Mi pc esta muy lenta creo que esta infectada pase el combofix

Este es un debate sobre Mi pc esta muy lenta creo que esta infectada pase el combofix escrito en el foro Foro de Virus y Spywares, parte de la categoria Seguridad informatica ; mi pc esta muy lenta creo que esta infectada pase el combofis y me sale esto ComboFix 08-01-23.2 - User ...

Foro de Virus y Spywares Foro dedicado a la Ayuda con Malware: Virus - Spywares - Troyanos - Adwares - Worms - Hijackers - Dialers - Rootkits - Keylogger - etc. Expón el problema en este foro.

Tema Cerrado

 

Herramientas Desplegado
  #1  
Antiguo 23-feb-2008, 05:02
Junior Member
 
Fecha de Ingreso: febrero-2008
Mensajes: 1
Predeterminado

mi pc esta muy lenta creo que esta infectada pase el combofis y me sale esto

ComboFix 08-01-23.2 - User 2008-02-21 15:36:15.4 - NTFSx86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.487 [GMT 0:00]

Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe



WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.



((((((((((((((((((((((((( Files Created from 2007-12-23 to 2008-01-23 )))))))))))))))))))))))))))))))

.



2008-01-23 15:29 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe

2008-01-21 20:44 . 2008-01-21 20:44 268 --ah----- C:\sqmdata07.sqm

2008-01-21 20:44 . 2008-01-21 20:44 244 --ah----- C:\sqmnoopt07.sqm

2008-01-20 21:53 . 2008-01-20 21:53 <DIR> d-------- C:&#092;Program Files&#092;MSXML 6.0

2008-01-20 21:44 . 2008-01-20 21:44 <DIR> d-------- C:&#092;Program Files&#092;MSXML 4.0

2008-01-20 14:59 . 2008-01-20 14:59 <DIR> d-------- C:&#092;WINDOWS&#092;system32&#092;Kaspersky Lab

2008-01-20 12:57 . 2008-01-20 12:57 <DIR> d-------- C:&#092;Program Files&#092;SigmaTel

2008-01-20 12:57 . 2008-01-20 12:57 <DIR> d-------- C:&#092;Program Files&#092;Sierra

2008-01-20 12:57 . 2008-01-20 12:57 <DIR> d-------- C:&#092;Program Files&#092;HP

2008-01-20 12:57 . 2008-01-20 12:57 <DIR> d-------- C:&#092;Program Files&#092;Hewlett-Packard

2008-01-20 12:57 . 2008-01-20 12:57 <DIR> d-------- C:&#092;PatchTrlm14RevB

2008-01-20 12:57 . 2008-01-20 12:57 <DIR> d-------- C:&#092;Kontiki

2008-01-20 12:03 . 2008-01-20 12:03 <DIR> d-------- C:&#092;Program Files&#092;Disk Space Visualizer

2008-01-20 11:34 . 2002-12-29 01:14 81,920 --a------ C:&#092;WINDOWS&#092;system32&#092;Startup.cpl

2008-01-17 20:07 . 2008-01-17 20:07 <DIR> d-------- C:&#092;Program Files&#092;Windows Defender

2008-01-16 00:05 . 2008-01-16 00:06 <DIR> d-------- C:&#092;WINDOWS&#092;ERUNT

2008-01-13 17:53 . 2008-01-13 17:53 <DIR> d-------- C:&#092;Program Files&#092;Java

2008-01-13 17:53 . 2008-01-13 17:53 <DIR> d-------- C:&#092;Program Files&#092;Common Files&#092;Java

2008-01-13 17:53 . 2007-09-24 23:31 69,632 --a------ C:&#092;WINDOWS&#092;system32&#092;javacpl.cpl

2007-12-28 00:46 . 2007-12-28 14:54 20 --a------ C:&#092;WINDOWS&#092;system32&#092;Rmvirus.lst

2007-12-27 13:17 . 2005-09-23 08:29 626,688 --a------ C:&#092;WINDOWS&#092;system32&#092;msvcr80.dll

2007-12-25 18:11 . 2005-05-26 15:34 2,297,552 --a------ C:&#092;WINDOWS&#092;system32&#092;d3dx9_26.dll

2007-12-25 17:55 . 2007-12-25 17:55 <DIR> d-------- C:&#092;Program Files&#092;Microsoft Games



.

(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))

.

2008-01-20 21:46 --------- d-----w C:&#092;Program Files&#092;Microsoft IntelliPoint

2008-01-20 12:30 --------- d--h--w C:&#092;Program Files&#092;InstallShield Installation Information

2008-01-20 12:27 --------- d-----w C:&#092;Program Files&#092;Common Files&#092;Adobe

2008-01-20 12:13 --------- d-----w C:&#092;Program Files&#092;DivX

2008-01-17 23:01 --------- d-----w C:&#092;Program Files&#092;Common Files&#092;Real

2008-01-13 17:30 --------- d-----w C:&#092;Program Files&#092;REGSHAVE

2008-01-13 17:30 --------- d-----w C:&#092;Program Files&#092;QuickTime

2008-01-06 20:54 --------- d-----w C:&#092;Program Files&#092;Maxis

2008-01-06 19:23 158,208 ----a-w C:&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;bi naries&#092;msconfig.exe

2008-01-05 23:31 150,528 -c--a-w C:&#092;WINDOWS&#092;pchealth&#092;UploadLB&#092;B inaries&#092;UploadM.exe

2008-01-05 20:26 9,728 -c--a-w C:&#092;WINDOWS&#092;inf&#092;unregpn.exe

2008-01-05 20:22 93,184 -c----r C:&#092;WINDOWS&#092;VIEW32.EXE

2008-01-05 20:22 86,016 -c--a-w C:&#092;WINDOWS&#092;unvise32qt.exe

2008-01-05 20:22 73,216 ----a-w C:&#092;WINDOWS&#092;ST6UNST.EXE

2008-01-05 20:22 45,568 ----a-w C:&#092;WINDOWS&#092;UniFish3.exe

2008-01-05 20:22 41,984 -c--a-w C:&#092;WINDOWS&#092;Ctregrun.exe

2008-01-05 20:22 33,280 -c--a-w C:&#092;WINDOWS&#092;DXTool.exe

2008-01-05 20:22 299,520 -c--a-w C:&#092;WINDOWS&#092;uninst.exe

2008-01-05 20:22 26,624 -c--a-w C:&#092;WINDOWS&#092;TBZoom.exe

2008-01-05 20:22 25,600 -c--a-w C:&#092;WINDOWS&#092;twunk_32.exe

2008-01-05 20:22 249,856 ----a-w C:&#092;WINDOWS&#092;Setup1.exe

2008-01-05 20:22 204,800 -c--a-w C:&#092;WINDOWS&#092;alcupd.exe

2008-01-05 20:22 2,058,752 -c--a-w C:&#092;WINDOWS&#092;QT32INST.EXE

2008-01-05 20:22 169,472 -c--a-w C:&#092;WINDOWS&#092;QTW32DEL.EXE

2008-01-05 20:22 165,888 -c--a-w C:&#092;WINDOWS&#092;CTDelLau.exe

2008-01-05 20:22 151,552 -c--a-w C:&#092;WINDOWS&#092;CTDEL.EXE

2008-01-05 20:22 15,360 -c--a-w C:&#092;WINDOWS&#092;TASKMAN.EXE

2008-01-05 20:22 107,008 -c--a-w C:&#092;WINDOWS&#092;PLAY32.EXE

2008-01-05 20:21 135,168 -c--a-w C:&#092;WINDOWS&#092;alcrmv.exe

2008-01-05 19:02 94,208 -c--a-w C:&#092;WINDOWS&#092;ScUnin.exe

2008-01-05 19:02 306,688 ----a-w C:&#092;WINDOWS&#092;IsUninst.exe

2008-01-05 19:02 --------- d-----w C:&#092;Program Files&#092;Railroad Tycoon II

2008-01-03 19:10 99,840 -c--a-w C:&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;bi naries&#092;HelpHost.exe

2008-01-03 19:10 743,936 ----a-w C:&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;bi naries&#092;HelpSvc.exe

2008-01-03 19:10 35,328 -c--a-w C:&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;bi naries&#092;notiflag.exe

2008-01-03 19:10 18,944 -c--a-w C:&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;bi naries&#092;HscUpd.exe

2008-01-03 19:10 158,208 ----a-w C:&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;bi naries&#092;MSConfig .exe

2008-01-03 19:05 98,304 -c--a-w C:&#092;WINDOWS&#092;system32&#092;verifier.exe

2008-01-03 19:05 8,704 -c--a-w C:&#092;WINDOWS&#092;system32&#092;wdfmgr.exe

2008-01-03 19:05 8,704 -c--a-w C:&#092;WINDOWS&#092;system32&#092;uwdf.exe

2008-01-03 19:05 77,824 -c--a-w C:&#092;WINDOWS&#092;system32&#092;usrmlnka.exe

2008-01-03 19:05 69,632 -c--a-w C:&#092;WINDOWS&#092;system32&#092;usrshuta.exe

2008-01-03 19:05 65,536 -c--a-w C:&#092;WINDOWS&#092;system32&#092;wextract.exe

2008-01-03 19:05 61,440 -c--a-w C:&#092;WINDOWS&#092;system32&#092;usrprbda.exe

2008-01-03 19:05 5,632 -c--a-w C:&#092;WINDOWS&#092;system32&#092;winver.exe

2008-01-03 19:05 5,632 ----a-w C:&#092;WINDOWS&#092;system32&#092;write.exe

2008-01-03 19:05 49,664 -c--a-w C:&#092;WINDOWS&#092;system32&#092;w32tm.exe

2008-01-03 19:05 47,104 -c--a-w C:&#092;WINDOWS&#092;system32&#092;WRKGADM.EXE

2008-01-03 19:05 33,792 -c--a-w C:&#092;WINDOWS&#092;system32&#092;vssadmin.exe

2008-01-03 19:05 32,256 -c--a-w C:&#092;WINDOWS&#092;system32&#092;wpabaln.exe

2008-01-03 19:05 30,720 -c--a-w C:&#092;WINDOWS&#092;system32&#092;xcopy.exe

2008-01-03 19:05 17,408 -c--a-w C:&#092;WINDOWS&#092;system32&#092;wpdshextautopla y.exe

2008-01-03 19:05 146,432 ----a-w C:&#092;WINDOWS&#092;system32&#092;WudfHost.exe

2008-01-03 19:05 13,824 -c--a-w C:&#092;WINDOWS&#092;system32&#092;wscntfy.exe

2008-01-03 19:05 119,808 ----a-w C:&#092;WINDOWS&#092;system32&#092;winmine.exe

2008-01-03 19:05 11,776 -c--a-w C:&#092;WINDOWS&#092;system32&#092;winmsd.exe

2008-01-03 19:00 9,216 -c--a-w C:&#092;WINDOWS&#092;system32&#092;subst.exe

2008-01-03 19:00 75,264 -c--a-w C:&#092;WINDOWS&#092;system32&#092;telnet.exe

2008-01-03 19:00 679,936 -c--a-w C:&#092;WINDOWS&#092;system32&#092;sstext3d.scr

2008-01-03 19:00 63,488 -c--a-w C:&#092;WINDOWS&#092;system32&#092;unam4ie.exe

2008-01-03 19:00 610,304 -c--a-w C:&#092;WINDOWS&#092;system32&#092;sspipes.scr

2008-01-03 19:00 51,200 -c--a-w C:&#092;WINDOWS&#092;system32&#092;syncapp.exe

2008-01-03 19:00 47,104 -c--a-w C:&#092;WINDOWS&#092;system32&#092;ssmypics.scr

2008-01-03 19:00 45,056 ----a-w C:&#092;WINDOWS&#092;system32&#092;UninstallBeetle .exe

2008-01-03 19:00 44,544 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tscupgrd.exe

2008-01-03 19:00 4,096 -c--a-w C:&#092;WINDOWS&#092;system32&#092;unlodctr.exe

2008-01-03 19:00 36,864 -c--a-w C:&#092;WINDOWS&#092;system32&#092;syskey.exe

2008-01-03 19:00 31,744 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tracert6.exe

2008-01-03 19:00 3,072 -c--a-w C:&#092;WINDOWS&#092;system32&#092;systray.exe

2008-01-03 19:00 20,992 -c--a-w C:&#092;WINDOWS&#092;system32&#092;ssmarque.scr

2008-01-03 19:00 19,456 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tcpsvcs.exe

2008-01-03 19:00 18,944 -c--a-w C:&#092;WINDOWS&#092;system32&#092;ssmyst.scr

2008-01-03 19:00 16,896 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tsshutdn.exe

2008-01-03 19:00 16,896 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tftp.exe

2008-01-03 19:00 16,384 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tskill.exe

2008-01-03 19:00 15,360 -c--a-w C:&#092;WINDOWS&#092;system32&#092;taskman.exe

2008-01-03 19:00 14,848 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tsdiscon.exe

2008-01-03 19:00 14,848 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tscon.exe

2008-01-03 19:00 14,848 -c--a-w C:&#092;WINDOWS&#092;system32&#092;stimon.exe

2008-01-03 19:00 14,336 -c--a-w C:&#092;WINDOWS&#092;system32&#092;ssstars.scr

2008-01-03 19:00 12,288 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tracert.exe

2008-01-03 19:00 12,288 -c--a-w C:&#092;WINDOWS&#092;system32&#092;tcmsetup.exe

2008-01-03 19:00 105,984 -c--a-w C:&#092;WINDOWS&#092;system32&#092;sysocmgr.exe

2008-01-03 18:59 9,728 -c--a-w C:&#092;WINDOWS&#092;system32&#092;sfc.exe

2008-01-03 18:59 9,728 -c--a-w C:&#092;WINDOWS&#092;system32&#092;reset.exe

2008-01-03 18:59 9,216 -c--a-w C:&#092;WINDOWS&#092;system32&#092;scrnsave.scr

2008-01-03 18:59 8,192 -c--a-w C:&#092;WINDOWS&#092;system32&#092;smbinst.exe

2008-01-03 18:59 77,824 -c--a-w C:&#092;WINDOWS&#092;system32&#092;shrpubw.exe

2008-01-03 18:59 77,312 -c--a-w C:&#092;WINDOWS&#092;system32&#092;sdbinst.exe

2008-01-03 18:59 77,312 -c--a-w C:&#092;WINDOWS&#092;system32&#092;rtcshare.exe

2008-01-03 18:59 704,512 -c--a-w C:&#092;WINDOWS&#092;system32&#092;ss3dfo.scr

2008-01-03 18:59 70,144 -c--a-w C:&#092;WINDOWS&#092;system32&#092;sigverif.exe

2008-01-03 18:59 7,168 -c--a-w C:&#092;WINDOWS&#092;system32&#092;recover.exe

2008-01-03 18:59 67,072 -c--a-w C:&#092;WINDOWS&#092;system32&#092;rdshost.exe

2008-01-03 18:59 62,464 -c--a-w C:&#092;WINDOWS&#092;system32&#092;rdpclip.exe

2008-01-03 18:59 56,832 ----a-w C:&#092;WINDOWS&#092;system32&#092;sol.exe

2008-01-03 18:59 538,624 ----a-w C:&#092;WINDOWS&#092;system32&#092;spider.exe

2008-01-03 18:59 50,176 -c--a-w C:&#092;WINDOWS&#092;system32&#092;reg.exe

2008-01-03 18:59 49,152 -c--a-w C:&#092;WINDOWS&#092;system32&#092;rsmui.exe

2008-01-03 18:59 49,152 -c--a-w C:&#092;WINDOWS&#092;system32&#092;rsm.exe

2007-06-17 07:43 44,544 --sha-w C:&#092;WINDOWS&#092;system32&#092;drwaton.exe

.

Código:
&#60;pre&#62;

----a-w********** 158,208 2008-01-03 19&#58;10&#58;52**C&#58;&#092;WINDOWS&#092;pchealth&#092;helpctr&#092;binaries&#092;MSConfig .exe
&#60;/pre&#62;




((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4



[HKEY_LOCAL_MACHINE&#092;SOFTWARE&#092;Microsoft&#0 92;Windows&#092;CurrentVersion&#092;Run]

"NvCplDaemon"="C:&#092;WINDOWS&#092;system32&#092; NvCpl.dll" [2006-06-01 17:22 7618560]

"nwiz"="nwiz.exe" [2008-01-03 16:02 1519616 C:&#092;WINDOWS&#092;system32&#092;nwiz.exe]

"NvMediaCenter"="C:&#092;WINDOWS&#092;system32&#09 2;NvMcTray.dll" [2006-06-01 17:22 86016]

"LVCOMSX"="C:&#092;WINDOWS&#092;system32&#092;LVCO MSX.EXE" [ ]

"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 12:00 110592 C:&#092;WINDOWS&#092;system32&#092;bthprops.cpl]

"Windows Defender"="C:&#092;Program Files&#092;Windows Defender&#092;MSASCui.exe" [2006-11-03 19:20 866584]



[HKEY_LOCAL_MACHINE&#092;system&#092;currentcontrol set&#092;control&#092;securityproviders]

SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, wowfx.dll



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^All Users^Start Menu^Programs^Startup^autorun.exe]

path=C:&#092;Documents and Settings&#092;All Users&#092;Start Menu&#092;Programs&#092;Startup&#092;autorun.exe

backup=C:&#092;WINDOWS&#092;pss&#092;autorun.exeCo mmon Startup



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]

path=C:&#092;Documents and Settings&#092;All Users&#092;Start Menu&#092;Programs&#092;Startup&#092;HP Digital Imaging Monitor.lnk

backup=C:&#092;WINDOWS&#092;pss&#092;HP Digital Imaging Monitor.lnkCommon Startup



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]

path=C:&#092;Documents and Settings&#092;All Users&#092;Start Menu&#092;Programs&#092;Startup&#092;Microsoft Find Fast.lnk

backup=C:&#092;WINDOWS&#092;pss&#092;Microsoft Find Fast.lnkCommon Startup



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^User^Start Menu^Programs^Startup^findfast .exe]

path=C:&#092;Documents and Settings&#092;User&#092;Start Menu&#092;Programs&#092;Startup&#092;findfast .exe

backup=C:&#092;WINDOWS&#092;pss&#092;findfast .exeStartup



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^User^Start Menu^Programs^Startup^findfast .exe]

path=C:&#092;Documents and Settings&#092;User&#092;Start Menu&#092;Programs&#092;Startup&#092;findfast .exe

backup=C:&#092;WINDOWS&#092;pss&#092;findfast .exeStartup



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^User^Start Menu^Programs^Startup^findfast.exe]

path=C:&#092;Documents and Settings&#092;User&#092;Start Menu&#092;Programs&#092;Startup&#092;findfast.exe

backup=C:&#092;WINDOWS&#092;pss&#092;findfast.exeS tartup



[HKLM&#092;~&#092;startupfolder&#092;C:^Documents and Settings^User^Start Menu^Programs^Startup^UDPixel.lnk]

path=C:&#092;Documents and Settings&#092;User&#092;Start Menu&#092;Programs&#092;Startup&#092;UDPixel.lnk

backup=C:&#092;WINDOWS&#092;pss&#092;UDPixel.lnkSt artup



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;4oD]

C:&#092;Program Files&#092;Kontiki&#092;KHost.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;avp]

C:&#092;WINDOWS&#092;TEMP&#092;win1F2E .exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;CaAvTray]

C:&#092;Program Files&#092;CA&#092;eTrust EZ Armor&#092;eTrust EZ Antivirus&#092;CAVTray.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;CAVRID]

C:&#092;Program Files&#092;CA&#092;eTrust EZ Armor&#092;eTrust EZ Antivirus&#092;CAVRID.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;CTDrive]

C:&#092;WINDOWS&#092;system32&#092;drvxes.dll



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;HP Component Manager]

C:&#092;Program Files&#092;HP&#092;hpcoretech&#092;hpcmpmgr.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;HP Software Update]

C:&#092;Program Files&#092;HP&#092;HP Software Update&#092;HPWuSchd2.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;HPHmon06]



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;HPHUPD06]



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;kdx]

C:&#092;Program Files&#092;Kontiki&#092;KHost.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;letqzsbm]

C:&#092;Program Files&#092;letqzsbm&#092;ponefefu.dll



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;Load]

C:&#092;WINDOWS&#092;system32&#092;jkkli.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;lsass]

C:&#092;WINDOWS&#092;lsass .exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;NapsterSh ell]

C:&#092;Program Files&#092;Napster&#092;napster.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;Printer]

C:&#092;WINDOWS&#092;system32&#092;printer.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;smgr]





[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;Spoolsv]

C:&#092;WINDOWS&#092;system32&#092;spoolvs.exe



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;WMC_AutoU pdate]



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;startupreg&#092;xanatkbc]

regsvr32 /u C:&#092;Documents and Settings&#092;All Users&#092;Application Data&#092;xanatkbc.dll



[HKEY_LOCAL_MACHINE&#092;software&#092;microsoft&#0 92;shared tools&#092;msconfig&#092;services]

"Spooler"=2 (0x2)



R1 CTSYN;Creative S/W Synth;C:&#092;WINDOWS&#092;system32&#092;drivers&# 092;CTSYN.SYS [1999-06-16 01:00]

S3 gel90xne;gel90xne;C:&#092;DOCUME~1&#092;User&#092; LOCALS~1&#092;Temp&#092;gel90xne.sys []

S4 avp ;avp ;"C:&#092;Program Files&#092;Kaspersky Lab&#092;Kaspersky Anti-Virus 7.0&#092;avp .exe" []

S4 avp ;avp ;"C:&#092;Program Files&#092;Kaspersky Lab&#092;Kaspersky Anti-Virus 7.0&#092;avp .exe" []



[HKEY_CURRENT_USER&#092;software&#092;microsoft&#09 2;windows&#092;currentversion&#092;explorer&#092;m ountpoints2&#092;E]

&#092;Shell&#092;AutoRun&#092;command - E:&#092;autorun.exe

&#092;Shell&#092;setup&#092;command - E:&#092;setup.exe



.

Contents of the &#39;Scheduled Tasks&#39; folder

"2008-01-17 00:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At1.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 09:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At10.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 10:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At11.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 11:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At12.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 12:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At13.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 13:00:02 C:&#092;WINDOWS&#092;Tasks&#092;At14.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 14:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At15.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 15:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At16.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-20 16:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At17.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-21 17:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At18.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-22 18:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At19.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-17 01:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At2.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-22 19:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At20.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-22 20:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At21.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-22 21:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At22.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-22 22:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At23.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-16 23:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At24.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-09 02:00:01 C:&#092;WINDOWS&#092;Tasks&#092;At3.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-09 03:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At4.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2007-12-29 04:01:30 C:&#092;WINDOWS&#092;Tasks&#092;At5.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2007-09-30 04:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At6.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2007-09-30 05:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At7.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2007-11-28 07:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At8.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2007-10-23 07:00:00 C:&#092;WINDOWS&#092;Tasks&#092;At9.job"

- C:&#092;WINDOWS&#092;system32&#92;&#48;KK8DX4O.ex e

"2008-01-23 15:24:56 C:&#092;WINDOWS&#092;Tasks&#092;MP Scheduled Scan.job"

- C:&#092;Program Files&#092;Windows Defender&#092;MpCmdRun.exe

.

************************************************** ************************



catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-23 15:37:08

Windows 5.1.2600 Service Pack 2 NTFS



scanning hidden processes ...



scanning hidden autostart entries ...



scanning hidden files ...



scan completed successfully

hidden files: 0



************************************************** ************************

.


ayudaaaa&#33;&#33;&#33;&#33;&#33;
  #2  
Antiguo 23-feb-2008, 13:53
francisco.javier
Guest
 
Mensajes: n/a
Predeterminado

Descarga el programa HijackThis 2.0.2
y colócalo en una carpeta propia para el HijackThis (por ejemplo una carpeta C:&#092;HijackThis&#092. Ejecútalo y presiona el botón "Do a system scan and save a logfile"; el programa realizará el escaneo e inmediatamente generará el Log, sólo te pedira el nombre del archivo y su ubicación, puedes simplemente guardarlo así como está. Se abrirá el Bloc de Notas, copia todo el contenido y pégalo como respuesta a este tema.
Una vez descargado, da doble click en el icono del HijackThis.exe.
Primero da click en el botón "Config", y aparecerán 7 opciones . Fíjate que no estén tildadas la primera ( “Mark everything found for fixing alter scan”) y la última (“Run Hijack This scan at startup and show it ítems are fond”).Luego presiona "Back"
Para empezar el escaneo de posibles hijackers, clickea en el botón "Scan". Se te presentará una lista con todos los elementos encontrados por el programa .

y sube su log, por cierto no pases el combofix sino te lo manda pasar nadie, ya que es una herramineta muy potente pero elimina cosas tambien de windows, asi que empecemos por partes, vale
Tema Cerrado

Marcadores

Etiquetas
combofix, creo, infectada, lenta


Herramientas
Desplegado

Normas de Publicación
No puedes crear nuevos temas
No puedes responder temas
No puedes subir archivos adjuntos
No puedes editar tus mensajes

Los Códigos BB están Activado
Las Caritas están Activado
[IMG] está Activado
El Código HTML está Desactivado
Trackbacks are Desactivado
Pingbacks are Desactivado
Refbacks are Desactivado

Ir al Foro

Temas Similares

Tema Autor Foro Respuestas Último mensaje
Ya está el Log Sikamikaniko Logs de HijackThis 7 02-sep-2008 21:07
Esta muy lenta mi PC aries65 Logs de HijackThis 9 01-jun-2008 18:24
Microsoft liberara una version de prueba de Windows 7 esta semana marga Noticias 0 26-may-2008 19:51
Windows Vista SP1… ya está disponible desde las actualizaciones automáticas marga Noticias 0 24-abr-2008 16:19
Aqui esta mi log CapoCañonero Logs de HijackThis 1 31-dic-2007 15:49


La franja horaria es GMT +2. Ahora son las 05:08.