This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help, strange behaivoir and some popup

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I'm having a lot of problem with mi computer, some popup, some crash of explorer and other stuff, here is my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:12:29, on 02-07-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Aventail\Connect\as32svc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Hyperion\BIPlus\bin\SQR\Remote\bin\atrls.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Archivos de programa\lotus\notes\ntmulti.exe
C:\OfficeScan NT\ntrtscan.exe
C:\Archivos de programa\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\OfficeScan NT\tmlisten.exe
C:\OfficeScan NT\PCCNTMON.EXE
C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
C:\OfficeScan NT\TmPfw.exe
C:\WINDOWS\TEMP\CR4B1F.EXE
C:\Archivos de programa\TortoiseSVN\bin\TSVNCache.exe
C:\OfficeScan NT\CNTAoSMgr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Archivos de programa\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Archivos de programa\Java\j2re1.4.2_04\bin\jusched.exe
C:\WINDOWS\system32\svuhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe
C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Archivos de programa\Hewlett-Packard\Shared\HpqToaster.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Archivos de programa\lotus\notes\NLNOTES.EXE
C:\Archivos de programa\lotus\notes\ntaskldr.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Archivos de programa\Microsoft Office\Office12\POWERPNT.EXE
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\explorer.exe
C:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0723DDEB-990D-418C-9ED9-8C994521C906} - C:\WINDOWS\system32\khfeBsrO.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {F53BAFE5-CE7A-4E95-95AC-A3912EFD3739} - C:\WINDOWS\system32\ljJASifE.dll
O3 - Toolbar: PDF de Adobe - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Archivos de programa\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Windows Sound] svuhost.exe
O4 - HKLM\..\Run: [BMa71aff1b] Rundll32.exe "C:\WINDOWS\system32\mvmpqvxc.dll",s
O4 - HKLM\..\Run: [a429cc87] rundll32.exe "C:\WINDOWS\system32\fsuisrhl.dll",b
O4 - HKLM\..\RunServices: [Microsoft Windows Sound] svuhost.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-21-1801213628-1823830300-1575050150-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-484763869-2000478354-839522115-1003\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1202486440984
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) - http://190.243.34.139/businessobjects/ente…dows-i586-p.exe
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://santiago-ns001.everis.int/dwa7W.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = everis.int
O20 - Winlogon Notify: ljJASifE - C:\WINDOWS\SYSTEM32\ljJASifE.dll
O23 - Service: Aventail Connect (As32Svc) - Aventail Corporation - C:\Archivos de programa\Aventail\Connect\as32svc.exe
O23 - Service: Ataman TCP Remote Logon Services - Unknown owner - C:\Hyperion\BIPlus\bin\SQR\Remote\bin\atrls.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Archivos de programa\lotus\notes\ntmulti.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
O23 - Service: OfficeScan NT Firewall (TmPfw) - Trend Micro Inc. - C:\OfficeScan NT\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\OfficeScan NT\TmProxy.exe

–
End of file - 7598 bytes
Hello

Please download RUNSCANNER to your desktop and run it.
  • When the first page comes up select Beginner Mode
  • On the next page select Save a binary .Run file (Recommended) then click Start full scan at the top.
  • At this time Runscanner.exe may request access to the Internet through your firewall please allow it to do so, it will then run for two or three minutes.
  • On completion it will ask for a location to save the file and a name. It will do this for both the .run file and the log
  • Call the file "Select a file name here" and save it to your desktop. You will see the .run file on your desktop. Please zip the .run file by right clicking and selecting send to Zip file

Then upload that as an attachment in your next post.
Hello

CLICK THIS TO LINK TO BE SURE YOU CAN VIEW HIDDEN FILES

Please go here:
The Spy Killer Forum
  • Click on "New Topic"
  • Put your name, e-mail address, and this as the title: "C:\WINDOWS\system32\svuhost.exe"
  • Put a link to this topic in the description box.
  • Then next to the file box, at the bottom, click the browse button, then navigate to this file:


    • C:\WINDOWS\system32\svuhost.exe

  • Click Open.
  • Click Post.
Thank you!




Download the zipped attachment at the end of this post(this will be your runscanner as fixed by me)

  • Unzip it to your desktop then double click the runscanner icon this will run the program.
  • Click on the "Item Fixer" tab
  • You will notice several entries with a tick in red, click Fix checked.
  • Accept the warning then repeat until they are all gone.



Reboot and do this

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
  • When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

Attachments:

Thanks, Here are the two logs:
(firts main then extra)

Deckard's System Scanner v20071014.68
Run by [removed] on 2008-07-02 12:17:46
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
49: 2008-07-02 16:18:03 UTC - RP49 - Deckard's System Scanner Restore Point
48: 2008-07-02 01:18:32 UTC - RP48 - Punto de control del sistema
47: 2008-06-30 19:09:56 UTC - RP47 - Last known good configuration
46: 2008-06-30 19:09:43 UTC - RP46 - Operación de restauración
45: 2008-06-30 19:09:42 UTC - RP45 - Punto de control del sistema


– First Restore Point –
1: 2008-06-30 19:09:28 UTC - RP1 - Punto de control del sistema


Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as ekemp.exe) ———————————————–

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:20:44, on 02-07-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Aventail\Connect\as32svc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Hyperion\BIPlus\bin\SQR\Remote\bin\atrls.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Archivos de programa\TortoiseSVN\bin\TSVNCache.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Archivos de programa\lotus\notes\ntmulti.exe
C:\OfficeScan NT\ntrtscan.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Archivos de programa\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\OfficeScan NT\pccntmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Archivos de programa\Java\j2re1.4.2_04\bin\jusched.exe
C:\WINDOWS\system32\svuhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe
C:\Archivos de programa\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\OfficeScan NT\tmlisten.exe
C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
C:\OfficeScan NT\TmPfw.exe
C:\WINDOWS\TEMP\CABA75.EXE
C:\OfficeScan NT\CNTAoSMgr.exe
D:\dss.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\ARCHIV~1\TRENDM~1\HIJACK~1\ekemp.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9D388BF4-E6B2-464C-9EA3-335A7ECE57A6} - C:\WINDOWS\system32\khfeBsrO.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {F53BAFE5-CE7A-4E95-95AC-A3912EFD3739} - C:\WINDOWS\system32\ljJASifE.dll
O3 - Toolbar: PDF de Adobe - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Archivos de programa\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Windows Sound] svuhost.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Sound] svuhost.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1202486440984
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) - http://190.243.34.139/businessobjects/ente…dows-i586-p.exe
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://santiago-ns001.everis.int/dwa7W.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = everis.int
O20 - Winlogon Notify: ljJASifE - C:\WINDOWS\SYSTEM32\ljJASifE.dll
O23 - Service: Aventail Connect (As32Svc) - Aventail Corporation - C:\Archivos de programa\Aventail\Connect\as32svc.exe
O23 - Service: Ataman TCP Remote Logon Services - Unknown owner - C:\Hyperion\BIPlus\bin\SQR\Remote\bin\atrls.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Archivos de programa\lotus\notes\ntmulti.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
O23 - Service: OfficeScan NT Firewall (TmPfw) - Trend Micro Inc. - C:\OfficeScan NT\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\OfficeScan NT\TmProxy.exe

–
End of file - 6650 bytes

– HijackThis Fixed Entries (C:\ARCHIV~1\TRENDM~1\HIJACK~1\backups\) ———–

backup-20080630-143928-204 O2 - BHO: (no name) - {C637B18B-1AB4-44B6-BB7B-AAAD9D3F3C96} - C:\WINDOWS\system32\khfeBsrO.dll
backup-20080630-143928-557 O2 - BHO: (no name) - {F53BAFE5-CE7A-4E95-95AC-A3912EFD3739} - C:\WINDOWS\system32\ljJASifE.dll
backup-20080630-144040-246 O2 - BHO: (no name) - {C637B18B-1AB4-44B6-BB7B-AAAD9D3F3C96} - C:\WINDOWS\system32\khfeBsrO.dll
backup-20080630-144040-579 O2 - BHO: (no name) - {F53BAFE5-CE7A-4E95-95AC-A3912EFD3739} - C:\WINDOWS\system32\ljJASifE.dll
backup-20080630-144052-228 O2 - BHO: (no name) - {F53BAFE5-CE7A-4E95-95AC-A3912EFD3739} - C:\WINDOWS\system32\ljJASifE.dll
backup-20080630-144052-530 O2 - BHO: (no name) - {C637B18B-1AB4-44B6-BB7B-AAAD9D3F3C96} - C:\WINDOWS\system32\khfeBsrO.dll
backup-20080630-145603-240 O2 - BHO: (no name) - {EF5CCAD0-308D-4BA6-A320-5E95A824B03E} - C:\WINDOWS\system32\khfeBsrO.dll
backup-20080630-145603-344 O2 - BHO: (no name) - {F53BAFE5-CE7A-4E95-95AC-A3912EFD3739} - C:\WINDOWS\system32\ljJASifE.dll
backup-20080702-092215-491 O2 - BHO: (no name) - {0723DDEB-990D-418C-9ED9-8C994521C906} - C:\WINDOWS\system32\khfeBsrO.dll
backup-20080702-092215-907 O2 - BHO: (no name) - {F53BAFE5-CE7A-4E95-95AC-A3912EFD3739} - C:\WINDOWS\system32\ljJASifE.dll
backup-20080702-092239-100 O2 - BHO: (no name) - {0723DDEB-990D-418C-9ED9-8C994521C906} - C:\WINDOWS\system32\khfeBsrO.dll
backup-20080702-092239-682 O2 - BHO: (no name) - {F53BAFE5-CE7A-4E95-95AC-A3912EFD3739} - C:\WINDOWS\system32\ljJASifE.dll
backup-20080702-092654-557 O2 - BHO: (no name) - {0723DDEB-990D-418C-9ED9-8C994521C906} - C:\WINDOWS\system32\khfeBsrO.dll
backup-20080702-092654-754 O2 - BHO: (no name) - {F53BAFE5-CE7A-4E95-95AC-A3912EFD3739} - C:\WINDOWS\system32\ljJASifE.dll

– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R1 Askernel - c:\archivos de programa\aventail\connect\asntkrnl.sys
Hello

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\WINDOWS\system32\fsuisrhl.dll
    C:\WINDOWS\system32\mvmpqvxc.dll
    C:\WINDOWS\system32\jcmkaqtf.dll
    C:\WINDOWS\system32\bqgpsrtc.dll
    C:\WINDOWS\system32\OrsBefhk.ini2
    C:\WINDOWS\system32\khfeBsrO.dll
    C:\WINDOWS\system32\wvUnMggg.dll
    C:\WINDOWS\system32\ljJASifE.dll
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



Reboot and post a new DSS log
Thanks… And, the new log: Explorer killed successfully DllUnregisterServer procedure not found in C:\WINDOWS\system32\fsuisrhl.dll C:\WINDOWS\system32\fsuisrhl.dll NOT unregistered. C:\WINDOWS\system32\fsuisrhl.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\mvmpqvxc.dll C:\WINDOWS\system32\mvmpqvxc.dll NOT unregistered. C:\WINDOWS\system32\mvmpqvxc.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\jcmkaqtf.dll C:\WINDOWS\system32\jcmkaqtf.dll NOT unregistered. C:\WINDOWS\system32\jcmkaqtf.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\bqgpsrtc.dll C:\WINDOWS\system32\bqgpsrtc.dll NOT unregistered. C:\WINDOWS\system32\bqgpsrtc.dll moved successfully. C:\WINDOWS\system32\OrsBefhk.ini2 moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\khfeBsrO.dll C:\WINDOWS\system32\khfeBsrO.dll NOT unregistered. C:\WINDOWS\system32\khfeBsrO.dll moved successfully. LoadLibrary failed for C:\WINDOWS\system32\wvUnMggg.dll C:\WINDOWS\system32\wvUnMggg.dll NOT unregistered. C:\WINDOWS\system32\wvUnMggg.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\system32\ljJASifE.dll C:\WINDOWS\system32\ljJASifE.dll NOT unregistered. File move failed. C:\WINDOWS\system32\ljJASifE.dll scheduled to be moved on reboot. < purity > < EmptyTemp > File delete failed. C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DF4D59.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DF54BE.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DF594C.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DF6685.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DF846E.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DFF764.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DFF780.tmp scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1a8.dat scheduled to be deleted on reboot. Temp folders emptied. IE temp folders emptied. Explorer started successfully OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07022008_124305 Files moved on Reboot… DllUnregisterServer procedure not found in C:\WINDOWS\system32\ljJASifE.dll C:\WINDOWS\system32\ljJASifE.dll NOT unregistered. File move failed. C:\WINDOWS\system32\ljJASifE.dll scheduled to be moved on reboot. File C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DF4D59.tmp not found! File C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DF54BE.tmp not found! File C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DF594C.tmp not found! File C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DF6685.tmp not found! File C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DF846E.tmp not found! File C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DFF764.tmp not found! File C:\DOCUME~1\ekemp\CONFIG~1\Temp\~DFF780.tmp not found! File C:\WINDOWS\temp\Perflib_Perfdata_1a8.dat not found!
Hera is the new DSS LOG:

Deckard's System Scanner v20071014.68
Run by [removed] on 2008-07-02 15:04:03
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as ekemp.exe) ———————————————–

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:04:28, on 02-07-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Aventail\Connect\as32svc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Hyperion\BIPlus\bin\SQR\Remote\bin\atrls.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Archivos de programa\lotus\notes\ntmulti.exe
C:\OfficeScan NT\ntrtscan.exe
C:\Archivos de programa\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\OfficeScan NT\PCCNTMON.EXE
C:\OfficeScan NT\tmlisten.exe
C:\Archivos de programa\TortoiseSVN\bin\TSVNCache.exe
C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Archivos de programa\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Archivos de programa\Java\j2re1.4.2_04\bin\jusched.exe
C:\WINDOWS\system32\svuhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe
C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\TEMP\DC241.EXE
C:\OfficeScan NT\TmPfw.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\OfficeScan NT\CNTAoSMgr.exe
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\Microsoft Office\Office12\WINWORD.EXE
C:\Archivos de programa\Microsoft Office\Office12\EXCEL.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Archivos de programa\lotus\notes\NLNOTES.EXE
C:\Archivos de programa\lotus\notes\ntaskldr.EXE
C:\Archivos de programa\Windows Media Player\wmplayer.exe
D:\dss.exe
C:\ARCHIV~1\TRENDM~1\HIJACK~1\ekemp.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A0724B2C-9618-4DF5-8F37-F7134DA7D823} - C:\WINDOWS\system32\khfeBsrO.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {F53BAFE5-CE7A-4E95-95AC-A3912EFD3739} - C:\WINDOWS\system32\ljJASifE.dll
O3 - Toolbar: PDF de Adobe - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Archivos de programa\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Microsoft Windows Sound] svuhost.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Sound] svuhost.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1202486440984
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) - http://190.243.34.139/businessobjects/ente…dows-i586-p.exe
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://santiago-ns001.everis.int/dwa7W.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = everis.int
O20 - Winlogon Notify: ljJASifE - C:\WINDOWS\SYSTEM32\ljJASifE.dll
O23 - Service: Aventail Connect (As32Svc) - Aventail Corporation - C:\Archivos de programa\Aventail\Connect\as32svc.exe
O23 - Service: Ataman TCP Remote Logon Services - Unknown owner - C:\Hyperion\BIPlus\bin\SQR\Remote\bin\atrls.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Archivos de programa\lotus\notes\ntmulti.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
O23 - Service: OfficeScan NT Firewall (TmPfw) - Trend Micro Inc. - C:\OfficeScan NT\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\OfficeScan NT\TmProxy.exe

–
End of file - 7124 bytes

– Files created between 2008-06-02 and 2008-07-02 —————————–

2008-07-02 12:49:05 465770 –ahs—- C:\WINDOWS\system32\OrsBefhk.ini2
2008-06-30 15:03:44 0 d——– C:\Archivos de programa\Vuze
2008-06-30 14:36:50 0 d——– C:\Archivos de programa\Trend Micro
2008-06-30 09:49:55 0 –a—— C:\WINDOWS\nsreg.dat
2008-06-30 09:49:30 0 d——– C:\Archivos de programa\Mozilla Firefox(2)
2008-06-30 09:25:03 0 d——– C:\WINDOWS\pss
2008-06-30 08:55:58 0 d——– C:\Archivos de programa\Lavasoft
2008-06-29 10:56:04 3145728 –a—— C:\Documents and Settings\ekemp\ntuser.dat
2008-06-29 10:55:17 319488 —–n— C:\WINDOWS\system32\khfeBsrO.dll
2008-06-28 23:06:03 58880 –a—— C:\WINDOWS\system32\ljJASifE.dll
2008-06-27 09:38:20 0 d——– C:\Documents and Settings\ekemp\Contacts
2008-06-27 09:36:10 0 d–hs–c- C:\Archivos de programa\Archivos comunes\WindowsLiveInstaller
2008-06-27 09:35:36 0 d——– C:\Archivos de programa\Windows Live
2008-06-25 11:48:01 148480 –a—— C:\WINDOWS\system32\TLBINF32.DLL
Hello


Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.
Thanks again:
The new two logs (first combofix, and then HijackThis )

ComboFix 08-07-01.5 - ekemp 2008-07-02 16:11:08.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.34.3082.18.1288 [GMT -4:00]
Se ejecuta desde: C:\Documents and Settings\ekemp\Escritorio\ComboFix.exe
* Creado un nuevo punto de restauración
.

(((((((((((((((((((((((((((((((((((( Otras eliminaciones )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\khfeBsrO.dll
C:\WINDOWS\system32\lhrsiusf.ini
C:\WINDOWS\system32\ljJASifE.dll
C:\WINDOWS\system32\lqeakixi.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mjgfcehu.ini
C:\WINDOWS\system32\OrsBefhk.ini
C:\WINDOWS\system32\OrsBefhk.ini2
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\rkxbajxy.dll
C:\WINDOWS\system32\vureyujb.ini
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\system32\yxjabxkr.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_NPF


(((((((((((((((((( Archivos creados desde 2008-06-02 - 2008-07-02 )))))))))))))))))))))))))))))))))
.

2008-07-02 12:17 . 2008-07-02 12:17 d——– C:\Deckard
2008-07-02 10:36 . 2008-07-02 10:36 96,193 –a—— C:\runscanner.zip
2008-07-02 10:35 . 2008-07-02 10:35 93,552 –a—— C:\runscannerfile.run
2008-06-30 15:30 . 2006-03-02 07:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-06-30 15:03 . 2008-06-30 15:03 d——– C:\Archivos de programa\Vuze
2008-06-30 14:56 . 2008-06-30 15:03 d——– C:\Documents and Settings\Administrador.HP530\Datos de programa\Subversion
2008-06-30 14:36 . 2008-06-30 14:36 d——– C:\Archivos de programa\Trend Micro
2008-06-30 09:49 . 2008-06-30 15:03 d——– C:\Archivos de programa\Mozilla Firefox(2)
2008-06-30 09:49 . 2008-06-30 09:49 0 –a—— C:\WINDOWS\nsreg.dat
2008-06-30 08:55 . 2008-06-30 08:55 d——– C:\Archivos de programa\Lavasoft
2008-06-30 08:35 . 2008-07-02 16:01 110,415 –a—— C:\WINDOWS\BMa71aff1b.xml
2008-06-28 23:05 . 2008-07-02 16:22 d-a—— C:\Documents and Settings\All Users\Datos de programa\TEMP
2008-06-28 22:32 . 2008-06-28 23:05 d——– C:\Documents and Settings\ekemp\Datos de programa\Azureus
2008-06-28 22:32 . 2008-06-28 22:32 d——– C:\Documents and Settings\All Users\Datos de programa\Azureus
2008-06-27 09:38 . 2008-06-30 15:04 d——– C:\Documents and Settings\ekemp\Contacts
2008-06-27 09:36 . 2008-06-27 09:36 d–hsc— C:\Archivos de programa\Archivos comunes\WindowsLiveInstaller
2008-06-27 09:35 . 2008-06-27 09:35 d——– C:\Documents and Settings\All Users\Datos de programa\WLInstaller
2008-06-27 09:35 . 2008-06-27 09:36 d——– C:\Archivos de programa\Windows Live
2008-06-26 18:04 . 2008-06-26 18:04 207,540 –a—— C:\Reporte.bqy
2008-06-25 11:50 . 2008-06-25 11:50 48,123 –a—— C:\WINDOWS\vpd.properties
2008-06-25 11:48 . 2007-06-27 00:16 148,480 –a—— C:\WINDOWS\system32\TLBINF32.DLL
2008-06-25 11:48 . 2007-06-27 00:16 109,248 –a—— C:\WINDOWS\system32\MSWINSCK.OCX
2008-06-25 11:48 . 2007-06-27 00:16 89,360 –a—— C:\WINDOWS\system32\VB5DB.DLL
2008-06-25 11:48 . 2008-06-25 11:48 49,590 –a—— C:\WINDOWS\bqmeta_ev0.ini
2008-06-25 11:48 . 2007-06-27 00:16 24,576 –a—— C:\WINDOWS\system32\msxml3a.dll
2008-06-25 11:42 . 2007-06-18 11:18 90,112 –a—— C:\WINDOWS\sqrrem32.dll
2008-06-25 11:42 . 2005-02-22 09:16 38,400 –a—— C:\WINDOWS\ptftp32c.dll
2008-06-25 11:42 . 2005-02-22 09:16 27,136 –a—— C:\WINDOWS\pttcp32c.dll
2008-06-25 11:42 . 2008-06-25 11:48 10,134 –a—— C:\WINDOWS\sqr.ini
2008-06-25 11:42 . 2008-06-25 11:42 111 –a—— C:\WINDOWS\libsti.ini
2008-06-25 11:38 . 2008-06-25 11:42 d——– C:\Hyperion
2008-06-19 23:02 . 2008-06-19 23:02 d—s—- C:\Documents and Settings\ekemp\UserData
2008-06-19 23:00 . 2008-06-19 23:01 d——– C:\Documents and Settings\ekemp\Datos de programa\Aventail
2008-06-18 17:16 . 2008-05-07 08:53 56,315 –a—— C:\WINDOWS\ofcscan.ini
2008-06-18 17:15 . 2008-06-18 17:15 0 –a—— C:\s3eg.3
2008-06-18 13:10 . 2008-06-18 13:10 d——– C:\Documents and Settings\ekemp\Datos de programa\Xerox
2008-06-17 12:41 . 2008-06-23 14:28 d——– C:\Documents and Settings\ekemp\Datos de programa\AdobeUM
2008-06-17 12:39 . 2008-06-17 12:39 d——– C:\Documents and Settings\LocalService\Men£ Inicio
2008-06-17 12:37 . 2007-12-24 11:37 138,384 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-17 12:36 . 2007-04-20 18:44 307,984 –a—— C:\WINDOWS\system32\drivers\TM_CFW.sys
2008-06-17 12:36 . 2006-11-14 12:14 73,288 –a—— C:\WINDOWS\system32\drivers\tmtdi.sys
2008-06-16 14:30 . 2008-06-16 14:30 d——– C:\WINDOWS\Sun
2008-06-16 14:30 . 2008-06-16 14:30 d——– C:\Archivos de programa\Java
2008-06-16 14:30 . 2008-06-16 14:30 d——– C:\Archivos de programa\Archivos comunes\Java
2008-06-16 14:30 . 2004-02-22 23:44 61,555 –a—— C:\WINDOWS\system32\jpicpl32.cpl
2008-06-16 14:02 . 2008-06-16 14:02 d——– C:\Documents and Settings\ekemp\Datos de programa\Business Objects
2008-06-16 13:13 . 2001-01-04 12:37 766 –a—— C:\WINDOWS\system32\uninst.ico
2008-06-16 13:03 . 2008-06-16 13:13 d——– C:\Archivos de programa\NotesSQL
2008-06-16 13:03 . 2008-06-16 13:08 d——– C:\Archivos de programa\Business Objects
2008-06-16 12:15 . 2008-06-16 12:15 d——– C:\Archivos de programa\MSXML 6.0
2008-06-16 12:07 . 2002-02-24 21:30 260,096 ——— C:\WINDOWS\system32\RICHTX32.OCX
2008-06-16 12:07 . 2000-05-22 01:00 140,488 ——— C:\WINDOWS\system32\COMDLG32.OCX
2008-06-16 12:06 . 2008-06-16 12:09 d——– C:\Documents and Settings\All Users\Datos de programa\PowerDesigner 12
2008-06-16 12:06 . 2008-06-16 12:07 d——– C:\Archivos de programa\Sybase
2008-06-14 23:08 . 2008-06-14 23:18 118 –a—— C:\WINDOWS\ChssBase.ini
2008-06-14 23:01 . 2008-06-14 23:28 d——– C:\Documents and Settings\ekemp\Datos de programa\ChessBase
2008-06-14 22:59 . 2008-06-14 23:28 d——– C:\Archivos de programa\ChessBase
2008-06-13 17:25 . 2008-06-13 17:25 d——– C:\Documents and Settings\ekemp\Datos de programa\Subversion
2008-06-13 17:01 . 2008-06-13 17:01 d——– C:\Archivos de programa\TortoiseSVN
2008-06-13 16:24 . 2008-06-13 16:24 d——– C:\Archivos de programa\SQLXML 4.0
2008-06-13 16:19 . 2008-06-16 13:10 d——– C:\Archivos de programa\Microsoft Visual Studio 8
2008-06-13 16:19 . 2008-06-13 16:19 d——– C:\Archivos de programa\Archivos comunes\Merge Modules
2008-06-13 16:18 . 2008-06-13 16:18 d——– C:\Archivos de programa\Microsoft.NET
2008-06-13 16:18 . 2008-06-13 16:18 d——– C:\Archivos de programa\Microsoft Analysis Services
2008-06-13 16:14 . 2008-06-18 16:56 d——– C:\Archivos de programa\Microsoft SQL Server
2008-06-13 15:12 . 2001-08-22 21:34 12,416 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-06-13 15:12 . 2001-08-22 21:34 12,416 –a–c— C:\WINDOWS\system32\dllcache\mouhid.sys
2008-06-13 15:12 . 2001-08-17 22:02 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-06-13 15:12 . 2001-08-17 22:02 9,600 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2008-06-13 13:22 . 2008-07-02 16:08 dr-h—– C:\Documents and Settings\ekemp\Reciente
2008-06-13 13:22 . 2008-04-08 11:32 d–h—– C:\Documents and Settings\ekemp\Plantillas
2008-06-13 13:22 . 2008-07-02 10:27 dr——- C:\Documents and Settings\ekemp\Mis documentos
2008-06-13 13:22 . 2008-04-08 06:25 dr——- C:\Documents and Settings\ekemp\Men£ Inicio
2008-06-13 13:22 . 2008-04-08 06:25 d–h—– C:\Documents and Settings\ekemp\Impresoras
2008-06-13 13:22 . 2008-07-02 16:08 dr——- C:\Documents and Settings\ekemp\Favoritos
2008-06-13 13:22 . 2008-07-02 16:07 d——– C:\Documents and Settings\ekemp\Escritorio
2008-06-13 13:22 . 2008-06-18 16:26 d–h—– C:\Documents and Settings\ekemp\Entorno de red
2008-06-13 13:22 . 2008-06-30 09:49 dr-h—– C:\Documents and Settings\ekemp\Datos de programa
2008-06-13 13:22 . 2008-07-02 16:17 d–h—– C:\Documents and Settings\ekemp\Configuraci¢n local
2008-06-13 13:22 . 2008-07-02 12:03 d——– C:\Documents and Settings\ekemp
2008-06-03 21:48 . 2008-06-03 21:48 d——– C:\VProRecovery
2008-06-03 21:35 . 2008-06-03 21:35 d——– C:\Documents and Settings\Administrador.HP530\Datos de programa\Symantec
2008-06-03 21:05 . 2008-06-03 21:05 d——– C:\Archivos de programa\Symantec
2008-06-03 21:05 . 2007-03-21 20:39 1,060,864 –a—— C:\WINDOWS\system32\MFC71.DLL
2008-06-03 21:05 . 2007-03-21 20:33 503,808 –a—— C:\WINDOWS\system32\MSVCP71.DLL
2008-06-03 21:05 . 2007-03-21 20:33 348,160 –a—— C:\WINDOWS\system32\MSVCR71.DLL
2008-06-03 21:03 . 2008-06-06 10:37 d——– C:\Documents and Settings\All Users\Datos de programa\Symantec
2008-06-03 20:54 . 2008-06-03 20:56 24 –a—— C:\WINDOWS\pccntmon.INI

.
(((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-02 20:22 42,512 —-a-w C:\WINDOWS\system32\drivers\npf.sys
2008-06-25 23:13 ——— d—–w C:\Archivos de programa\Archivos comunes\InstallShield
2008-06-18 20:57 ——— d—–w C:\Documents and Settings\All Users\Datos de programa\Microsoft Help
2008-06-17 16:40 ——— d—–w C:\Archivos de programa\Archivos comunes\Adobe
2008-06-16 17:14 31 —-a-w C:\Archivos de programa\Notes.ini
2008-06-16 17:13 ——— d–h–w C:\Archivos de programa\InstallShield Installation Information
2004-10-01 19:00 40,960 —-a-w C:\Archivos de programa\Uninstall_CDS.exe
2007-06-13 13:22 946,176 –sh–r C:\WINDOWS\system32\svuhost.exe
.

((((((((((((((((((((((((((((((((( Cargando Puntos Reg ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* entradas vac¡as & entradas leg¡timas predeterminadas no son mostradas

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 07:00 15360]
"MsnMsgr"="C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-09-18 22:29 141848]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-09-18 22:29 166424]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-09-18 22:29 137752]
"QlbCtrl.exe"="C:\Archivos de programa\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-10-19 13:05 177456]
"OfficeScanNT Monitor"="C:\OfficeScan NT\pccntmon.exe" [2007-08-08 06:33 705904]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"SunJavaUpdateSched"="C:\Archivos de programa\Java\j2re1.4.2_04\bin\jusched.exe" [2004-02-22 23:44 32881]
"Microsoft Windows Sound"="svuhost.exe" [2007-06-13 09:22 946176 C:\WINDOWS\system32\svuhost.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Microsoft Windows Sound"="svuhost.exe" [2007-06-13 09:22 946176 C:\WINDOWS\system32\svuhost.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 07:00 15360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Archivos de programa\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Archivos de programa\\Windows Live\\Messenger\\livecall.exe"=

R2 Ataman TCP Remote Logon Services;Ataman TCP Remote Logon Services;C:\Hyperion\BIPlus\bin\SQR\Remote\bin\atrls.exe [1998-09-09 23:04]
R2 MsDtsServer;SQL Server Integration Services;"C:\Archivos de programa\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe" [2007-02-10 05:23]
R3 Astdi;Astdi;C:\Archivos de programa\Aventail\Connect\asnttdi.sys [2003-06-11 17:24]
S3 Ascrypto;Ascrypto;C:\Archivos de programa\Aventail\Connect\ascrypto.sys [2003-06-11 17:26]
S3 NPF;Netgroup Packet Filter;C:\WINDOWS\system32\drivers\npf.sys [2008-07-02 16:22]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Archivos de programa\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 []

.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-BMa71aff1b - C:\WINDOWS\system32\lqeakixi.dll
HKLM-Run-a429cc87 - C:\WINDOWS\system32\rkxbajxy.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-02 16:21:31
Windows 5.1.2600 Service Pack 2 NTFS

escaneando procesos ocultos …

escaneando entradas ocultas de autostart …

escaneando archivos ocultos …


C:\WINDOWS\system32\wpcap.dll 240240 bytes executable

el escaneo se completo con exito
archivos ocultos: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\msftesql]
"ImagePath"="\"C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:MSSQLSERVER"
.
———————— Other Running Processes ————————
.
C:\Archivos de programa\Aventail\Connect\as32svc.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Archivos de programa\lotus\notes\ntmulti.exe
C:\OfficeScan NT\ntrtscan.exe
C:\Archivos de programa\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\OfficeScan NT\tmlisten.exe
C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
C:\OfficeScan NT\TmPfw.exe
C:\Archivos de programa\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\Temp\PG8505.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\OfficeScan NT\CNTAoSMgr.exe
C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Tiempo completado: 2008-07-02 16:25:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-02 20:25:08

10 dirs 21,185,732,608 bytes libres
14 dirs 21,098,655,744 bytes libres

241


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:25, on 2008-07-02
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Aventail\Connect\as32svc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Hyperion\BIPlus\bin\SQR\Remote\bin\atrls.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Archivos de programa\lotus\notes\ntmulti.exe
C:\OfficeScan NT\ntrtscan.exe
C:\Archivos de programa\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\OfficeScan NT\tmlisten.exe
C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
C:\OfficeScan NT\PCCNTMON.EXE
C:\OfficeScan NT\TmPfw.exe
C:\Archivos de programa\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\TEMP\PG8505.EXE
C:\WINDOWS\system32\svuhost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Archivos de programa\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\OfficeScan NT\CNTAoSMgr.exe
C:\Archivos de programa\Java\j2re1.4.2_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe
C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: PDF de Adobe - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Microsoft Windows Sound] svuhost.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Archivos de programa\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Sound] svuhost.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1202486440984
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) - http://190.243.34.139/businessobjects/ente…dows-i586-p.exe
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://santiago-ns001.everis.int/dwa7W.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = everis.int
O23 - Service: Aventail Connect (As32Svc) - Aventail Corporation - C:\Archivos de programa\Aventail\Connect\as32svc.exe
O23 - Service: Ataman TCP Remote Logon Services - Unknown owner - C:\Hyperion\BIPlus\bin\SQR\Remote\bin\atrls.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Archivos de programa\lotus\notes\ntmulti.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
O23 - Service: OfficeScan NT Firewall (TmPfw) - Trend Micro Inc. - C:\OfficeScan NT\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\OfficeScan NT\TmProxy.exe

–
End of file - 6880 bytes
Hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O4 - HKLM\..\RunServices: [Microsoft Windows Sound] svuhost.exe


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.




1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\BMa71aff1b.xml
C:\WINDOWS\system32\svuhost.exe

Folder::

Registry::

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall





Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.


Also post a new HijackThis log
Thnaks , here is the new log: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Thursday, July 03, 2008 2:34:02 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 3/07/2008 Kaspersky Anti-Virus database records: 910352 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 142426 Number of viruses found: 8 Number of infected objects: 40 Number of suspicious objects: 0 Duration of the scan process: 05:18:42 Infected Object Name / Virus Name / Last Action C:\Archivos de programa\Aventail\Connect\aslog.lgf Object is locked skipped C:\Archivos de programa\lotus\notes\data\Mail\ekemp.nsf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Data\GrupoDWH.mdf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Data\GrupoDWH_log.ldf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Data\master.mdf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Data\mastlog.ldf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Data\model.mdf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Data\modellog.ldf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdbdata.mdf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdblog.ldf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Data\tempdb.mdf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Data\templog.ldf Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\ERRORLOG Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\log_30.trc Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.2\OLAP\Log\FlightRecorderCurrent.trc Object is locked skipped C:\Archivos de programa\Microsoft SQL Server\MSSQL.2\OLAP\Log\msmdsrv.log Object is locked skipped C:\Archivos de programa\Trend Micro\HijackThis\backups\backup-20080702-092215-491.dll Infected: Trojan.Win32.Monder.wl skipped C:\Archivos de programa\Trend Micro\HijackThis\backups\backup-20080702-092215-907.dll Infected: Trojan.Win32.Monder.mh skipped C:\Archivos de programa\Trend Micro\HijackThis\backups\backup-20080702-092239-100.dll Infected: Trojan.Win32.Monder.wl skipped C:\Archivos de programa\Trend Micro\HijackThis\backups\backup-20080702-092239-682.dll Infected: Trojan.Win32.Monder.mh skipped C:\Archivos de programa\Trend Micro\HijackThis\backups\backup-20080702-092654-557.dll Infected: Trojan.Win32.Monder.wl skipped C:\Archivos de programa\Trend Micro\HijackThis\backups\backup-20080702-092654-754.dll Infected: Trojan.Win32.Monder.mh skipped C:\Deckard\System Scanner\20080702150402\backup\DOCUME~1\ekemp\CONFIG~1\Temp\Mad Cars.exe/file555 Infected: Trojan-Downloader.Win32.Agent.rip skipped C:\Deckard\System Scanner\20080702150402\backup\DOCUME~1\ekemp\CONFIG~1\Temp\Mad Cars.exe Inno: infected - 1 skipped C:\Documents and Settings\ekemp\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Datos de programa\Lotus\Notes\Data\bookmark.nsf Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Datos de programa\Lotus\Notes\Data\Cache.NDK Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Datos de programa\Lotus\Notes\Data\desktop6.ndk Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Datos de programa\Lotus\Notes\Data\headline.nsf Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Datos de programa\Lotus\Notes\Data\IBM_TECHNICAL_SUPPORT\console.log Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Datos de programa\Lotus\Notes\Data\IBM_TECHNICAL_SUPPORT\SmartUpgrade\SmartUpgrade.log Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Datos de programa\Lotus\Notes\Data\log.nsf Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Datos de programa\Lotus\Notes\Data\names.nsf Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Datos de programa\Lotus\Notes\Data\~notes.lck Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Historial\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Historial\History.IE5\MSHist012008070220080703\index.dat Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Historial\History.IE5\MSHist012008070320080704\index.dat Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Temp\notesEAA22C\~editclp.ncf Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Temp\~DF4C80.tmp Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Temp\~DF8138.tmp Object is locked skipped C:\Documents and Settings\ekemp\Configuración local\Temp\~DF8ABC.tmp Object is locked skipped C:\Documents and Settings\ekemp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\ekemp\Datos de programa\Microsoft\MS Project\11\3082\Global.MPT Object is locked skipped C:\Documents and Settings\ekemp\ntuser.dat Object is locked skipped C:\Documents and Settings\ekemp\NtUser.dat.LOG Object is locked skipped C:\Documents and Settings\ekemp\UserData\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Configuración local\Historial\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\QooBox\Quarantine\C\WINDOWS\system32\khfeBsrO.dll.vir Infected: Trojan.Win32.Monder.wl skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ljJASifE.dll.vir Infected: Trojan.Win32.Monder.mh skipped C:\QooBox\Quarantine\C\WINDOWS\system32\lqeakixi.dll.vir Infected: Trojan.Win32.Monderc.gen skipped C:\QooBox\Quarantine\C\WINDOWS\system32\rkxbajxy.dll.vir Infected: Trojan.Win32.Monderc.gen skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP44\A0014088.dll Infected: Trojan.Win32.Monder.ahv skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP46\A0014338.dll Infected: Trojan.Win32.Monder.mh skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP46\A0014339.dll Infected: Trojan.Win32.Monder.wl skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP46\A0014355.dll Infected: Trojan.Win32.Monder.mh skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP46\A0014356.dll Infected: Trojan.Win32.Monder.wl skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP46\A0014357.dll Infected: Trojan.Win32.Monder.mh skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP46\A0014358.dll Infected: Trojan.Win32.Monder.wl skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP46\A0014359.dll Infected: Trojan.Win32.Monder.mh skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP46\A0014360.dll Infected: Trojan.Win32.Monder.wl skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP46\A0014496.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.zji skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP46\A0014497.dll Infected: Trojan.Win32.Monderc.a skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP48\A0014747.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.zji skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP48\A0014748.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.zji skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP49\A0014779.dll Infected: Trojan.Win32.Monderc.gen skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP49\A0014780.dll Infected: Trojan.Win32.Monderc.gen skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP49\A0014781.dll Infected: Trojan.Win32.Monderc.a skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP49\A0014782.dll Infected: Trojan.Win32.Monderc.a skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP49\A0014783.dll Infected: Trojan.Win32.Monder.wi skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP50\A0014827.dll Infected: Trojan.Win32.Monder.wl skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP50\A0014828.dll Infected: Trojan.Win32.Monder.mh skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP50\A0014829.dll Infected: Trojan.Win32.Monderc.gen skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP50\A0014830.dll Infected: Trojan.Win32.Monderc.gen skipped C:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP51\change.log Object is locked skipped C:\WINDOWS\CSC\00000001 Object is locked skipped C:\WINDOWS\Debug\Netlogon.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped C:\WINDOWS\system32\config\OSession.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_720.dat Object is locked skipped D:\Propuestas\VTR\Normalización DW\everis - Estimación de Esfuerzo Normalización DWH_v2.1.xls Object is locked skipped D:\Propuestas\VTR\Normalización DW\everis - Planificación Detallada Normalización DWH_v0.21.mpp Object is locked skipped D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped D:\System Volume Information\_restore{98C004BF-B4EF-4810-A965-36317268CEBF}\RP51\change.log Object is locked skipped D:\_OTMoveIt\MovedFiles\07022008_124305\WINDOWS\system32\bqgpsrtc.dll Infected: Trojan.Win32.Monderc.a skipped D:\_OTMoveIt\MovedFiles\07022008_124305\WINDOWS\system32\fsuisrhl.dll Infected: Trojan.Win32.Monderc.gen skipped D:\_OTMoveIt\MovedFiles\07022008_124305\WINDOWS\system32\jcmkaqtf.dll Infected: Trojan.Win32.Monderc.a skipped D:\_OTMoveIt\MovedFiles\07022008_124305\WINDOWS\system32\khfeBsrO.dll Infected: Trojan.Win32.Monder.wl skipped D:\_OTMoveIt\MovedFiles\07022008_124305\WINDOWS\system32\mvmpqvxc.dll Infected: Trojan.Win32.Monderc.gen skipped D:\_OTMoveIt\MovedFiles\07022008_124305\WINDOWS\system32\wvUnMggg.dll Infected: Trojan.Win32.Monder.wi skipped Scan process completed.
Thanks,
Combo Fix Log and Hijackthis logs:


ComboFix 08-07-01.5 - ekemp 2008-07-03 15:27:41.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.34.3082.18.1118 [GMT -4:00]
Se ejecuta desde: C:\Documents and Settings\ekemp\Escritorio\ComboFix.exe
.

(((((((((((((((((( Archivos creados desde 2008-06-03 - 2008-07-03 )))))))))))))))))))))))))))))))))
.

2008-07-02 20:19 . 2008-07-02 20:19 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-07-02 20:19 . 2008-07-02 20:19 d——– C:\WINDOWS\LastGood
2008-07-02 20:19 . 2008-07-02 20:19 d——– C:\Documents and Settings\All Users\Datos de programa\Kaspersky Lab
2008-07-02 16:25 . 2008-07-02 16:25 d——– C:\WINDOWS\system32\config\systemprofile\Configuraci¾n local
2008-07-02 16:25 . 2008-07-02 16:25 d——– C:\Documents and Settings\NetworkService\Configuraci¾n local
2008-07-02 16:25 . 2008-07-02 16:25 d——– C:\Documents and Settings\LocalService\Configuraci¾n local
2008-07-02 16:25 . 2008-07-02 16:25 d——– C:\Documents and Settings\Everis\Configuraci¾n local
2008-07-02 16:25 . 2008-07-02 16:25 d——– C:\Documents and Settings\ekemp\Configuraci¾n local
2008-07-02 16:25 . 2008-07-02 16:25 d——– C:\Documents and Settings\Administrador\Configuraci¾n local
2008-07-02 16:25 . 2008-07-02 16:25 d——– C:\Documents and Settings\Administrador.HP530\Configuraci¾n local
2008-07-02 12:17 . 2008-07-02 12:17 d——– C:\Deckard
2008-07-02 10:36 . 2008-07-02 10:36 96,193 –a—— C:\runscanner.zip
2008-07-02 10:35 . 2008-07-02 10:35 93,552 –a—— C:\runscannerfile.run
2008-06-30 15:30 . 2006-03-02 07:00 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2008-06-30 15:03 . 2008-06-30 15:03 d——– C:\Archivos de programa\Vuze
2008-06-30 14:56 . 2008-06-30 15:03 d——– C:\Documents and Settings\Administrador.HP530\Datos de programa\Subversion
2008-06-30 14:36 . 2008-06-30 14:36 d——– C:\Archivos de programa\Trend Micro
2008-06-30 09:49 . 2008-06-30 15:03 d——– C:\Archivos de programa\Mozilla Firefox(2)
2008-06-30 09:49 . 2008-06-30 09:49 0 –a—— C:\WINDOWS\nsreg.dat
2008-06-30 08:55 . 2008-06-30 08:55 d——– C:\Archivos de programa\Lavasoft
2008-06-28 23:05 . 2008-07-02 16:22 d-a—— C:\Documents and Settings\All Users\Datos de programa\TEMP
2008-06-28 22:32 . 2008-06-28 23:05 d——– C:\Documents and Settings\ekemp\Datos de programa\Azureus
2008-06-28 22:32 . 2008-06-28 22:32 d——– C:\Documents and Settings\All Users\Datos de programa\Azureus
2008-06-27 09:38 . 2008-07-02 17:27 d——– C:\Documents and Settings\ekemp\Contacts
2008-06-27 09:36 . 2008-06-27 09:36 d–hsc— C:\Archivos de programa\Archivos comunes\WindowsLiveInstaller
2008-06-27 09:35 . 2008-06-27 09:35 d——– C:\Documents and Settings\All Users\Datos de programa\WLInstaller
2008-06-27 09:35 . 2008-06-27 09:36 d——– C:\Archivos de programa\Windows Live
2008-06-26 18:04 . 2008-06-26 18:04 207,540 –a—— C:\Reporte.bqy
2008-06-25 11:50 . 2008-06-25 11:50 48,123 –a—— C:\WINDOWS\vpd.properties
2008-06-25 11:48 . 2007-06-27 00:16 148,480 –a—— C:\WINDOWS\system32\TLBINF32.DLL
2008-06-25 11:48 . 2007-06-27 00:16 109,248 –a—— C:\WINDOWS\system32\MSWINSCK.OCX
2008-06-25 11:48 . 2007-06-27 00:16 89,360 –a—— C:\WINDOWS\system32\VB5DB.DLL
2008-06-25 11:48 . 2008-06-25 11:48 49,590 –a—— C:\WINDOWS\bqmeta_ev0.ini
2008-06-25 11:48 . 2007-06-27 00:16 24,576 –a—— C:\WINDOWS\system32\msxml3a.dll
2008-06-25 11:42 . 2007-06-18 11:18 90,112 –a—— C:\WINDOWS\sqrrem32.dll
2008-06-25 11:42 . 2005-02-22 09:16 38,400 –a—— C:\WINDOWS\ptftp32c.dll
2008-06-25 11:42 . 2005-02-22 09:16 27,136 –a—— C:\WINDOWS\pttcp32c.dll
2008-06-25 11:42 . 2008-06-25 11:48 10,134 –a—— C:\WINDOWS\sqr.ini
2008-06-25 11:42 . 2008-06-25 11:42 111 –a—— C:\WINDOWS\libsti.ini
2008-06-25 11:38 . 2008-06-25 11:42 d——– C:\Hyperion
2008-06-19 23:02 . 2008-06-19 23:02 d—s—- C:\Documents and Settings\ekemp\UserData
2008-06-19 23:00 . 2008-06-19 23:01 d——– C:\Documents and Settings\ekemp\Datos de programa\Aventail
2008-06-18 17:16 . 2008-05-07 08:53 56,315 –a—— C:\WINDOWS\ofcscan.ini
2008-06-18 17:15 . 2008-06-18 17:15 0 –a—— C:\s3eg.3
2008-06-18 13:10 . 2008-06-18 13:10 d——– C:\Documents and Settings\ekemp\Datos de programa\Xerox
2008-06-17 12:41 . 2008-06-23 14:28 d——– C:\Documents and Settings\ekemp\Datos de programa\AdobeUM
2008-06-17 12:39 . 2008-06-17 12:39 d——– C:\Documents and Settings\LocalService\Menú Inicio
2008-06-17 12:37 . 2007-12-24 11:37 138,384 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-17 12:36 . 2007-04-20 18:44 307,984 –a—— C:\WINDOWS\system32\drivers\TM_CFW.sys
2008-06-17 12:36 . 2006-11-14 12:14 73,288 –a—— C:\WINDOWS\system32\drivers\tmtdi.sys
2008-06-16 14:30 . 2008-06-16 14:30 d——– C:\WINDOWS\Sun
2008-06-16 14:30 . 2008-06-16 14:30 d——– C:\Archivos de programa\Java
2008-06-16 14:30 . 2008-06-16 14:30 d——– C:\Archivos de programa\Archivos comunes\Java
2008-06-16 14:30 . 2004-02-22 23:44 61,555 –a—— C:\WINDOWS\system32\jpicpl32.cpl
2008-06-16 14:02 . 2008-06-16 14:02 d——– C:\Documents and Settings\ekemp\Datos de programa\Business Objects
2008-06-16 13:13 . 2001-01-04 12:37 766 –a—— C:\WINDOWS\system32\uninst.ico
2008-06-16 13:03 . 2008-06-16 13:13 d——– C:\Archivos de programa\NotesSQL
2008-06-16 13:03 . 2008-06-16 13:08 d——– C:\Archivos de programa\Business Objects
2008-06-16 12:15 . 2008-06-16 12:15 d——– C:\Archivos de programa\MSXML 6.0
2008-06-16 12:07 . 2002-02-24 21:30 260,096 ——— C:\WINDOWS\system32\RICHTX32.OCX
2008-06-16 12:07 . 2000-05-22 01:00 140,488 ——— C:\WINDOWS\system32\COMDLG32.OCX
2008-06-16 12:06 . 2008-06-16 12:09 d——– C:\Documents and Settings\All Users\Datos de programa\PowerDesigner 12
2008-06-16 12:06 . 2008-06-16 12:07 d——– C:\Archivos de programa\Sybase
2008-06-14 23:08 . 2008-06-14 23:18 118 –a—— C:\WINDOWS\ChssBase.ini
2008-06-14 23:01 . 2008-06-14 23:28 d——– C:\Documents and Settings\ekemp\Datos de programa\ChessBase
2008-06-14 22:59 . 2008-06-14 23:28 d——– C:\Archivos de programa\ChessBase
2008-06-13 17:25 . 2008-06-13 17:25 d——– C:\Documents and Settings\ekemp\Datos de programa\Subversion
2008-06-13 17:01 . 2008-06-13 17:01 d——– C:\Archivos de programa\TortoiseSVN
2008-06-13 16:24 . 2008-06-13 16:24 d——– C:\Archivos de programa\SQLXML 4.0
2008-06-13 16:19 . 2008-06-16 13:10 d——– C:\Archivos de programa\Microsoft Visual Studio 8
2008-06-13 16:19 . 2008-06-13 16:19 d——– C:\Archivos de programa\Archivos comunes\Merge Modules
2008-06-13 16:18 . 2008-06-13 16:18 d——– C:\Archivos de programa\Microsoft.NET
2008-06-13 16:18 . 2008-06-13 16:18 d——– C:\Archivos de programa\Microsoft Analysis Services
2008-06-13 16:14 . 2008-06-18 16:56 d——– C:\Archivos de programa\Microsoft SQL Server
2008-06-13 15:12 . 2001-08-22 21:34 12,416 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-06-13 15:12 . 2001-08-22 21:34 12,416 –a–c— C:\WINDOWS\system32\dllcache\mouhid.sys
2008-06-13 15:12 . 2001-08-17 22:02 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-06-13 15:12 . 2001-08-17 22:02 9,600 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2008-06-13 13:22 . 2008-07-03 14:34 dr-h—– C:\Documents and Settings\ekemp\Reciente
2008-06-13 13:22 . 2008-04-08 11:32 d–h—– C:\Documents and Settings\ekemp\Plantillas
2008-06-13 13:22 . 2008-07-02 10:27 dr——- C:\Documents and Settings\ekemp\Mis documentos
2008-06-13 13:22 . 2008-04-08 06:25 dr——- C:\Documents and Settings\ekemp\Menú Inicio
2008-06-13 13:22 . 2008-04-08 06:25 d–h—– C:\Documents and Settings\ekemp\Impresoras
2008-06-13 13:22 . 2008-07-02 16:08 dr——- C:\Documents and Settings\ekemp\Favoritos
2008-06-13 13:22 . 2008-07-03 14:34 d——– C:\Documents and Settings\ekemp\Escritorio
2008-06-13 13:22 . 2008-06-18 16:26 d–h—– C:\Documents and Settings\ekemp\Entorno de red
2008-06-13 13:22 . 2008-06-30 09:49 dr-h—– C:\Documents and Settings\ekemp\Datos de programa
2008-06-13 13:22 . 2008-07-03 15:31 d–h—– C:\Documents and Settings\ekemp\Configuración local
2008-06-13 13:22 . 2008-07-03 10:40 d——– C:\Documents and Settings\ekemp
2008-06-03 21:48 . 2008-06-03 21:48 d——– C:\VProRecovery
2008-06-03 21:35 . 2008-06-03 21:35 d——– C:\Documents and Settings\Administrador.HP530\Datos de programa\Symantec
2008-06-03 21:05 . 2008-06-03 21:05 d——– C:\Archivos de programa\Symantec
2008-06-03 21:05 . 2007-03-21 20:39 1,060,864 –a—— C:\WINDOWS\system32\MFC71.DLL
2008-06-03 21:05 . 2007-03-21 20:33 503,808 –a—— C:\WINDOWS\system32\MSVCP71.DLL
2008-06-03 21:05 . 2007-03-21 20:33 348,160 –a—— C:\WINDOWS\system32\MSVCR71.DLL
2008-06-03 21:03 . 2008-06-06 10:37 d——– C:\Documents and Settings\All Users\Datos de programa\Symantec
2008-06-03 20:54 . 2008-06-03 20:56 24 –a—— C:\WINDOWS\pccntmon.INI

.
(((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-25 23:13 ——— d—–w C:\Archivos de programa\Archivos comunes\InstallShield
2008-06-18 20:57 ——— d—–w C:\Documents and Settings\All Users\Datos de programa\Microsoft Help
2008-06-17 16:40 ——— d—–w C:\Archivos de programa\Archivos comunes\Adobe
2008-06-16 17:14 31 —-a-w C:\Archivos de programa\Notes.ini
2008-06-16 17:13 ——— d–h–w C:\Archivos de programa\InstallShield Installation Information
2004-10-01 19:00 40,960 —-a-w C:\Archivos de programa\Uninstall_CDS.exe
.

((((((((((((((((((((((((((((( snapshot@2008-07-02_16.24.59.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-05-24 16:27:16 213,048 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 —-a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
- 2008-07-02 16:50:43 107,294 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-07-02 20:25:09 107,744 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-07-02 16:50:43 127,746 —-a-w C:\WINDOWS\system32\perfc00A.dat
+ 2008-07-02 20:25:09 128,292 —-a-w C:\WINDOWS\system32\perfc00A.dat
- 2008-07-02 16:50:43 516,464 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-07-02 20:25:09 517,106 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2008-07-02 16:50:43 583,008 —-a-w C:\WINDOWS\system32\perfh00A.dat
+ 2008-07-02 20:25:09 583,976 —-a-w C:\WINDOWS\system32\perfh00A.dat
.
((((((((((((((((((((((((((((((((( Cargando Puntos Reg ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* entradas vacías & entradas legítimas predeterminadas no son mostradas

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 –a—— C:\Archivos de programa\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 07:00 15360]
"MsnMsgr"="C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-09-18 22:29 141848]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-09-18 22:29 166424]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-09-18 22:29 137752]
"QlbCtrl.exe"="C:\Archivos de programa\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-10-19 13:05 177456]
"OfficeScanNT Monitor"="C:\OfficeScan NT\pccntmon.exe" [2007-08-08 06:33 705904]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"SunJavaUpdateSched"="C:\Archivos de programa\Java\j2re1.4.2_04\bin\jusched.exe" [2004-02-22 23:44 32881]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 07:00 15360]

C:\Documents and Settings\All Users\Men£ Inicio\Programas\Inicio\
Acrobat Assistant.lnk - C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 00:19:50 217193]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Archivos de programa\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Archivos de programa\\Windows Live\\Messenger\\livecall.exe"=

R2 Ataman TCP Remote Logon Services;Ataman TCP Remote Logon Services;C:\Hyperion\BIPlus\bin\SQR\Remote\bin\atrls.exe [1998-09-09 23:04]
R2 MsDtsServer;SQL Server Integration Services;"C:\Archivos de programa\Microsoft SQL Server\90\DTS\Binn\MsDtsSrvr.exe" [2007-02-10 05:23]
R3 Astdi;Astdi;C:\Archivos de programa\Aventail\Connect\asnttdi.sys [2003-06-11 17:24]
S3 Ascrypto;Ascrypto;C:\Archivos de programa\Aventail\Connect\ascrypto.sys [2003-06-11 17:26]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Archivos de programa\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" /service msvsmon80 []

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-03 15:32:10
Windows 5.1.2600 Service Pack 2 NTFS

escaneando procesos ocultos …

escaneando entradas ocultas de autostart …

escaneando archivos ocultos …

el escaneo se completo con exito
archivos ocultos: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet002\Services\msftesql]
"ImagePath"="\"C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:MSSQLSERVER"
.
——————— DLLs cargados bajo los procesos en ejecución ———————

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Archivos de programa\TortoiseSVN\iconv\_tbl_simple.so
-> C:\Archivos de programa\TortoiseSVN\iconv\windows-1252.so
-> C:\Archivos de programa\TortoiseSVN\iconv\utf-8.so
.
Tiempo completado: 2008-07-03 15:35:31
ComboFix-quarantined-files.txt 2008-07-03 19:35:11
ComboFix2.txt 2008-07-02 21:21:16
ComboFix3.txt 2008-07-02 20:25:12

10 dirs 20,233,535,488 bytes libres
14 dirs 20,227,768,320 bytes libres

220


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:36, on 2008-07-03
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Aventail\Connect\as32svc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Hyperion\BIPlus\bin\SQR\Remote\bin\atrls.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Archivos de programa\Microsoft SQL Server\MSSQL.2\OLAP\bin\msmdsrv.exe
C:\Archivos de programa\lotus\notes\ntmulti.exe
C:\OfficeScan NT\ntrtscan.exe
C:\Archivos de programa\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\OfficeScan NT\tmlisten.exe
C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
C:\OfficeScan NT\PCCNTMON.EXE
C:\OfficeScan NT\TmPfw.exe
C:\Archivos de programa\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Archivos de programa\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\OfficeScan NT\CNTAoSMgr.exe
C:\Archivos de programa\Java\j2re1.4.2_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe
C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Archivos de programa\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: PDF de Adobe - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Archivos de programa\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acrobat Assistant.lnk = C:\Archivos de programa\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.nl/scanforvirus-en/ka…can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1202486440984
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2) - http://190.243.34.139/businessobjects/ente…dows-i586-p.exe
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - http://santiago-ns001.everis.int/dwa7W.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = everis.int
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = everis.int
O23 - Service: Aventail Connect (As32Svc) - Aventail Corporation - C:\Archivos de programa\Aventail\Connect\as32svc.exe
O23 - Service: Ataman TCP Remote Logon Services - Unknown owner - C:\Hyperion\BIPlus\bin\SQR\Remote\bin\atrls.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Multi-user Cleanup Service - IBM Corp - C:\Archivos de programa\lotus\notes\ntmulti.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScan NT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
O23 - Service: OfficeScan NT Firewall (TmPfw) - Trend Micro Inc. - C:\OfficeScan NT\TmPfw.exe
O23 - Service: OfficeScan NT Proxy Service (TmProxy) - Trend Micro Inc. - C:\OfficeScan NT\TmProxy.exe

–
End of file - 6748 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI