Ver Mensaje Individual
  post #3 (permalink)  
Antiguo 03/02/08, 18:40:18
jomicope jomicope está offline
Usuario
 
Registrado: feb 2008
Ubicación: España
Mensajes: 3
Re: Problemas virus Windows Vista

He escaneado por completo el equipo. me ha eliminado 4 archivos identifocados como virus. despues de esto si me ha dejado instalar un antivirus. pero el equipo tiene secuelas. no me permite actualizar el antivirus y me ha dejado de funcionar el wifi. no me encuentra las redes inhalambricas. tb me ha borrado los puntos de restauracion.

en fin. axl456, te adjunto el log del combofix a ver si me podeis ayudar. gracias.

ComboFix 08-02.03.1 - JOSE Y ANA 2008-02-03 22:38:34.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.3082.18.851 [GMT 1:00]
Se ejecuta desde: C:\Users\JOSE Y ANA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G2ABQI1N\ComboFix[1].exe
* Creado un nuevo punto de restauración
.

(((((((((((((((((((((((((((((((((((( Otras eliminaciones )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\System32\Desktop_.ini
C:\Windows\system32\drivers\down
C:\Windows\system32\x64
C:\Windows\system32\x64\csnp2uvc.dll
C:\Windows\system32\x64\rsnpvc64.dll
C:\Windows\system32\x64\sncduvc.sys
C:\Windows\system32\x64\snp2uvc.sys
C:\Windows\system32\x64\vsnpvc64.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_SROSA


(((((((((((((((((( Archivos creados desde 2008-01-03 - 2008-02-03 )))))))))))))))))))))))))))))))))
.

2008-02-03 22:16 . 2008-02-03 22:16 <DIR> d-------- C:\Users\JOSE Y ANA\WIFI3
2008-02-03 22:16 . 2008-02-03 22:16 <DIR> d-------- C:\temp
2008-02-03 22:16 . 2006-12-06 11:48 621 --a------ C:\Windows\System32\drivers\AW1012d.ini
2008-02-03 19:55 . 2008-02-03 19:55 <DIR> d-------- C:\Users\All Users\Broadcom
2008-02-03 19:55 . 2008-02-03 19:55 <DIR> d-------- C:\ProgramData\Broadcom
2008-02-03 19:55 . 2008-02-03 19:55 <DIR> d-------- C:\Program Files\Broadcom
2008-02-03 19:53 . 2008-02-03 19:53 <DIR> d-------- C:\Windows\Options
2008-02-03 19:53 . 2008-02-03 19:53 <DIR> d-------- C:\Users\JOSE Y ANA\WIFI2
2008-02-03 19:53 . 2008-02-03 19:53 <DIR> d-------- C:\Users\All Users\Atheros
2008-02-03 19:53 . 2008-02-03 19:53 <DIR> d-------- C:\ProgramData\Atheros
2008-02-03 19:53 . 2008-02-03 19:53 <DIR> d-------- C:\Program Files\Atheros
2008-02-03 19:53 . 2007-06-18 18:03 737,280 --a------ C:\Windows\System32\athr.sys
2008-02-03 19:53 . 2007-06-18 18:02 89,991 --a------ C:\Windows\System32\netathr.inf
2008-02-03 19:53 . 2007-06-22 10:28 30,578 --a------ C:\Windows\System32\athrext.cat
2008-02-03 19:53 . 2007-05-16 10:29 24,576 --a------ C:\Windows\System32\PressCancel.exe
2008-02-03 19:52 . 2008-02-03 19:55 <DIR> d-------- C:\Users\JOSE Y ANA\WIFI
2008-02-03 16:25 . 2008-02-03 16:25 <DIR> d-------- C:\Windows\System32\Kaspersky Lab
2008-02-03 15:21 . 2008-02-03 15:22 <DIR> d-------- C:\Users\JOSE Y ANA\AppData\Roaming\AVG7
2008-02-03 15:20 . 2008-02-03 15:20 55,304 --a------ C:\Windows\System32\drivers\avgwfp.sys
2008-02-03 15:20 . 2008-02-03 15:20 9,216 --a------ C:\Windows\System32\avgwlntf.dll
2008-02-03 01:44 . 2008-02-03 01:44 <DIR> dr------- C:\Windows\System32\config\systemprofile\Documents
2008-02-03 01:27 . 2008-02-03 01:27 <DIR> d-------- C:\Windows\System32\config\systemprofile\DoctorWeb
2008-02-03 00:36 . 2008-02-03 00:36 <DIR> d-------- C:\Users\JOSE Y ANA\AppData\Roaming\PeerNetworking
2008-02-03 00:01 . 2008-02-03 00:19 <DIR> d-------- C:\PRUEBA
2008-02-02 23:52 . 2008-02-02 23:52 <DIR> d-------- C:\Program Files\ewido anti-spyware 4.0
2008-02-02 23:42 . 2008-02-02 23:42 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-02 23:33 . 2008-02-02 23:29 6,020,448 --a------ C:\ewido-setup_4.0.0.172c.exe
2008-02-02 16:36 . 2008-02-03 00:48 69 --a------ C:\Windows\NeroDigital.ini
2008-02-02 00:07 . 2008-02-02 00:08 1,593 --a------ C:\Windows\VPNUnInstall.MIF
2008-02-01 23:51 . 2008-02-01 23:51 <DIR> d-------- C:\Users\All Users\Grisoft
2008-02-01 23:51 . 2008-02-03 16:21 <DIR> d-------- C:\Users\All Users\avg7
2008-02-01 23:51 . 2008-02-01 23:51 <DIR> d-------- C:\ProgramData\Grisoft
2008-02-01 23:51 . 2008-02-03 16:21 <DIR> d-------- C:\ProgramData\avg7
2008-02-01 20:26 . 2008-02-02 23:55 116,337,310 --a------ C:\Windows\MEMORY.DMP
2008-02-01 00:43 . 2008-02-01 00:43 1,593 --a------ C:\Windows\VPNInstall.MIF
2008-02-01 00:42 . 2007-01-31 13:45 127,376 --a------ C:\Windows\System32\drivers\dne2000.sys
2008-02-01 00:42 . 2007-01-31 13:45 101,904 --a------ C:\Windows\System32\dneinobj.dll
2008-01-31 23:03 . 2006-04-20 08:34 29,752 --------- C:\Windows\System32\InstHelper.dll
2008-01-31 23:02 . 2008-02-01 00:41 <DIR> d-------- C:\Program Files\Cisco Systems
2008-01-18 00:38 . 2008-01-18 00:38 <DIR> d-------- C:\Users\JOSE Y ANA\Program Files
2008-01-14 23:58 . 2008-02-03 22:41 12 --a------ C:\Windows\bthservsdp.dat
2008-01-09 03:05 . 2008-01-09 03:05 802,816 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-01-09 03:05 . 2008-01-09 03:05 216,760 --a------ C:\Windows\System32\drivers\netio.sys
2008-01-09 03:05 . 2008-01-09 03:05 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-01-09 03:05 . 2008-01-09 03:05 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-01-09 03:05 . 2008-01-09 03:05 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-01-09 03:03 . 2008-01-09 03:03 4,247,552 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-09 03:03 . 2008-01-09 03:03 1,686,016 --a------ C:\Windows\System32\gameux.dll
2008-01-09 03:02 . 2008-01-09 03:02 1,060,920 --a------ C:\Windows\System32\drivers\ntfs.sys
2008-01-09 03:02 . 2008-01-09 03:02 211,000 --a------ C:\Windows\System32\drivers\volsnap.sys
2008-01-09 03:02 . 2008-01-09 03:02 154,624 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-01-09 03:02 . 2008-01-09 03:02 109,624 --a------ C:\Windows\System32\drivers\ataport.sys
2008-01-09 03:02 . 2008-01-09 03:02 45,112 --a------ C:\Windows\System32\drivers\pciidex.sys
2008-01-09 03:02 . 2008-01-09 03:02 21,560 --a------ C:\Windows\System32\drivers\atapi.sys
2008-01-09 03:02 . 2008-01-09 03:02 15,928 --a------ C:\Windows\System32\drivers\pciide.sys
2008-01-09 03:02 . 2008-01-09 03:02 11,776 --a------ C:\Windows\System32\sbunattend.exe

.
(((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))))))))))))))))))))))))))))))))))))))))))) )
.
2008-02-03 18:59 27,810 ----a-w C:\Users\JOSE Y ANA\AppData\Roaming\nvModes.dat
2008-02-03 18:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-02 23:41 --------- d-----w C:\Program Files\Acer GameZone
2008-02-02 23:32 --------- d-----w C:\ProgramData\eMule
2008-02-02 21:16 --------- d-----w C:\Users\JOSE Y ANA\AppData\Roaming\uTorrent
2008-02-02 21:16 --------- d-----w C:\Program Files\Norton Internet Security
2008-02-02 21:16 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-01 23:13 --------- d-----w C:\ProgramData\Symantec
2008-01-15 08:54 10,537 ----a-w C:\Windows\system32\drivers\COH_Mon.cat
2008-01-15 04:28 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
2008-01-12 17:32 23,904 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
2008-01-09 02:15 --------- d-----w C:\Program Files\Windows Sidebar
2008-01-09 02:15 --------- d-----w C:\Program Files\Windows Mail
2008-01-09 02:03 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-09 02:03 449,024 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-09 02:03 2,143,744 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-09 02:03 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2007-12-30 23:38 --------- d-----w C:\Program Files\QuickTime
2007-12-28 16:48 --------- d-----w C:\ProgramData\Downloaded Installations
2007-12-28 16:48 --------- d-----w C:\Program Files\Nokia
2007-12-28 16:48 --------- d-----w C:\Program Files\Common Files\PCSuite
2007-12-28 15:15 --------- d-----w C:\ProgramData\CyberLink
2007-12-27 23:23 --------- d-----w C:\Program Files\Google
2007-12-27 19:35 --------- d-----w C:\Users\JOSE Y ANA\AppData\Roaming\Datalayer
2007-12-27 19:22 --------- d-----w C:\Users\JOSE Y ANA\AppData\Roaming\Nokia
2007-12-27 19:21 --------- d-----w C:\Users\JOSE Y ANA\AppData\Roaming\PC Suite
2007-12-27 19:21 --------- d-----w C:\ProgramData\PC Suite
2007-12-27 18:51 --------- d-----w C:\Program Files\Java
2007-12-27 18:48 --------- d-----w C:\Program Files\Common Files\Java
2007-12-13 20:41 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-13 20:41 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-13 20:41 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-12-13 20:40 824,832 ----a-w C:\Windows\System32\wininet.dll
2007-12-13 20:40 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-12-13 20:40 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-13 20:40 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-12-13 20:39 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-13 20:39 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-13 20:39 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2007-12-13 20:39 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-13 20:36 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe
2007-12-13 20:36 3,470,520 ----a-w C:\Windows\System32\ntoskrnl.exe
2007-12-09 23:26 --------- d-----w C:\Program Files\Crystal Player
2007-12-06 23:02 --------- d-----w C:\Users\JOSE Y ANA\AppData\Roaming\Crystal Player
2007-12-06 08:27 8,704 ----a-w C:\Windows\System32\hcrstco.dll
2007-12-06 08:27 8,704 ----a-w C:\Windows\System32\hccoin.dll
2007-12-06 08:27 73,216 ----a-w C:\Windows\system32\drivers\usbccgp.sys
2007-12-06 08:27 5,888 ----a-w C:\Windows\system32\drivers\usbd.sys
2007-12-06 08:27 38,400 ----a-w C:\Windows\system32\drivers\usbehci.sys
2007-12-06 08:27 224,768 ----a-w C:\Windows\system32\drivers\usbport.sys
2007-12-06 08:27 193,536 ----a-w C:\Windows\system32\drivers\usbhub.sys
2007-12-06 08:27 19,456 ----a-w C:\Windows\system32\drivers\usbohci.sys
2007-12-05 20:49 805 ----a-w C:\Windows\system32\drivers\SYMEVENT.INF
2007-12-05 20:49 123,952 ----a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2007-12-05 20:49 10,740 ----a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2007-12-05 20:49 --------- d-----w C:\Program Files\Symantec
2007-11-17 18:52 174 --sha-w C:\Program Files\desktop.ini
2007-11-17 18:46 8,192 ----a-w C:\Windows\System32\riched32.dll
2007-11-17 18:46 77,824 ----a-w C:\Windows\System32\rascfg.dll
2007-11-17 18:46 694,784 ----a-w C:\Windows\System32\localspl.dll
2007-11-17 18:46 52,736 ----a-w C:\Windows\System32\rasdiag.dll
2007-11-17 18:46 384,000 ----a-w C:\Windows\System32\netcfgx.dll
2007-11-17 18:46 36,864 ----a-w C:\Windows\System32\cdd.dll
2007-11-17 18:46 33,280 ----a-w C:\Windows\System32\traffic.dll
2007-11-17 18:46 32,768 ----a-w C:\Windows\System32\rasmxs.dll
2007-11-17 18:46 286,208 ----a-w C:\Windows\System32\ipnathlp.dll
2007-11-17 18:46 22,016 ----a-w C:\Windows\System32\rasser.dll
2007-11-17 18:46 15,360 ----a-w C:\Windows\System32\pacerprf.dll
2007-11-17 18:46 134,656 ----a-w C:\Windows\System32\dps.dll
2007-11-17 18:46 13,824 ----a-w C:\Windows\System32\wshqos.dll
2007-11-17 18:46 13,824 ----a-w C:\Windows\System32\icsunattend.exe
2007-11-17 18:45 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2007-11-17 18:45 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2007-11-17 18:45 542,720 ----a-w C:\Windows\System32\sysmain.dll
2007-11-17 18:45 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2007-11-17 18:45 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2007-11-17 18:45 297,984 ----a-w C:\Windows\System32\wlansec.dll
2007-11-17 18:45 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2007-11-17 18:45 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2007-11-17 18:45 2,923,520 ----a-w C:\Windows\explorer.exe
2007-11-17 18:45 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2007-11-17 18:42 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2007-11-17 18:42 7,680 ----a-w C:\Windows\System32\spwmp.dll
2007-11-17 18:42 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2007-11-17 18:42 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-11-17 18:41 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2007-11-17 18:38 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
2007-11-17 18:38 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-17 18:37 88,576 ----a-w C:\Windows\System32\avifil32.dll
2007-11-17 18:37 84,480 ----a-w C:\Windows\System32\INETRES.dll
2007-11-17 18:37 82,944 ----a-w C:\Windows\System32\mciavi32.dll
2007-11-17 18:37 8,138,240 ----a-w C:\Windows\System32\ssBranded.scr
2007-11-17 18:37 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2007-11-17 18:37 712,192 ----a-w C:\Windows\System32\WindowsCodecs.dll
2007-11-17 18:37 69,632 ----a-w C:\Windows\System32\sendmail.dll
2007-11-17 18:37 65,024 ----a-w C:\Windows\System32\avicap32.dll
2007-11-17 18:37 61,440 ----a-w C:\Windows\System32\ntprint.exe
2007-11-17 18:37 31,232 ----a-w C:\Windows\System32\msvidc32.dll
2007-11-17 18:37 269,824 ----a-w C:\Windows\System32\schannel.dll
2007-11-17 18:37 220,160 ----a-w C:\Windows\System32\ntprint.dll
.

((((((((((((((((((((((((((((((((( Cargando Puntos Reg ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* entradas vac¡as & entradas leg¡timas predeterminadas no son mostradas

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe" [2007-12-27 20:07 171448]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 03:02 1232896]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunOnce]
"CISCO"="D:\Descargas emule\Cisco.VPN.Client.WinALL.v4.8.01.0300.Retail-NGEN\Cisco.VPN.Client.WinALL.v4.8.01.0300.Retail-NGEN\setup\DelayInst.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Acer Tour"="" []
"eRecoveryService"="" []
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-07-28 06:06 1006264]
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp. exe" [2006-11-05 21:48 57344]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22 517768]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"SetPanel"="C:\Acer\APanel\APanel.cmd" [ ]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 04:06 4669440 C:\Windows\RtHDVCpl.exe]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"PLFSetL"="C:\Windows\PLFSetL.exe" [2007-07-05 11:35 94208]
"PlayMovie"="C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2007-05-24 12:38 206952]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2008-02-03 01:18 22696]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-25 13:53 86016]
"NvMediaCenter"="C:\Windows\system32\NvMcTray. dll" [2007-07-25 13:53 81920]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-25 13:53 8433664]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2007-08-15 10:21 772616]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-11-15 13:11 267048]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 15:33 457216]
"eAudio"="C:\Acer\Empowering Technology\eAudio\eAudio.exe" [2007-06-11 13:54 1286144]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-03 01:18 107112]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2007-06-06 09:06 159744]
"ALaunch"="C:\Acer\ALaunch\AlaunchClient.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-03-08 03:38 40048]
"!ewido"="G:\NUEVA\ewido anti-spyware 4.0\ewido.exe" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-03 15:20 579072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-03 15:20 219136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2008-02-03 15:20 9216 C:\Windows\System32\avgwlntf.dll

R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\ps dfilter.sys [2007-04-25 15:34]
R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PS DNServ.sys [2007-04-25 15:34]
R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdv disk.sys [2007-04-25 15:34]
R1 DritekPortIO;Dritek General Port I/O;C:\PROGRA~1\LAUNCH~1\DPortIO.sys [2006-11-02 14:27]
R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsd efs\20080122.002\IDSvix86.sys [2007-11-06 17:28]
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files\Acer Arcade Deluxe\Play Movie\000.fcl [2006-11-02 15:51]
R2 ALaunchService;ALaunch Service;C:\Acer\ALaunch\ALaunchSvc.exe [2007-01-26 13:24]
R2 eDataSecurity Service;eDSService.exe;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-04-25 15:34]
R2 eNet Service;eNet Service;C:\Acer\Empowering Technology\eNet\eNet Service.exe [2007-06-13 15:54]
R2 eSettingsService;eSettings Service;C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-06-28 17:50]
R2 int15;int15;C:\Acer\Empowering Technology\eRecovery\int15.sys [2006-12-07 17:12]
R2 MobilityService;MobilityService;C:\Acer\Mobility Center\MobilityService.exe [2006-11-24 11:57]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.s ys [2007-05-17 01:46]
R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2007-06-18 11:03]
R3 AvgWFP;AVG7 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfp.sys [2008-02-03 15:20]
R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys [2007-05-16 13:47]
R3 nvsmu;nvsmu;C:\Windows\system32\DRIVERS\nvsmu.sys [2007-05-17 02:05]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC);C:\Windows\system32\DRIVERS\snp2uvc.sys [2007-08-02 14:17]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMN DISV.SYS [2007-10-30 19:55]
S2 Programador de LiveUpdate automático;Programador de LiveUpdate automático;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-27 11:38]
S3 stusb2ir;Puente USB 2.0 IrDA;C:\Windows\system32\DRIVERS\stusb2ir.sys [2006-11-02 08:30]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{4c6df610-c930-11dc-8d9c-001b3856bd38}]
\shell\AutoRun\command - F:\InstallTomTomHOME.exe

*Newly Created Service* - COMHOST
.
Contenido de carpeta 'Tareas Programadas'
"2007-11-17 00:49:14 C:\Windows\Tasks\Comprobar actualizaciones de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
************************************************** ************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-03 22:43:06
Windows 6.0.6000 NTFS

escaneando procesos ocultos ...

escaneando entradas ocultas de autostart ...

escaneando archivos ocultos ...

el escaneo se completo con exito
archivos ocultos: 0

************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\JOSEYA~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
.
************************************************** ************************
.
Tiempo completado: 2008-02-03 22:44:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-03 21:44:33
.
2008-01-31 22:04:25 --- E O F ---