Blog Registrarse Manuales Programas Glosario

Regresar   Foro de Spyware » Spyware - Adware - Hijackers - Malwares » Temas Solucionados
 

Para evitar Virus, Spyware y otros Malwares, te recomendamos mantenerte informado en: InfoSpyware Blog


Temas Solucionados Casos de HijackThis y Malwares resueltos.
(Solo lectura)

Respuesta
 
Enviar a: Herramientas
  post #1  
Antiguo 02/10/08, 12:29:15
Usuario
 
Registrado: dic 2006
Ubicación: Colombia
Mensajes: 20
Virus messenger(Solucionado)

Buenos día esta semana en el messenger recibi un mensaje de un contacto invitandomene a ver unas fotos (DVC-Foto00019.zip) la verdad cahi en la tentación y creo que ahi fue donde se originó el problema. He intentado realizar los acciones rutinarias para solución de este tipo de problemas pero hay varias acciones que no me dejaq hacer. No me deja iniciar en modo seguro, he inttentado ejecuitar los siguientes programas y no me deja: CCleaner, HijackThis, Malwarebytes’ Anti-Malware, el Ewido Anti-Spyware Micro Scanner, no meja abrir el regedit. Es mas hay páginas de internet que no puedo abrir (incluyendo la de forospyware). Lo único que le he podido correr es el regseeker, el kaspersky online (que no detectó nada), he borrado los archivos temporales de Internet. Pero no se que mas hacerle, agradeciendo su colaboración. Cordial saludo
Responder Con Cita
InfoSpyware

  post #2  
Antiguo 02/10/08, 12:34:48
Avatar de Kirigi
Warrior
 
Registrado: jun 2007
Ubicación: Venezuela- Vargas- La Guaira
Mensajes: 6.544
Re: Virus messenger

Hola oscaanzc


Hazte lo siguiente:

Descarga SDFix guardala y descomprimela en tu escritorio pero no la ejecutes aun.


Ve a Inicio >> Ejecutar y pegas lo siguiente y luego aceptas:


Código:
%systemdrive%\SDFix\apps\swreg IMPORT %systemdrive%\SDFix\apps\Restore_SafeBoot_WindowsXP_SP2.reg
Con eso se tendria que reparar el modo a prueba de fallos para que luego continúes con los demas pasos.


Inicia en Modo a Prueba de Fallos


Ejecuta SDFix.exe en el escritorio, se creará una nueva carpeta en el escritorio, entra en dicha carpeta y ejecuta el archivo "Runthis.bat" luego, presiona la tecla "Y" para que comience el chequeo, al terminar, se creará un archivo dentro de la carpeta llamado Report.txt, copia y pega lo que indique ese reporte acá.


Luego que tu pc inicie en modo normal y termine el análisis con el SDfix pegas su reporte aquí.


Salu2


Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog


* Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando.
* Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
* No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.
Responder Con Cita
  post #3  
Antiguo 02/10/08, 12:56:41
Usuario
 
Registrado: dic 2006
Ubicación: Colombia
Mensajes: 20
Re: Virus messenger

Beunos días Inicio/ejecutar tambien quedóp deshabilitado
Responder Con Cita
  post #4  
Antiguo 02/10/08, 20:42:00
Avatar de Kirigi
Warrior
 
Registrado: jun 2007
Ubicación: Venezuela- Vargas- La Guaira
Mensajes: 6.544
Re: Virus messenger

Hola,

Cita:
Originalmente publicado por oscaanzc Ver Mensaje
Beunos días Inicio/ejecutar tambien quedóp deshabilitado

Descarga RegUnlocker.exe y ejecútalo así:

En la pestaña de "A - Restricciones" selecciona las 2 primeras opciones y luego en la pestaña "B - Reparadores" seleccionas la opción 4:


Pestaña A:
  • Eliminar Restricciones del Sistema
  • Eliminar Restricciones del Explorador

Pestaña B:
  • Reparar el modo a prueba de fallos


Y das clic a "Aplicar", reinicias y verificas resultados para que luego prosigas hacer lo que te indique en mi respuesta anterior.


Salu2


Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog


* Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando.
* Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
* No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.
Responder Con Cita
  post #5  
Antiguo 02/10/08, 21:56:03
Usuario
 
Registrado: dic 2006
Ubicación: Colombia
Mensajes: 20
Re: Virus messenger

Buenas noches

Ya pudé iniciar en modo a prueba de fallos, pero al ejecutar el Runthis.bat del SDFix me sale un mensaje. "El administrador ha deshabilitado el simbolo del sistema. Presiones una tecla para continuar" y no me generó ningun reporte. De todas maneras ya me dejó correr el Ccleaner y el MSNCleaner, lo mismo que ya me dejo ejecutar el HijackThis (no se si sirva de algo)

Logfile of HijackThis v1.99.1
Scan saved at 07:44:10 p.m., on 02/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Archivos de programa\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.forospyware.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.forospyware.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoritos
R3 - URLSearchHook: Barra Yahoo! con bloqueador de ventanas emergentes - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {444FC7D1-8F08-4377-B39B-4D75AE0E9F70} - (no file)
O2 - BHO: (no name) - {455630CC-7526-4878-8AAA-9B5BC6D7D483} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A161F7A6-15F8-4504-B573-42DFD8A95B9F} - (no file)
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [RemoteControl] C:\Archivos de programa\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Archivos de programa\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Archivos de programa\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [NVIDIA Remote Control Panel] NVAREM.EXE /S /Q /R /L /A1 /B0 /C0 /D2 /E0
O4 - HKLM\..\Run: [NexusServer] "C:\Archivos de programa\Archivos comunes\Canopus Shared\ProCoder 2\Kernel\PNXSERVR.exe" -SelfLaunch
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Archivos de programa\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [avast!] "C:\Archivos de programa\Alwil Software\Avast4\ashDisp.exe"
O4 - HKLM\..\Run: [Symantec Admin Service] symlasrvc.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Archivos de programa\Archivos comunes\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ares] "C:\Archivos de programa\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15031/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15034/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Archivos de programa\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: LMIinit - LMIinit.dll (file missing)
O20 - Winlogon Notify: vtUolLEt - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Archivos de programa\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Archivos de programa\Ares\chatServer.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Archivos de programa\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Archivos de programa\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Archivos de programa\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Archivos de programa\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - Unknown owner - (no file)
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Archivos de programa\LogMeIn\LogMeIn.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Archivos de programa\Archivos comunes\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NBService - Nero AG - C:\Archivos de programa\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Archivos de programa\Archivos comunes\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\WINDOWS\system32\x10nets.exe
Responder Con Cita
  post #6  
Antiguo 02/10/08, 22:01:37
Avatar de Kirigi
Warrior
 
Registrado: jun 2007
Ubicación: Venezuela- Vargas- La Guaira
Mensajes: 6.544
Re: Virus messenger

Hola,


La version del hijackthis que has colocado no es la correcta, pero sigamos con el SDFix.


Hazte lo siguiente:


Ir a Inicio >> Ejecutar y pegar lo siguiente:


Código:
rundll32 setupapi,InstallHinfSection DefaultInstall 128 %systemdrive%\SDFix\apps\Enable_Command_Prompt.inf

Reinicias en modo seguro e intentas corres el SDFix nuevamente


Salu2


Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog


* Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando.
* Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
* No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.
Responder Con Cita
  post #7  
Antiguo 03/10/08, 08:34:11
Usuario
 
Registrado: dic 2006
Ubicación: Colombia
Mensajes: 20
Re: Virus messenger

Buenos días

Al intentar hacer esto sale error de instalación
Responder Con Cita
  post #8  
Antiguo 03/10/08, 19:34:03
Usuario
 
Registrado: dic 2006
Ubicación: Colombia
Mensajes: 20
Re: Virus messenger

Buenas tardes, ejecuté el Malwarebytes' Anti-Malware y ahi si me dejó ejectuar el SDFix.. El siguiente es el reporte


SDFix: Version 1.230
Run by Administrador on 03/10/2008 at 05:25 p.m.

Microsoft Windows XP [Versi¢n 5.1.2600]
Running From: C:\Documents and Settings\Administrador.PERSONAL\Escritorio\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found
Responder Con Cita
  post #9  
Antiguo 04/10/08, 01:46:42
Avatar de Kirigi
Warrior
 
Registrado: jun 2007
Ubicación: Venezuela- Vargas- La Guaira
Mensajes: 6.544
Re: Virus messenger

Hola,

El reporte esta incompleto ya que lo debes pegar todo completo sin quitarle nada.

También hazte un scanner con Kaspersky Online y dejas su reporte acá


Salu2


Novedades del Foro | Antivirus Online | Eliminar Malwares | Políticas del Foro | Blog


* Ayúdanos haciendo una DONACIÓN para poder seguir Ayudando.
* Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
* No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.
Responder Con Cita
  post #10  
Antiguo 04/10/08, 14:19:04
Usuario
 
Registrado: dic 2006
Ubicación: Colombia
Mensajes: 20
Re: Virus messenger

Reporte SDFix


SDFix: Version 1.230
Run by Administrador on 03/10/2008 at 05:25 p.m.

Microsoft Windows XP [Versi¢n 5.1.2600]
Running From: C:\Documents and Settings\Administrador.PERSONAL\Escritorio\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-03 17:29:01
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
NVIDIA Remote Control Panel = NVAREM.EXE /S /Q /R /L /A1 /B0 /C0 /D2 /E0???????????????????????????????????????????????? ?????????????????????????????????????????????????? ?????????????????????????????????????????????????? ?????????????????????????? ????????? ?? ?????????????????? !"#$%&'

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Archivos de programa\\uTorrent\\utorrent.exe"="C:\\Archivos de programa\\uTorrent\\utorrent.exe:*:Enabled:æTorren t"
"C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe"="C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Archivos de programa\\MSN Messenger\\livecall.exe"="C:\\Archivos de programa\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Archivos de programa\\Internet Explorer\\iexplore.exe"="C:\\Archivos de programa\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Archivos de programa\\Conference\\Conference.dll"="C:\\Archivo s de programa\\Conference\\Conference.dll:*:Enabled:Aud io/Video Conference"
"C:\\Archivos de programa\\Ares\\Ares.exe"="C:\\Archivos de programa\\Ares\\Ares.exe:*:Enabled:Ares p2p for windows"
"C:\\Archivos de programa\\Mozilla Firefox\\FIREFOX.EXE"="C:\\Archivos de programa\\Mozilla Firefox\\FIREFOX.EXE:*:Enabled:Firefox"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe"="C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Archivos de programa\\MSN Messenger\\livecall.exe"="C:\\Archivos de programa\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files :



Files with Hidden Attributes :

Fri 3 Oct 2008 72 A..H. --- "C:\WINDOWS\system32\x10prod.sys"
Tue 16 Sep 2008 1,833,296 A.SHR --- "C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe"
Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Archivos de programa\Spybot - Search & Destroy\SDHelper.dll"
Sun 31 Aug 2003 857,600 A..H. --- "C:\Archivos Familiares\LUISA FDA\LOGISTICA\~WRL0002.tmp"
Thu 4 Sep 2008 146,944 ...H. --- "C:\Archivos Familiares\OSCAR\FOREX\~WRL0003.tmp"
Sun 10 Feb 2008 4,348 ..SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\DRMv1.bak"
Sun 6 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP25\A0022281.SYS"
Mon 7 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP25\A0022291.SYS"
Tue 8 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP25\A0022313.SYS"
Tue 8 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP25\A0022320.SYS"
Tue 8 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP25\A0022330.SYS"
Wed 9 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP25\A0022339.SYS"
Wed 9 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP25\A0022354.SYS"
Thu 10 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP25\A0022363.SYS"
Thu 10 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP25\A0022382.SYS"
Fri 11 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP25\A0022421.SYS"
Fri 11 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP25\A0022428.SYS"
Fri 11 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP25\A0022442.SYS"
Sat 12 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP26\A0022454.SYS"
Sat 12 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP26\A0022461.SYS"
Sat 12 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP26\A0022471.SYS"
Sun 13 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP26\A0022478.SYS"
Sun 13 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP26\A0022488.SYS"
Sun 13 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP26\A0022498.SYS"
Sun 13 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP26\A0022527.SYS"
Mon 14 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP26\A0022537.SYS"
Mon 14 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP26\A0022559.SYS"
Tue 15 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP26\A0022573.SYS"
Tue 15 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP27\A0022587.SYS"
Tue 15 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP27\A0022597.SYS"
Tue 15 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP27\A0022618.SYS"
Tue 15 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP27\A0022626.SYS"
Wed 16 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP27\A0022634.SYS"
Wed 16 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP28\A0022649.SYS"
Thu 17 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP28\A0022656.SYS"
Thu 17 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP28\A0022670.SYS"
Thu 17 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP28\A0022680.SYS"
Thu 17 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP28\A0022690.SYS"
Thu 17 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP28\A0022700.SYS"
Fri 18 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP29\A0022748.SYS"
Fri 18 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP29\A0022758.SYS"
Sat 19 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP29\A0022766.SYS"
Sat 19 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP29\A0022773.SYS"
Sun 20 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP29\A0022780.SYS"
Sun 20 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP30\A0022794.SYS"
Sun 20 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP30\A0022801.SYS"
Mon 21 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP30\A0022811.SYS"
Mon 21 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP30\A0022818.SYS"
Mon 21 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP30\A0022825.SYS"
Mon 21 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP31\A0022837.sys"
Tue 22 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP31\A0022848.sys"
Wed 23 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP32\A0022862.sys"
Wed 23 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP32\A0022869.sys"
Wed 23 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP32\A0022878.SYS"
Thu 24 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP32\A0022885.SYS"
Thu 24 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP32\A0022892.SYS"
Thu 24 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP32\A0022902.sys"
Thu 24 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP32\A0022914.sys"
Thu 24 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP32\A0022923.sys"
Fri 25 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP32\A0022930.sys"
Fri 25 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP33\A0022948.sys"
Fri 25 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP33\A0022956.SYS"
Sat 26 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP33\A0022964.SYS"
Sat 26 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP33\A0023002.SYS"
Sat 26 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP33\A0023050.SYS"
Sun 27 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP33\A0023061.SYS"
Mon 28 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP33\A0023069.SYS"
Mon 28 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP34\A0023085.SYS"
Mon 28 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP34\A0023096.SYS"
Mon 28 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP34\A0023105.SYS"
Tue 29 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP34\A0023112.SYS"
Tue 29 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP35\A0023249.SYS"
Wed 30 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP35\A0023269.SYS"
Wed 30 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP35\A0023282.SYS"
Wed 30 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP35\A0023293.SYS"
Wed 30 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP35\A0023308.SYS"
Wed 30 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP35\A0023331.SYS"
Thu 31 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP36\A0023341.SYS"
Thu 31 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP36\A0023351.SYS"
Thu 31 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP36\A0023368.SYS"
Thu 31 Jul 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP36\A0023378.SYS"
Fri 1 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP36\A0023388.SYS"
Fri 1 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP36\A0023398.SYS"
Fri 1 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP36\A0023413.SYS"
Fri 1 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP36\A0023472.SYS"
Sat 2 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP37\A0023484.SYS"
Sun 3 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0023529.SYS"
Sun 3 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0023542.SYS"
Sun 3 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0023549.sys"
Mon 4 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0023561.sys"
Tue 5 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0023619.SYS"
Mon 4 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0023573.SYS"
Mon 4 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0023580.SYS"
Mon 4 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0023594.SYS"
Tue 5 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0023603.SYS"
Wed 6 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0023642.SYS"
Wed 6 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0023652.SYS"
Thu 7 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0023667.SYS"
Thu 7 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0024670.SYS"
Thu 7 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0024679.SYS"
Thu 7 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0024689.SYS"
Thu 7 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0024696.SYS"
Thu 7 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0024704.SYS"
Fri 8 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0024713.SYS"
Fri 8 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0024740.SYS"
Sat 9 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0025743.SYS"
Sat 9 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP38\A0025750.SYS"
Sun 10 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP39\A0025769.SYS"
Mon 11 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP39\A0025776.SYS"
Mon 11 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP39\A0025785.SYS"
Mon 11 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP39\A0025796.sys"
Mon 11 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP39\A0025803.sys"
Tue 12 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP40\A0026806.SYS"
Tue 12 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP40\A0026849.SYS"
Wed 13 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP40\A0026856.sys"
Wed 13 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP40\A0026866.SYS"
Wed 13 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP40\A0026901.sys"
Wed 13 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP40\A0026908.sys"
Thu 14 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP40\A0026920.sys"
Thu 14 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP41\A0026941.sys"
Thu 14 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP41\A0026955.sys"
Fri 15 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP41\A0026967.sys"
Fri 15 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP41\A0026974.sys"
Fri 15 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP41\A0026984.SYS"
Fri 15 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP41\A0027985.SYS"
Fri 15 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP41\A0027990.sys"
Fri 15 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP41\A0028000.sys"
Fri 15 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP41\A0028017.SYS"
Fri 15 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP41\A0028029.sys"
Sat 16 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP41\A0028039.SYS"
Sat 16 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP41\A0028064.SYS"
Sun 17 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0028116.sys"
Sun 17 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0028136.SYS"
Mon 18 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0028165.sys"
Mon 18 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0028177.SYS"
Tue 19 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0029177.SYS"
Wed 20 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0029189.sys"
Wed 20 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0029264.SYS"
Wed 20 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0029199.sys"
Wed 20 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0029209.sys"
Wed 20 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0029215.sys"
Wed 20 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0029222.SYS"
Wed 20 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0029246.SYS"
Wed 20 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP42\A0029276.SYS"
Thu 21 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP43\A0030275.SYS"
Thu 21 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP43\A0030317.SYS"
Fri 22 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP44\A0030338.SYS"
Sat 23 Aug 2008 268,435,456 A.SH. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP44\A0031342.sys"
Fri 22 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP44\A0031351.SYS"
Sat 23 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP44\A0031367.SYS"
Sat 23 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP44\A0031383.SYS"
Sat 23 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP44\A0031408.SYS"
Sun 24 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP45\A0031439.sys"
Mon 25 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP45\A0031452.sys"
Mon 25 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP45\A0031460.sys"
Mon 25 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP45\A0031487.SYS"
Mon 25 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP45\A0031494.SYS"
Tue 26 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP46\A0031509.SYS"
Tue 26 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP46\A0031551.SYS"
Wed 27 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP46\A0031571.SYS"
Wed 27 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0031605.SYS"
Thu 28 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0031617.SYS"
Thu 28 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0031632.SYS"
Thu 28 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032681.SYS"
Thu 28 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032635.SYS"
Thu 28 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032648.SYS"
Thu 28 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032657.SYS"
Thu 28 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032664.SYS"
Thu 28 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032671.SYS"
Thu 28 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032688.SYS"
Fri 29 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032699.SYS"
Fri 29 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032716.SYS"
Sat 30 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032722.SYS"
Sat 30 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032729.SYS"
Sat 30 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032736.sys"
Sun 31 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032743.sys"
Sun 31 Aug 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032776.SYS"
Mon 1 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032783.sys"
Mon 1 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032793.sys"
Mon 1 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032800.sys"
Mon 1 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP47\A0032823.sys"
Wed 3 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0032931.sys"
Tue 2 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0032842.sys"
Tue 2 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0032850.sys"
Tue 2 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0032900.SYS"
Wed 3 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0032912.sys"
Wed 3 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0032922.sys"
Wed 3 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0032943.SYS"
Thu 4 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0032957.sys"
Thu 4 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0032976.sys"
Thu 4 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0033001.sys"
Thu 4 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0033023.sys"
Fri 5 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0033033.sys"
Fri 5 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0033052.sys"
Sat 6 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0033063.sys"
Sat 6 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP48\A0033082.sys"
Sat 6 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP49\A0033142.SYS"
Sun 7 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP49\A0033201.sys"
Mon 8 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP49\A0033212.sys"
Mon 8 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP49\A0033235.sys"
Mon 8 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP49\A0033303.SYS"
Tue 9 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP50\A0033320.sys"
Tue 9 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP50\A0033383.SYS"
Wed 10 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP51\A0033418.SYS"
Wed 10 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP51\A0033447.SYS"
Thu 11 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP52\A0033461.SYS"
Thu 11 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP52\A0034464.SYS"
Thu 11 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP52\A0034485.SYS"
Thu 11 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP52\A0034496.SYS"
Fri 12 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP52\A0034504.SYS"
Fri 12 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP52\A0034516.sys"
Sat 13 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP52\A0034533.sys"
Sun 14 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP52\A0035536.SYS"
Sun 14 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP52\A0035544.SYS"
Sun 14 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP52\A0035552.SYS"
Sun 14 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP52\A0035559.SYS"
Sun 14 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP53\A0035792.SYS"
Mon 15 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP53\A0035816.SYS"
Mon 15 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP53\A0035837.SYS"
Mon 15 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP53\A0035845.SYS"
Tue 16 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP54\A0035908.SYS"
Wed 17 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP55\A0036908.SYS"
Wed 17 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP55\A0036920.SYS"
Wed 17 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP55\A0036945.SYS"
Thu 18 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP55\A0036967.sys"
Fri 19 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP55\A0037030.sys"
Fri 19 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP55\A0037054.sys"
Sat 20 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP55\A0037063.SYS"
Sat 20 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP56\A0037122.SYS"
Sun 21 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP56\A0037170.SYS"
Mon 22 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP57\A0037227.sys"
Tue 23 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP57\A0037262.sys"
Tue 23 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP57\A0038265.SYS"
Tue 23 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP57\A0038357.sys"
Thu 25 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP58\A0038483.sys"
Wed 24 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP58\A0038448.sys"
Thu 25 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP58\A0038560.sys"
Thu 25 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP58\A0038567.sys"
Fri 26 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP58\A0039570.SYS"
Fri 26 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP59\A0040570.SYS"
Fri 26 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP59\A0040585.sys"
Fri 26 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP59\A0040608.sys"
Sat 27 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP59\A0040696.sys"
Sat 27 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP60\A0040768.sys"
Sun 28 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP60\A0040830.sys"
Mon 29 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP60\A0040856.SYS"
Mon 29 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP60\A0040842.sys"
Mon 29 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP60\A0040873.sys"
Mon 29 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP60\A0040880.sys"
Tue 30 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0040902.sys"
Tue 30 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0040923.sys"
Tue 30 Sep 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0040936.sys"
Wed 1 Oct 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0040944.SYS"
Wed 1 Oct 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0040952.SYS"
Wed 1 Oct 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0040982.SYS"
Wed 1 Oct 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0041186.sys"
Thu 2 Oct 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0041206.SYS"
Thu 2 Oct 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0041239.SYS"
Thu 2 Oct 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0041273.SYS"
Thu 2 Oct 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0041297.SYS"
Thu 2 Oct 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0041312.sys"
Fri 3 Oct 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0041328.sys"
Fri 3 Oct 2008 72 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0041393.sys"
Wed 17 Sep 2008 262,144 A..H. --- "C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP56\snapshot\_REGISTRY_USER_NTUSER_ S-1-5-21-2025429265-1085031214-839522115-1010.bak"
Thu 19 Oct 2006 113,664 A..H. --- "C:\Archivos Familiares\LUISA FDA\SENA\Sistemas de informaci¢n en los centros de distribuci¢n\SEMANA 2\~WRL0003.tmp"
Thu 19 Oct 2006 113,664 A..H. --- "C:\Archivos Familiares\LUISA FDA\SENA\Sistemas de informaci¢n en los centros de distribuci¢n\SEMANA 2\~WRL0005.tmp"
Mon 5 Feb 2007 154,624 A..H. --- "C:\Archivos Familiares\LUISA FDA\SENA\INGLES\Semana 1\~WRL0329.tmp"

Finished!




*****************************************

kaspersky:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER INFORME
sábado, 04 de octubre de 2008 9:28:45
Sistema operativo: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner versión: 5.0.98.0
Ultima actualización: 4/10/2008
Registros en la base antivirus: 1289130
-------------------------------------------------------------------------------

Configuración del análisis:
Analizar usando las siguientes bases: estendidas
Analizar archivos: verdadero
Analizar bases de correo: verdadero

Objetivo a analizar - Mi PC:
A:\
C:\
D:\
E:\
F:\

Estadísticas:
Número de objeros analizados: 60438
Virus encontrados: 3
Objetos infectados: 2
Objetos sospechosos: 3
Duración del análisis: 01:35:01

Bombre del objeto infectado / Nombre del virus / Última acción
C:\WINDOWS\system32\config\SECURITY Object is locked saltado
C:\WINDOWS\system32\config\SAM Object is locked saltado
C:\WINDOWS\system32\config\SAM.LOG Object is locked saltado
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked saltado
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked saltado
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked saltado
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked saltado
C:\WINDOWS\system32\config\SYSTEM Object is locked saltado
C:\WINDOWS\system32\config\SOFTWARE Object is locked saltado
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked saltado
C:\WINDOWS\system32\config\DEFAULT Object is locked saltado
C:\WINDOWS\system32\config\system.LOG Object is locked saltado
C:\WINDOWS\system32\config\software.LOG Object is locked saltado
C:\WINDOWS\system32\config\default.LOG Object is locked saltado
C:\WINDOWS\system32\drivers\atapi.sys Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked saltado
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked saltado
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked saltado
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked saltado
C:\WINDOWS\system32\CatRoot2\edbtmp.log Object is locked saltado
C:\WINDOWS\system32\h323log.txt Object is locked saltado
C:\WINDOWS\Temp\Perflib_Perfdata_4e8.dat Object is locked saltado
C:\WINDOWS\Temp\etilqs_tl6RE4O80fFDfB30SdWw Object is locked saltado
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked saltado
C:\WINDOWS\Temp\_avast4_\unp105188462.tmp Object is locked saltado
C:\WINDOWS\Debug\PASSWD.LOG Object is locked saltado
C:\WINDOWS\WindowsUpdate.log Object is locked saltado
C:\WINDOWS\Sti_Trace.log Object is locked saltado
C:\WINDOWS\wiaservc.log Object is locked saltado
C:\WINDOWS\wiadebug.log Object is locked saltado
C:\WINDOWS\SchedLgU.Txt Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\2aeaf54e7 e4b5f583622470fe7c5fdef\backup\ocmanage.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\2aeaf54e7 e4b5f583622470fe7c5fdef\backup\pcl4res.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\2aeaf54e7 e4b5f583622470fe7c5fdef\backup\progman.exe Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\2aeaf54e7 e4b5f583622470fe7c5fdef\backup\regsvr32.exe Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\2aeaf54e7 e4b5f583622470fe7c5fdef\backup\telnet.exe Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\xptht19w.htm Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\xptht16w.htm Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\xptht14w.htm Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\xptht13w.htm Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\xpprint.wav Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\xpnotify.wav Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\sysrestw.chm Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\stdnames.gpd Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\sqloledb.rll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\smartnav.js Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\slbcsp.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\cnbjmon.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\wshrm.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\wlan_bmu.xsd Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\srchctls.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\6to4svc.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\snmp.exe Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\lang\chtskf.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\lang\imjpcus.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\lang\pintlgc.imd Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\lang\pintlgl.imd Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\sffp_sd.sys Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\mmc30r.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\tscinst.vbs Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\utopiawi.wav Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\spru0c0a.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\mmcex.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\msdtctm.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\mfc42u.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\wuapi.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\nt5.cat Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\quartz.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\msi.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\apps_sp.chm Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\cscomp.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\ntkrnlmp.exe Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\system.design.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\shell32.dll Object is locked saltado
C:\WINDOWS\SoftwareDistribution\Download\7564047df 60fd0079d87159ef3eed933\xpstartu.wav Object is locked saltado
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\tmp .edb Object is locked saltado
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb .log Object is locked saltado
C:\WINDOWS\SoftwareDistribution\DataStore\DataStor e.edb Object is locked saltado
C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked saltado
C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked saltado
C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked saltado
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked saltado
C:\Documents and Settings\NetworkService.NT AUTHORITY\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado
C:\Documents and Settings\NetworkService.NT AUTHORITY\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked saltado
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked saltado
C:\Documents and Settings\LocalService.NT AUTHORITY\Configuración local\Historial\History.IE5\index.dat Object is locked saltado
C:\Documents and Settings\LocalService.NT AUTHORITY\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked saltado
C:\Documents and Settings\LocalService.NT AUTHORITY\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado
C:\Documents and Settings\LocalService.NT AUTHORITY\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked saltado
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\NTUSER.DAT Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Historial\History.IE5\index.dat Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Historial\History.IE5\MSHist0120081004200810 05\index.dat Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Ares\My Shared Folder\per antivirus 9 8 cracked by the dark of msn hacker.exe/INSTALA1.BIN/PAV.EXE Sospechosos: Password-protected-EXE saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Ares\My Shared Folder\per antivirus 9 8 cracked by the dark of msn hacker.exe/INSTALA1.BIN Sospechosos: Password-protected-EXE saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Ares\My Shared Folder\per antivirus 9 8 cracked by the dark of msn hacker.exe ZIP: sospechoso - 2 saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \Cache\_CACHE_MAP_ Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \Cache\_CACHE_001_ Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \Cache\_CACHE_002_ Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \Cache\_CACHE_003_ Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \urlclassifier3.sqlite Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Apple Computer\QuickTime\downloads\03\14\3ee13a93-daf6a7d9-6dce7c55-53fe6614.qtch Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Apple Computer\QuickTime\downloads\07\13\7d72bc60-a5cb7666-02cc79fc-1f8c7337.qtch Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Ahead\Nero Home\bl.db Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Ahead\Nero Home\is2.db Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Identities\{F792A2DF-CBA7-48D3-A6D5-DDF06FA0EB65}\Microsoft\Outlook Express\Folders.dbx Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Configuración local\Datos de programa\Identities\{F792A2DF-CBA7-48D3-A6D5-DDF06FA0EB65}\Microsoft\Outlook Express\Offline.dbx Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Cookies\index.dat Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \parent.lock Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \cert8.db Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \key3.db Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \permissions.sqlite Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \places.sqlite-journal Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \places.sqlite Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \cookies.sqlite Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \formhistory.sqlite Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \content-prefs.sqlite Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \search.sqlite Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Datos de programa\Mozilla\Firefox\Profiles\3aaqho8w.default \downloads.sqlite Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\Datos de programa\SUPERAntiSpyware.com\SUPERAntiSpyware\App Logs\SUPERANTISPYWARE-10-4-2008( 7-31-40 ).SDB Object is locked saltado
C:\Documents and Settings\Administrador.PERSONAL\ntuser.dat.LOG Object is locked saltado
C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0041223.exe Infectados: Worm.Win32.AutoRun.pvr saltado
C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP61\A0041392.dll Infectados: Trojan-Downloader.Win32.Injecter.aqh saltado
C:\System Volume Information\_restore{E2266D5C-316A-4702-ACCD-3289F5CAF004}\RP62\change.log Object is locked saltado
C:\Archivos de programa\Alwil Software\Avast4\DATA\report\Protección residente.txt Object is locked saltado
C:\Archivos de programa\Alwil Software\Avast4\DATA\log\selfdef.log Object is locked saltado
C:\Archivos de programa\Alwil Software\Avast4\DATA\log\nshield.log Object is locked saltado
C:\Archivos de programa\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked saltado
C:\Archivos de programa\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked saltado
C:\Archivos de programa\Alwil Software\Avast4\DATA\aswResp.dat Object is locked saltado
C:\Archivos de programa\Alwil Software\Avast4\DATA\Avast4.db Object is locked saltado

Análisis completado.
Responder Con Cita
Respuesta

Herramientas

Reglas del foro
No puedes crear nuevos temas
No puedes responder temas
No puedes subir adjuntos
No puedes editar tus mensajes

BB code is activado
Las caritas están activado
Código [IMG] está activado
Código HTML está desactivado
Trackbacks are desactivado
Pingbacks are activado
Refbacks are activado


Temas Similares
Tema Autor Foro Respuestas Último mensaje
virus avpo0.dll (Solucionado) jonalara Temas Solucionados 28 05/12/07 01:27:53
ventanas emergentes de Internet explorer..(Solucionado) misbel Temas Solucionados 9 21/05/07 16:40:00
P2P-Worm.Win32.VB.dw tav Foro de Virus y Spywares 5 20/01/07 14:01:29
Zulú, virus made in Argentina (entrevista a fondo) skiavi Off-Topic 6 16/12/06 04:15:56
problema con el vroomsearch dasanlos Foro Oficial de HijackThis en español 5 05/05/05 12:31:01




Todas las horas son GMT -4. La hora es 02:34:35.


 

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31