the-father | |
| 2009-08-04 02:31 - Respuestas: 23 - Tema nº: 2610261
Malwarebytes' Anti-Malware 1.40
Versión de la Base de Datos: 2553
Windows 5.1.2600 Service Pack 2
03/08/2009 08:21:45 p.m.
mbam-log-2009-08-03 (20-21-39).txt
Tipo de examen : Examen Completo (C:\|D:\|)
Objetos examinados: 127570
Tiempo transcurrido: 27 minute(s), 11 second(s)
Procesos en Memoria Infectados: 2
Módulos en Memoria Infectados: 2
Claves del Registro Infectadas: 27
Valores del Registro Infectados: 4
Elementos de Datos del Registro Infectados: 4
Carpetas Infectadas: 4
Ficheros Infectados: 95
Procesos en Memoria Infectados:
C:\WINDOWS\system32\scvhosts.exe (Worm.AutoRun) -> No action taken.
C:\WINDOWS\system32\scvhosts.exe (Worm.AutoRun) -> No action taken.
Módulos en Memoria Infectados:
C:\Archivos de programa\Windows Live\Messenger\msimg32.dll (Adware.MyWebSearch) -> No action taken.
C:\WINDOWS\system32\e8main1.dll (Spyware.OnlineGames) -> No action taken.
Claves del Registro Infectadas:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-21cx3c644241} (Generic.Bot.H) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{bb4c402f-882a-4526-8c08-51278ea437c1} (Spyware.OnlineGames) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
Valores del Registro Infectados:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yahoo messengger (Worm.AutoRun) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{bb4c402f-882a-4526-8c08-51278ea437c1} (Spyware.OnlineGames) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xp-d05b25a0 (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cdoosoft (Spyware.OnlineGames) -> No action taken.
Elementos de Datos del Registro Infectados:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> No action taken.
Carpetas Infectadas:
C:\Archivos de programa\MyWebSearch (Adware.MyWebSearch) -> No action taken.
C:\Archivos de programa\MyWebSearch\bar (Adware.MyWebSearch) -> No action taken.
C:\CONFIG\S-1-5-21-1482476501-1644491937-682003330-1013 (Backdoor.IRCBot) -> No action taken.
C:\Documents and Settings\elizardo\Configuración local\Temp\E_4 (Autorun.Worm) -> No action taken.
Ficheros Infectados:
C:\CONFIG\S-1-5-21-1482476501-1644491937-682003330-1013\usr.exe (Generic.Bot.H) -> No action taken.
C:\WINDOWS\system32\scvhosts.exe (Worm.AutoRun) -> No action taken.
C:\Archivos de programa\Windows Live\Messenger\msimg32.dll (Adware.MyWebSearch) -> No action taken.
C:\WINDOWS\system32\e8main1.dll (Spyware.OnlineGames) -> No action taken.
C:\Archivos de programa\Uninstall Fun Web Products.dll (Adware.MyWeb) -> No action taken.
C:\Archivos de programa\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043437.scr (Adware.MyWebSearch) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043444.DLL (Adware.MyWebSearch) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043447.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043451.SCR (Adware.MyWebSearch) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043452.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043453.DLL (Adware.MyWebSearch) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043458.EXE (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043459.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043460.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043461.EXE (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043462.EXE (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043463.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043465.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043466.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043467.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043468.EXE (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043469.EXE (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043470.EXE (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043471.EXE (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043472.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043486.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043487.EXE (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043488.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043489.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043490.DLL (Adware.MyWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP6\A0043475.DLL (Adware.FunWeb) -> No action taken.
C:\System Volume Information\_restore{A50AFF23-FF05-4550-914F-BE9DFDF2D227}\RP9\A0070816.exe (Worm.AutoRun) -> No action taken.
C:\WINDOWS\hinhem.scr (Worm.AutoRun) -> No action taken.
C:\WINDOWS\scvhosts.exe (Worm.AutoRun) -> No action taken.
C:\WINDOWS\system32\blastclnnn.exe (Worm.AutoRun) -> No action taken.
D:\hm1bfpuj.exe (Spyware.OnlineGames) -> No action taken.
D:\nkbd1v.exe (Spyware.OnlineGames) -> No action taken.
D:\u0riu2.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP1\A0000013.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP1\A0001018.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP1\A0002015.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP1\A0003015.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP10\A0058224.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP10\A0060224.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP10\A0061224.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP10\A0061242.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP10\A0061265.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP10\A0062265.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP10\A0063266.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP10\A0064302.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP10\A0066265.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP10\A0067266.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP10\A0068266.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP10\A0069266.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP2\A0003056.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP2\A0003382.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP2\A0003407.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP2\A0004408.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP3\A0004415.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP3\A0005435.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP3\A0007439.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP3\A0008434.exe (Spyware.OnlineGames) -> No action taken.
D:\System Volume Information\_restore{4360B6AF-86D1-4633-B87C-B9FC7074786C}\RP3\A0008469.exe (Spyware.OnlineGames) -> No action taken.
C:\CONFIG\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Backdoor.IRCBot) -> No action taken.
C:\Documents and Settings\elizardo\Configuración local\Temp\E_4\com.run (Autorun.Worm) -> No action taken.
C:\Documents and Settings\elizardo\Configuración local\Temp\E_4\dp1.fne (Autorun.Worm) -> No action taken.
C:\Documents and Settings\elizardo\Configuración local\Temp\E_4\eAPI.fne (Autorun.Worm) -> No action taken.
C:\Documents and Settings\elizardo\Configuración local\Temp\E_4\internet.fne (Autorun.Worm) -> No action taken.
C:\Documents and Settings\elizardo\Configuración local\Temp\E_4\krnln.fnr (Autorun.Worm) -> No action taken.
C:\Documents and Settings\elizardo\Configuración local\Temp\E_4\RegEx.fnr (Autorun.Worm) -> No action taken.
C:\Documents and Settings\elizardo\Configuración local\Temp\E_4\shell.fne (Autorun.Worm) -> No action taken.
C:\Documents and Settings\elizardo\Configuración local\Temp\E_4\spec.fne (Autorun.Worm) -> No action taken.
C:\Documents and Settings\elizardo\Menú Inicio\Programas\Inicio\¡¡¡¡¡¡.lnk (Autorun.Worm) -> No action taken.
C:\WINDOWS\system32\XP-D05B25A0.EXE (Trojan.Agent) -> No action taken.
C:\mqhnawe.bat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\olhrwef.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\krnln.fnr (Trojan.Agent) -> No action taken.
C:\Documents and Settings\elizardo\Configuración local\Temp\herss.exe (Spyware.OnlineGames) -> No action taken.
C:\WINDOWS\system32\nmdfgds0.dll (Spyware.OnlineGames) -> No action taken.
C:\WINDOWS\AhnRpta.exe (Trojan.Backdoor) -> No action taken.
C:\WINDOWS\system32\dp1.fne (Autorun.Worm) -> No action taken.
C:\WINDOWS\system32\eAPI.fne (Autorun.Worm) -> No action taken.
C:\WINDOWS\system32\internet.fne (Autorun.Worm) -> No action taken.
C:\WINDOWS\system32\og.dll (Autorun.Worm) -> No action taken.
C:\WINDOWS\system32\og.EDT (Autorun.Worm) -> No action taken.
C:\WINDOWS\system32\RegEx.fnr (Autorun.Worm) -> No action taken.
C:\WINDOWS\system32\shell.fne (Autorun.Worm) -> No action taken.
C:\WINDOWS\system32\spec.fne (Autorun.Worm) -> No action taken.
C:\WINDOWS\system32\ul.dll (Autorun.Worm) -> No action taken.
C:\WINDOWS\system32\com.run (Trojan.Banker) -> No action taken.
C:\WINDOWS\system32\e8main0.dll (Worm.Autorun) -> No action taken.
C:\qr.exe (Trojan.GamesThief) -> No action taken.
C:\Documents and Settings\elizardo\Configuración local\Temp\cvasds0.dll (Spyware.OnlineGames) -> No action taken.
C:\Documents and Settings\elizardo\Configuración local\Temp\cvasds1.dll (Spyware.OnlineGames) -> No action taken.
| |
|
|
the-father | |
|
Re: Problema con la computadora - 2009-08-05 02:19 - Respuesta 22
man respondeme que es lo k tengo k hacer sigue el mismo problema a pesar de hacer todo lo k me dijiste se me digue frisando y ya no se que hacer | |
|
|
caterpilar | |
|
Re: Problema con la computadora - 2009-08-05 03:42 - Respuesta 23
... el log que debes pegar es el del HijackThis ... | |
|
|
the-father | |
|
Re: Problema con la computadora - 2009-08-06 04:07 - Respuesta 24
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:48:58 p.m., on 02/08/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\scvhosts.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe
C:\Archivos de programa\Messenger\msmsgs.exe
C:\WINDOWS\system32\scvhosts.exe
C:\WINDOWS\system32\XP-D05B25A0.EXE
C:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
F2 - REG:system.ini: Shell=Explorer.exe scvhosts.exe
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [XP-D05B25A0] C:\WINDOWS\system32\XP-D05B25A0.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [cdoosoft] C:\DOCUME~1\elizardo\CONFIG~1\Temp\herss.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo Messengger] C:\WINDOWS\system32\scvhosts.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ¡¡¡¡¡¡.lnk = C:\WINDOWS\system32\XP-D05B25A0.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
End of file - 2729 bytes
| |
|
|
|