ComboFix 09-03-18.01 - Usuario 2009-03-19 0:29:59.11 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.767.592 [GMT -3:00]
Running from: c:\documents and settings\Usuario\Mis documentos\programa para virus\ComboFixnew.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Muestras
.
((((((((((((((((((((((((( Files Created from 2009-02-19 to 2009-03-19 )))))))))))))))))))))))))))))))
.
2009-03-18 19:48 . 2005-07-31 08:07 172,032 --a------ c:\windows\system32\OSSMTP.dll
2009-03-17 01:30 . 2009-03-17 01:30 23 --ahs---- c:\windows\system32\edacded0_x.dat
2009-03-17 01:30 . 2009-03-17 01:30 23 --a------ c:\windows\system32\bcdadac7_x.xml
2009-03-17 01:29 . 2009-03-17 01:29 <DIR> d-------- c:\archivos de programa\RegCleaner
2009-03-16 21:53 . 2009-03-16 21:53 <DIR> d-------- c:\documents and settings\All Users\Datos de programa\Kaspersky Lab Setup Files
2009-03-14 19:55 . 2009-03-17 20:42 <DIR> d-------- c:\archivos de programa\VoipCheapCom
2009-03-14 17:00 . 2009-03-19 00:29 <DIR> d-------- C:\ComboFix
2009-03-09 00:08 . 2009-03-09 00:08 <DIR> d-------- C:\Games
2009-03-08 21:47 . 2009-03-14 15:44 <DIR> d-------- c:\archivos de programa\Dachshund Software
2009-03-08 21:47 . 2009-03-09 09:15 303 --ah----- c:\windows\wininf.dat
2009-03-04 20:12 . 2009-03-04 20:12 <DIR> d-------- c:\documents and settings\All Users\Datos de programa\Trymedia
2009-02-25 19:19 . 2009-01-09 16:19 1,089,883 -----c--- c:\windows\system32\dllcache\ntprint.cat
2009-02-22 18:50 . 2009-03-14 15:44 <DIR> d-------- c:\archivos de programa\Panda Security
2009-02-21 14:56 . 2009-02-21 14:57 <DIR> d-------- c:\archivos de programa\Ultra RM Converter
2009-02-21 14:56 . 2007-04-12 14:19 129,024 --a------ c:\windows\system32\AVERM.dll
2009-02-21 12:57 . 2009-02-21 14:49 <DIR> d-------- c:\archivos de programa\WinAVI Video Converter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-18 23:40 --------- d-----w c:\documents and settings\Usuario\Datos de programa\SUPERAntiSpyware.com
2009-03-18 23:40 --------- d-----w c:\archivos de programa\Archivos comunes\Wise Installation Wizard
2009-03-18 23:36 --------- d-----w c:\documents and settings\All Users\Datos de programa\Spybot - Search & Destroy
2009-03-18 23:36 --------- d-----w c:\archivos de programa\Spybot - Search & Destroy
2009-03-17 04:11 --------- d-----w c:\archivos de programa\CCleaner
2009-03-16 13:29 --------- d-----w c:\archivos de programa\eMule
2009-03-16 13:21 --------- d-----w c:\documents and settings\All Users\Datos de programa\Grisoft
2009-03-14 22:57 --------- d-----w c:\documents and settings\Usuario\Datos de programa\VoipCheapCom
2009-03-14 18:43 --------- d-----w c:\archivos de programa\Comical
2009-03-14 01:35 --------- d-----w c:\documents and settings\Usuario\Datos de programa\FreeCall
2009-03-09 12:17 --------- d-----w c:\archivos de programa\SUPERAntiSpyware
2009-02-26 00:36 --------- d-----w c:\archivos de programa\Microsoft Silverlight
2009-02-25 13:27 --------- d-----w c:\archivos de programa\Messenger Plus! Live
2009-02-10 13:50 --------- d-----w c:\documents and settings\Usuario\Datos de programa\Snapter Images
2009-02-09 14:06 1,846,912 ----a-w c:\windows\system32\win32k.sys
2009-02-08 16:53 --------- d-----w c:\documents and settings\Usuario\Datos de programa\Auslogics
2009-02-08 16:53 --------- d-----w c:\archivos de programa\Auslogics
2009-01-31 17:45 --------- d-----w c:\archivos de programa\DivX
2009-01-29 01:54 --------- d-----w c:\archivos de programa\Project64 1.6
2009-01-28 19:10 --------- d-----w c:\documents and settings\All Users\Datos de programa\Office Genuine Advantage
2009-01-27 01:10 --------- d-----w c:\documents and settings\All Users\Datos de programa\SUPERAntiSpyware.com
2008-12-20 22:47 826,368 ----a-w c:\windows\system32\wininet.dll
2008-07-26 03:19 22 -c--a-w c:\documents and settings\Usuario\liberar.vbe
2008-04-06 00:15 1,776,512 -c--a-w c:\archivos de programa\_Alcohol.exe
2008-04-03 17:21 24,192 -c--a-w c:\documents and settings\Usuario\usbsermptxp.sys
2008-04-03 17:21 22,768 -c--a-w c:\documents and settings\Usuario\usbsermpt.sys
2008-03-27 21:47 57,344 -c--a-w c:\documents and settings\Usuario\lametritonus.dll
2008-03-27 21:47 162,304 -c--a-w c:\documents and settings\Usuario\lame_enc.dll
2008-10-08 03:26 56 -csh--r c:\windows\system32\95FE997E61.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"VoipCheapCom"="c:\archivos de programa\VoipCheapCom\VoipCheapCom.exe" [2007-02-20 7202360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\archivos de programa\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"RemoteControl"="c:\archivos de programa\CyberLink\PowerDVD\PDVDServ.exe" [2006-09-18 29696]
"LanguageShortcut"="c:\archivos de programa\CyberLink\PowerDVD\Language\Language.exe" [2006-09-29 49152]
"SunJavaUpdateSched"="c:\archivos de programa\Java\jre6\bin\jusched.exe" [2008-12-11 136600]
"TkBellExe"="c:\archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe" [2008-04-17 185896]
"iTunesHelper"="c:\archivos de programa\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"ZSSnp211"="c:\windows\ZSSnp211.exe" [2007-04-06 57344]
"Domino"="c:\windows\Domino.exe" [2006-08-18 49152]
"WinampAgent"="c:\archivos de programa\Winamp\winampa.exe" [2008-08-03 36352]
"Pinnacle WebUpdater"="c:\archivos de programa\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe -s -f=UpdateVersion.xml" [BU]
"RTHDCPL"="RTHDCPL.EXE" [2007-01-31 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-17 c:\windows\SkyTel.exe]
"VTTimer"="VTTimer.exe" [2006-08-03 c:\windows\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [2006-07-11 c:\windows\system32\S3Trayp.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Men£ Inicio\Programas\Inicio\
DSLMON.lnk - c:\archivos de programa\Huawei Technologies\Huawei SmartAX MT810\dslmon.exe [2008-02-13 946302]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.FFDS"= c:\archiv~1\Combined Community Codec Pack\Filters\ff_vfw.dll
"vidc.wmv3"= c:\archiv~1\Combined Community Codec Pack\Filters\wmv9vcm.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Archivos de programa\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Archivos de programa\\iTunes\\iTunes.exe"=
"c:\\Archivos de programa\\Messenger\\msmsgs.exe"=
"c:\\Archivos de programa\\ooVoo\\ooVoo.exe"=
"c:\\Archivos de programa\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Archivos de programa\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Archivos de programa\\eMule\\emule.exe"=
"c:\\Archivos de programa\\MSN Messenger\\WINKS_s_f\\winks\\mcoinstall.exe"=
"c:\\Archivos de programa\\Java\\jre6\\bin\\java.exe"=
"c:\\Archivos de programa\\VoipCheapCom\\VoipCheapCom.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"443:UDP"= 443:UDP:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:ooVoo UDP port 37675
"443:TCP"= 443:TCP:ooVoo TCP puerto 443
S2 BT848;CxVCap, WDM Video Capture;c:\windows\system32\drivers\cxvcap.sys [2007-12-15 56704]
S2 CAMTHWDM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\CAMTHWDM.sys [2008-02-09 941784]
S2 CXTUNER;CxTuner, WDM TvTuner;c:\windows\system32\drivers\cxtuner.sys [2007-12-15 26752]
S2 CXXBAR;CxBar, WDM Crossbar;c:\windows\system32\drivers\cxxbar.sys [2007-12-15 9728]
S2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-03-24 46112]
S3 3xHybrid;Pinnacle PCTV 110i service;c:\windows\system32\drivers\3xHybrid.sys [2008-01-12 827008]
S3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [2007-12-12 659456]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [2007-02-15 26624]
S3 tapavpn;Steganos Anonym VPN Adapter;c:\windows\system32\drivers\tapavpn.sys [2007-10-19 24320]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
Contents of the 'Scheduled Tasks' folder
2009-03-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\archivos de programa\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&xportar a Microsoft Excel - c:\archiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
.
------- File Associations -------
.
inffile=Notepad.exe "%1"
inifile=Notepad.exe "%1"
txtfile=Notepad.exe "%1"
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-19 00:32:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-527237240-1284227242-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,ec,60,9f,0f,c7,
ab,53,38,e2,63,26,f1,3f,c8,ff,68,99,85,41,f6,be,18,16,e1,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,3c,02,c3,dc,31,
c8,11,3e,6a,9c,d6,61,af,45,84,18,1f,17,04,94,47,ff,df,5c,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:7a,45,05,fd,91,e8,6f,31,3f,f8,68,bd,93,
40,6e,63,ff,7c,85,e0,43,d4,0e,fe,cd,e0,be,a1,da,c0,4c,82,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,bb,58,1f,1c,b7,
50,aa,e1,86,8c,21,01,be,91,eb,e7,09,97,b3,65,68,ef,80,e4,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:e9,02,6c,fa,fb,1d,47,57,be,76,04,49,ab,
4c,41,7c,f5,1d,4d,73,a8,13,5c,05,ee,4f,8f,25,21,af,56,6a,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:b0,18,ed,a7,3f,8d,37,a4,ed,a4,5c,5f,0f,
f8,f1,81,df,20,58,62,78,6b,cf,c8,f0,87,1b,ca,52,f7,a0,08,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,06,e4,80,55,81,
8d,cd,22,fb,a7,78,e6,12,2f,9a,ea,1d,e7,87,18,1e,2c,91,ca,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:83,6c,56,8b,a0,85,96,ab,c2,c9,e3,d3,9f,
0c,90,af,01,3a,48,fc,e8,04,4a,f1,3c,c4,21,37,69,66,a0,e6,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:b2,46,9a,e2,1b,fe,1b,94,37,5b,de,9d,b6,
11,81,44,f6,0f,4e,58,98,5b,89,c9,e6,e4,78,04,81,d4,98,f0,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,ad,7b,44,e0,ea,
95,68,4b,3d,ce,ea,26,2d,45,aa,78,95,63,3a,53,1f,6e,0d,d0,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:2a,b7,cc,b5,b9,7f,41,e7,68,16,e3,5d,e1,
b4,83,b7,2a,b7,cc,b5,b9,7f,41,e7,5c,7b,14,b9,da,79,6c,30,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,96,ea,d1,b2,f0,
42,c8,a0,6c,43,2d,1e,aa,22,2f,9c,9c,20,a7,18,32,7f,dd,47,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|é•9~*]
"A0C0110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(272)
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-03-19 0:34:20
ComboFix-quarantined-files.txt 2009-03-19 03:34:18
ComboFix2.txt 2009-02-21 02:40:11
ComboFix3.txt 2009-02-08 16:25:24
ComboFix4.txt 2009-01-30 16:41:50
ComboFix5.txt 2009-03-14 01:36:50
Pre-Run: 108,697,468,928 bytes libres
Post-Run: 108,684,496,896 bytes libres
Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
237 --- E O F --- 2009-03-15 07:46:53