41 | 000,000,000 | —D | C] – C:\Users\Mario\Desktop\20120309 VIRUS
[2012/03/07 21:56:15 | 000,041,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ycfucsbk.sys
[2012/03/07 21:34:04 | 000,041,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ugrxcnxh.sys
[2012/03/07 21:32:57 | 000,041,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\fchjjxky.sys
[2012/03/07 19:26:05 | 000,000,000 | –SD | C] – C:\ComboFix
[2012/03/07 18:46:17 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/03/07 18:46:17 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/03/07 18:46:17 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/03/07 18:46:09 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2012/03/07 18:46:02 | 000,000,000 | —D | C] – C:\Qoobox
[2012/03/07 18:44:37 | 004,430,732 | R— | C] (Swearware) – C:\Users\Mario\ComboFix.exe
[2012/03/07 17:30:28 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2012/03/07 17:30:03 | 000,240,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2012/03/07 17:27:32 | 008,336,664 | —- | C] (Microsoft Corporation) – C:\Users\Mario\mseinstall.exe
[2012/03/07 16:37:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/03/07 16:37:44 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/03/07 16:33:47 | 003,628,016 | —- | C] (Piriform Ltd) – C:\Users\Mario\ccsetup316.exe
[2012/03/07 16:13:45 | 000,000,000 | —D | C] – C:\Users\Mario\AppData\Roaming\Malwarebytes
[2012/03/07 16:13:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/07 16:13:41 | 000,020,464 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2012/03/07 16:13:41 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/03/07 16:13:41 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/03/07 16:12:59 | 009,502,424 | —- | C] (Malwarebytes Corporation ) – C:\Users\Mario\mbam–setup-1.60.1.1000.exe
[2012/03/07 13:44:49 | 000,000,000 | -HSD | C] – C:\Windows\System32\%APPDATA%
[2012/03/07 13:40:32 | 000,000,000 | -HSD | C] – C:\Users\Mario\AppData\Local\60b830f7
[2012/02/25 01:49:17 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2012/02/25 01:49:17 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/02/25 01:49:17 | 001,798,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/02/25 01:49:17 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/02/25 01:49:17 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/02/25 01:49:17 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2012/02/25 01:49:17 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2012/02/25 01:49:17 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2012/02/25 01:49:17 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2012/02/25 01:49:17 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/02/25 01:49:17 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2012/02/25 01:49:17 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2012/02/25 01:49:17 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/02/25 01:49:17 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2012/02/25 01:49:17 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2012/02/25 01:49:17 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2012/02/25 01:49:17 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2012/02/25 01:49:17 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2012/02/25 01:49:17 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/02/25 01:49:17 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2012/02/25 01:49:17 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2012/02/25 01:49:17 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2012/02/25 01:49:17 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2012/02/25 01:49:17 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2012/02/25 01:49:17 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2012/02/25 01:49:17 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2012/02/25 01:49:17 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2012/02/25 01:49:17 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2012/02/25 01:49:17 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2012/02/25 01:49:17 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/02/25 01:49:17 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2012/02/25 01:49:17 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2012/02/25 01:49:17 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2012/02/25 01:49:17 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2012/02/25 01:49:17 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2012/02/25 01:49:17 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2012/02/25 01:49:17 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2012/02/25 01:48:33 | 003,181,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2012/02/25 01:48:33 | 001,619,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2012/02/25 01:48:33 | 001,495,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ExplorerFrame.dll
[2012/02/25 01:48:33 | 001,170,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2012/02/25 01:48:33 | 001,074,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2012/02/25 01:48:33 | 000,739,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2012/02/25 01:48:33 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2012/02/25 01:48:33 | 000,283,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2012/02/25 01:48:33 | 000,219,008 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2012/02/25 01:48:33 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2012/02/25 01:48:33 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2012/02/25 01:48:33 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2012/02/25 01:48:33 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2012/02/25 01:48:33 | 000,107,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2012/02/15 15:17:04 | 002,340,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[6 C:\Users\Mario\*.tmp files -> C:\Users\Mario\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/03/07 23:02:02 | 000,001,086 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/07 22:44:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/03/07 22:29:22 | 000,041,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tmhxnbbn.sys
[2012/03/07 22:23:17 | 000,041,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\quzddyui.sys
[2012/03/07 21:56:15 | 000,041,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\ycfucsbk.sys
[2012/03/07 21:38:52 | 000,011,104 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/07 21:38:52 | 000,011,104 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/07 21:34:04 | 000,041,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\ugrxcnxh.sys
[2012/03/07 21:32:58 | 000,041,680 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\fchjjxky.sys
[2012/03/07 21:32:20 | 000,001,082 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/07 19:34:16 | 000,000,000 | -HS- | M] () – C:\Windows\System32\dds_log_trash.cmd
[2012/03/07 19:34:06 | 2389,991,424 | -HS- | M] () – C:\hiberfil.sys
[2012/03/07 18:44:51 | 004,430,732 | R— | M] (Swearware) – C:\Users\Mario\ComboFix.exe
[2012/03/07 17:33:29 | 000,002,154 | —- | M] () – C:\Windows\epplauncher.mif
[2012/03/07 17:31:44 | 000,696,486 | —- | M] () – C:\Windows\System32\perfh00A.dat
[2012/03/07 17:31:44 | 000,609,290 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/03/07 17:31:44 | 000,135,448 | —- | M] () – C:\Windows\System32\perfc00A.dat
[2012/03/07 17:31:44 | 000,104,568 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/03/07 17:27:34 | 008,336,664 | —- | M] (Microsoft Corporation) – C:\Users\Mario\mseinstall.exe
[2012/03/07 16:39:15 | 000,079,350 | —- | M] () – C:\Users\Public\Documents\cc_20120307_163909.reg
[2012/03/07 16:34:17 | 002,044,980 | —- | M] () – C:\Users\Mario\tdsskiller.zip
[2012/03/07 16:33:50 | 003,628,016 | —- | M] (Piriform Ltd) – C:\Users\Mario\ccsetup316.exe
[2012/03/07 16:13:04 | 009,502,424 | —- | M] (Malwarebytes Corporation ) – C:\Users\Mario\mbam–setup-1.60.1.1000.exe
[2012/03/07 13:43:05 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/03/07 09:08:07 | 000,002,290 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/03/05 21:34:35 | 000,133,541 | —- | M] () – C:\Users\Mario\TO2262542 NOCHE DEL 09 Y 10 MARZO.pdf
[2012/03/05 21:34:06 | 000,132,686 | —- | M] () – C:\Users\Mario\TO2262542 NOCHE DEL 08MARZO.pdf
[2012/03/05 11:35:46 | 000,065,018 | —- | M] () – C:\Users\Mario\CASO_ADICIONAL_IR-DC_TAREA_INDIVIDUAL.pdf
[2012/03/04 11:08:50 | 055,871,870 | —- | M] () – C:\Users\Mario\SD_STORY_WEB_EU_SPAN_x264.zip
[2012/03/02 19:38:28 | 056,576,329 | —- | M] () – C:\Users\Mario\SD_STORY_WEB_EU_SPAN_x264.wmv
[2012/02/28 20:21:10 | 000,048,677 | —- | M] () – C:\Users\Mario\GeneratePDFTickets.pdf
[2012/02/28 16:53:24 | 000,132,385 | —- | M] () – C:\Users\Mario\De_Roma_a_Lisboa-_Enrique_Gonzalez_Sanchez_nov09.pdf
[2012/02/27 19:58:40 | 000,166,410 | —- | M] () – C:\Users\Mario\RyanairBoardingPass.pdf
[2012/02/26 16:52:53 | 000,352,983 | —- | M] () – C:\Users\Mario\buses.pdf
[2012/02/26 16:52:49 | 001,682,896 | —- | M] () – C:\Users\Mario\tube_map_apr08_es.pdf
[2012/02/25 01:49:17 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2012/02/25 01:49:17 | 002,382,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/02/25 01:49:17 | 001,798,656 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2012/02/25 01:49:17 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/02/25 01:49:17 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/02/25 01:49:17 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2012/02/25 01:49:17 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2012/02/25 01:49:17 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2012/02/25 01:49:17 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2012/02/25 01:49:17 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/02/25 01:49:17 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2012/02/25 01:49:17 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2012/02/25 01:49:17 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/02/25 01:49:17 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2012/02/25 01:49:17 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2012/02/25 01:49:17 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2012/02/25 01:49:17 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2012/02/25 01:49:17 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2012/02/25 01:49:17 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2012/02/25 01:49:17 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2012/02/25 01:49:17 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2012/02/25 01:49:17 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2012/02/25 01:49:17 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2012/02/25 01:49:17 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2012/02/25 01:49:17 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2012/02/25 01:49:17 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2012/02/25 01:49:17 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2012/02/25 01:49:17 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2012/02/25 01:49:17 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2012/02/25 01:49:17 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2012/02/25 01:49:17 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/02/25 01:49:17 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2012/02/25 01:49:17 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2012/02/25 01:49:17 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2012/02/25 01:49:17 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2012/02/25 01:49:17 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2012/02/25 01:49:17 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2012/02/25 01:49:17 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2012/02/25 01:48:33 | 003,181,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2012/02/25 01:48:33 | 001,619,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WMVDECOD.DLL
[2012/02/25 01:48:33 | 001,495,040 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ExplorerFrame.dll
[2012/02/25 01:48:33 | 001,170,944 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10warp.dll
[2012/02/25 01:48:33 | 001,074,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2012/02/25 01:48:33 | 000,739,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d2d1.dll
[2012/02/25 01:48:33 | 000,442,880 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsPrint.dll
[2012/02/25 01:48:33 | 000,283,648 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2012/02/25 01:48:33 | 000,219,008 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\dxgmms1.sys
[2012/02/25 01:48:33 | 000,218,624 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1core.dll
[2012/02/25 01:48:33 | 000,196,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mfreadwrite.dll
[2012/02/25 01:48:33 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2012/02/25 01:48:33 | 000,135,168 | —- | M] (Microsoft Corporation) – C:\Windows\System32\XpsRasterService.dll
[2012/02/25 01:48:33 | 000,107,520 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2012/02/24 11:24:48 | 000,395,096 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/02/11 14:57:33 | 000,007,598 | —- | M] () – C:\Users\Mario\AppData\Local\Resmon.ResmonCfg
[2012/02/07 16:27:27 | 000,001,984 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[6 C:\Users\Mario\*.tmp files -> C:\Users\Mario\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/03/07 18:46:17 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/03/07 18:46:17 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/03/07 18:46:17 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/03/07 18:46:17 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/03/07 18:46:17 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/03/07 17:33:29 | 000,002,154 | —- | C] () – C:\Windows\epplauncher.mif
[2012/03/07 17:30:40 | 000,001,897 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/03/07 16:39:12 | 000,079,350 | —- | C] () – C:\Users\Public\Documents\cc_20120307_163909.reg
[2012/03/07 16:34:16 | 002,044,980 | —- | C] () – C:\Users\Mario\tdsskiller.zip
[2012/03/07 13:41:33 | 000,000,000 | -HS- | C] () – C:\Windows\System32\dds_log_trash.cmd
[2012/03/05 21:34:34 | 000,133,541 | —- | C] () – C:\Users\Mario\TO2262542 NOCHE DEL 09 Y 10 MARZO.pdf
[2012/03/05 21:34:05 | 000,132,686 | —- | C] () – C:\Users\Mario\TO2262542 NOCHE DEL 08MARZO.pdf
[2012/03/05 11:35:46 | 000,065,018 | —- | C] () – C:\Users\Mario\CASO_ADICIONAL_IR-DC_TAREA_INDIVIDUAL.pdf
[2012/03/04 11:12:07 | 056,576,329 | —- | C] () – C:\Users\Mario\SD_STORY_WEB_EU_SPAN_x264.wmv
[2012/03/04 11:07:24 | 055,871,870 | —- | C] () – C:\Users\Mario\SD_STORY_WEB_EU_SPAN_x264.zip
[2012/02/28 20:21:10 | 000,048,677 | —- | C] () – C:\Users\Mario\GeneratePDFTickets.pdf
[2012/02/28 16:53:24 | 000,132,385 | —- | C] () – C:\Users\Mario\De_Roma_a_Lisboa-_Enrique_Gonzalez_Sanchez_nov09.pdf
[2012/02/27 19:58:36 | 000,166,410 | —- | C] () – C:\Users\Mario\RyanairBoardingPass.pdf
[2012/02/26 16:52:53 | 000,352,983 | —- | C] () – C:\Users\Mario\buses.pdf
[2012/02/26 16:52:46 | 001,682,896 | —- | C] () – C:\Users\Mario\tube_map_apr08_es.pdf
[2012/02/25 01:49:17 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2012/02/11 14:57:33 | 000,007,598 | —- | C] () – C:\Users\Mario\AppData\Local\Resmon.ResmonCfg
[2012/02/07 16:27:27 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012/02/07 16:27:27 | 000,001,984 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/11/30 16:28:12 | 000,004,608 | —- | C] () – C:\Users\Mario\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/16 11:09:53 | 000,000,181 | —- | C] () – C:\Windows\WININIT.INI
[2011/09/25 18:47:35 | 000,021,648 | —- | C] () – C:\Windows\System32\emptyregdb.dat
[2011/09/25 18:28:39 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2011/09/25 17:32:07 | 000,000,000 | —- | C] () – C:\Windows\VAIOUpdt.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 680 bytes -> C:\Windows\System32\drivers\fchjjxky.sys:changelist
@Alternate Data Stream - 308 bytes -> C:\Windows\System32\drivers\ycfucsbk.sys:changelist
@Alternate Data Stream - 308 bytes -> C:\Windows\System32\drivers\tmhxnbbn.sys:changelist
@Alternate Data Stream - 292 bytes -> C:\Windows\System32\drivers\ugrxcnxh.sys:changelist
@Alternate Data Stream - 292 bytes -> C:\Windows\System32\drivers\quzddyui.sys:changelist

< End of report >

OTL Extras logfile created on: 07/03/2012 22:09:00 - Run 1
OTL by OldTimer - Version 3.2.35.1 Folder = C:\Users\Mario\Desktop\20120309 VIRUS
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000C0A | Country: España | Language: ESN | Date Format: dd/MM/yyyy

2,97 Gb Total Physical Memory | 1,92 Gb Available Physical Memory | 64,58% Memory free
5,93 Gb Paging File | 4,66 Gb Available in Paging File | 78,53% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288,22 Gb Total Space | 133,53 Gb Free Space | 46,33% Space Free | Partition Type: NTFS

Computer Name: MARIETE | User Name: Mario | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{018F8F57-B46B-B9B9-C452-DE8F5618434F}" = Catalyst Control Center Graphics Full Existing
"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony Video Shared Library
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{068F037B-2723-48E3-85F1-4D7D93A29D2A}" = VAIO Content Metadata Intelligent Analyzing Manager
"{07C93E59-2DE3-1565-28A9-8C848B26D0F5}" = CCC Help German
"{095A5DB5-0917-4A63-B68D-9D0B6070B31B}" = Windows Live Asistente para el inicio de sesión
"{0A6F9244-8C79-1296-3A43-097F67EB666A}" = Catalyst Control Center Localization Dutch
"{10E73DB4-FDF1-4B58-B13E-4FC75B27CA4C}" = BlackBerry Device Software v6.0.0 para el smartphone BlackBerry 9300
"{12BAA98C-F8DD-4BC9-BBE6-1C8463114197}" = BlackBerry Device Software Updater
"{13D946AF-DAD9-0200-0000-000000000000}" = Android Sync Manager WiFi
"{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}" = Primo
"{15D5C238-4C2E-4AEA-A66D-D6989A4C586B}" = VAIO Launcher
"{1790FDA2-938F-C886-8988-1ECB74E45517}" = Catalyst Control Center Localization Norwegian
"{1C815731-19F3-0770-8776-D78D6BEBC291}" = Catalyst Control Center Localization Hungarian
"{1EC06E70-BE43-DAAA-A217-E5C98869B1F8}" = Catalyst Control Center Localization Greek
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
"{2018C019-30D9-4240-8C01-0865C10DCF5A}" = Soporte para Presentación VAIO
"{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for VAIO
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Herramienta de carga de Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23825B69-36DF-4DAD-9CFD-118D11D80F16}" = VAIO Content Folder Setting
"{252E50FD-F27C-C8DD-C9E2-D2845A2DC399}" = ATI Catalyst Install Manager
"{25BA8D5A-228A-7192-6FA1-890D9F1C679F}" = CCC Help Korean
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216029FF}" = Java™ 6 Update 29
"{2878C3C9-9D91-430F-8F50-885BB23DB001}" = VAIO Content Folder Watcher
"{327B75F0-92AF-420A-988F-FA596A218E0B}" = VAIO Content Folder Watcher
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{38BB21D5-B0D1-41DA-A0B0-1EFB5EF4AAC2}" = Microsoft Works
"{3B311FB9-5B6A-328C-D7AE-2445D639D886}" = CCC Help Norwegian
"{3B659FAD-E772-44A3-B7E7-560FF084669F}" = VAIO Smart Network
"{3D035310-3D86-4537-93B5-D390A6CF1778}" = ANNO 2070 DEMO
"{3D333C7C-102B-F474-9524-72AAA3F292B8}" = Catalyst Control Center Localization Danish
"{4529BC6B-16AE-6829-4946-36C33DBF8DD1}" = Catalyst Control Center Localization French
"{46D7A7FB-305B-F77D-60F8-8FAE1C432374}" = Catalyst Control Center InstallProxy
"{47A2CE5C-EA1F-4F58-8A0A-9452CBA795CD}" = Click to Disc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B930AE3-61C6-4D02-A9D4-84F4ACBCEC25}" = OpenOffice.org 3.3
"{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}" = Click to Disc Editor
"{50779A29-834E-4E36-BBEB-B7CABC67A825}" = Microsoft Security Client ES-ES Language Pack
"{527EB2A4-BF51-B1B6-3F09-2032A861548E}" = Catalyst Control Center Graphics Light
"{54B6DC7D-8C5B-4DFB-BC15-C010A3326B2B}" = Microsoft Security Client
"{55C0F7C1-8B6D-CBBD-2B88-EE7261A87254}" = CCC Help Greek
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{596BED91-A1D8-4DF1-8CD1-1C777F7588AC}" = VAIO DVD Menu Data Basic
"{5F5867F0-2D23-4338-A206-01A76C823924}" = Administración de energía del VAIO
"{629FD96D-5877-0832-2D31-0EFE781F870D}" = CCC Help Portuguese
"{64DBE9FE-A07D-41A0-B81A-8D416D9647FF}" = VAIO Content Folder Watcher
"{652C5DED-9B9F-93D0-5E94-931B8C38EF0E}" = Catalyst Control Center Localization Thai
"{68A69CFF-130D-4CDE-AB0E-7374ECB144C8}" = Click to Disc
"{69C8B1E3-2665-4A0F-B049-67746E5C4CE3}" = Software Info for Me&My VAIO
"{6A54CB6A-59D1-6A3A-08F3-E34ECF8905A9}" = Catalyst Control Center Graphics Previews Vista
"{6AA6EEA5-BF09-932B-AC25-0E9CCA4B709A}" = CCC Help Danish
"{6B1F20F2-6321-4669-A58C-33DF8E7517FF}" = VAIO Entertainment Platform
"{6C4EF0CA-A9DD-96CF-B722-CCDEB589DD26}" = Catalyst Control Center Localization Chinese Traditional
"{6EB6A82E-4918-481F-9AF8-3129E6D29B7E}" = Sony Home Network Library
"{6FA8BA2C-052B-4072-B8E2-2302C268BE9E}" = VAIO Movie Story Template Data
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{711D43D7-24FE-A2B7-CC52-A48BCAAF3926}" = Catalyst Control Center Graphics Previews Common
"{72042FA6-5609-489F-A8EA-3C2DD650F667}" = VAIO Control Center
"{7232478E-E01E-4F7D-A8EE-ABDA4CB3578D}" = Windows Live Call
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73496381-83C9-7BE6-6EB6-4CF97C00E5FD}" = CCC Help Polish
"{76D7CCD6-8369-405C-B494-5F34FAE67249}" = Me&My VAIO
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{79BBD55C-9FF6-D496-8AE6-E2EC2829F974}" = Catalyst Control Center Localization Czech
"{7B79CD75-F848-4B33-83E3-0EE1A1805A8C}" = VAIO Movie Story
"{7BB90344-0647-468E-925A-7F69F7983421}" = ArcSoft Magic-i Visual Effects 2
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7CC28423-465C-F4B9-9379-343DF715BE62}" = CCC Help Swedish
"{7D481DFF-88C5-4685-B0EA-D167F0B46CF1}" = Microsoft Antimalware Service ES-ES Language Pack
"{80828DF5-270E-F8E6-6274-55ACA4C7E229}" = Catalyst Control Center Localization Japanese
"{8153ED9A-C94A-426E-9880-5E6775C08B62}" = Apple Mobile Device Support
"{83CDA18E-0BF3-4ACA-872C-B4CDABF2360E}" = VAIO Update 4
"{84037798-D63A-F5CA-9FB2-829B362BF712}" = CCC Help Finnish
"{8470A1D9-536E-C7C1-AE2D-24B739B1665A}" = Catalyst Control Center Localization Russian
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{882683C6-8B60-5CBC-38A8-55ED185FD975}" = CCC Help Turkish
"{8843C5E1-51E5-DFA6-1AD8-757C8DCA7E37}" = CCC Help Russian
"{88C596E4-6882-8E76-EBEF-AB739F5A3B69}" = Catalyst Control Center Localization Italian
"{8C467DE1-6E04-0888-B281-172909C96F37}" = Skins
"{8C7FB08D-7A84-22E0-F553-F6B827023E17}" = CCC Help Chinese Traditional
"{8DE50158-80AA-4FF2-9E9F-0A7C46F71FCD}" = VAIO Media plus
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{90120000-0012-0000-0000-0000000FF1CE}_STANDARD_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0C0A-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Spanish) 2007
"{90120000-0016-0C0A-0000-0000000FF1CE}_STANDARD_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0C0A-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Spanish) 2007
"{90120000-0018-0C0A-0000-0000000FF1CE}_STANDARD_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Spanish) 2007
"{90120000-001A-0C0A-0000-0000000FF1CE}_STANDARD_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0C0A-0000-0000000FF1CE}" = Microsoft Office Word MUI (Spanish) 2007
"{90120000-001B-0C0A-0000-0000000FF1CE}_STANDARD_{D79E9128-A250-4155-BE90-2BE81DE0406A}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0403-0000-0000000FF1CE}" = Microsoft Office Proof (Catalan) 2007
"{90120000-001F-0403-0000-0000000FF1CE}_STANDARD_{BEADB115-DB47-4BD0-A9EC-AE585AFAB2D8}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARD_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARD_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2007
"{90120000-001F-0416-0000-0000000FF1CE}_STANDARD_{8A524694-0CA4-476A-9301-B1E9D70FC952}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-042D-0000-0000000FF1CE}" = Microsoft Office Proof (Basque) 2007
"{90120000-001F-042D-0000-0000000FF1CE}_STANDARD_{017A6981-5E03-4A97-830A-35FE0927BB7F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0456-0000-0000000FF1CE}" = Microsoft Office Proof (Galician) 2007
"{90120000-001F-0456-0000-0000000FF1CE}_STANDARD_{A3A03B41-14EA-4E50-97D8-FCF429AE0CCB}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARD_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0C0A-0000-0000000FF1CE}" = Paquete de compatibilidad para 2007 Office system
"{90120000-002C-0C0A-0000-0000000FF1CE}" = Microsoft Office Proofing (Spanish) 2007
"{90120000-006E-0C0A-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Spanish) 2007
"{90120000-006E-0C0A-0000-0000000FF1CE}_STANDARD_{430AE3E6-E982-4958-90FC-1C062BC74E22}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{9238E8A4-BEBA-43A3-B926-769BDBF194C5}" = VAIO Media plus Opening Movie
"{93F32124-BB54-C599-CF55-E1E57565BCE3}" = CCC Help Czech
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96C951BB-47C8-8497-78F0-7D8D328B58E3}" = Catalyst Control Center Localization Portuguese
"{96D0B6C6-5A72-4B47-8583-A87E55F5FE81}" =
"{98FC7A64-774B-49B5-B046-4B4EBC053FA9}" = VAIO MusicBox Sample Music
"{9973498D-EA29-4A68-BE0B-C88D6E03E928}" = ArcSoft WebCam Companion 2
"{99D8CD4E-A5D2-A9DF-A152-B28EB5A71F85}" = Catalyst Control Center Localization German
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9EAC0E21-510E-4259-A9C6-F5D5B8969036}" = Catalyst Control Center - Branding
"{A63E7492-A0BC-4BB9-89A7-352965222380}" = VAIO Original Function Setting
"{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}" = Setting Utility Series
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939F952-1C7E-CBF8-EE77-CFBD9C6A4ECC}" = ccc-core-static
"{A9D3D707-4A1A-4227-BE6E-F16448B4CB63}" = VAIO Entertainment Platform
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AA75988E-9EC1-EECE-CE00-D5D935974528}" = CCC Help Dutch
"{AC76BA86-7AD7-1034-7B44-A95000000001}" = Adobe Reader 9.5.0 - Español
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{ACB5FD4A-6C58-972C-180C-9677C037E71D}" = Catalyst Control Center Localization Chinese Standard
"{ADBDB038-FF77-C672-04A1-7A0E67E8C73C}" = Catalyst Control Center Core Implementation
"{ADECE95F-585D-8B33-BF50-53C2BDA1E241}" = Catalyst Control Center Localization Korean
"{AE0FBCB5-3193-4583-C6CB-AA96F307EA70}" = ccc-utility
"{AFF10119-F154-4888-77F3-B149DE987976}" = Catalyst Control Center Localization Polish
"{B25563A0-41F4-4A81-A6C1-6DBC0911B1F3}" = VAIO Movie Story
"{BD1BBE79-BB25-460D-A2BD-D496A5E13786}" = Windows Live Messenger
"{BFD85D24-D4F3-4CCC-B518-D7C4FC29C76D}" = VAIO Content Metadata Intelligent Analyzing Manager
"{C1555BC5-88B1-466B-BC79-062B5715DF92}" = VAIO Content Metadata XML Interface Library
"{C62AEA0E-90B0-4049-9780-8499A18A34D7}" = VAIO Content Metadata Manager Setting
"{C7477742-DDB4-43E5-AC8D-0259E1E661B1}" = VAIO Event Service
"{C767EE67-9AA4-1CBF-8FD4-87F52CBB041D}" = CCC Help Italian
"{C8E57F8C-64FE-28D7-0F65-7BE87AF49745}" = Catalyst Control Center Graphics Full New
"{CAE07D54-A400-DAF9-912B-306DD941B61C}" = Catalyst Control Center Localization Finnish
"{CB6CF566-E06F-2556-55EF-EE149FC6EE7F}" = CCC Help French
"{CD7E6232-D41D-4E5B-ABE1-0264B6260309}" = VAIO Content Metadata Intelligent Analyzing Manager
"{CE2121C6-C94D-4A73-8EA4-6943F33EE335}" = Music Transfer
"{D03D02D8-AB64-4785-A48E-5AA8B0FB8C14}" = Sony Home Network Library
"{D0F1DC40-37A4-4401-AC80-1FCCF01DEAF5}" = Windows Live Essentials
"{D355ECA7-DBF5-F22E-4E1A-BF69CFC5CED8}" = CCC Help Japanese
"{D44DF260-2D5A-3277-97D6-C97D1A806CF5}" = CCC Help Thai
"{D5068583-D569-468B-9755-5FBF5848F46F}" = Sony Picture Utility
"{D60F97EC-EF06-4E1E-B0D1-C2CBABA62FA3}" = VAIO Wallpaper Contents
"{D613E659-6503-42A8-9617-4F599061EAD5}" = VAIO MusicBox
"{D7019E24-BF07-3690-18C7-3D0DE87D09AB}" = CCC Help Chinese Standard
"{D7FFE7EB-1A15-864C-B335-E768BF623B84}" = Catalyst Control Center Localization Swedish
"{DABF43D9-1104-4764-927B-5BED1274A3B0}" = Runtime
"{DE1F799A-0A02-FF3B-8786-195E91D0DE94}" = CCC Help Spanish
"{DEF97A70-C67D-41E1-837C-6462C97A6F65}" = OpenMG Secure Module 5.3.00
"{E2C98732-F973-4985-A9C5-DC06178E16EE}" = Microsoft Mathematics Add-in (32-bit)
"{E31010F6-DE18-0E9F-E028-FC709306C6F1}" = Catalyst Control Center Localization Turkish
"{E3453B1B-C91B-4C48-B046-8DF635DD46F2}" = VAIO Content Metadata XML Interface Library
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E5BD6683-301D-B224-FB7C-320299CD51F9}" = CCC Help Hungarian
"{E9730C7A-E5DA-8222-45FE-2D71E810BE46}" = Catalyst Control Center Localization Spanish
"{EA39F1F5-D4A1-C02A-0865-7F6A95A33A56}" = CCC Help English
"{EADE97A7-E7AA-43FD-A042-92A68E0187A6}" = VAIO Content Metadata Manager Setting
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony Ericsson PC Companion 2.02.002
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F570A6CC-53ED-4AA9-8B08-551CD3E38D8B}" =
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F6D6B258-E3CA-4AAC-965A-68D3E3140A8C}" = iTunes
"{F909BB1B-3FC1-4EDA-AF1F-8F1A89163591}" = BlackBerry Desktop Software 6.1
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"5513-1208-7298-9440" = JDownloader 0.9
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"aTube Catcher" = aTube Catcher
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.1
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_104D0200" = HDAUDIO SoftV92 Data Fax Modem with SmartCP
"DAEMON Tools Lite" = DAEMON Tools Lite
"dt icon module" =
"eMusic Promotion" = 50 FREE MP3s +1 Free Audiobook!
"Flashtool" = Flashtool
"Free PDF to Word Doc Converter_is1" = Free PDF to Word Doc Converter v1.1
"FXWebPlayer" = FXWebPlayer
"Google Chrome" = Google Chrome
"InstallShield_{20471B27-D702-4FE8-8DEC-0702CC8C0A85}" = WinDVD for VAIO
"InstallShield_{4DCEA9C1-4D6E-41BF-A854-28CFA8B56DBF}" = Click to Disc Editor
"InstallShield_{DEF97A70-C67D-41E1-837C-6462C97A6F65}" = OpenMG Secure Module 5.3.00
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware versión 1.60.1.1000
"MarketingTools" = VAIO Marketing Tools
"MFU Module" =
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 10.0.2 (x86 es-ES)" = Mozilla Firefox 10.0.2 (x86 es-ES)
"Patrician III - Imperio de los Mares" = Patrician III - Imperio de los Mares
"STANDARD" = Microsoft Office Standard 2007
"Steam App 12200" = Bully: Scholarship Edition
"SubtitleWorkshop" = Subtitle Workshop 2.51
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Update Engine" = Sony Ericsson Update Engine
"uTorrent" = µTorrent
"VAIO Help and Support" =
"Veetle TV" = Veetle TV
"VLC media player" = VLC media player 1.1.11
"Winamp" = Winamp
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.01 (32-bit)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = aTube Toolbar Updater
"Spotify" = Spotify
"Winamp Detect" = Aplicación para detectar Winamp

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 15/02/2012 4:14:39 | Computer Name = Mariete | Source = VzCdbSvc | ID = 7
Description = Failed to load the plug-in module. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error
code = 0x80042019)

Error - 15/02/2012 4:15:03 | Computer Name = Mariete | Source = WinMgmt | ID = 10
Description =

Error - 15/02/2012 8:46:21 | Computer Name = Mariete | Source = VzCdbSvc | ID = 7
Description = Failed to load the plug-in module. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error
code = 0x80042019)

Error - 15/02/2012 8:47:20 | Computer Name = Mariete | Source = WinMgmt | ID = 10
Description =

Error - 15/02/2012 10:58:01 | Computer Name = Mariete | Source = SideBySide | ID = 16842785
Description = Error al generar el contexto de activación para "C:\Program Files\Common
Files\Research In Motion\AppLoader\MailServerMAPIProxy64.exe". No se encontró el
ensamblado dependiente Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Use
sxstrace.exe para obtener un diagnóstico detallado.

Error - 15/02/2012 10:59:29 | Computer Name = Mariete | Source = SideBySide | ID = 16842785
Description = Error al generar el contexto de activación para "C:\Program Files\Research
In Motion\BlackBerry Desktop\MailServerMAPIProxy64.exe". No se encontró el ensamblado
dependiente Microsoft.VC90.ATL,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Use
sxstrace.exe para obtener un diagnóstico detallado.

Error - 15/02/2012 11:01:31 | Computer Name = Mariete | Source = SideBySide | ID = 16842785
Description = Error al generar el contexto de activación para "c:\program files\sony
ericsson\sony ericsson pc companion\Drivers\DPInst64.exe". No se encontró el ensamblado
dependiente Microsoft.Windows.Common-Controls,language="*",processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0".
Use
sxstrace.exe para obtener un diagnóstico detallado.

Error - 15/02/2012 11:12:13 | Computer Name = Mariete | Source = Microsoft-Windows-Defrag | ID = 257
Description =

Error - 24/02/2012 6:25:02 | Computer Name = Mariete | Source = VzCdbSvc | ID = 7
Description = Failed to load the plug-in module. (GUID = {56F9312C-C989-4E04-8C23-299DEE3A36F5})(Error
code = 0x80042019)

Error - 24/02/2012 6:25:39 | Computer Name = Mariete | Source = WinMgmt | ID = 10
Description =

[ OSession Events ]
Error - 24/11/2011 5:24:55 | Computer Name = Mariete | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 6779
seconds with 60 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 09/12/2011 18:10:50 | Computer Name = Mariete | Source = Service Control Manager | ID = 7031
Description = El servicio Apple Mobile Device terminó inesperadamente. Esto se ha
repetido 2 veces. Se realizará la siguiente acción correctora en 60000 milisegundos:
Reiniciar el servicio.

Error - 09/12/2011 18:11:50 | Computer Name = Mariete | Source = Service Control Manager | ID = 7032
Description = El Administrador de control de servicios intentó realizar una acción
correctora (Reiniciar el servicio) después de la terminación inesperada del servicio
Apple Mobile Device, pero ocurrió el siguiente error: %%1056

Error - 09/12/2011 18:34:31 | Computer Name = Mariete | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 10/12/2011 6:26:08 | Computer Name = Mariete | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 10/12/2011 6:26:08 | Computer Name = Mariete | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 10/12/2011 10:04:30 | Computer Name = Mariete | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 11/12/2011 6:55:19 | Computer Name = Mariete | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 11/12/2011 6:55:19 | Computer Name = Mariete | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 11/12/2011 7:45:12 | Computer Name = Mariete | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 11/12/2011 7:45:12 | Computer Name = Mariete | Source = atikmdag | ID = 43029
Description = Display is not active


< End of report >
Hello, I Am Alander :)

Welcome to the Malware Removal forums.

I would be glad to take a look at your log and help you with solving any malware problems.

OTL logs can take a while to research so please be patient while I work on your log and I will post back here with any recommendations.

As I am still training, everything that I post to you, must be checked by an Admin or Moderator.

Thus, there may be a tiny bit of a delay between posts. While it shouldn't be too long, you can be assured you will get the best possible advice.

  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Rootkit Warning
Your computer has a serious infection, including a ZeroAccess rootkit.
A rootkit is a set of software tools intended for concealing running processes, files or system data from the operating system.

You are strongly advised to do the following:
  • Disconnect the computer from the Internet and from any networked computers until it is cleaned.
  • Call all your banks, financial institutions, credit card companies and inform them that you may be a victim of identity theft and put a watch on your accounts.
    If you don't mind the hassle, change all your account numbers.
  • From a clean computer, change all your passwords
    (Internet login, your email address(es), financial accounts, PayPal, eBay, Amazon…any online activities you carry out which require a username and password).
    Do NOT change your passwords from this computer, the attacker can still get all the new passwords and transaction records.
  • Back up all your important data except programs. The programs can be reinstalled back from the original disc or from the Net.

Due to its rootkit functionality, your computer is very likely to have been compromised and there is no way that it can be trusted again.
Many experts in the security community believe that once infected with this type of trojan, the best course of action would be to do a reformat and re-installation of the operating system (OS).
This decision will have to be made by you…

To help you understand more, please take some time to read the following articles:
When should I re-format and reinstall my OS
What are Remote Access Trojans and why are they dangerous
How do I respond to a possible identity theft and how do I prevent it
Back up and restore: frequently asked questions
Restoring your Vista-W7 backups … Restoring your XP backups

Please let me know how you wish to proceed.
HI I haven't used my laptop since I was infected and I didnt make any purchase. Is possible to know when My laptop became infected? can this have acces to previous card and data ? for example buying someting in december and having acces to those data ? Could this infect other pc,s in the network ? I havent used paypal for two months…are those past logs in danger too? IM going to reinstall windows i dont mind but i want to know which passswords or logs are in danger… Many thanks
Hi :), sorry for the late reply..
I had to verify some answers posed by ur questions

It is not possible to determine the actual day of your infection, and hence, I am unable to confirm whether your past transactions are affected.

It is best that you change all your passwords from a safe computer ..

The infection should not infect your network

If you are goin with a reformat and have no other questions, notify me after you read this and I will have this thread close..

Alander

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI