This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Something consuming 100% of my CPU all the time - Please help [Solved]

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,

From about a month ago my pc is working really slow and freezing all the time. I Checked the tasked manager and i saw that it is using all the time 100% of the CPU, making my laptop almost useless. Please Help me and thanks in advance.

Here its my HTJ log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:34:12, on 10/03/2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Archivos de programa\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Archivos de programa\iTunes\iTunesHelper.exe
C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe
C:\Archivos de programa\Jumi\Jumi.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
C:\Archivos de programa\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\Mohamed\CONFIG~1\Temp\RtkBtMnt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Mohamed\Escritorio\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Archivos de programa\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Archivos de programa\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Archivos de programa\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Archivos de programa\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: @C:\Archivos de programa\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Archivos de programa\MSN Toolbar\Platform\6.3.2291.0\npwinext.dll
O4 - HKLM\..\Run: [AzMixerSel] C:\Archivos de programa\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Archivos de programa\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Archivos de programa\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKCU\..\Run: [msnmsgr] "C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [JumiController] C:\Archivos de programa\Jumi\Jumi.exe
O4 - HKCU\..\Run: [Kdjojy] C:\Documents and Settings\Mohamed\Datos de programa\Kdjojy.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadwin PrintScreen] C:\Archivos de programa\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10p_ActiveX.exe -update activex
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enviar a &Bluetooth - C:\Archivos de programa\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Agregar entrada - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Archivos de programa\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Agregar entrada en Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Archivos de programa\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Archivos de programa\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Archivos de programa\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O22 - SharedTaskScheduler: Precargador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Demonio de caché de las categorías de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Servicio Bonjour (Bonjour Service) - Apple Inc. - C:\Archivos de programa\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Archivos de programa\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Servicio del administrador de discos lógicos (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Registro de sucesos (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Servicio de Google Update (gupdate) (gupdate) - Unknown owner - C:\Archivos de programa\Google\Update\GoogleUpdate.exe
O23 - Service: Servicio de Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Archivos de programa\Google\Update\GoogleUpdate.exe
O23 - Service: Administración de IIS (IISADMIN) - Unknown owner - C:\WINDOWS\system32\inetsrv\inetinfo.exe
O23 - Service: Servicio COM de grabación de CD de IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Servicio del iPod (iPod Service) - Apple Inc. - C:\Archivos de programa\iPod\bin\iPodService.exe
O23 - Service: Escritorio remoto compartido de NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Administrador de sesión de Ayuda de escritorio remoto (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Tarjeta inteligente (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Protocolo simple de transferencia de correo (SMTP) (SMTPSVC) - Unknown owner - C:\WINDOWS\system32\inetsrv\inetinfo.exe
O23 - Service: Registros y alertas de rendimiento (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Telnet (TlntSvr) - Unknown owner - C:\WINDOWS\system32\tlntsvr.exe
O23 - Service: Instantáneas de volumen (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Publicación en World Wide Web (W3SVC) - Unknown owner - C:\WINDOWS\system32\inetsrv\inetinfo.exe
O23 - Service: Adaptador de rendimiento de WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe

–
End of file - 9471 bytes


Thanks for any help…
Hi Moe_J_AK,

Is this the same computer we worked on about 5 months ago HERE ?

Looking at that thread we never finished cleaning it and the same infection remains.

Any reason this machine only has XP Service Pack 2 installed?

Open hijackthis, do a system scan only and checkmark these lines, if present

O4 - HKCU\..\Run: [Kdjojy] C:\Documents and Settings\Mohamed\Datos de programa\Kdjojy.exe


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT and reboot the machine.

Next

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.



Next

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it. If asked to download Avast's database please do so.

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

Please post back with
  • both OTL logs
  • aswMBR log
  • mbr.zip (attached)
No need for a HJt log this time.
Hi oldman960,

Yeah it is… hmmmm I guess because pc worked fine and i had a tight schedule at the time… i didnt continue… Sorry…

And i have to tell you, since i had already run these programs 5 months ago, some of the files were on the desktop and some files were over written, but others didnt…. so I have the new OLT.txt file, but the extra.txt when i opened it, its the old one (old date)…. the same happened when i ran the aswMBR…. so i cleaned the old files and ran again the aswMBR and now i have the new files…should i run the OLT again… Anyways here im posting the new files:



OTL logfile created on: 12/03/2012 20:36:59 - Run 4
OTL by OldTimer - Version 3.2.36.3 Folder = C:\Documents and Settings\Mohamed\Escritorio
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C0A | Country: España | Language: ESN | Date Format: dd/MM/yyyy

766,36 Mb Total Physical Memory | 339,52 Mb Available Physical Memory | 44,30% Memory free
1,83 Gb Paging File | 1,45 Gb Available in Paging File | 79,34% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa
Drive C: | 74,52 Gb Total Space | 61,35 Gb Free Space | 82,32% Space Free | Partition Type: NTFS

Computer Name: MYPC | User Name: Mohamed | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Mohamed\Escritorio\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Mohamed\Configuración local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Archivos de programa\Jumi\jumi.exe (Jumi Technologies)
PRC - C:\Archivos de programa\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc)
PRC - C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Archivos de programa\Jumi\PreloadedProducts.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\5adb0f89d469632511aed9d88cfe05c4\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\d987cf1de4ba688da92e212a374232c2\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll ()
MOD - C:\Archivos de programa\Archivos comunes\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Archivos de programa\Jumi\libvorbis.dll ()
MOD - C:\Archivos de programa\Jumi\libtheora.dll ()
MOD - C:\Archivos de programa\Jumi\libogg.dll ()
MOD - C:\Archivos de programa\HP\Digital Imaging\bin\crm\xmltok.dll ()
MOD - C:\Archivos de programa\HP\Digital Imaging\bin\crm\xmlparse.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) – C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (msvsmon80) – c:\Archivos de programa\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (W3SVC) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Protocolo simple de transferencia de correo (SMTP) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (ose) – C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (MBAMSwissArmy) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – File not found
DRV - (jumi) – C:\WINDOWS\system32\drivers\jumi.sys (Windows ® Win 7 DDK provider)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (nvsmu) – C:\WINDOWS\system32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://es.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = es
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 08 C0 FA 3D A3 00 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.update: false

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Archivos de programa\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Archivos de programa\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Archivos de programa\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Archivos de programa\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Archivos de programa\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Archivos de programa\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Archivos de programa\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Archivos de programa\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/07/09 17:26:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Archivos de programa\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/07/09 17:26:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Archivos de programa\Mozilla Firefox\components [2011/08/01 19:20:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Archivos de programa\Mozilla Firefox\plugins

[2011/08/01 19:21:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Mohamed\Datos de programa\Mozilla\Extensions
[2011/08/01 19:20:53 | 000,000,000 | —D | M] (No name found) – C:\Archivos de programa\Mozilla Firefox\extensions
[2011/05/05 13:48:47 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/04/14 12:43:44 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Archivos de programa\mozilla firefox\components\browsercomps.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Archivos de programa\mozilla firefox\searchplugins\bing.xml
[2010/01/01 04:00:00 | 000,003,996 | —- | M] () – C:\Archivos de programa\mozilla firefox\searchplugins\drae.xml
[2010/01/01 04:00:00 | 000,001,143 | —- | M] () – C:\Archivos de programa\mozilla firefox\searchplugins\eBay-es.xml
[2010/01/01 04:00:00 | 000,001,178 | —- | M] () – C:\Archivos de programa\mozilla firefox\searchplugins\wikipedia-es.xml
[2010/01/01 04:00:00 | 000,001,102 | —- | M] () – C:\Archivos de programa\mozilla firefox\searchplugins\yahoo-es.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Archivos de programa\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Archivos de programa\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Archivos de programa\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Archivos de programa\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Archivos de programa\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Archivos de programa\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Archivos de programa\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Archivos de programa\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Archivos de programa\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Archivos de programa\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Archivos de programa\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Archivos de programa\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2011/10/12 17:16:06 | 000,000,098 | —- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Aplicación auxiliar de inicio de sesión) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [AzMixerSel] C:\Archivos de programa\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKCU..\Run: [Gadwin PrintScreen] C:\Archivos de programa\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc)
O4 - HKCU..\Run: [JumiController] C:\Archivos de programa\Jumi\jumi.exe (Jumi Technologies)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Enviar a &Bluetooth - C:\Archivos de programa\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Archivos de programa\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Archivos de programa\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Archivos de programa\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{96A2F297-FB43-4144-BF25-5A46CDA4A1BD}: DhcpNameServer = 10.1.192.12 10.1.192.13
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D2697178-B478-4F06-95E6-6A56471D5BFF}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - c:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - c:\Archivos de programa\Archivos comunes\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Mi página de inicio actual) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Mohamed\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mohamed\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/29 22:11:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/03/12 19:43:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Mohamed\Escritorio\backups
[2012/03/10 20:28:26 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Mohamed\Escritorio\HiJackThis.exe
[2011/10/16 11:30:25 | 000,157,696 | —- | C] (Thorsten Blauhut http://www.desksave.de) – C:\Documents and Settings\Mohamed\Datos de programa\Kdjojy.exe
[2011/10/14 10:12:06 | 000,111,616 | —- | C] (Thorsten Blauhut http://www.desksave.de) – C:\Documents and Settings\Mohamed\Datos de programa\24.exe
[2011/10/14 10:11:53 | 000,111,616 | —- | C] (Thorsten Blauhut http://www.desksave.de) – C:\Documents and Settings\Mohamed\Datos de programa\23.exe
[10 C:\Documents and Settings\Mohamed\Datos de programa\*.tmp files -> C:\Documents and Settings\Mohamed\Datos de programa\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/03/12 21:08:00 | 000,000,492 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{E647A242-7FC7-4F6B-94E4-C11FFAE6D111}.job
[2012/03/12 21:03:10 | 000,001,104 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/12 19:48:34 | 000,594,944 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mohamed\Escritorio\OTL.exe
[2012/03/12 19:33:32 | 000,001,876 | —- | M] () – C:\Documents and Settings\All Users\Escritorio\Google Chrome.lnk
[2012/03/12 18:35:56 | 000,001,100 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/12 18:34:33 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/03/12 18:34:27 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/03/10 20:28:37 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Mohamed\Escritorio\HiJackThis.exe
[2012/03/10 19:21:58 | 000,603,426 | —- | M] () – C:\WINDOWS\System32\perfh00A.dat
[2012/03/10 19:21:58 | 000,534,026 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/03/10 19:21:58 | 000,127,670 | —- | M] () – C:\WINDOWS\System32\perfc00A.dat
[2012/03/10 19:21:58 | 000,106,704 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/03/02 22:53:29 | 000,240,671 | —- | M] () – C:\setup_av_free.exe
[10 C:\Documents and Settings\Mohamed\Datos de programa\*.tmp files -> C:\Documents and Settings\Mohamed\Datos de programa\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/03/02 22:53:23 | 000,240,671 | —- | C] () – C:\setup_av_free.exe
[2011/10/16 11:30:33 | 000,013,151 | —- | C] () – C:\Documents and Settings\Mohamed\Datos de programa\2A.exe
[2011/10/15 15:45:03 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Mohamed\Datos de programa\I1kIfJMHH0fH
[2011/10/14 13:55:45 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/10/14 10:12:00 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Mohamed\Datos de programa\ey70t1h11gK1
[2011/10/12 17:18:58 | 000,453,071 | —- | C] () – C:\Documents and Settings\Mohamed\Datos de programa\1D.exe
[2011/10/11 23:45:27 | 000,453,071 | —- | C] () – C:\Documents and Settings\Mohamed\Datos de programa\1B.exe
[2011/10/11 20:27:10 | 000,453,071 | —- | C] () – C:\Documents and Settings\Mohamed\Datos de programa\1A.exe
[2011/10/04 21:46:05 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/10/04 21:46:05 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/10/04 21:46:05 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/10/04 21:46:05 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/10/04 21:46:05 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/07/31 17:42:07 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/06/01 01:56:06 | 000,003,584 | —- | C] () – C:\Documents and Settings\Mohamed\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/30 18:23:33 | 000,000,000 | —- | C] () – C:\Documents and Settings\Mohamed\Configuración local\Datos de programa\{A596FA9B-DFE2-4F9D-AA43-A3CC00FB55F8}
[2011/05/30 00:47:20 | 000,127,888 | —- | C] () – C:\WINDOWS\hpoins11.dat
[2011/05/30 00:47:12 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2011/05/01 19:55:43 | 000,023,449 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2011/05/01 19:55:42 | 000,001,135 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2011/05/01 19:55:26 | 000,061,186 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2011/05/01 19:55:25 | 000,015,241 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2011/05/01 19:55:23 | 000,017,947 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2011/04/30 01:23:56 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2011/04/30 00:31:10 | 000,000,379 | —- | C] () – C:\WINDOWS\ODBC.INI
[2011/04/29 23:29:27 | 000,001,732 | —- | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2011/04/29 22:52:24 | 000,000,008 | -HS- | C] () – C:\WINDOWS\System32\Desktop_.ini
[2011/04/29 22:45:50 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2011/04/29 22:28:35 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2011/04/29 22:21:23 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2011/04/29 22:21:21 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\mmswitch.dll
[2011/04/29 22:21:18 | 000,421,888 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2011/04/29 22:21:18 | 000,168,448 | —- | C] () – C:\WINDOWS\System32\ympg.dll
[2011/04/29 22:21:16 | 000,000,695 | —- | C] () – C:\WINDOWS\M3JPEG.INI
[2011/04/29 22:21:16 | 000,000,079 | —- | C] () – C:\WINDOWS\huffyuv.ini
[2011/04/29 22:21:14 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2011/04/29 22:21:14 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\ffvfw.dll
[2011/04/29 22:21:14 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\ff_theora.dll
[2011/04/29 22:14:19 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/04/29 22:08:26 | 000,021,900 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/04/29 16:54:37 | 000,004,205 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/04/29 16:53:18 | 000,195,368 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

========== LOP Check ==========

[2011/05/23 22:17:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Datos de programa\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/04/30 00:48:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Mohamed\Datos de programa\Blitware
[2011/11/12 12:20:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Mohamed\Datos de programa\PhotoScape
[2011/11/13 15:02:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Mohamed\Datos de programa\TP
[2011/08/28 02:38:00 | 000,000,354 | —- | M] () – C:\WINDOWS\Tasks\Driver Robot.job
[2012/03/12 21:08:00 | 000,000,492 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{E647A242-7FC7-4F6B-94E4-C11FFAE6D111}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/04/29 22:11:29 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/05/01 19:23:57 | 000,000,211 | —- | M] () – C:\Boot.bak
[2011/10/04 21:55:57 | 000,000,327 | RHS- | M] () – C:\boot.ini
[2002/09/24 08:00:00 | 000,004,952 | RHS- | M] () – C:\Bootfont.bin
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2011/10/05 22:11:41 | 000,010,525 | —- | M] () – C:\ComboFix.txt
[2011/04/29 22:11:29 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2011/05/04 19:25:18 | 000,042,752 | —- | M] () – C:\GDIPFONTCACHEV1.DAT
[2011/04/29 22:11:29 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/03/12 18:35:47 | 000,167,065 | —- | M] () – C:\Jumi.Log
[2012/03/12 21:11:43 | 000,085,605 | -H– | M] () – C:\Jumi.Log.Run
[2011/04/29 22:11:29 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/03 16:38:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/03 16:59:42 | 000,250,640 | RHS- | M] () – C:\ntldr
[2012/03/12 18:34:08 | 1207,959,552 | -HS- | M] () – C:\pagefile.sys
[2012/03/02 22:53:29 | 000,240,671 | —- | M] () – C:\setup_av_free.exe

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2011/04/29 22:10:57 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/04/10 14:02:32 | 000,074,240 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp054.dll
[2004/03/22 09:17:08 | 000,025,840 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/17 01:14:24 | 000,307,056 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2011/04/29 17:51:59 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2011/04/29 17:51:59 | 000,667,648 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2011/04/29 17:51:59 | 000,487,424 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-06-03 03:43:16

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s >


< MD5 for: EXPLORER.EXE >
[2008/04/13 22:18:57 | 001,036,288 | —- | M] (Microsoft Corporation) MD5=7522F548A84ABAD8FA516DE5AB3931EF – C:\WINDOWS\SoftwareDistribution\Download\4fcdf3a74fe834ce16dc12a720df5cc7\explorer.exe
[2004/08/19 09:42:48 | 001,034,752 | —- | M] (Microsoft Corporation) MD5=89C8DD146CEAF482D82822766437D93F – C:\WINDOWS\ERDNT\cache\explorer.exe
[2004/08/19 09:42:48 | 001,034,752 | —- | M] (Microsoft Corporation) MD5=89C8DD146CEAF482D82822766437D93F – C:\WINDOWS\explorer.exe
[2004/08/19 09:42:48 | 001,034,752 | —- | M] (Microsoft Corporation) MD5=89C8DD146CEAF482D82822766437D93F – C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2012/03/08 21:55:50 | 000,092,504 | —- | M] () MD5=837212DB53E44995C25148F2F45CF04C – C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf

< MD5 for: EXPLORER.SCF >
[2002/09/24 08:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/25 02:48:52 | 000,577,960 | —- | M] () MD5=18E446367A68F4D08A33942B337C14D0 – C:\WINDOWS\Help\iexplore.chm
[2004/07/17 05:34:36 | 000,227,056 | —- | M] () MD5=C7DA6EA87D41CD653EFE6D315E678FD6 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2008/04/13 22:18:59 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=12CE2CACCF25D99944CA69F6A3A83441 – C:\WINDOWS\SoftwareDistribution\Download\4fcdf3a74fe834ce16dc12a720df5cc7\iexplore.exe
[2004/08/19 09:42:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=2E47EC1812526240B1F9E00FB9E5036D – C:\WINDOWS\ie8\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Archivos de programa\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\ERDNT\cache\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\system32\dllcache\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:13:40 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=EA808DE2547B585255430B85F82CC1A0 – C:\Archivos de programa\Internet Explorer\es-ES\iexplore.exe.mui
[2009/03/08 14:13:40 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=EA808DE2547B585255430B85F82CC1A0 – C:\Archivos de programa\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-07A56490.PF >
[2012/03/12 19:47:23 | 000,093,606 | —- | M] () MD5=55748A153CC078AB00DB84BD2757895B – C:\WINDOWS\Prefetch\IEXPLORE.EXE-07A56490.pf

< MD5 for: IEXPLORE.HLP >
[2002/09/24 08:00:00 | 000,096,973 | —- | M] () MD5=F9111B7FB74FA32922370CC51E6D485E – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: WINLOGON.EXE >
[2008/04/13 22:19:15 | 000,510,976 | —- | M] (Microsoft Corporation) MD5=213C80D912880BBF04453D09FFCCB28C – C:\WINDOWS\SoftwareDistribution\Download\4fcdf3a74fe834ce16dc12a720df5cc7\winlogon.exe
[2004/08/19 09:43:16 | 000,505,344 | —- | M] (Microsoft Corporation) MD5=FCB59D25D628B4D3181DC816D14679DD – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2004/08/19 09:43:16 | 000,505,344 | —- | M] (Microsoft Corporation) MD5=FCB59D25D628B4D3181DC816D14679DD – C:\WINDOWS\system32\dllcache\winlogon.exe
[2004/08/19 09:43:16 | 000,505,344 | —- | M] (Microsoft Corporation) MD5=FCB59D25D628B4D3181DC816D14679DD – C:\WINDOWS\system32\winlogon.exe

< End of report >




aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-03-13 19:12:51
—————————–
19:12:51.906 OS Version: Windows 5.1.2600 Service Pack 2
19:12:51.906 Number of processors: 1 586 0x4C02
19:12:51.906 ComputerName: MYPC UserName:
19:12:52.875 Initialize success
19:13:05.937 AVAST engine defs: 12031200
19:13:45.828 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
19:13:45.828 Disk 0 Vendor: ST980811AS 3.ALD Size: 76319MB BusType: 3
19:13:45.843 Disk 0 MBR read successfully
19:13:45.843 Disk 0 MBR scan
19:13:45.906 Disk 0 Windows XP default MBR code
19:13:45.906 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76308 MB offset 63
19:13:45.921 Disk 0 scanning sectors +156280320
19:13:45.984 Disk 0 scanning C:\WINDOWS\system32\drivers
19:13:54.890 Service scanning
19:14:16.359 Modules scanning
19:14:25.875 Disk 0 trace - called modules:
19:14:25.921 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
19:14:25.921 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82fcdab8]
19:14:26.250 3 CLASSPNP.SYS[f74e805b] -> nt!IofCallDriver -> \Device\00000067[0x82f63a98]
19:14:26.250 5 ACPI.sys[f735d620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x82fbc940]
19:14:27.312 AVAST engine scan C:\WINDOWS
19:14:38.078 AVAST engine scan C:\WINDOWS\system32
19:17:08.328 AVAST engine scan C:\WINDOWS\system32\drivers
19:17:18.921 AVAST engine scan C:\Documents and Settings\Mohamed
19:21:57.875 File: C:\Documents and Settings\Mohamed\Configuración local\Temp\2VffHhr4oh1a1d3ald.tmp **INFECTED** Win32:Tiny-AMS [Trj]
19:21:58.593 File: C:\Documents and Settings\Mohamed\Configuración local\Temp\acd\z.exe **INFECTED** Win32:Malware-gen
19:21:59.671 File: C:\Documents and Settings\Mohamed\Configuración local\Temp\install-0.exe **INFECTED** Win32:VBCrypter-A [Cryp]
19:22:10.531 File: C:\Documents and Settings\Mohamed\Configuración local\Temp\POSITION4DLLNAME.txt **INFECTED** Win32:Tiny-AMS [Trj]
19:22:27.265 File: C:\Documents and Settings\Mohamed\Datos de programa\14.tmp **INFECTED** Win32:VBCrypter-A [Cryp]
19:22:27.328 File: C:\Documents and Settings\Mohamed\Datos de programa\15.tmp **INFECTED** Win32:VBCrypter-A [Cryp]
19:22:27.359 File: C:\Documents and Settings\Mohamed\Datos de programa\18.tmp **INFECTED** Win32:VBCrypter-A [Cryp]
19:22:27.421 File: C:\Documents and Settings\Mohamed\Datos de programa\19.tmp **INFECTED** Win32:VBCrypter-A [Cryp]
19:22:27.531 File: C:\Documents and Settings\Mohamed\Datos de programa\1A.tmp **INFECTED** Win32:VBCrypter-A [Cryp]
19:22:27.703 File: C:\Documents and Settings\Mohamed\Datos de programa\22.tmp **INFECTED** Win32:VBCrypter-A [Cryp]
19:22:27.734 File: C:\Documents and Settings\Mohamed\Datos de programa\23.exe **INFECTED** Win32:Crypt-KQI [Trj]
19:22:27.765 File: C:\Documents and Settings\Mohamed\Datos de programa\24.exe **INFECTED** Win32:Crypt-KQI [Trj]
19:22:27.812 File: C:\Documents and Settings\Mohamed\Datos de programa\26.tmp **INFECTED** Win32:VBCrypter-A [Cryp]
19:22:27.859 File: C:\Documents and Settings\Mohamed\Datos de programa\27.tmp **INFECTED** Win32:VBCrypter-A [Cryp]
19:22:28.000 File: C:\Documents and Settings\Mohamed\Datos de programa\7.tmp **INFECTED** Win32:VBCrypter-A [Cryp]
19:24:42.515 AVAST engine scan C:\Documents and Settings\All Users
19:25:05.484 Scan finished successfully
19:26:33.265 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Mohamed\Escritorio\MBR.dat"
19:26:33.265 The log file has been saved successfully to "C:\Documents and Settings\Mohamed\Escritorio\aswMBR.txt"


So the only file missing is extra.txt…. should i run OLT again?…. by the way pc is running smoother…

Thanks once again my friend for helping me…

Attachments:

Hi Moe_J_AK,

We'll get the Extra.txt later.

If you have a copy of combofix currently on your desktop please right click it and click delete.

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3.CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.
Hey oldman960,


here its the combofix log:

ComboFix 12-03-13.01 - Mohamed 13/03/2012 20:04:12.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.34.3082.18.766.404 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Escritorio\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Mohamed\Datos de programa\14.tmp
c:\documents and settings\Mohamed\Datos de programa\15.tmp
c:\documents and settings\Mohamed\Datos de programa\18.tmp
c:\documents and settings\Mohamed\Datos de programa\19.tmp
c:\documents and settings\Mohamed\Datos de programa\1A.exe
c:\documents and settings\Mohamed\Datos de programa\1A.tmp
c:\documents and settings\Mohamed\Datos de programa\1B.exe
c:\documents and settings\Mohamed\Datos de programa\1D.exe
c:\documents and settings\Mohamed\Datos de programa\22.tmp
c:\documents and settings\Mohamed\Datos de programa\23.exe
c:\documents and settings\Mohamed\Datos de programa\24.exe
c:\documents and settings\Mohamed\Datos de programa\26.tmp
c:\documents and settings\Mohamed\Datos de programa\27.tmp
c:\documents and settings\Mohamed\Datos de programa\29.tmp
c:\documents and settings\Mohamed\Datos de programa\2A.exe
c:\documents and settings\Mohamed\Datos de programa\7.tmp
c:\windows\system32\ympgcdc.cfg
.
.
((((((((((((((((((((((((( Files Created from 2012-02-14 to 2012-03-14 )))))))))))))))))))))))))))))))
.
.
2012-03-03 02:53 . 2012-03-03 02:53 240671 —-a-w- C:\setup_av_free.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-14 16:43 . 2011-08-01 23:20 142296 —-a-w- c:\archivos de programa\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-10-05_02.08.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-10-17 00:46 . 2011-08-31 21:00 22216 c:\windows\system32\drivers\mbam.sys
+ 2012-02-03 01:58 . 2012-02-03 01:58 22016 c:\windows\Installer\2521b1.msi
+ 2011-11-22 01:12 . 2011-11-22 01:12 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2011-11-22 01:12 . 2011-11-22 01:12 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2011-11-22 01:12 . 2011-11-22 01:12 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2011-11-22 01:12 . 2011-11-22 01:12 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2011-11-22 01:12 . 2011-11-22 01:12 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2011-11-22 01:12 . 2011-11-22 01:12 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2011-11-22 01:12 . 2011-11-22 01:12 65536 c:\windows\Installer\{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}\ARPPRODUCTICON.exe
+ 2002-09-24 12:00 . 2012-03-10 23:21 603426 c:\windows\system32\perfh00A.dat
+ 2002-09-24 12:00 . 2012-03-10 23:21 534026 c:\windows\system32\perfh009.dat
+ 2002-09-24 12:00 . 2012-03-10 23:21 127670 c:\windows\system32\perfc00A.dat
+ 2002-09-24 12:00 . 2012-03-10 23:21 106704 c:\windows\system32\perfc009.dat
+ 2011-05-01 23:55 . 2012-03-13 22:51 256652 c:\windows\system32\inetsrv\MetaBase.bin
+ 2011-11-22 01:12 . 2011-11-22 01:12 1435136 c:\windows\Installer\2cb90c.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JumiController"="c:\archivos de programa\Jumi\Jumi.exe" [2011-06-05 3427328]
"Gadwin PrintScreen"="c:\archivos de programa\Gadwin Systems\PrintScreen\PrintScreen.exe" [2011-05-03 487424]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="c:\archivos de programa\Realtek\InstallShield\AzMixerSel.exe" [2007-07-12 53248]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-12 16132608]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-07-12 8429568]
"nwiz"="nwiz.exe" [2007-07-12 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-07-12 81920]
"QuickTime Task"="c:\archivos de programa\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\archivos de programa\iTunes\iTunesHelper.exe" [2011-04-27 421160]
"HP Software Update"="c:\archivos de programa\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
"Microsoft Default Manager"="c:\archivos de programa\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
.
c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\
HP Digital Imaging Monitor.lnk - c:\archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menú Inicio^Programas^Inicio^BTTray.lnk]
path=c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SQLWriter"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Archivos de programa\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Archivos de programa\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Archivos de programa\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Archivos de programa\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Archivos de programa\\Bonjour\\mDNSResponder.exe"=
"c:\\Archivos de programa\\iTunes\\iTunes.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Archivos de programa\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Archivos de programa\\Jumi\\jumi.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1433:TCP"= 1433:TCP:sqlserver
"5720:TCP"= 5720:TCP:Jumi Controller
"5720:UDP"= 5720:UDP:Jumi Controller
"8888:TCP"= 8888:TCP:iphone
.
R2 ReportServer$SQLEXPRESS;SQL Server Reporting Services (SQLEXPRESS);c:\archivos de programa\Microsoft SQL Server\MSSQL.2\Reporting Services\ReportServer\bin\ReportingServicesService.exe [14/04/2006 9:59 14624]
R3 jumi;%Jumi%;c:\windows\system32\drivers\jumi.sys [03/06/2010 11:07 13112]
S2 gupdate;Servicio de Google Update (gupdate);c:\archivos de programa\Google\Update\GoogleUpdate.exe [11/05/2011 23:25 136176]
S3 gupdatem;Servicio de Google Update (gupdatem);c:\archivos de programa\Google\Update\GoogleUpdate.exe [11/05/2011 23:25 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\archivos de programa\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [23/09/2005 7:01 2799808]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - aswMBR
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\archivos de programa\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
.
2011-08-28 c:\windows\Tasks\Driver Robot.job
- c:\archivos de programa\Driver Robot\Driver Robot.lnk [2011-04-30 04:48]
.
2012-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\archivos de programa\Google\Update\GoogleUpdate.exe [2011-05-12 03:24]
.
2012-03-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\archivos de programa\Google\Update\GoogleUpdate.exe [2011-05-12 03:24]
.
2012-03-13 c:\windows\Tasks\User_Feed_Synchronization-{E647A242-7FC7-4F6B-94E4-C11FFAE6D111}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportar a Microsoft Excel - c:\archiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Enviar a &Bluetooth - c:\archivos de programa\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 192.168.0.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Mohamed\Datos de programa\Mozilla\Firefox\Profiles\9i5urqgs.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-13 20:12
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-03-13 20:14:46
ComboFix-quarantined-files.txt 2012-03-14 00:14
ComboFix2.txt 2011-10-06 02:11
ComboFix3.txt 2011-10-05 02:13
.
Pre-Run: 65.676.922.880 bytes libres
Post-Run: 66.221.993.984 bytes libres
.
- - End Of File - - 72D60129B624D48B2E478484921716E5
Hi Moe_J_AK,

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
[2011/10/14 10:12:06 | 000,111,616 | —- | C] (Thorsten Blauhut http://www.desksave.de) – C:\Documents and Settings\Mohamed\Datos de programa\24.exe
[2011/10/14 10:11:53 | 000,111,616 | —- | C] (Thorsten Blauhut http://www.desksave.de) – C:\Documents and Settings\Mohamed\Datos de programa\23.exe
[2011/10/15 15:45:03 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Mohamed\Datos de programa\I1kIfJMHH0fH
[2011/10/14 10:12:00 | 000,000,000 | -H– | C] () – C:\Documents and Settings\Mohamed\Datos de programa\ey70t1h11gK1

:Files
C:\Documents and Settings\Mohamed\Datos de programa\Kdjojy.exe

:Commands
[purity]
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Next

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • check the box beside scan all users
  • In the Extra Registry section change it to All
  • UNCheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • OTL fix log
  • OTL.txt
  • Extra.txt
How's the computer?
hey oldman960,

Its weird, because after following ur first reply, my laptop was working way better (running smoother), but now after restarting my laptop as you asked me todo in your last post computer is freezing again and running very slow. I went to check the task manager and once again its consuming all the cpu 100% of usage.

Anyways here are the logs you asked for:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
File C:\Documents and Settings\Mohamed\Datos de programa\24.exe not found.
File C:\Documents and Settings\Mohamed\Datos de programa\23.exe not found.
C:\Documents and Settings\Mohamed\Datos de programa\I1kIfJMHH0fH moved successfully.
C:\Documents and Settings\Mohamed\Datos de programa\ey70t1h11gK1 moved successfully.
========== FILES ==========
C:\Documents and Settings\Mohamed\Datos de programa\Kdjojy.exe moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrador
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Administrador.MYPC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32835 bytes

User: Mohamed
->Temp folder emptied: 532132 bytes
->Temporary Internet Files folder emptied: 21332701 bytes
->FireFox cache emptied: 95381279 bytes
->Google Chrome cache emptied: 9238672 bytes
->Flash cache emptied: 14811 bytes

User: MYPC

User: NetworkService
->Temp folder emptied: 16384 bytes
->Temporary Internet Files folder emptied: 32835 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 707216 bytes

Total Files Cleaned = 121,00 mb

Restore point Set: OTL Restore Point (0)

OTL by OldTimer - Version 3.2.36.3 log created on 03132012_213259

Files\Folders moved on Reboot…
File\Folder C:\Documents and Settings\NetworkService\Configuración local\Temp\Perflib_Perfdata_7c8.dat not found!

Registry entries deleted on Reboot…


OTL logfile created on: 13/03/2012 22:12:00 - Run 5
OTL by OldTimer - Version 3.2.36.3 Folder = C:\Documents and Settings\Mohamed\Escritorio
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C0A | Country: España | Language: ESN | Date Format: dd/MM/yyyy

766,36 Mb Total Physical Memory | 360,42 Mb Available Physical Memory | 47,03% Memory free
1,83 Gb Paging File | 1,49 Gb Available in Paging File | 81,42% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa
Drive C: | 74,52 Gb Total Space | 61,79 Gb Free Space | 82,91% Space Free | Partition Type: NTFS

Computer Name: MYPC | User Name: Mohamed | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Mohamed\Configuración local\Temp\RtkBtMnt.exe (Realtek Semiconductor Corp.)
PRC - C:\Documents and Settings\Mohamed\Escritorio\OTL.exe (OldTimer Tools)
PRC - C:\Archivos de programa\Jumi\jumi.exe (Jumi Technologies)
PRC - C:\Archivos de programa\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc)
PRC - C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Archivos de programa\Jumi\PreloadedProducts.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\5adb0f89d469632511aed9d88cfe05c4\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\d987cf1de4ba688da92e212a374232c2\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\WINDOWS\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\WINDOWS\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll ()
MOD - C:\Archivos de programa\Archivos comunes\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Archivos de programa\Jumi\libvorbis.dll ()
MOD - C:\Archivos de programa\Jumi\libtheora.dll ()
MOD - C:\Archivos de programa\Jumi\libogg.dll ()
MOD - C:\Archivos de programa\HP\Digital Imaging\bin\crm\xmltok.dll ()
MOD - C:\Archivos de programa\HP\Digital Imaging\bin\crm\xmlparse.dll ()


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) – C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (msvsmon80) – c:\Archivos de programa\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe (Microsoft Corporation)
SRV - (W3SVC) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Protocolo simple de transferencia de correo (SMTP) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (ose) – C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (MBAMSwissArmy) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (catchme) – File not found
DRV - (jumi) – C:\WINDOWS\system32\drivers\jumi.sys (Windows ® Win 7 DDK provider)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (nvsmu) – C:\WINDOWS\system32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (BTKRNL) – C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (btaudio) – C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.)
DRV - (BTWDNDIS) – C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.)
DRV - (btwhid) – C:\WINDOWS\system32\drivers\btwhid.sys (Broadcom Corporation.)
DRV - (BTDriver) – C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-854245398-1214440339-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://es.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-854245398-1214440339-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = es
IE - HKU\S-1-5-21-854245398-1214440339-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 48 16 FC 8A 77 01 CD 01 [binary data]
IE - HKU\S-1-5-21-854245398-1214440339-839522115-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-854245398-1214440339-839522115-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-854245398-1214440339-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-854245398-1214440339-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.update: false

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Archivos de programa\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Archivos de programa\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Archivos de programa\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Archivos de programa\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Archivos de programa\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Archivos de programa\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Archivos de programa\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Archivos de programa\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/07/09 17:26:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Archivos de programa\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/07/09 17:26:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Archivos de programa\Mozilla Firefox\components [2011/08/01 19:20:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Archivos de programa\Mozilla Firefox\plugins

[2011/08/01 19:21:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Mohamed\Datos de programa\Mozilla\Extensions
[2011/08/01 19:20:53 | 000,000,000 | —D | M] (No name found) – C:\Archivos de programa\Mozilla Firefox\extensions
[2011/05/05 13:48:47 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/04/14 12:43:44 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Archivos de programa\mozilla firefox\components\browsercomps.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Archivos de programa\mozilla firefox\searchplugins\bing.xml
[2010/01/01 04:00:00 | 000,003,996 | —- | M] () – C:\Archivos de programa\mozilla firefox\searchplugins\drae.xml
[2010/01/01 04:00:00 | 000,001,143 | —- | M] () – C:\Archivos de programa\mozilla firefox\searchplugins\eBay-es.xml
[2010/01/01 04:00:00 | 000,001,178 | —- | M] () – C:\Archivos de programa\mozilla firefox\searchplugins\wikipedia-es.xml
[2010/01/01 04:00:00 | 000,001,102 | —- | M] () – C:\Archivos de programa\mozilla firefox\searchplugins\yahoo-es.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Archivos de programa\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Archivos de programa\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Archivos de programa\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Archivos de programa\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Archivos de programa\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Archivos de programa\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Archivos de programa\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Archivos de programa\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Archivos de programa\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Archivos de programa\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Archivos de programa\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Archivos de programa\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Archivos de programa\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2012/03/13 20:12:16 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Windows Live Aplicación auxiliar de inicio de sesión) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-854245398-1214440339-839522115-1003\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKLM..\Run: [AzMixerSel] C:\Archivos de programa\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKU\S-1-5-21-854245398-1214440339-839522115-1003..\Run: [Gadwin PrintScreen] C:\Archivos de programa\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc)
O4 - HKU\S-1-5-21-854245398-1214440339-839522115-1003..\Run: [JumiController] C:\Archivos de programa\Jumi\jumi.exe (Jumi Technologies)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-854245398-1214440339-839522115-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-854245398-1214440339-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-854245398-1214440339-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-854245398-1214440339-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Enviar a &Bluetooth - C:\Archivos de programa\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Archivos de programa\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Archivos de programa\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Archivos de programa\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{96A2F297-FB43-4144-BF25-5A46CDA4A1BD}: DhcpNameServer = 10.1.192.12 10.1.192.13
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D2697178-B478-4F06-95E6-6A56471D5BFF}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - c:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - c:\Archivos de programa\Archivos comunes\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Mi página de inicio actual) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Mohamed\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Mohamed\Configuración local\Datos de programa\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/29 22:11:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/03/13 21:31:14 | 000,594,944 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Mohamed\Escritorio\OTL.exe
[2012/03/13 21:30:21 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2012/03/13 20:14:48 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2012/03/13 20:00:23 | 004,434,769 | R— | C] (Swearware) – C:\Documents and Settings\Mohamed\Escritorio\ComboFix.exe
[2012/03/13 19:12:28 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Mohamed\Escritorio\aswMBR.exe
[2012/03/12 19:43:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Mohamed\Escritorio\backups
[2012/03/10 20:28:26 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Mohamed\Escritorio\HiJackThis.exe

========== Files - Modified Within 30 Days ==========

[2012/03/13 22:38:00 | 000,000,492 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{E647A242-7FC7-4F6B-94E4-C11FFAE6D111}.job
[2012/03/13 22:04:06 | 000,001,100 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/13 22:04:01 | 000,001,104 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/13 22:00:01 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/03/13 21:31:25 | 000,594,944 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Mohamed\Escritorio\OTL.exe
[2012/03/13 20:12:16 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2012/03/13 20:01:16 | 004,434,769 | R— | M] (Swearware) – C:\Documents and Settings\Mohamed\Escritorio\ComboFix.exe
[2012/03/13 19:39:22 | 000,000,502 | —- | M] () – C:\Documents and Settings\Mohamed\Escritorio\MBR.zip
[2012/03/13 19:26:33 | 000,000,512 | —- | M] () – C:\Documents and Settings\Mohamed\Escritorio\MBR.dat
[2012/03/13 19:12:51 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Mohamed\Escritorio\aswMBR.exe
[2012/03/13 18:50:00 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/03/12 19:33:32 | 000,001,876 | —- | M] () – C:\Documents and Settings\All Users\Escritorio\Google Chrome.lnk
[2012/03/10 20:28:37 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Mohamed\Escritorio\HiJackThis.exe
[2012/03/10 19:21:58 | 000,603,426 | —- | M] () – C:\WINDOWS\System32\perfh00A.dat
[2012/03/10 19:21:58 | 000,534,026 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/03/10 19:21:58 | 000,127,670 | —- | M] () – C:\WINDOWS\System32\perfc00A.dat
[2012/03/10 19:21:58 | 000,106,704 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/03/02 22:53:29 | 000,240,671 | —- | M] () – C:\setup_av_free.exe

========== Files Created - No Company Name ==========

[2012/03/13 19:26:45 | 000,000,502 | —- | C] () – C:\Documents and Settings\Mohamed\Escritorio\MBR.zip
[2012/03/13 19:26:33 | 000,000,512 | —- | C] () – C:\Documents and Settings\Mohamed\Escritorio\MBR.dat
[2012/03/02 22:53:23 | 000,240,671 | —- | C] () – C:\setup_av_free.exe
[2011/10/14 13:55:45 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/10/04 21:46:05 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2011/10/04 21:46:05 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2011/10/04 21:46:05 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2011/10/04 21:46:05 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2011/10/04 21:46:05 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2011/07/31 17:42:07 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/06/01 01:56:06 | 000,003,584 | —- | C] () – C:\Documents and Settings\Mohamed\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/30 18:23:33 | 000,000,000 | —- | C] () – C:\Documents and Settings\Mohamed\Configuración local\Datos de programa\{A596FA9B-DFE2-4F9D-AA43-A3CC00FB55F8}
[2011/05/30 00:47:20 | 000,127,888 | —- | C] () – C:\WINDOWS\hpoins11.dat
[2011/05/30 00:47:12 | 000,077,824 | R— | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2011/05/01 19:55:43 | 000,023,449 | —- | C] () – C:\WINDOWS\System32\smtpctrs.ini
[2011/05/01 19:55:42 | 000,001,135 | —- | C] () – C:\WINDOWS\System32\ntfsdrct.ini
[2011/05/01 19:55:26 | 000,061,186 | —- | C] () – C:\WINDOWS\System32\w3ctrs.ini
[2011/05/01 19:55:25 | 000,015,241 | —- | C] () – C:\WINDOWS\System32\axperf.ini
[2011/05/01 19:55:23 | 000,017,947 | —- | C] () – C:\WINDOWS\System32\infoctrs.ini
[2011/04/30 01:23:56 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2011/04/30 00:31:10 | 000,000,379 | —- | C] () – C:\WINDOWS\ODBC.INI
[2011/04/29 23:29:27 | 000,001,732 | —- | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2011/04/29 22:52:24 | 000,000,008 | -HS- | C] () – C:\WINDOWS\System32\Desktop_.ini
[2011/04/29 22:45:50 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2011/04/29 22:28:35 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2011/04/29 22:21:23 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2011/04/29 22:21:21 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\mmswitch.dll
[2011/04/29 22:21:18 | 000,421,888 | —- | C] () – C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2011/04/29 22:21:18 | 000,168,448 | —- | C] () – C:\WINDOWS\System32\ympg.dll
[2011/04/29 22:21:16 | 000,000,695 | —- | C] () – C:\WINDOWS\M3JPEG.INI
[2011/04/29 22:21:16 | 000,000,079 | —- | C] () – C:\WINDOWS\huffyuv.ini
[2011/04/29 22:21:14 | 000,770,048 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2011/04/29 22:21:14 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\ffvfw.dll
[2011/04/29 22:21:14 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\ff_theora.dll
[2011/04/29 22:14:19 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/04/29 22:08:26 | 000,021,900 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/04/29 16:54:37 | 000,004,205 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/04/29 16:53:18 | 000,195,368 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT

< End of report >



OTL Extras logfile created on: 13/03/2012 22:12:00 - Run 5
OTL by OldTimer - Version 3.2.36.3 Folder = C:\Documents and Settings\Mohamed\Escritorio
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C0A | Country: España | Language: ESN | Date Format: dd/MM/yyyy

766,36 Mb Total Physical Memory | 360,42 Mb Available Physical Memory | 47,03% Memory free
1,83 Gb Paging File | 1,49 Gb Available in Paging File | 81,42% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa
Drive C: | 74,52 Gb Total Space | 61,79 Gb Free Space | 82,91% Space Free | Partition Type: NTFS

Computer Name: MYPC | User Name: Mohamed | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.bat [@ = batfile] – "%1" %*
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] – "%1" %*
.com [@ = ComFile] – "%1" %*
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.exe [@ = exefile] – "%1" %*
.hlp [@ = hlpfile] – C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\WINDOWS\System32\mshta.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Archivos de programa\Google\Chrome\Application\chrome.exe (Google Inc.)
.inf [@ = inffile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
.js [@ = JSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] – "%1" %*
.reg [@ = regfile] – C:\WINDOWS\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] – "%1" /S
.txt [@ = txtfile] – C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-854245398-1214440339-839522115-1003\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Archivos de programa\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] – "%1" %*
batfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] – "%SYSTEMROOT%\hh.exe" %1 (Microsoft Corporation)
cmdfile – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] – "%1" %*
cmdfile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] – %SystemRoot%\System32\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] – C:\WINDOWS\system32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile – "C:\Archivos de programa\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Archivos de programa\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Archivos de programa\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Archivos de programa\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] – "C:\Archivos de programa\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] – %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] – %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
InternetShortcut [print] – "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
regfile [open] – regedit.exe "%1" (Microsoft Corporation)
regfile [merge] – Reg Error: Key error.
regfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
txtfile [open] – %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] – %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] – %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbefile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
vbsfile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbsfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wsffile – %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
wsffile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
wsffile [print] – %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wshfile [open] – %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Archivos de programa\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1433:TCP" = 1433:TCP:*:Enabled:sqlserver
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"5720:TCP" = 5720:TCP:*:Enabled:Jumi Controller
"5720:UDP" = 5720:UDP:*:Enabled:Jumi Controller
"8888:TCP" = 8888:TCP:*:Enabled:iphone

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Archivos de programa\Google\Google Earth\client\googleearth.exe" = C:\Archivos de programa\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"C:\Archivos de programa\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Archivos de programa\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Archivos de programa\HP\Digital Imaging\bin\hposfx08.exe" = C:\Archivos de programa\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Archivos de programa\HP\Digital Imaging\bin\hposid01.exe" = C:\Archivos de programa\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Archivos de programa\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Archivos de programa\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Archivos de programa\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Archivos de programa\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Archivos de programa\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Archivos de programa\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Archivos de programa\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Archivos de programa\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – (Hewlett-Packard)
"C:\Archivos de programa\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Archivos de programa\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Archivos de programa\HP\Digital Imaging\bin\hpoews01.exe" = C:\Archivos de programa\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Archivos de programa\Jumi\jumi.exe" = C:\Archivos de programa\Jumi\jumi.exe:*:Enabled:Jumi Controller – (Jumi Technologies)
"C:\Archivos de programa\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe" = C:\Archivos de programa\HP\HP Deskjet 3050 J610 series\Bin\DeviceSetup.exe:LocalSubNet:Enabled:Configuración de dispositivo HP – (Hewlett-Packard Co.)
"C:\Archivos de programa\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe" = C:\Archivos de programa\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicator.exe:LocalSubNet:Enabled:Comunicador de red HP – (Hewlett-Packard Co.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Barra de Bing
"{0DAA9912-3FE2-4B84-B926-8D7F71A8A99A}" = Microsoft SQL Server 2005 Reporting Services (SQLEXPRESS)
"{1A36CF15-DF66-4756-9482-A9ABF3DDACE6}_is1" = Driver Robot
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Herramienta de carga de Windows Live
"{2161D304-A4F4-4029-95F3-F9CDDC43853E}" = Estudio de mejora de productos de HP Deskjet 3050 J610 series
"{21DD56B6-A7C1-4EA6-BC53-28A63A4A1820}" = Windows Live Toolbar
"{221125DC-6A40-4900-B844-591F5E1195B0}" = Microsoft Visual Web Developer 2005 Express Edition - ENU
"{2243F21A-E132-44F7-BA13-024D0845C815}" = Microsoft SQL Server 2005 Backward compatibility
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2376813B-2E5A-4641-B7B3-A0D5ADB55229}" = HPPhotoSmartExpress
"{2B83A043-BA8C-4164-98AA-29529D0BE756}" = Windows Live Essentials
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C9C0A-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{363790D2-DA98-41DD-9C9F-69FA36B169DE}" = PanoStandAlone
"{3FBC5FCA-F989-4D5D-93F6-B185EEE1EC76}" = IIS6 Manager
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{50A0893D-47D8-48E0-A7E8-44BCD7E4422E}" = Microsoft SQL Server Native Client
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{623B8278-8CAD-45C1-B844-58B687C07805}" = Bing Bar Platform
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{68763C27-235D-4165-A961-FDEA228CE504}" = AiOSoftwareNPI
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{6EF59C2E-E355-4AA8-B18A-3E19A7B8EDE9}" = UltraEdit 16.10
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{736C803C-DD3B-4015-BC51-AFB9E67B9076}" = Readme
"{7593234B-2AEB-4FC9-B02D-C9B30D86084C}" = Windows Live Asistente para el inicio de sesión
"{7CB9546E-BF2C-47DE-9DB4-C4364FBE57EC}" = Broadcom Wireless LAN Driver 4.100.15.7_Negative_Foxconn
"{7E7B7865-6C80-4373-8BC1-C2EB9431F9DE}" = ProductContextNPI
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{84814E6B-2581-46EC-926A-823BD1C670F6}" = WIDCOMM Bluetooth Software
"{84E6A538-D3AE-4510-B32F-2415361D2770}" = Windows Live Protección Infantil
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8924FD04-AFF1-4387-B08B-6A979485F2BD}" = Windows Live Call
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}" = Unload
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90110C0A-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{914DD274-9C5D-44CA-9AC7-12B8D2D4DA08}" = Windows Live Sync
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0C0A-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{996512CF-F35B-48DE-9291-557FA5316967}" = ScannerCopy
"{9FC8D8F8-AF3A-4488-98AF-51C6DEC732F2}" = c3100_Help
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A30965BD-2D4D-45CE-8F04-6A6889818CF1}" = Microsoft SQL Server 2005 Tools
"{A4512736-8D63-4298-9271-5329931FA46B}" = Microsoft SQL Server Management Studio Express
"{A7BBE3D6-F19A-40E6-96EC-84E1DC88F262}" = Galería fotográfica de Windows Live
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9E5C983-1B44-405D-9725-CD92C49863B3}" = UltraCompare v7.20
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1034-7B44-A00000000001}" = Adobe Reader 6.0.1 - Español
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B0F9497C-52B4-4686-8E73-74D866BBDF59}" = Microsoft SQL Server 2005 (SQLEXPRESS)
"{B8583CB3-8ABE-407E-8BC6-F9A83EAC9133}" = Windows Live Writer
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{BEC001F9-0451-4396-92D7-E1A4E7854BF3}" = Windows Live Mail
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C0D2F614-5CE5-4DCB-8678-E5C9AF7044F8}" = Microsoft SQL Server VSS Writer
"{C25EF637-BE7A-4761-9B45-9069989C319F}" = Microsoft Visual Studio 2005 Premier Partner Edition - ENU
"{C2E4B5BD-32DB-4817-A060-341AB17C3F90}" = Bonjour
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4156B59-DD7E-40DF-AF08-E568A27A6409}" = Windows Live Messenger
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D04DCD77-B454-4E4F-824C-2B9504C5ED2C}" = Software básico del dispositivo HP Deskjet 3050 J610 series
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{EB8C9964-09AC-48bf-8B98-027609C78251}" = C3100
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F157460F-720E-482f-8625-AD7843891E5F}" = InstantShareDevicesMFC
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{F59A9E08-A6A4-4ACF-91F2-D0344956C30B}" = iTunes
"{F6076EF9-08E1-442F-B6A2-BFB61B295A14}" = Fax_CDA
"{F70D5D8C-C1AF-40B3-9E47-3BB5F19EEA3A}" = Atheros for Acer Driver 5.3.0.45_Foxconn Installation Program
"{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}" = HP Deskjet 3050 J610 series Ayuda
"{F8FBDC28-C265-4F0D-8B91-6E92913E19F6}" = IIS 6.0 Resource Kit Tools
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{FBB980B0-63F8-4B48-8D65-90F1D9F81D9F}" = NewCopy_CDA
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Codec Pack de ELISOFT v14.0" = Codec Pack de ELISOFT v14.0
"ESET Online Scanner" = ESET Online Scanner v3
"Gadwin PrintScreen" = Gadwin PrintScreen
"Google Chrome" = Google Chrome
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Photo Creations" = HP Photo Creations
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"ie8" = Windows Internet Explorer 8
"InstallShield_{F8FBDC28-C265-4F0D-8B91-6E92913E19F6}" = IIS 6.0 Resource Kit Tools
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Microsoft Visual Web Developer 2005 Express Edition - ENU" = Microsoft Visual Web Developer 2005 Express Edition - ENU
"Mozilla Firefox 4.0.1 (x86 es-ES)" = Mozilla Firefox 4.0.1 (x86 es-ES)
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoScape" = PhotoScape
"WIC" = Windows Imaging Component
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = Compresor WinRAR

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 02/03/2012 21:45:59 | Computer Name = MYPC | Source = Report Server Windows Service (SQLEXPRESS) | ID = 107
Description = Report Server Windows Service (SQLEXPRESS) cannot connect to the report
server database.

Error - 02/03/2012 21:48:28 | Computer Name = MYPC | Source = Report Server Windows Service (SQLEXPRESS) | ID = 107
Description = Report Server Windows Service (SQLEXPRESS) cannot connect to the report
server database.

Error - 02/03/2012 23:03:05 | Computer Name = MYPC | Source = VsJITDebugger | ID = 4096
Description = An unhandled win32 exception occurred in process #3092. Just-In-Time
debugging this exception failed with the following error: The process ID is invalid.

Check
the documentation index for 'Just-in-time debugging, errors' for more information.

Error - 04/03/2012 12:04:31 | Computer Name = MYPC | Source = VsJITDebugger | ID = 4096
Description = An unhandled win32 exception occurred in process #1496. Just-In-Time
debugging this exception failed with the following error: The process ID is invalid.

Check
the documentation index for 'Just-in-time debugging, errors' for more information.

Error - 08/03/2012 22:03:15 | Computer Name = MYPC | Source = VsJITDebugger | ID = 4096
Description = An unhandled win32 exception occurred in process #3440. Just-In-Time
debugging this exception failed with the following error: The process ID is invalid.

Check
the documentation index for 'Just-in-time debugging, errors' for more information.

Error - 12/03/2012 20:35:33 | Computer Name = MYPC | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.exe, versión 3.2.36.3, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.

Error - 12/03/2012 20:35:45 | Computer Name = MYPC | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.exe, versión 3.2.36.3, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.

Error - 12/03/2012 20:35:56 | Computer Name = MYPC | Source = Application Hang | ID = 1002
Description = Aplicación que no responde: OTL.exe, versión 3.2.36.3, módulo que
no responde hungapp, versión 0.0.0.0, dirección que no responde 0x00000000.

Error - 13/03/2012 18:51:54 | Computer Name = MYPC | Source = Report Server Windows Service (SQLEXPRESS) | ID = 107
Description = Report Server Windows Service (SQLEXPRESS) cannot connect to the report
server database.

Error - 13/03/2012 20:09:07 | Computer Name = MYPC | Source = crypt32 | ID = 131080
Description = Error en la recuperación de actualización automática del número de
secuencia de la lista raíz de terceros de: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
con el error: A connection with the server could not be established

[ System Events ]
Error - 07/03/2012 22:01:02 | Computer Name = MYPC | Source = Service Control Manager | ID = 7022
Description = El servicio SQL Server Reporting Services (SQLEXPRESS) permanece en
inicio.

Error - 07/03/2012 22:01:04 | Computer Name = MYPC | Source = Service Control Manager | ID = 7022
Description = El servicio Adquisición de imágenes de Windows (WIA) permanece en
inicio.

Error - 07/03/2012 22:06:31 | Computer Name = MYPC | Source = Dhcp | ID = 1000
Description = Su equipo ha perdido la concesión de su dirección IP 192.168.100.11
en la tarjeta de red con dirección de red 001B24BC1DCE.

Error - 10/03/2012 18:55:40 | Computer Name = MYPC | Source = Service Control Manager | ID = 7009
Description = Intervalo de espera (30000 ms.) para la conexión con el servicio SQL
Server Reporting Services (SQLEXPRESS).

Error - 10/03/2012 18:55:41 | Computer Name = MYPC | Source = Service Control Manager | ID = 7000
Description = El servicio SQL Server Reporting Services (SQLEXPRESS) no pudo iniciarse
debido al siguiente error: %%1053


< End of report >
Hi Moe_J_AK,

About the only thing we did in the last fix was empty some temporary caches. Reboot a couple of times.

Open task manager and click on the processes tab. Anything there using a high amount?

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
Hi oldman960, I really dont know, but i can assure you that after the last restart you asked me in the last solution, pmy laptop is running pretty slow again. (After your first reply it was working good) Ichecked the task manager, and its using 100% of my cpu. Anyways here im attaching the images of the process running and the usage of the CPU. By the way pc wont restart, i have to force it…. Im starting to update MBAM, then ill make it run and when it finishes ill post you the logs… Thanks my friend…
Hey Oldman960, Here it is, the log from the MBAM: Malwarebytes Anti-Malware 1.60.1.1000 www.malwarebytes.org Database version: v2012.03.14.07 Windows XP Service Pack 2 x86 NTFS Internet Explorer 8.0.6001.18702 Mohamed :: MYPC [administrator] 14/03/2012 20:43:27 mbam-log-2012-03-14 (20-43-27).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 242656 Time elapsed: 23 minute(s), 4 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 1 C:\Documents and Settings\Mohamed\Start Menu\Programs\Startup\dat.exe (Backdoor.Agent) -> Quarantined and deleted successfully. (end) Computer still slow and continues using 100% of CPU.
Hi Moe_J_AK, Is there any thing on the process tab that is using a lot of CPU? The screenshot you posted doesn't show the entire list.
Hi Moe_J_AK,



If you have 2 Internet Explorer tabs open it's normal for 3 instances of iexplore in the processes list 1 for IE and one for each tab.


Let's see if we can get a deeper look.

Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Saffe Mode
Hi oldman960,

After a couple of hours, it finally finished and generated the following:

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-03-16 08:38:53
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST980811AS rev.3.ALD
Running: 5tjwxemt.exe; Driver: C:\DOCUME~1\Mohamed\CONFIG~1\Temp\pxtdypob.sys


—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6430380, 0x2F1147, 0xE8000020]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi Moe_J_AK,

Nothing is showing in these logs. Please rerun aswMBR the same way you did last time.

After the scan is complete save the log. Reboot your computer to Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Is the computer any better in safe mode?

Please post back with the aswMBR log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI