Ver Mensaje Individual
Antiguo 02/07/08, 15:18:59
pedo92 pedo92 está offline
Usuario
 
Registrado: may 2008
Ubicación: España
Mensajes: 30
Re: Troyano "WinNT / Bagle.gen"

- Aquí pego el log después de arrastrar el archivo "CFScript.txt" hacia el Combo-Fix.exe

Código:
ComboFix 08-07-01.5 - jose 2008-07-02 20:09:23.4 - NTFSx86

.

((((((((((((((((((((((((((((((((((((   Otras eliminaciones   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\sdlflzoip
C:\WINDOWS\system32\ban_list.txt
C:\WINDOWS\system32\drivers\downld
C:\WINDOWS\system32\drivers\downld\597093.exe
C:\WINDOWS\system32\drivers\downld\598406.exe
C:\WINDOWS\system32\drivers\downld\598515.exe
C:\WINDOWS\system32\drivers\downld\599437.exe
C:\WINDOWS\system32\drivers\downld\599750.exe
C:\WINDOWS\system32\drivers\downld\603625.exe
C:\WINDOWS\system32\drivers\downld\603937.exe
C:\WINDOWS\system32\drivers\downld\604062.exe
C:\WINDOWS\system32\drivers\downld\604312.exe
C:\WINDOWS\system32\drivers\downld\606156.exe
C:\WINDOWS\system32\drivers\downld\607781.exe
C:\WINDOWS\system32\drivers\downld\611812.exe
C:\WINDOWS\system32\drivers\downld\614453.exe
C:\WINDOWS\system32\drivers\downld\627421.exe
C:\WINDOWS\system32\drivers\downld\651375.exe
C:\WINDOWS\system32\drivers\downld\659953.exe
C:\WINDOWS\system32\drivers\downld\661953.exe
C:\WINDOWS\system32\drivers\downld\665687.exe
C:\WINDOWS\system32\drivers\downld\671109.exe
C:\WINDOWS\system32\drivers\downld\677281.exe
C:\WINDOWS\system32\drivers\downld\684281.exe
C:\WINDOWS\system32\drivers\downld\694484.exe
C:\WINDOWS\system32\drivers\downld\705515.exe
C:\WINDOWS\system32\drivers\downld\729156.exe
C:\WINDOWS\system32\drivers\downld\741671.exe
C:\WINDOWS\system32\drivers\downld\746843.exe
C:\WINDOWS\system32\drivers\downld\758531.exe
C:\WINDOWS\system32\drivers\downld\770875.exe
C:\WINDOWS\system32\drivers\downld\774500.exe
C:\WINDOWS\system32\drivers\downld\782125.exe
C:\WINDOWS\system32\drivers\downld\786500.exe
C:\WINDOWS\system32\drivers\downld\881093.exe
C:\WINDOWS\system32\drivers\downld\907296.exe
C:\WINDOWS\system32\drivers\downld\925578.exe
C:\WINDOWS\system32\drivers\downld\932109.exe
C:\WINDOWS\system32\drivers\downld\941875.exe
C:\WINDOWS\system32\drivers\downld\949093.exe
C:\WINDOWS\system32\drivers\downld\966125.exe
C:\WINDOWS\system32\drivers\downld\977625.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\mdelk.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\wintems.exe
D:\Documents and Settings\jose\Datos de programa\m
D:\Documents and Settings\jose\Datos de programa\m\data.oct
D:\Documents and Settings\jose\Datos de programa\m\flec006.exe
D:\Documents and Settings\jose\Datos de programa\m\list.oct
D:\Documents and Settings\jose\Datos de programa\m\shared
D:\Documents and Settings\jose\Datos de programa\m\shared\Sun Set Screensaver 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sun Sight Gadget 1.0.0.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sun Spotter 2.2.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sun Times 7.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunbowsoft Secure Storage 1.08.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunClock 2.5.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Suncycle 1.0.9.7.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sundi 1.060.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SundryTools XV 4.0.0 Build 516.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunflow 0.07.2.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunflower Clock ScreenSaver 2.3.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunflower Excel .Net 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunflowers - Animated Screensaver 5.07.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunflowers - Animated Wallpaper 5.07.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunflowers Screensaver 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunflowers Screensaver1 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunflowers Screensaver2 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunGlance 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunken Pirate Ship 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunlitGreen Photo Editor 1.2.0.20.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunMetronome 3.8.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunny Morning - Animated Screensaver 5.07.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunny Morning - Animated Wallpaper 5.07.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunoSoft Overwrite Protect Free 2.0.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunoSoft S-Crypto II 2.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunRav BookOffice 3.2.1.467.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunRav Fonter 1.2.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunRav PDF Creator 1.1.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunRav TestOfficePro 5.1.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunRav TestOfficePro.WEB 2.3.2.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunrise Calculator 1.5.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunrise Wallpaper Changer 3.4.0513.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Suns NBA Schedule 1.1.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SUNSET 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunset And Sky Screen Saver 1.3.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunset And Sunrise Screen Saver 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunset Glory Screensaver.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunset on Jetty Screensaver 1.0.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunset Screen Saver 2.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunset Screensaver 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunset Screensaver EV.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunset Slideshow 3.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunset Splendor Screensaver 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunset Thoughts Demo Screensaver 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunsets and Sunscapes Screensaver 1.0.6.2634.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Sunsets Around The World 1.0.6.2634.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunSys Screensaver 1.1.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Suntereo 1.2.3.1254.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Suntime 1.0.2.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SunXi Viewer Install 1.0b.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SupaMario 1.2.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SupaNova MP3 Explorer 2.1.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SupaWeegi 1.3.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SUPER 2008 Build 30.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Ad Blocker 4.6.1000.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super AJAX Programming Seed 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Amazing 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Audio Assistant 1.3.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Audio Converter 5.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Audio Factory 5.4.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Audio Grabber 3.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Audio Recorder 3.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Browser Washer 1.10.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super calculator 1.00.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Capture 6.11.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super CD Cover Maker 4.2.5.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super CD Ripper 2.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super CD to WMA Maker 1.00.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Cipher P2P Messenger 4.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Clock Screensaver City.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Clock Screensaver Rain.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Clone DVD 5.2.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Color Picker 1.2.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Copy 2.1.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Crossword Creator 2.3.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Deluxe Daily Premieres 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DIY 1.8.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DragAndGo 0.2.6.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Duper Music Looper XPress 2 build 63.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DVD CD Backup Studio 3.1.0.0612.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DVD Copier 5.6.1.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DVD Copy 2.28i.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DVD Creator 9.8.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DVD Factory 5.8.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DVD ripper 2.11.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DVD Ripper 2.39i.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DVD to iPod Converter + Video to iPod PowerPack build 2006 5.0.1.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DVD to iPod Converter 3.1.1.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DVD to PSP Converter 5.5.5.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super DVD to Zune Converter 2.37.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Echo SE-i 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Editor 7.6.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Email Extractor 2.81.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Email Harvester 5.54.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Email Sender 2.97.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Email Spider 2.80.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Email Verifier 1.75.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Explorer 1.5.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Fast File Splitter 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Fax Search 1.82.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Fdisk 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super File Encryption 4.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Finder 1.5.2.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Flash Player Manager 2.18.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Flexible File Synchronizer 4.12d Build 71.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SUPER GIR 2.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Heros Vista Icons.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super History 1.0.0.5 Beta.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Icon Helper 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Image Picture Finder Grabber 4.15.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Internet TV 7.2.0.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Invoice 1.01.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super iPod Video Converter 3.5.1.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Lister 1.3.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Magnifier 1.0.4.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\SUPER MAGNIFY 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Maildisk 1.03.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Mario Bros Z Screensaver 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Mario Bros. Screensaver 1.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Mp3 Converter 5.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Mp3 Editor 5.2.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super MP3 Recorder 2.50.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Mp3 Recorder 3.0.zip
D:\Documents and Settings\jose\Datos de programa\m\shared\Super Mp3 Recorder Pro 6.5.5.zip
D:\Documents and Settings\jose\Datos de programa\m\srvlist.oct

.
((((((((((((((((((   Archivos creados desde 2008-06-02 - 2008-07-02  )))))))))))))))))))))))))))))))))
.

2008-06-18 15:06 . 2008-06-18 15:09	<DIR>	d--------	C:\Archivos de programa\SopCast
2008-06-16 21:24 . 2008-06-16 21:24	<DIR>	d--------	C:\Archivos de programa\Ares
2008-06-16 14:27 . 2008-06-16 20:54	<DIR>	d--------	D:\Documents and Settings\jose\Datos de programa\Hide IP NG
2008-06-15 13:18 . 2008-06-15 18:49	<DIR>	d--------	C:\Archivos de programa\beon Widgets
2008-06-15 13:18 . 2008-06-15 18:47	0	--a------	C:\WINDOWS\system32\beon3.bok
2008-06-12 18:00 . 2008-06-12 16:25	92,208	--a------	C:\WINDOWS\system32\drivers\srosa.sys.vir
2008-06-12 17:44 . 2008-06-12 17:44	<DIR>	d--------	D:\Documents and Settings\jose\Datos de programa\Simply Super Software
2008-06-12 17:44 . 2008-06-12 17:44	<DIR>	d--------	D:\Documents and Settings\All Users\Datos de programa\Simply Super Software
2008-06-12 17:44 . 2008-06-12 17:44	<DIR>	d--------	C:\Archivos de programa\Trojan Remover
2008-06-12 17:44 . 2006-05-25 15:52	162,304	--a------	C:\WINDOWS\system32\ztvunrar36.dll
2008-06-12 17:44 . 2003-02-02 20:06	153,088	--a------	C:\WINDOWS\system32\UNRAR3.dll
2008-06-12 17:44 . 2005-08-26 01:50	77,312	--a------	C:\WINDOWS\system32\ztvunace26.dll
2008-06-12 17:44 . 2002-03-06 01:00	75,264	--a------	C:\WINDOWS\system32\unacev2.dll
2008-06-12 17:44 . 2006-06-19 13:01	69,632	--a------	C:\WINDOWS\system32\ztvcabinet.dll
2008-06-12 13:53 . 2006-10-26 19:56	32,592	--a------	C:\WINDOWS\system32\msonpmon.dll
2008-06-12 13:49 . 2008-06-12 13:49	<DIR>	d--------	C:\Archivos de programa\MSBuild
2008-06-12 13:49 . 2008-06-12 13:49	<DIR>	d--------	C:\Archivos de programa\Microsoft Works
2008-06-12 13:48 . 2008-06-12 13:48	<DIR>	d--------	C:\Archivos de programa\Microsoft.NET
2008-06-12 13:44 . 2008-06-17 13:06	<DIR>	d--------	D:\Documents and Settings\All Users\Datos de programa\Microsoft Help
2008-06-12 13:44 . 2008-06-12 13:44	<DIR>	d--------	C:\Archivos de programa\Microsoft Visual Studio 8
2008-06-12 13:43 . 2008-06-12 13:43	<DIR>	dr-h-----	C:\MSOCache

.
((((((((((((((((((((((((((((((((((((((   Reporte Find3M   )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-01 20:11	---------	d-----w	C:\Archivos de programa\MultiMedia Spain Toolbar
2008-06-27 22:35	---------	d-----w	C:\Archivos de programa\TrackMania Nations ESWC
2008-06-19 13:59	---------	d-----w	C:\Archivos de programa\Opera
2008-06-12 16:17	---------	d---a-w	D:\Documents and Settings\All Users\Datos de programa\TEMP
2008-06-11 14:30	---------	d-----w	C:\Archivos de programa\MSECache
2008-05-29 13:30	---------	d-----w	D:\Documents and Settings\jose\Datos de programa\AdobeUM
2008-05-23 19:54	---------	d--h--w	C:\Archivos de programa\InstallShield Installation Information
2008-05-23 19:54	---------	d-----w	C:\Archivos de programa\Kit ADSL USB
2008-05-23 19:16	---------	d-----w	C:\Archivos de programa\Java
2008-05-15 19:41	---------	d-----w	D:\Documents and Settings\jose\Datos de programa\FileZilla
2008-05-12 18:47	---------	d-----w	D:\Documents and Settings\jose\Datos de programa\SmartFTP
2008-05-10 08:07	---------	d-----w	C:\Archivos de programa\FileZilla FTP Client
2008-05-07 21:16	---------	d-----w	C:\Archivos de programa\Archivos comunes\Symantec Shared
2008-05-06 12:49	---------	d-----w	C:\Archivos de programa\Malwarebytes' Anti-Malware
2008-05-05 20:12	---------	d-----w	C:\Archivos de programa\ESET
2008-05-05 18:46	27,048	----a-w	C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-05 18:46	15,864	----a-w	C:\WINDOWS\system32\drivers\mbam.sys
2008-05-05 15:41	---------	d-----w	C:\Archivos de programa\Panda Security
2008-05-02 22:18	---------	d-----w	D:\Documents and Settings\jose\Datos de programa\IObit
2008-05-02 11:35	---------	d-----w	C:\Archivos de programa\IObit
2008-05-02 10:51	---------	d-----w	C:\Archivos de programa\Paint.NET
2008-05-02 09:54	---------	d-----w	C:\Archivos de programa\Symantec
2008-05-02 09:49	---------	d-----w	D:\Documents and Settings\All Users\Datos de programa\Symantec
2008-03-29 20:02	65,280	----a-w	D:\Documents and Settings\jose\Datos de programa\GDIPFONTCACHEV1.DAT
2007-04-27 20:44	2,516	--sha-w	C:\WINDOWS\system32\KGyGaAvL.sys
.

(((((((((((((((((((((((((((((   snapshot@2008-07-01_19.51.28.92   )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-01 17:46:49	2,048	--s-a-w	C:\WINDOWS\bootstat.dat
+ 2008-07-02 18:08:30	2,048	--s-a-w	C:\WINDOWS\bootstat.dat
.
(((((((((((((((((((((((((((((((((   Cargando Puntos Reg   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* entradas vacías & entradas legítimas predeterminadas no son mostradas

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 14:00 15360]
"msnmsgr"="C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"updateMgr"="C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-20 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-20 14:00 455168]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-05-11 13:48 127118]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-20 14:00 208952]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 11:31 24576]
"TkBellExe"="C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe" [2005-10-21 07:06 180269]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-06-10 13:48 286720]
"SunJavaUpdateSched"="C:\Archivos de programa\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"GrooveMonitor"="C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"TrojanScanner"="C:\Archivos de programa\Trojan Remover\Trjscan.exe" [2008-07-02 19:54 877136]
"VTTimer"="VTTimer.exe" [2004-05-15 01:03 929170 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-03-11 17:33 147456 C:\WINDOWS\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-01-20 20:04 77824 C:\WINDOWS\SOUNDMAN.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-20 14:00 15360]

D:\Documents and Settings\All Users\Men£ Inicio\Programas\Inicio\
Adobe Reader Speed Launch.lnk - C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
Microsoft Office.lnk - C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Archivos de programa\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 12:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 12:41 294912 C:\Archivos de programa\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\ARCHIV~1\ARCHIV~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ulmp3acm"= C:\ARCHIV~1\ARCHIV~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.mpegacm"= C:\ARCHIV~1\ARCHIV~1\ULEADS~1\MPEG\mpegacm.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\APPS\\skype\\phone\\Skype.exe"=
"D:\\Documents and Settings\\jose\\Datos de programa\\SopCast\\adv\\SopAdver.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"D:\\Documents and Settings\\jose\\Mis documentos\\Otros programas\\eMule\\emule.exe"=
"C:\\Archivos de programa\\Zattoo\\zattood.exe"=
"C:\\Archivos de programa\\Zattoo\\Zattoo.exe"=
"C:\\Archivos de programa\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"C:\\Archivos de programa\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19576:TCP"= 19576:TCP:BitComet 19576 TCP
"19576:UDP"= 19576:UDP:BitComet 19576 UDP


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{29306126-c752-11db-8e04-000e50b64875}]
\Shell\AutoRun\command - J:\nideiect.com
\Shell\explore\Command - J:\nideiect.com
\Shell\open\Command - J:\nideiect.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6dc461ea-e858-11dc-9233-000e50b64875}]
\Shell\AutoRun\command - J:\nideiect.com
\Shell\explore\Command - J:\nideiect.com
\Shell\open\Command - J:\nideiect.com

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-02 20:11:20
Windows 5.1.2600 Service Pack 2 NTFS

escaneando procesos ocultos ...

escaneando entradas ocultas de autostart ...

escaneando archivos ocultos ...

el escaneo se completo con exito
archivos ocultos: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Archivos de programa\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Archivos de programa\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\APPS\HIDSERVICE\HidService.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\PAStiSvc.exe
C:\Archivos de programa\Archivos comunes\Ulead Systems\DVD\ULCDRSvr.exe
C:\APPS\Powercinema\Kernel\TV\CLSched.exe
.
**************************************************************************
.
Tiempo completado: 2008-07-02 20:12:22 - machine was rebooted
ComboFix-quarantined-files.txt  2008-07-02 18:12:18
ComboFix2.txt  2008-07-01 17:52:06
ComboFix3.txt  2008-05-04 10:09:00

              16 dirs  15,708,413,952 bytes libres
              16 dirs  15,689,183,232 bytes libres

334	--- E O F ---	2008-04-11 16:24:33

Última edición por pedo92 fecha: 02/07/08 a las 18:40:02.
Responder Con Cita