Hola, tengo un problema que no logro resolver. He leído mucho en el foro y he seguido muchas de las instrucciones al pie de la letra. Después de mucho bucear y testear el equipo con Ccleaner, Nod32 4, Tojan Killer, Malwarebytes Anti-Malware, HiJackthis, etc... al final di con ComboFix y aquí les traigo el log. Espero de corazón que puedan arrojar algo de luz sobre mi problema ya que no se qué más hacer. Les agradezco de antemano la ayuda para no tener que formatear.
ComboFix 12-02-13.01 - Bita 18/02/2012 22:47:41.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.2013.1285 [GMT 1:00]
Running from: h:\documents and settings\Bita\Escritorio\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
.
.
- REDUCED FUNCTIONALITY MODE -
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
h:\windows\assembly\GAC_MSIL\desktop.ini
h:\windows\isRS-000.tmp
h:\windows\system32\bcm42rly.dll
h:\windows\system32\dds_log_trash.cmd
.
.
((((((((((((((((((((((((( Files Created from 2012-01-18 to 2012-02-18 )))))))))))))))))))))))))))))))
.
.
2012-02-18 21:06 . 2012-02-18 21:06 -------- d-----w- h:\archivos de programa\CCleaner
2012-02-18 20:56 . 2012-02-18 20:56 -------- d-----w- h:\documents and settings\LocalService\Configuración local\Datos de programa\ESET
2012-02-18 20:37 . 2012-02-18 20:37 -------- d-----w- h:\archivos de programa\Archivos comunes\Java
2012-02-18 20:36 . 2012-02-16 14:58 134104 ----a-w- h:\archivos de programa\Mozilla Firefox\components\browsercomps.dll
2012-02-18 20:36 . 2012-02-16 14:58 97240 ----a-w- h:\archivos de programa\Mozilla Firefox\libEGL.dll
2012-02-18 20:36 . 2012-02-16 14:58 801752 ----a-w- h:\archivos de programa\Mozilla Firefox\mozsqlite3.dll
2012-02-18 20:36 . 2012-02-16 14:58 45016 ----a-w- h:\archivos de programa\Mozilla Firefox\mozutils.dll
2012-02-18 20:36 . 2012-02-16 14:58 437208 ----a-w- h:\archivos de programa\Mozilla Firefox\libGLESv2.dll
2012-02-18 20:36 . 2012-02-16 14:58 1911768 ----a-w- h:\archivos de programa\Mozilla Firefox\mozjs.dll
2012-02-18 20:36 . 2012-02-16 14:58 15832 ----a-w- h:\archivos de programa\Mozilla Firefox\mozalloc.dll
2012-02-18 20:36 . 2012-02-16 10:42 2106216 ----a-w- h:\archivos de programa\Mozilla Firefox\D3DCompiler_43.dll
2012-02-18 20:36 . 2012-02-16 10:42 1998168 ----a-w- h:\archivos de programa\Mozilla Firefox\d3dx9_43.dll
2012-02-18 20:36 . 2012-02-16 10:41 626688 ----a-w- h:\archivos de programa\Mozilla Firefox\msvcr80.dll
2012-02-18 20:36 . 2012-02-16 10:41 548864 ----a-w- h:\archivos de programa\Mozilla Firefox\msvcp80.dll
2012-02-18 20:36 . 2012-02-16 10:41 479232 ----a-w- h:\archivos de programa\Mozilla Firefox\msvcm80.dll
2012-02-18 19:59 . 2012-02-18 20:22 -------- d-----w- h:\archivos de programa\GridinSoft Trojan Killer
2012-02-18 19:38 . 2012-02-18 19:38 -------- d-----w- h:\documents and settings\Administrador
2012-02-18 19:35 . 2012-02-18 21:13 -------- d-----w- h:\windows\system32\LogFiles
2012-02-18 18:43 . 2012-02-18 18:43 -------- d-----w- h:\documents and settings\Bita\Configuración local\Datos de programa\ESET
2012-02-18 18:21 . 2012-02-18 18:21 -------- d-----w- h:\documents and settings\All Users\Datos de programa\ESET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2012-02-18 21:23 . 2011-02-01 20:48 40776 ----a-w- h:\windows\system32\drivers\mbamswissarmy.sys
2012-02-18 20:37 . 2011-01-31 23:09 73728 ----a-w- h:\windows\system32\javacpl.cpl
2012-02-18 20:37 . 2011-01-31 23:09 472808 ----a-w- h:\windows\system32\deployJava1.dll
2012-01-04 14:28 . 2012-01-04 14:28 16128 ----a-w- h:\windows\system32\drivers\gtkdrv.sys
2011-12-10 14:24 . 2011-02-01 20:48 20464 ----a-w- h:\windows\system32\drivers\mbam.sys
2011-11-23 10:11 . 2011-11-23 10:11 404640 ----a-w- h:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-16 14:58 . 2012-02-18 20:36 134104 ----a-w- h:\archivos de programa\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\atapi.sys
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . h:\windows\system32\drivers\atapi.sys
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . h:\windows\system32\ReinstallBackups\0004\DriverFi les\i386\atapi.sys
[7] 2008-04-13 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . h:\windows\system32\ReinstallBackups\0005\DriverFi les\i386\atapi.sys
.
[7] 2008-04-14 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\asyncmac.sys
[7] 2008-04-14 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . h:\windows\system32\drivers\asyncmac.sys
.
[7] 2008-04-14 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . h:\windows\system32\dllcache\beep.sys
[7] 2008-04-14 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . h:\windows\system32\drivers\beep.sys
.
[7] 2008-04-14 . 188DDD286BC0DAEA6984858C6A4D7BBF . 25088 . . [5.1.2600.5512] . . h:\windows\system32\drivers\kbdclass.sys
.
[7] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\ndis.sys
[7] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . h:\windows\system32\drivers\ndis.sys
.
[7] 2008-04-14 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\ntfs.sys
[7] 2008-04-14 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . h:\windows\system32\drivers\ntfs.sys
.
[7] 2008-04-14 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . h:\windows\system32\dllcache\null.sys
[7] 2008-04-14 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . h:\windows\system32\drivers\null.sys
.
[7] 2008-04-14 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\tcpip.sys
[7] 2008-04-14 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . h:\windows\system32\drivers\tcpip.sys
.
[7] 2008-04-14 . E28818BD591F8AF8FBE9897472B9665E . 77824 . . [5.1.2600.5512] . . h:\windows\system32\browser.dll
[7] 2008-04-14 . E28818BD591F8AF8FBE9897472B9665E . 77824 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\browser.dll
.
[7] 2008-04-14 . 671ACA589DA3733FAC878A751C5BF0ED . 13312 . . [5.1.2600.5512] . . h:\windows\system32\lsass.exe
[7] 2008-04-14 . 671ACA589DA3733FAC878A751C5BF0ED . 13312 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\lsass.exe
.
[7] 2008-04-14 . A48884C9359EE9F1FC8F3F0D93FB1D95 . 198144 . . [5.1.2600.5512] . . h:\windows\system32\netman.dll
[7] 2008-04-14 . A48884C9359EE9F1FC8F3F0D93FB1D95 . 198144 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\netman.dll
.
[7] 2008-04-14 12:00 . 93F4E612C695E81512110956454E6E25 . 837120 . . [2001.12.4414.700] . . h:\windows\system32\comres.dll
[7] 2008-04-14 12:00 . 93F4E612C695E81512110956454E6E25 . 837120 . . [2001.12.4414.700] . . h:\windows\system32\dllcache\comres.dll
.
[7] 2008-04-14 . 8EE9639C01B92490E09638CAA1B16C3C . 409088 . . [6.7.2600.5512] . . h:\windows\system32\qmgr.dll
[7] 2008-04-14 . 8EE9639C01B92490E09638CAA1B16C3C . 409088 . . [6.7.2600.5512] . . h:\windows\system32\dllcache\qmgr.dll
.
[7] 2008-04-14 . 53D02EFFA72CA5C57687BEE20610ABA6 . 399360 . . [5.1.2600.5512] . . h:\windows\system32\rpcss.dll
[7] 2008-04-14 . 53D02EFFA72CA5C57687BEE20610ABA6 . 399360 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\rpcss.dll
.
[7] 2008-04-14 . D658A8C2FC7B2AD53D1259741A09EE04 . 109056 . . [5.1.2600.5512] . . h:\windows\system32\services.exe
[7] 2008-04-14 . D658A8C2FC7B2AD53D1259741A09EE04 . 109056 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\services.exe
.
[7] 2008-04-14 . CDD2DC6AE65084481E723E746C20539A . 57856 . . [5.1.2600.5512] . . h:\windows\system32\spoolsv.exe
[7] 2008-04-14 . CDD2DC6AE65084481E723E746C20539A . 57856 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\spoolsv.exe
.
[7] 2008-04-14 . 213C80D912880BBF04453D09FFCCB28C . 510976 . . [5.1.2600.5512] . . h:\windows\system32\winlogon.exe
[7] 2008-04-14 . 213C80D912880BBF04453D09FFCCB28C . 510976 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\winlogon.exe
.
[7] 2008-04-14 . 846908F3A9F03F85E78103ED9D87B441 . 112128 . . [5.4.3790.5512] . . h:\windows\system32\wuauclt.exe
[7] 2008-04-14 . 846908F3A9F03F85E78103ED9D87B441 . 112128 . . [5.4.3790.5512] . . h:\windows\system32\dllcache\wuauclt.exe
.
[7] 2008-04-14 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\ipsec.sys
[7] 2008-04-14 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . h:\windows\system32\drivers\ipsec.sys
.
[7] 2008-04-14 . 618A4C7A7C0CA86DA884C8C0FACAD8C2 . 617472 . . [5.82] . . h:\windows\system32\comctl32.dll
[7] 2008-04-14 . 618A4C7A7C0CA86DA884C8C0FACAD8C2 . 617472 . . [5.82] . . h:\windows\system32\dllcache\comctl32.dll
[7] 2008-04-14 . AEF3D788DBF40C7C4D204EA45EB0C505 . 921088 . . [6.0] . . h:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
[7] 2008-04-14 . 08D17A982CD6191B34D1B8C8A2E694B6 . 1054208 . . [6.0] . . h:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
.
[7] 2008-04-14 . E423C9C1946C656E0E4840210A0A8681 . 62464 . . [5.1.2600.5512] . . h:\windows\system32\cryptsvc.dll
[7] 2008-04-14 . E423C9C1946C656E0E4840210A0A8681 . 62464 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\cryptsvc.dll
.
[7] 2008-04-14 12:00 . 76ABF3BB5A6D684641EC92B28240811D . 246272 . . [2001.12.4414.701] . . h:\windows\system32\es.dll
[7] 2008-04-14 12:00 . 76ABF3BB5A6D684641EC92B28240811D . 246272 . . [2001.12.4414.701] . . h:\windows\system32\dllcache\es.dll
.
[7] 2008-04-14 . 95DF6A7520912B1040F748A287EA382A . 110080 . . [5.1.2600.5512] . . h:\windows\system32\imm32.dll
[7] 2008-04-14 . 95DF6A7520912B1040F748A287EA382A . 110080 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\imm32.dll
.
[7] 2008-04-14 . F43FE49CF77EC1CEF9DB9E67BDDB970F . 1042944 . . [5.1.2600.5512] . . h:\windows\system32\kernel32.dll
[7] 2008-04-14 . F43FE49CF77EC1CEF9DB9E67BDDB970F . 1042944 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\kernel32.dll
.
[7] 2008-04-14 . FB67F1E092AB9967D0CD17300D751874 . 19968 . . [5.1.2600.5512] . . h:\windows\system32\linkinfo.dll
[7] 2008-04-14 . FB67F1E092AB9967D0CD17300D751874 . 19968 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\linkinfo.dll
.
[7] 2008-04-14 . 87F15A88AA3376B48F75D7D176B312A0 . 22016 . . [5.1.2600.5512] . . h:\windows\system32\lpk.dll
[7] 2008-04-14 . 87F15A88AA3376B48F75D7D176B312A0 . 22016 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\lpk.dll
.
[7] 2008-06-02 . C6EC2493346ED8888A549F59210A8ED3 . 3578368 . . [7.00.5730.13] . . h:\windows\system32\mshtml.dll
[7] 2008-06-02 . C6EC2493346ED8888A549F59210A8ED3 . 3578368 . . [7.00.5730.13] . . h:\windows\system32\dllcache\mshtml.dll
.
[7] 2008-04-14 . 0F021B29E0C2C9D897258399FB2149CD . 343040 . . [7.0.2600.5512] . . h:\windows\system32\msvcrt.dll
[7] 2008-04-14 . 0F021B29E0C2C9D897258399FB2149CD . 343040 . . [7.0.2600.5512] . . h:\windows\system32\dllcache\msvcrt.dll
[7] 2008-04-14 . 4200BE3808F6406DBE45A7B88DAE5035 . 322560 . . [7.0.2600.0] . . h:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusR untime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcrt.dll
[7] 2008-04-14 . B1CB86D70023988360DA136B317D8546 . 343040 . . [7.0.2600.5512] . . h:\windows\WinSxS\x86_Microsoft.Windows.CPlusPlusR untime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll
.
[7] 2008-04-14 . AD893C9D3A09081D55A4BDFBC66AD592 . 248320 . . [5.1.2600.5512] . . h:\windows\system32\mswsock.dll
[7] 2008-04-14 . AD893C9D3A09081D55A4BDFBC66AD592 . 248320 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\mswsock.dll
.
[7] 2008-04-14 . CD2BBB52DFAAB666B812A51B1E96F2A0 . 407040 . . [5.1.2600.5512] . . h:\windows\system32\netlogon.dll
[7] 2008-04-14 . CD2BBB52DFAAB666B812A51B1E96F2A0 . 407040 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\netlogon.dll
.
[7] 2008-04-14 . 56DE6FD410B277C4345D7A2C3414DB64 . 17408 . . [6.00.2900.5512] . . h:\windows\system32\powrprof.dll
[7] 2008-04-14 . 56DE6FD410B277C4345D7A2C3414DB64 . 17408 . . [6.00.2900.5512] . . h:\windows\system32\dllcache\powrprof.dll
.
[7] 2008-04-14 . B6BE3C96CD33336A551DB3F2299A8E69 . 185856 . . [5.1.2600.5512] . . h:\windows\system32\scecli.dll
[7] 2008-04-14 . B6BE3C96CD33336A551DB3F2299A8E69 . 185856 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\scecli.dll
.
[7] 2008-04-14 . D5AC9FA63EBEFD7AACCB14BA0DB1BAC3 . 5120 . . [5.1.2600.5512] . . h:\windows\system32\sfc.dll
[7] 2008-04-14 . D5AC9FA63EBEFD7AACCB14BA0DB1BAC3 . 5120 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\sfc.dll
.
[7] 2008-04-14 . 4F2340F0BD5B6365C38E74DD391919A8 . 14336 . . [5.1.2600.5512] . . h:\windows\system32\svchost.exe
[7] 2008-04-14 . 4F2340F0BD5B6365C38E74DD391919A8 . 14336 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\svchost.exe
.
[7] 2008-04-14 . 04A5B8EA326951DB27DF60A14F2999FF . 249856 . . [5.1.2600.5512] . . h:\windows\system32\tapisrv.dll
[7] 2008-04-14 . 04A5B8EA326951DB27DF60A14F2999FF . 249856 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\tapisrv.dll
.
[7] 2008-04-14 . DA8898129E0075C7DE4DEE457514A73C . 579584 . . [5.1.2600.5512] . . h:\windows\system32\user32.dll
[7] 2008-04-14 . DA8898129E0075C7DE4DEE457514A73C . 579584 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\user32.dll
.
[7] 2008-04-14 . F5B8745B9A90EAF17E30C0574E049AA3 . 26624 . . [5.1.2600.5512] . . h:\windows\system32\userinit.exe
[7] 2008-04-14 . F5B8745B9A90EAF17E30C0574E049AA3 . 26624 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\userinit.exe
.
[7] 2008-06-02 . A4A0FC92358F39538A6494C42EF99FE9 . 818688 . . [7.00.5730.13] . . h:\windows\system32\wininet.dll
[7] 2008-06-02 . A4A0FC92358F39538A6494C42EF99FE9 . 818688 . . [7.00.5730.13] . . h:\windows\system32\dllcache\wininet.dll
.
[7] 2008-04-14 . 22DB5B3DA7005C6472D35BEF3FFDA5EC . 82432 . . [5.1.2600.5512] . . h:\windows\system32\ws2_32.dll
[7] 2008-04-14 . 22DB5B3DA7005C6472D35BEF3FFDA5EC . 82432 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\ws2_32.dll
.
[7] 2008-04-14 . F7EE4BBFB48437EDC6F7F061DE1E8F2F . 19968 . . [5.1.2600.5512] . . h:\windows\system32\ws2help.dll
[7] 2008-04-14 . F7EE4BBFB48437EDC6F7F061DE1E8F2F . 19968 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\ws2help.dll
.
[7] 2008-04-14 . 7522F548A84ABAD8FA516DE5AB3931EF . 1036288 . . [6.00.2900.5512] . . h:\windows\explorer.exe
[7] 2008-04-14 . 7522F548A84ABAD8FA516DE5AB3931EF . 1036288 . . [6.00.2900.5512] . . h:\windows\system32\dllcache\explorer.exe
.
[7] 2008-04-14 . F4B9F9AA2F72FAD20D09C3E3FF2BE224 . 152064 . . [5.1.2600.5512] . . h:\windows\regedit.exe
[7] 2008-04-14 . F4B9F9AA2F72FAD20D09C3E3FF2BE224 . 152064 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\regedit.exe
.
[7] 2008-04-14 . 463D57BF9FE5871208FF99399360A57D . 1287168 . . [5.1.2600.5512] . . h:\windows\system32\ole32.dll
[7] 2008-04-14 . 463D57BF9FE5871208FF99399360A57D . 1287168 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\ole32.dll
.
[7] 2008-04-14 . D2ABEB6AF76DA414D1FFF8B409F00635 . 406016 . . [1.0420.2600.5512] . . h:\windows\system32\usp10.dll
[7] 2008-04-14 . D2ABEB6AF76DA414D1FFF8B409F00635 . 406016 . . [1.0420.2600.5512] . . h:\windows\system32\dllcache\usp10.dll
.
[7] 2008-04-14 . D9A84134776399F6BD244BC456076575 . 4096 . . [5.3.2600.5512] . . h:\windows\system32\ksuser.dll
[7] 2008-04-14 . D9A84134776399F6BD244BC456076575 . 4096 . . [5.3.2600.5512] . . h:\windows\system32\dllcache\ksuser.dll
.
[7] 2008-04-14 . DAAE1CB1B1875B760496E7D3336DA1AD . 15360 . . [5.1.2600.5512] . . h:\windows\system32\ctfmon.exe
[7] 2008-04-14 . DAAE1CB1B1875B760496E7D3336DA1AD . 15360 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\ctfmon.exe
.
[7] 2008-04-14 . CA70EDBF32032EA53F114CB930741CB5 . 135168 . . [6.00.2900.5512] . . h:\windows\system32\shsvcs.dll
[7] 2008-04-14 . CA70EDBF32032EA53F114CB930741CB5 . 135168 . . [6.00.2900.5512] . . h:\windows\system32\dllcache\shsvcs.dll
.
[7] 2008-04-14 . 0F30EEC6013FCF76693405EC4A7DF899 . 171520 . . [5.1.2600.5512] . . h:\windows\system32\srsvc.dll
[7] 2008-04-14 . 0F30EEC6013FCF76693405EC4A7DF899 . 171520 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\srsvc.dll
.
[7] 2008-04-14 . B2718EC9DC738E915D4177498E92BC4D . 13824 . . [5.1.2600.5512] . . h:\windows\system32\wscntfy.exe
[7] 2008-04-14 . B2718EC9DC738E915D4177498E92BC4D . 13824 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\wscntfy.exe
.
[7] 2008-04-14 . 14FDADCF05A37582399DAF1DA1DE1C7B . 129024 . . [5.1.2600.5512] . . h:\windows\system32\xmlprov.dll
[7] 2008-04-14 . 14FDADCF05A37582399DAF1DA1DE1C7B . 129024 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\xmlprov.dll
.
[7] 2008-04-14 . 2744C713F0217BD8FFD13E2EF731371C . 56320 . . [5.1.2600.5512] . . h:\windows\system32\eventlog.dll
[7] 2008-04-14 . 2744C713F0217BD8FFD13E2EF731371C . 56320 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\eventlog.dll
.
[-] 2008-06-02 . A984FD70323F1BADC33C170F60DBD5F6 . 1572352 . . [5.1.2600.5512] . . h:\windows\system32\sfcfiles.dll
.
[7] 2008-04-14 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\ipsec.sys
[7] 2008-04-14 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] . . h:\windows\system32\drivers\ipsec.sys
.
[7] 2008-04-14 . E424F05B07AC4357DC08D06218D76C7C . 59904 . . [5.1.2600.5512] . . h:\windows\system32\regsvc.dll
[7] 2008-04-14 . E424F05B07AC4357DC08D06218D76C7C . 59904 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\regsvc.dll
.
[7] 2008-04-14 . 51BE25C404D3DD344C6079DE715E4977 . 193536 . . [5.1.2600.5512] . . h:\windows\system32\schedsvc.dll
[7] 2008-04-14 . 51BE25C404D3DD344C6079DE715E4977 . 193536 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\schedsvc.dll
.
[7] 2008-04-14 . B622A432EF02895DE4AA38AC8B85FA4C . 71680 . . [5.1.2600.5512] . . h:\windows\system32\ssdpsrv.dll
[7] 2008-04-14 . B622A432EF02895DE4AA38AC8B85FA4C . 71680 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\ssdpsrv.dll
.
[7] 2008-04-14 . 288B20D56D5F0EC4BCC77FBFA5A81740 . 296960 . . [5.1.2600.5512] . . h:\windows\system32\termsrv.dll
[7] 2008-04-14 . 288B20D56D5F0EC4BCC77FBFA5A81740 . 296960 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\termsrv.dll
.
[7] 2008-04-14 . 54B34DA91EAF52A8EAC654CED8977980 . 347136 . . [5.1.2600.5512] . . h:\windows\system32\hnetcfg.dll
[7] 2008-04-14 . 54B34DA91EAF52A8EAC654CED8977980 . 347136 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\hnetcfg.dll
.
[7] 2008-04-14 . 30CD42BFCDAFEFE8567B9E527DD3AE08 . 175104 . . [5.1.2600.5512] . . h:\windows\system32\appmgmts.dll
[7] 2008-04-14 . 30CD42BFCDAFEFE8567B9E527DD3AE08 . 175104 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\appmgmts.dll
.
[7] 2008-04-14 . 1C905333C0B9F3D7C68DDF25E54B00F9 . 12032 . . [5.1.2600.0] . . h:\windows\system32\drivers\acpiec.sys
.
[7] 2008-04-13 21:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . h:\windows\system32\dllcache\aec.sys
[7] 2008-04-13 21:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . h:\windows\system32\drivers\aec.sys
.
[7] 2008-04-14 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\ip6fw.sys
[7] 2008-04-14 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . h:\windows\system32\drivers\ip6fw.sys
.
[7] 2008-04-14 12:00 . 27415CEEB58C8C2F92AFF8CFE2517A3C . 927504 . . [4.1.0.61] . . h:\windows\system32\mfc40u.dll
[7] 2008-04-14 12:00 . 27415CEEB58C8C2F92AFF8CFE2517A3C . 927504 . . [4.1.0.61] . . h:\windows\system32\dllcache\mfc40u.dll
.
[7] 2008-04-14 . 047E70B04B288439245DDC8DD1A31982 . 33792 . . [5.1.2600.5512] . . h:\windows\system32\msgsvc.dll
[7] 2008-04-14 . 047E70B04B288439245DDC8DD1A31982 . 33792 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\msgsvc.dll
.
[7] 2008-06-02 04:18 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . h:\windows\system32\mspmsnsv.dll
[7] 2008-06-02 04:18 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . h:\windows\system32\dllcache\mspmsnsv.dll
.
[7] 2008-04-14 . B4604169BB187939CAE61D62B41E85E0 . 2026496 . . [5.1.2600.5512] . . h:\windows\system32\ntkrnlpa.exe
.
[7] 2008-04-14 12:00 . D60C40D71A4D874C903255E4827AFA0C . 437760 . . [5.1.2400.5512] . . h:\windows\system32\ntmssvc.dll
[7] 2008-04-14 12:00 . D60C40D71A4D874C903255E4827AFA0C . 437760 . . [5.1.2400.5512] . . h:\windows\system32\dllcache\ntmssvc.dll
.
[7] 2008-04-14 . 7594203F459ABDB5FE53C08D6B1BD53B . 186368 . . [5.1.2600.5512] . . h:\windows\system32\upnphost.dll
[7] 2008-04-14 . 7594203F459ABDB5FE53C08D6B1BD53B . 186368 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\upnphost.dll
.
[7] 2008-04-14 . 9EF059A2C76BCE8DB9B0DD95EFE23A48 . 367616 . . [5.3.2600.5512] . . h:\windows\system32\dsound.dll
[7] 2008-04-14 . 9EF059A2C76BCE8DB9B0DD95EFE23A48 . 367616 . . [5.3.2600.5512] . . h:\windows\system32\dllcache\dsound.dll
.
[7] 2008-04-14 . AE5DD931EFAB3687BA4DF0671F4CE078 . 1689088 . . [5.03.2600.5512] . . h:\windows\system32\d3d9.dll
[7] 2008-04-14 . AE5DD931EFAB3687BA4DF0671F4CE078 . 1689088 . . [5.03.2600.5512] . . h:\windows\system32\dllcache\d3d9.dll
.
[7] 2008-04-14 . 28D0D87445F4ADD6614155EC13F042DD . 279552 . . [5.03.2600.5512] . . h:\windows\system32\ddraw.dll
[7] 2008-04-14 . 28D0D87445F4ADD6614155EC13F042DD . 279552 . . [5.03.2600.5512] . . h:\windows\system32\dllcache\ddraw.dll
.
[7] 2008-04-14 12:00 . F71CB6064DFC10DFB767B537BFA33D61 . 84992 . . [5.1.2600.5512] . . h:\windows\system32\olepro32.dll
[7] 2008-04-14 12:00 . F71CB6064DFC10DFB767B537BFA33D61 . 84992 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\olepro32.dll
.
[7] 2008-04-14 . 91C2A139745F2AF17E4685A1E54B4FDA . 41984 . . [5.1.2600.5512] . . h:\windows\system32\perfctrs.dll
[7] 2008-04-14 . 91C2A139745F2AF17E4685A1E54B4FDA . 41984 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\perfctrs.dll
.
[7] 2008-04-14 . F4968D88123785BCF95A31E0225C5592 . 18944 . . [5.1.2600.5512] . . h:\windows\system32\version.dll
[7] 2008-04-14 . F4968D88123785BCF95A31E0225C5592 . 18944 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\version.dll
.
[7] 2008-06-02 . DE49B348A18369B4626FBA1D49B07FB4 . 622080 . . [7.00.5730.13] . . h:\windows\system32\dllcache\iexplore.exe
.
.
[7] 2008-04-14 . 5865859247703A0E7211267AB92A02B7 . 2147840 . . [5.1.2600.5512] . . h:\windows\system32\ntoskrnl.exe
.
[7] 2008-04-14 . 0F30EEC6013FCF76693405EC4A7DF899 . 171520 . . [5.1.2600.5512] . . h:\windows\system32\srsvc.dll
[7] 2008-04-14 . 0F30EEC6013FCF76693405EC4A7DF899 . 171520 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\srsvc.dll
.
[7] 2008-04-14 . C71CFACDBFADD819736F61F5738BDDC1 . 177152 . . [5.1.2600.5512] . . h:\windows\system32\w32time.dll
[7] 2008-04-14 . C71CFACDBFADD819736F61F5738BDDC1 . 177152 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\w32time.dll
.
[7] 2008-04-14 . 7226422C95FDF8AA6092EE964912B0DF . 334336 . . [5.1.2600.5512] . . h:\windows\system32\wiaservc.dll
[7] 2008-04-14 . 7226422C95FDF8AA6092EE964912B0DF . 334336 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\wiaservc.dll
.
[7] 2008-04-14 . D94FF77931D467AC3ED916F767FA7E1F . 18944 . . [5.1.2600.5512] . . h:\windows\system32\midimap.dll
[7] 2008-04-14 . D94FF77931D467AC3ED916F767FA7E1F . 18944 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\midimap.dll
.
[7] 2008-04-14 . 73ECA7B33EB3F7262D92EA80B61708CD . 7680 . . [5.1.2600.5512] . . h:\windows\system32\rasadhlp.dll
[7] 2008-04-14 . 73ECA7B33EB3F7262D92EA80B61708CD . 7680 . . [5.1.2600.5512] . . h:\windows\system32\dllcache\rasadhlp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"egui"="h:\archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
"SunJavaUpdateSched"="h:\archivos de programa\Archivos comunes\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Malwarebytes' Anti-Malware"="h:\archivos de programa\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="h:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce]
"nltide_2"="shell32" [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Device Detector]
DevDetect.exe -autorun [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- h:\archivos de programa\Archivos comunes\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 ----a-w- h:\archivos de programa\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 12:00 15360 ----a-w- h:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON SX100 Series]
2008-02-05 06:00 188928 ----a-w- h:\windows\system32\spool\drivers\w32x86\3\E_FATIE DE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-03-04 11:53 136176 ----atw- h:\documents and settings\Bita\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2007-08-24 06:00 33648 ----a-w- h:\archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-12-18 06:28 178712 ----a-r- h:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-12-18 06:28 150040 ----a-r- h:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-06-24 15:06 1840424 ----a-w- h:\archivos de programa\Archivos comunes\Nero\Lib\NMIndexStoreSvr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-03-07 13:33 421160 ----a-w- h:\archivos de programa\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-01-13 13:53 460872 ----a-w- h:\archivos de programa\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2008-06-08 08:31 2221352 ----a-w- h:\archivos de programa\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2008-06-19 08:53 570664 ----a-w- h:\archivos de programa\Archivos comunes\Nero\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-12-18 06:28 150040 ----a-r- h:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- h:\archivos de programa\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2009-03-02 08:01 17530368 ----a-r- h:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-18 13:02 254696 ----a-w- h:\archivos de programa\Archivos comunes\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"h:\\Archivos de programa\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"h:\\Archivos de programa\\Microsoft Office\\Office12\\GROOVE.EXE"=
"h:\\Archivos de programa\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"h:\\Archivos de programa\\Spotify\\spotify.exe"=
"h:\\Archivos de programa\\Skype\\Phone\\Skype.exe"=
"h:\\Archivos de programa\\Skype\\Plugin Manager\\skypePM.exe"=
"h:\\Archivos de programa\\Bonjour\\mDNSResponder.exe"=
"h:\\Archivos de programa\\iTunes\\iTunes.exe"=
.
R1 ehdrv;ehdrv;h:\windows\system32\drivers\ehdrv.sys [06/02/2009 14:23 106208]
R1 epfwtdir;epfwtdir;h:\windows\system32\drivers\epfw tdir.sys [06/02/2009 14:24 93336]
R2 ekrn;ESET Service;h:\archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe [06/02/2009 14:23 727720]
R2 MBAMService;MBAMService;h:\archivos de programa\Malwarebytes' Anti-Malware\mbamservice.exe [01/02/2011 21:48 652360]
R3 MBAMProtector;MBAMProtector;h:\windows\system32\dr ivers\mbam.sys [01/02/2011 21:48 20464]
S2 .EsetTrialReset;Eset Trial Reset;h:\windows\system32\regedt32.exe [14/04/2008 13:00 3584]
S3 Ambfilt;Ambfilt;h:\windows\system32\drivers\Ambfil t.sys [31/01/2011 22:38 1684736]
S3 FXDrv32;FXDrv32;\??\g:\fxdrv32.sys --> g:\FXDrv32.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;h:\windows\system32\dr ivers\mbamswissarmy.sys [01/02/2011 21:48 40776]
S3 TrojanKillerDriver;GridinSoft Trojan Killer Driver;h:\windows\system32\drivers\gtkdrv.sys [04/01/2012 15:28 16128]
S3 WDC_SAM;WD SCSI Pass Thru driver;h:\windows\system32\drivers\wdcsam.sys [21/03/2011 0:25 11520]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
nv_agp
lvckap
nsvcip
EpmShd
swwd
roxupnprenderer
FET5X86V
.
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{bf066eba-52e8-11e0-8a52-e2770f2d4a12}]
\Shell\AutoRun\command - "I:\WD SmartWare.exe" autoplay=true
.
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{f9d45244-f0c1-11e0-8bd6-d3392e9fd636}]
\Shell\AutoRun\command - I:\wubi.exe --cdmenu
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.es/
uInternet Settings,ProxyOverride = *.local
IE: E&xportar a Microsoft Excel - h:\archiv~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: mswsock.dll
TCP: DhcpNameServer = 213.60.205.175 213.60.205.173 212.51.32.254
DPF: {B785FA3C-1DE9-4D20-8396-613C486FE95E} - hxxps://www2.agenciatributaria.gob.es/es13/h/cactivex.cab
FF - ProfilePath - h:\documents and settings\Bita\Datos de programa\Mozilla\Firefox\Profiles\sfhfkmr8.default \
FF - prefs.js: browser.startup.homepage - hxxp://www.google.es
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-Internet Security - h:\documents and settings\All Users\Datos de programa\isecurity.exe
MSConfigStartUp-UpdateReminder - h:\archivos de programa\Eset\UpdateReminder.exe
.
.
.
************************************************** ************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2012-02-18 22:50
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
h:\windows\$NtUninstallKB60949$:SummaryInformation 0 bytes hidden from API
.
scan completed successfully
hidden files: 1
.
************************************************** ************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(812)
h:\windows\system32\mswsock.dll
mswsock.dll 719d0000 262144 \\?\globalroot\systemroot\system32\mswsock.dll
.
------------------------ Other Running Processes ------------------------
.
h:\archivos de programa\Archivos comunes\Apple\Mobile Device Support\AppleMobileDeviceService.exe
h:\archivos de programa\Bonjour\mDNSResponder.exe
h:\archivos de programa\Java\jre6\bin\jqs.exe
h:\archivos de programa\Nero\Nero8\Nero BackItUp\NBService.exe
h:\windows\system32\IoctlSvc.exe
h:\windows\system32\wscntfy.exe
h:\windows\system32\wbem\wmiapsrv.exe
.
************************************************** ************************
.
Completion time: 2012-02-18 22:53:34 - machine was rebooted
ComboFix-quarantined-files.txt 2012-02-18 21:53
.
Pre-Run: 177.524.944.896 bytes libres
Post-Run: 182.920.261.632 bytes libres
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 0D759C9A148BCBC99204ABFBC939AEDE

