• Registrarse
  • Iniciar sesión


  • Página 1 de 2 12 ÚltimoÚltimo
    Resultados 1 al 10 de 16

    Múltiples problemas, errores de .dll, pant. azules y desconexiones. (Solucionado)

    Resumen del tema: Múltiples problemas, errores de .dll, pant. azules y desconexiones. (Solucionado) - Bueno, abro el tema para buscar una solución frente a los diversos problemas encontrados; he hecho los pasos para una limpieza total y con el SUPERAntiSpyware eliminé 61 amenazas, lo cual no fue suficiente. Error ...

      
    1. #1
      Usuario Avatar de Freddie90
      Registrado
      oct 2008
      Ubicación
      Montevideo, Uruguay
      Mensajes
      8

      Múltiples problemas, errores de .dll, pant. azules y desconexiones. (Solucionado)

      Bueno, abro el tema para buscar una solución frente a los diversos problemas encontrados; he hecho los pasos para una limpieza total y con el SUPERAntiSpyware eliminé 61 amenazas, lo cual no fue suficiente.

      Error 1: svchost.exe, Error de aplicación, la instrucción en "0x7c9200e8" hace referencia a "0x00000000", la memoria no se puede "read", le hago click en Cancelar dos veces (a veces, la instrucción es "0x00000000".

      Error 2: A veces un archivo me salta con error de .dll y sale desconfigurado (como Advanced System Care).

      Error 3: El mIRC reinicia su configuración, en ciertas ocasiones.

      Error 4: El error de nmsrvc.exe salta también, llega a un momento en el que el teclado no funciona, no hay nada en inicio (las carpetas están, pero no tienen nada, están vacías), al querer abrir el Administrador de Tareas me salta un error de que no hay suficiente memoria y tengo que reiniciar.

      Error 5: De vez en cuando me salta la pantalla azul reiniciándose al instante, y si mal no recuerdo, el mensaje "DRIVER_IRQL_NOT_EQUAL_OR_LESS" aparece como razón, me han dicho que debo actualizar el driver de Nvidia pero cuando lo bajo de FileHippo u otro lugar lo bajo correctamente, pero al instalar me tira el error 7Zip, sin poder instalar.

      Error 6: Llega un momento en el que la internet se corta de repente y tengo que reiniciar para poder volver a entrar.

      Error 7: Activé Act. Automáticas para poder ver si podía arreglar el error de svchost.exe, y a veces me aparece para instalar, pero todo falla.

      Error 8: El driver de sonido a veces anda, a veces no, funciona cuando quiere.

      Error 9: Al intentar iniciar el Audio de Windows a través de services.msc, aparece una ventana blanca sin poder clickear nada.

      Error 10: Opciones de Internet no abre.

      Esto empezó a suceder probablemente luego de haber usado el Spybot Search and Destroy, donde borró aproximadamente 24 amenazas, y restauró configuraciones, quise hacer un backup pero no tenía el espacio suficiente y seguí adelante, cuando quería detener el proceso de Actualización Automática, me aparecía una ventana blanca y no podía hacer nada.

      Ah, y al escanear, me saltaron dos errores #5, ¿pasa algo también con el HijackThis?

      LOG:

      Logfile of Trend Micro HijackThis v2.0.4
      Scan saved at 00:34:36, on 24/09/2010
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18372)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\SYSTEM32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\ctfmon.exe
      D:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe
      C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\WINDOWS\RTHDCPL.EXE
      D:\Archivos de programa\DAEMON Tools Lite\daemon.exe
      C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
      C:\Archivos de programa\Messenger\msmsgs.exe
      C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe
      C:\Archivos de programa\Java\jre6\bin\jqs.exe
      C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\PnkBstrA.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Update\1.2.183.29\GoogleCrashHandler.exe
      D:\Archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\WINDOWS\system32\PnkBstrB.exe
      C:\WINDOWS\System32\snmp.exe
      D:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\WINDOWS\system32\msiexec.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Documents and Settings\Facerplast\Datos de programa\mIRC\mirc.exe
      C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\wuauclt.exe
      D:\Archivos de programa\Trend Micro\HiJackThis\HiJackThis.exe
      C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe
      C:\Archivos de programa\Mozilla Firefox 3.6 Beta 3\firefox.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://windiwsfsearch.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2233703
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
      O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Archivos de programa\Windows Live\Messenger\wlchtc.dll
      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll
      O2 - BHO: Windows Live Aplicaci? auxiliar de inicio de sesi? - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Archivos de programa\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Archivos de programa\Megaupload\Mega Manager\MegaIEMn.dll
      O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - D:\Archivos de programa\Ask.com\GenericAskToolbar.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Archivos de programa\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Archivos de programa\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: Bandoo IE Plugin - {EB5CEE80-030A-4ED8-8E20-454E9C68380F} - (no file)
      O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
      O3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - D:\ARCHIV~1\TEXTAL~1\TAForIE.dll
      O3 - Toolbar: AnchorFree Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - D:\Archivos de programa\Ask.com\GenericAskToolbar.dll
      O4 - HKLM\..\Run: [GrooveMonitor] "D:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe"
      O4 - HKLM\..\Run: [egui] "C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
      O4 - HKLM\..\Run: [nwiz] C:\Archivos de programa\NVIDIA Corporation\nView\nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Archivos de programa\DAEMON Tools Lite\daemon.exe" -autorun
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [ares] "D:\Archivos de programa\Ares\Ares.exe" -h
      O4 - HKCU\..\Run: [uTorrent] "D:\Archivos de programa\uTorrent\uTorrent.exe"
      O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe" /c
      O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O4 - HKUS\S-1-5-21-2052111302-1035525444-839522115-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
      O4 - HKUS\S-1-5-21-2052111302-1035525444-839522115-1003\..\Run: [DAEMON Tools Lite] "D:\Archivos de programa\DAEMON Tools Lite\daemon.exe" -autorun (User '?')
      O4 - HKUS\S-1-5-21-2052111302-1035525444-839522115-1003\..\Run: [MsnMsgr] "C:\Archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" /background (User '?')
      O4 - HKUS\S-1-5-21-2052111302-1035525444-839522115-1003\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background (User '?')
      O4 - HKUS\S-1-5-21-2052111302-1035525444-839522115-1003\..\Run: [ares] "D:\Archivos de programa\Ares\Ares.exe" -h (User '?')
      O4 - HKUS\S-1-5-21-2052111302-1035525444-839522115-1003\..\Run: [uTorrent] "D:\Archivos de programa\uTorrent\uTorrent.exe" (User '?')
      O4 - HKUS\S-1-5-21-2052111302-1035525444-839522115-1003\..\Run: [Google Update] "C:\Documents and Settings\Facerplast\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe" /c (User '?')
      O4 - HKUS\S-1-5-21-2052111302-1035525444-839522115-1003\..\Run: [SUPERAntiSpyware] D:\Archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe (User '?')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O8 - Extra context menu item: &Search - ?p=ZKfox000
      O8 - Extra context menu item: E&xportar a Microsoft Excel - res://D:\ARCHIV~1\MICROS~1\Office12\EXCEL.EXE/3000
      O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\ARCHIV~1\MICROS~1\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\ARCHIV~1\MICROS~1\Office12\ONBttnIE.dll
      O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\ARCHIV~1\MICROS~1\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Archivos de programa\PokerStars.NET\PokerStarsUpdate.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/ES-MX/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228573275609
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O17 - HKLM\System\CS7\Services\Tcpip\..\{09D1F545-40C8-4D55-AD0A-1116CDE060C7}: NameServer = 200.40.220.245 200.40.30.245
      O17 - HKLM\System\CS10\Services\Tcpip\..\{09D1F545-40C8-4D55-AD0A-1116CDE060C7}: NameServer = 200.40.220.245 200.40.30.245
      O17 - HKLM\System\CS11\Services\Tcpip\..\{09D1F545-40C8-4D55-AD0A-1116CDE060C7}: NameServer = 200.40.220.245 200.40.30.245
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Archivos de programa\Microsoft Office\Office12\GrooveSystemServices.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARCHIV~1\ARCHIV~1\Skype\SKYPE4~1.DLL
      O20 - Winlogon Notify: !SASWinLogon - D:\Archivos de programa\SUPERAntiSpyware\SASWINLO.DLL
      O22 - SharedTaskScheduler: Precargador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
      O22 - SharedTaskScheduler: Demonio de caché de las categorías de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
      O23 - Service: Apache2.2 - Unknown owner - D:\xampp\apache\bin\apache.exe (file missing)
      O23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - C:\Archivos de programa\Ares\chatServer.exe (file missing)
      O23 - Service: Servicio del administrador de discos lógicos (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
      O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Archivos de programa\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
      O23 - Service: ESET Service (ekrn) - ESET - C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe
      O23 - Service: Registro de sucesos (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
      O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Archivos de programa\Archivos comunes\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Servicio COM de grabación de CD de IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Archivos de programa\Java\jre6\bin\jqs.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Plug and Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
      O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
      O23 - Service: Administrador de sesión de Ayuda de escritorio remoto (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
      O23 - Service: Tarjeta inteligente (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
      O23 - Service: Protocolo simple de transferencia de correo (SMTP) (SMTPSVC) - Unknown owner - C:\WINDOWS\system32\inetsrv\inetinfo.exe
      O23 - Service: Servicio SNMP (SNMP) - Unknown owner - C:\WINDOWS\System32\snmp.exe
      O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
      O23 - Service: Instantáneas de volumen (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
      O23 - Service: wampapache - Apache Software Foundation - D:\wamp\bin\apache\apache2.2.11\bin\httpd.exe
      O23 - Service: wampmysqld - Unknown owner - D:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe
      O23 - Service: Adaptador de rendimiento de WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
      O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/FACERP~1/CONFIG~1/Temp/msohtml1/01/clip_image002.jpg

      --
      End of file - 15932 bytes
      Espero poder encontrar junto a ustedes una solución, esto me está complicando el uso de la computadora :/, gracias de antemano.

      Por cierto, disculpen que ande agregando errores, trato de recordar todos.
      Última edición por Freddie90 fecha: 24/09/10 a las 02:17:18

    2. #2
      Moderador Gral.
      Avatar de Damianl_77
      Registrado
      ene 2008
      Ubicación
      Argentina
      Mensajes
      22.895

      Re: Múltiples problemas, errores de .dll, pant. azules y desconexiones.

      Hola Freddie90 bienvenid@ al foro de InfoSpyware

      Antes que nada intenta usar restaurar sistema:
      Inicio--->todos los programas---->accesorios---->herramientas del sistema---->restaurar sistema. busca un punto donde la PC funcionaba con normalidad.

      2: SpyBot trae Back Up!
      MANUAL DE USO DE Spybot S&D

      Salu2!

      Blog | Antivirus Online | Eliminar Malwares | Antivirus Gratis


      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    3. #3
      Usuario Avatar de Freddie90
      Registrado
      oct 2008
      Ubicación
      Montevideo, Uruguay
      Mensajes
      8

      Re: Múltiples problemas, errores de .dll, pant. azules y desconexiones.

      Gracias por la bienvenida.

      Ahora, al grano:

      Recuperé los archivos (como MyWebSearch o FunWebSearch o algo así) de SpyBot, y los errores 1, 4, 6, y 7 de momento no están apareciendo, pero los demás problemas persisten (igual no puedo fijarme mucho en este momento ya que me voy de viaje por el fin de semana), pero trataré de aparecer cuando pueda en este fin de semana.

      Edito: Luego de horas, me salta error de aplicación de svchost.exe. "La instrucción en "0x56cd7803" hace referencia a la memoria en "0x56cd7803". La memoria no se puede "written".
      Última edición por Freddie90 fecha: 24/09/10 a las 14:44:57

    4. #4
      Moderador Gral.
      Avatar de Damianl_77
      Registrado
      ene 2008
      Ubicación
      Argentina
      Mensajes
      22.895

      Re: Múltiples problemas, errores de .dll, pant. azules y desconexiones.

      Podes tener la Memoria dañada

      Pero antes veamos si el problema es por malwares

      Descarga Actualiza y Ejecuta en Modo Completo MalwareBytes-anti malware (leer manual) Manda a cuarentena lo detectado por MalwareBytes para luego poder eliminarlo, apretando en el botón ver resultados/ quitar seleccionado. Luego de reiniciar la PC en la pestaña registros abrí el log para copiar y pegar en este tema.


      Descarga CCleaner y ejecútalo usando primero su opción de "Limpiador" para borrar cookies, temporales de Internet y todos los archivos que este te muestre como obsoletos, y luego usa su opción de "Registro" para limpiar todo el registro de Windows (haciendo copia de seguridad).


      - Descarga la herramienta ComboFix.exe y guárdala en el escritorio.
      • Desactiva temporalmente el Antivirus y/o Antispyware.
      • Cierra todas las ventanas abiertas.
      • Haz doble clic al archivo ComboFix.exe y sigue las instrucciones.
      • Cuando termine, generará un registro en C:\ComboFix.txt.
        • *Nota* Mientras CF este trabajando no mover el mouse ya que pararía su proceso.
        • *Nota* ComboFix puede reiniciar automáticamente el PC para completar el proceso de eliminación.

      • pega el reporte de C:\ComboFix.txt en este mismo mensaje junto al reporte de MalwareBytes.


      Saludos

      Blog | Antivirus Online | Eliminar Malwares | Antivirus Gratis


      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    5. #5
      Usuario Avatar de Freddie90
      Registrado
      oct 2008
      Ubicación
      Montevideo, Uruguay
      Mensajes
      8

      Re: Múltiples problemas, errores de .dll, pant. azules y desconexiones.

      Ok, aquí los logs:
      Cita Originalmente publicado por Malwarebytes
      Malwarebytes' Anti-Malware 1.46
      www.malwarebytes.org

      Versión de la Base de Datos: 4700

      Windows 5.1.2600 Service Pack 3
      Internet Explorer 8.0.6001.18372

      26/09/2010 2254
      mbam-log-2010-09-26 (22-10-54).txt

      Tipos de Análisis: Análisis Completo (C:\|D:\|)
      Objetos examinados: 424764
      Tiempo transcurrido: 1 hora(s), 58 minuto(s), 49 segundo(s)

      Procesos en Memoria Infectados: 0
      Módulos de Memoria Infectados: 0
      Claves del Registro Infectadas: 25
      Valores del Registro Infectados: 5
      Elementos de Datos del Registro Infectados: 6
      Carpetas Infectadas: 1
      Archivos Infectados: 2

      Procesos en Memoria Infectados:
      (No se han detectado elementos maliciosos)

      Módulos de Memoria Infectados:
      (No se han detectado elementos maliciosos)

      Claves del Registro Infectadas:
      HKEY_CLASSES_ROOT\Typelib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

      Valores del Registro Infectados:
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.

      Elementos de Datos del Registro Infectados:
      HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\Homepage (Hijack.Homepage) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.SearchPage) -> Bad: (http://windiwsfsearch.com/search?q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.SearchPage) -> Bad: (http://windiwsfsearch.com/search?q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\(default) (Hijack.SearchPage) -> Bad: (http://windiwsfsearch.com/search?q=%s) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.SearchPage) -> Bad: (http://windiwsfsearch.com) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.

      Carpetas Infectadas:
      C:\WINDOWS\system32\675873 (Trojan.BHO) -> Quarantined and deleted successfully.

      Archivos Infectados:
      D:\Pokémon Platinum\No$gba\NOZ_EN.exe (Spyware.Passwords) -> Quarantined and deleted successfully.
      D:\pokemonplatinum\NO$GBA_2.6a\No$Zoomer\HERRAMIENTAS\NDS Top System 0.2\NDS Top System.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
      ...y también:
      Cita Originalmente publicado por Combofix
      ComboFix 10-09-25.07 - Facerplast 26/09/2010 22:43:05.2.2 - x86
      Running from: c:\documents and settings\Facerplast\Escritorio\ComboFix.exe
      * Created a new restore point
      * Resident AV is active

      .
      ADS - WINDOWS: deleted 24 bytes in 1 streams.

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\Autorun.inf
      C:\Documents
      C:\Thumbs.db
      c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
      c:\windows\Fonts\Pokemon Unown GB.fon
      c:\windows\My.ini
      c:\windows\system32\_000010_.tmp.dll
      c:\windows\system32\3577332.dll
      c:\windows\system32\keylog.txt
      c:\windows\system32\pe.dll
      c:\windows\system32\Thumbs.db

      c:\windows\system32\midimap.dll . . . is infected!!

      .
      ((((((((((((((((((((((((( Files Created from 2010-08-27 to 2010-09-27 )))))))))))))))))))))))))))))))
      .

      2010-09-26 23:02 . 2010-09-26 23:02 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Malwarebytes
      2010-09-26 23:01 . 2010-04-29 18:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
      2010-09-26 23:01 . 2010-09-26 23:01 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Malwarebytes
      2010-09-26 23:01 . 2010-04-29 18:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
      2010-09-26 23:01 . 2010-09-26 23:01 -------- dc----w- d:\archivos de programa\Malwarebytes' Anti-Malware
      2010-09-24 16:11 . 2010-09-24 16:11 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR
      2010-09-24 16:11 . 2008-08-02 08:39 837576 ----a-w- c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\megauper.exe
      2010-09-24 03:29 . 2010-09-24 03:29 388096 ----a-r- c:\documents and settings\Facerplast\Datos de programa\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
      2010-09-24 03:29 . 2010-09-24 03:29 -------- dc----w- d:\archivos de programa\Trend Micro
      2010-09-23 22:20 . 2010-06-30 03:13 52224 ----a-w- c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
      2010-09-23 22:20 . 2010-06-30 03:13 101376 ----a-w- c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
      2010-09-22 04:08 . 2010-09-22 04:08 63488 ----a-w- c:\documents and settings\Facerplast\Datos de programa\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
      2010-09-22 04:08 . 2010-09-22 04:08 52224 ----a-w- c:\documents and settings\Facerplast\Datos de programa\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
      2010-09-22 04:08 . 2010-09-22 04:08 117760 ----a-w- c:\documents and settings\Facerplast\Datos de programa\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
      2010-09-22 04:06 . 2010-09-22 04:06 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\SUPERAntiSpyware.com
      2010-09-22 04:06 . 2010-09-22 04:06 -------- d-----w- c:\documents and settings\All Users\Datos de programa\SUPERAntiSpyware.com
      2010-09-22 04:06 . 2010-09-22 04:06 -------- dc----w- d:\archivos de programa\SUPERAntiSpyware
      2010-09-22 04:06 . 2010-09-22 04:06 -------- dc----w- d:\archivos de programa\SpywareBlaster
      2010-09-21 13:48 . 2010-09-21 13:48 -------- dc----w- d:\archivos de programa\MSXML 4.0
      2010-09-21 08:39 . 2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
      2010-09-21 08:39 . 2010-09-21 08:39 -------- dc----w- d:\archivos de programa\Realtek
      2010-09-19 06:36 . 2009-11-21 15:58 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
      2010-09-19 06:34 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
      2010-09-18 03:20 . 2010-09-08 14:04 114360 ----a-w- c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
      2010-09-12 18:35 . 2010-07-30 14:37 3184800 ----a-w- c:\documents and settings\Facerplast\Datos de programa\mIRC\mirc.exe
      2010-09-05 01:04 . 2010-09-05 01:04 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\netz
      2010-09-04 23:07 . 2010-09-04 23:07 -------- dc----w- d:\archivos de programa\VID_0E8F&PID_0003
      2010-09-04 23:07 . 2006-04-28 16:33 9216 ----a-w- c:\windows\system32\drivers\GF0003.sys
      2010-09-04 23:07 . 2010-09-04 23:07 -------- d-----w- c:\archivos de programa\Archivos comunes\VID_0E8F&PID_0003
      2010-09-02 13:16 . 2010-09-19 01:34 -------- dc----w- d:\archivos de programa\Ask.com
      2010-08-31 17:55 . 2010-09-25 13:27 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Spybot - Search & Destroy
      2010-08-31 17:55 . 2010-09-24 16:09 -------- dc----w- d:\archivos de programa\Spybot - Search & Destroy
      2010-08-31 13:59 . 2010-08-31 13:59 -------- d-----w- c:\documents and settings\All Users\Datos de programa\WNR
      2010-08-31 13:58 . 2010-08-31 13:58 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\WNR
      2010-08-31 01:07 . 2010-08-31 01:07 -------- dc----w- d:\archivos de programa\Microsoft Silverlight
      2010-08-30 11:34 . 2010-08-30 11:31 178176 ----a-w- c:\windows\system32\wbemdisp.dll
      2010-08-29 16:55 . 2010-08-29 16:55 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\SynthMaker
      2010-08-29 12:59 . 2010-08-30 13:27 -------- dc----w- d:\archivos de programa\Acoustica Shared Effects
      2010-08-29 12:58 . 2010-08-30 10:19 -------- dc----w- d:\archivos de programa\Acoustica Mixcraft 5

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-09-27 01:30 . 2008-08-01 05:16 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\uTorrent
      2010-09-27 00:56 . 2008-09-05 21:51 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\mIRC
      2010-09-26 22:54 . 2008-07-28 23:04 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Google Updater
      2010-09-23 18:53 . 2009-04-13 05:04 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Microsoft Help
      2010-09-23 18:49 . 2004-08-20 12:00 94648 ----a-w- c:\windows\system32\perfc00A.dat
      2010-09-23 18:49 . 2004-08-20 12:00 509142 ----a-w- c:\windows\system32\perfh00A.dat
      2010-09-23 14:15 . 2009-05-16 13:37 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\MessengerDiscovery 2
      2010-09-23 03:25 . 2008-08-30 12:09 401304 ---ha-w- c:\windows\system32\mlfcache.dat
      2010-09-22 09:24 . 2009-07-24 23:09 620664 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
      2010-09-22 04:05 . 2010-03-18 04:01 -------- dc----w- d:\archivos de programa\CCleaner
      2010-09-21 08:57 . 2010-04-09 17:55 -------- dc----w- d:\archivos de programa\Total Video Converter
      2010-09-21 08:57 . 2010-07-05 13:10 -------- dc----w- d:\archivos de programa\TextAloud
      2010-09-19 08:42 . 2009-12-19 12:11 -------- dc----w- d:\archivos de programa\Garena
      2010-09-19 07:54 . 2010-05-22 08:34 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Mipony
      2010-09-19 01:37 . 2010-06-18 00:04 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Facebook
      2010-09-19 01:34 . 2010-01-03 11:36 -------- dc----w- d:\archivos de programa\Rockstar
      2010-09-19 01:34 . 2010-02-10 03:58 -------- dc----w- d:\archivos de programa\CamStudio
      2010-09-19 01:34 . 2010-03-28 04:33 -------- dc----w- d:\archivos de programa\Avi
      2010-09-19 01:34 . 2008-12-03 20:13 -------- d-----w- d:\archivos de programa\GameSpy Arcade
      2010-09-19 01:34 . 2010-07-06 11:03 -------- dc----w- d:\archivos de programa\AV Vcs 6.0 DIAMOND
      2010-09-19 01:30 . 2009-11-10 05:22 -------- dc----w- d:\archivos de programa\Inkscape
      2010-09-17 17:31 . 2009-06-13 22:54 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Winamp
      2010-09-14 22:05 . 2009-11-16 14:28 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Rosetta Stone
      2010-09-12 20:40 . 2010-06-04 14:15 -------- dc----w- d:\archivos de programa\wamp
      2010-09-12 10:09 . 2008-09-03 18:03 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Skype
      2010-09-12 06:11 . 2008-09-03 18:04 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\skypePM
      2010-09-06 06:46 . 2009-05-15 22:03 81920 ----a-w- c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\npNxGameeu.dll
      2010-09-06 06:46 . 2009-05-15 22:03 98304 -c--a-w- c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\nxgameeu.dll
      2010-09-06 06:46 . 2009-05-15 22:03 331776 ----a-w- c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\NGMResource.dll
      2010-09-06 06:46 . 2009-05-15 22:03 258352 -c--a-w- c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\unicows.dll
      2010-09-06 06:46 . 2009-05-15 22:02 532480 ----a-w- c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\NGMDll.dll
      2010-09-06 06:46 . 2009-05-15 22:02 155648 ----a-w- c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\NGM.exe
      2010-09-06 06:45 . 2009-05-15 14:23 421888 -c--a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe
      2010-09-04 23:07 . 2010-06-24 02:47 -------- dc-h--w- d:\archivos de programa\InstallShield Installation Information
      2010-08-30 10:19 . 2010-08-09 04:18 -------- dc----w- d:\archivos de programa\Livestream Procaster
      2010-08-30 10:19 . 2010-07-21 08:08 -------- dc----w- d:\archivos de programa\Chess3D
      2010-08-30 10:19 . 2010-02-05 00:08 -------- dc----w- d:\archivos de programa\Metin2
      2010-08-30 10:19 . 2010-06-20 03:47 -------- dc----w- d:\archivos de programa\TrucoTec 2008 V400
      2010-08-30 10:19 . 2010-03-29 04:40 -------- dc----w- d:\archivos de programa\uTorrent
      2010-08-29 16:36 . 2009-08-06 19:33 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Acoustica
      2010-08-29 13:01 . 2009-08-06 19:34 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Acoustica
      2010-08-27 20:17 . 2008-08-01 02:01 -------- d---a-w- c:\documents and settings\All Users\Datos de programa\TEMP
      2010-08-26 14:35 . 2009-06-12 19:42 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\gtk-2.0
      2010-08-20 18:23 . 2010-08-20 17:55 848 --sha-w- c:\windows\system32\KGyGaAvL.sys
      2010-08-20 18:23 . 2010-08-20 17:55 56 --sh--r- c:\windows\system32\2A6F47CBAA.sys
      2010-08-17 13:17 . 2006-03-02 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
      2010-08-17 07:42 . 2010-08-17 07:42 -------- dc----w- d:\archivos de programa\Enterbrain
      2010-08-04 13:50 . 2008-10-04 12:28 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Anvil Studio
      2010-08-03 21:32 . 2010-08-03 21:03 -------- dc----w- d:\archivos de programa\SynthFont
      2010-08-03 21:03 . 2010-08-03 21:03 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\SynthFont
      2010-08-03 20:30 . 2010-08-03 20:30 -------- dc----w- d:\archivos de programa\VST
      2010-08-03 20:11 . 2009-06-01 05:41 -------- d-----w- d:\archivos de programa\Image-Line
      2010-07-22 15:46 . 2006-03-02 12:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
      2010-07-22 06:19 . 2008-05-05 10:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
      2010-07-14 19:58 . 2010-07-14 19:58 10806 ----a-r- c:\documents and settings\Facerplast\Datos de programa\Microsoft\Installer\{9F83E009-A168-4E65-A6CF-8FFB2F4E0C7B}\_68FD413B433F3D7874F6ED.exe
      2010-07-14 19:58 . 2010-07-14 19:58 10806 ----a-r- c:\documents and settings\Facerplast\Datos de programa\Microsoft\Installer\{9F83E009-A168-4E65-A6CF-8FFB2F4E0C7B}\_44C63FAA304844377BFF37.exe
      2010-07-06 08:25 . 2008-09-10 08:45 711 -c--a-w- c:\windows\eReg.dat
      2010-07-04 07:25 . 2010-06-20 03:48 22 ----a-w- c:\windows\Fonts\Times.txt
      2010-06-30 12:32 . 2006-03-02 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
      2010-06-29 21:36 . 2010-06-29 21:35 2167292 ----a-w- c:\documents and settings\Facerplast\Datos de programa\MessengerDiscovery 2\0\Update.exe
      .

      ------- Sigcheck -------

      [-] 2008-04-14 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
      [-] 2008-04-14 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\drivers\atapi.sys
      [-] 2006-03-02 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys

      [-] 2008-04-14 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\asyncmac.sys
      [-] 2008-04-14 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\drivers\asyncmac.sys
      [-] 2006-03-02 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\asyncmac.sys

      [-] 2006-03-02 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys
      [-] 2006-03-02 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys

      [-] 2008-04-14 . 188DDD286BC0DAEA6984858C6A4D7BBF . 25088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kbdclass.sys
      [-] 2008-04-14 . 188DDD286BC0DAEA6984858C6A4D7BBF . 25088 . . [5.1.2600.5512] . . c:\windows\system32\drivers\kbdclass.sys
      [-] 2006-03-02 . 71BFDDA7B3006B45B18D8BAC92BC9993 . 25088 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\kbdclass.sys

      [-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ndis.sys
      [-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys
      [-] 2006-03-02 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ndis.sys

      [-] 2008-04-14 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntfs.sys
      [-] 2008-04-14 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ntfs.sys
      [-] 2007-02-09 . 05AB81909514BFD69CBB1F2C147CF6B9 . 574976 . . [5.1.2600.3081] . . c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys
      [-] 2007-02-09 . 19A811EF5F1ED5C926A028CE107FF1AF . 574464 . . [5.1.2600.3081] . . c:\windows\$NtServicePackUninstall$\ntfs.sys

      [-] 2006-03-02 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys
      [-] 2006-03-02 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys

      [-] 2008-04-14 . E28818BD591F8AF8FBE9897472B9665E . 77824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\browser.dll
      [-] 2008-04-14 . E28818BD591F8AF8FBE9897472B9665E . 77824 . . [5.1.2600.5512] . . c:\windows\system32\browser.dll
      [-] 2006-03-02 . D01CFCC753B09E70F5B7622501FF5383 . 77312 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\browser.dll

      [-] 2008-04-14 . 671ACA589DA3733FAC878A751C5BF0ED . 13312 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lsass.exe
      [-] 2008-04-14 . 671ACA589DA3733FAC878A751C5BF0ED . 13312 . . [5.1.2600.5512] . . c:\windows\system32\lsass.exe
      [-] 2006-03-02 . 2B0B88652C9F6714FD4886839B3B0442 . 13312 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\lsass.exe

      [-] 2008-04-14 . A48884C9359EE9F1FC8F3F0D93FB1D95 . 198144 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netman.dll
      [-] 2008-04-14 . A48884C9359EE9F1FC8F3F0D93FB1D95 . 198144 . . [5.1.2600.5512] . . c:\windows\system32\netman.dll
      [-] 2005-08-22 . 7BDB3A1B78A33455F3704AA12B9A0FE1 . 197632 . . [5.1.2600.2743] . . c:\windows\$NtServicePackUninstall$\netman.dll
      [-] 2005-08-22 . 157B6FCB58270E3DF3ED67D316DCECE0 . 197632 . . [5.1.2600.2743] . . c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll

      [-] 2008-04-14 . 8EE9639C01B92490E09638CAA1B16C3C . 409088 . . [6.7.2600.5512] . . c:\windows\ServicePackFiles\i386\qmgr.dll
      [-] 2008-04-14 . 8EE9639C01B92490E09638CAA1B16C3C . 409088 . . [6.7.2600.5512] . . c:\windows\system32\qmgr.dll
      [-] 2008-04-14 . 8EE9639C01B92490E09638CAA1B16C3C . 409088 . . [6.7.2600.5512] . . c:\windows\system32\bits\qmgr.dll
      [-] 2006-03-02 . 02451268DC47E4DC228210DA0E3C3274 . 382464 . . [6.6.2600.2180] . . c:\windows\$NtServicePackUninstall$\qmgr.dll

      [-] 2008-04-14 . 3F5B7DD84DB17717502FB9F9954C17A7 . 550400 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
      [-] 2008-04-14 . 3F5B7DD84DB17717502FB9F9954C17A7 . 550400 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
      [-] 2008-04-14 . 213C80D912880BBF04453D09FFCCB28C . 510976 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\winlogon.exe
      [-] 2006-03-02 . B7D1DE4D0BBC5E6B920C31951FC9F4C7 . 544768 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe

      [-] 2008-04-14 . 1D6969BDDFC5DE38F92572FF286330FB . 724992 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll
      [-] 2008-04-14 . 1D6969BDDFC5DE38F92572FF286330FB . 724992 . . [5.82] . . c:\windows\system32\comctl32.dll
      [-] 2008-04-14 . 618A4C7A7C0CA86DA884C8C0FACAD8C2 . 617472 . . [5.82] . . c:\windows\VistaMizer\old\comctl32.dll
      [-] 2006-08-25 . 3567E0A82689A55907F8D9D70B58F88E . 724992 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll

      [-] 2008-04-14 . E423C9C1946C656E0E4840210A0A8681 . 62464 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\cryptsvc.dll
      [-] 2008-04-14 . E423C9C1946C656E0E4840210A0A8681 . 62464 . . [5.1.2600.5512] . . c:\windows\system32\cryptsvc.dll
      [-] 2006-03-02 . 149CFFBF77CC1306FC535557CF513B91 . 60416 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\cryptsvc.dll

      [-] 2008-04-14 . 95DF6A7520912B1040F748A287EA382A . 110080 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\imm32.dll
      [-] 2008-04-14 . 95DF6A7520912B1040F748A287EA382A . 110080 . . [5.1.2600.5512] . . c:\windows\system32\imm32.dll
      [-] 2006-03-02 . BE2282FBEAFBB76577D47B06071139BB . 110080 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\imm32.dll

      [-] 2008-04-14 . FB67F1E092AB9967D0CD17300D751874 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll
      [-] 2008-04-14 . FB67F1E092AB9967D0CD17300D751874 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\linkinfo.dll
      [-] 2005-09-01 . C4E7CEFD3802415865E631BE3AB6AC3B . 19968 . . [5.1.2600.2751] . . c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
      [-] 2005-09-01 . EB7A3E05F297799847AACFA00B4B9218 . 19968 . . [5.1.2600.2751] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll

      [-] 2008-04-14 . 87F15A88AA3376B48F75D7D176B312A0 . 22016 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lpk.dll
      [-] 2008-04-14 . 87F15A88AA3376B48F75D7D176B312A0 . 22016 . . [5.1.2600.5512] . . c:\windows\system32\lpk.dll
      [-] 2006-03-02 . 24B2A5D3EE366A3E9C1E0941363618C7 . 22016 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\lpk.dll

      [-] 2008-04-14 . 0F021B29E0C2C9D897258399FB2149CD . 343040 . . [7.0.2600.5512] . . c:\windows\ServicePackFiles\i386\msvcrt.dll
      [-] 2008-04-14 . 0F021B29E0C2C9D897258399FB2149CD . 343040 . . [7.0.2600.5512] . . c:\windows\system32\msvcrt.dll
      [-] 2006-03-02 . 3CDD949F8340F06FD99667B4F75409D0 . 343040 . . [7.0.2600.2180] . . c:\windows\$NtServicePackUninstall$\msvcrt.dll

      [-] 2008-04-14 . CD2BBB52DFAAB666B812A51B1E96F2A0 . 407040 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netlogon.dll
      [-] 2008-04-14 . CD2BBB52DFAAB666B812A51B1E96F2A0 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\netlogon.dll
      [-] 2006-03-02 . 7FD182B1B80117C353983565D60B1CAF . 407040 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\netlogon.dll

      [-] 2008-04-14 . 56DE6FD410B277C4345D7A2C3414DB64 . 17408 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\powrprof.dll
      [-] 2008-04-14 . 56DE6FD410B277C4345D7A2C3414DB64 . 17408 . . [6.00.2900.5512] . . c:\windows\system32\powrprof.dll
      [-] 2006-03-02 . 75EFF6383C2F9BC1198C5351754D27AC . 17408 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\powrprof.dll

      [-] 2008-04-14 . B6BE3C96CD33336A551DB3F2299A8E69 . 185856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\scecli.dll
      [-] 2008-04-14 . B6BE3C96CD33336A551DB3F2299A8E69 . 185856 . . [5.1.2600.5512] . . c:\windows\system32\scecli.dll
      [-] 2006-03-02 . C6347748F2E9F310EA1E1915482ABFEF . 184832 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\scecli.dll

      [-] 2008-04-14 . D5AC9FA63EBEFD7AACCB14BA0DB1BAC3 . 5120 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfc.dll
      [-] 2008-04-14 . D5AC9FA63EBEFD7AACCB14BA0DB1BAC3 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\sfc.dll
      [-] 2006-03-02 . CA557E5E31C7BCFC2CB61CCFE9F6C945 . 5120 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\sfc.dll

      [-] 2008-04-14 . 4F2340F0BD5B6365C38E74DD391919A8 . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\svchost.exe
      [-] 2008-04-14 . 4F2340F0BD5B6365C38E74DD391919A8 . 14336 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe
      [-] 2006-03-02 . FA03E1FC17F38FBDBA81470D08B3E416 . 14336 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\svchost.exe

      [-] 2008-04-14 . 04A5B8EA326951DB27DF60A14F2999FF . 249856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll
      [-] 2008-04-14 . 04A5B8EA326951DB27DF60A14F2999FF . 249856 . . [5.1.2600.5512] . . c:\windows\system32\tapisrv.dll
      [-] 2005-07-08 . 861E25215BA370D4CA9337C2BC0E647F . 249344 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
      [-] 2005-07-08 . FB0794BE642E50D2284A8841043B5867 . 249344 . . [5.1.2600.2716] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll

      [-] 2008-04-14 . BCEAB836D3EF27938B90D5FF88C0FE26 . 588288 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
      [-] 2008-04-14 . BCEAB836D3EF27938B90D5FF88C0FE26 . 588288 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
      [-] 2008-04-14 . DA8898129E0075C7DE4DEE457514A73C . 579584 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\user32.dll
      [-] 2007-03-08 . 237FB93C6B4330D8EE7D2448CF71C5ED . 579072 . . [5.1.2600.3099] . . c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
      [-] 2007-03-08 . FED9881C07A301271F52B51389A028C9 . 578560 . . [5.1.2600.3099] . . c:\windows\$NtServicePackUninstall$\user32.dll
      [-] 2005-03-02 . 37CE819E8ECB3517B9981A886876EF72 . 578048 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll

      [-] 2008-04-14 . F5B8745B9A90EAF17E30C0574E049AA3 . 26624 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe
      [-] 2008-04-14 . F5B8745B9A90EAF17E30C0574E049AA3 . 26624 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe
      [-] 2006-03-02 . 7B30B4D55B4562C733A5DDF6D6F72B3F . 25088 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\userinit.exe

      [-] 2009-01-15 . 2557EC018A4FE11589415F7C26D116F1 . 1013248 . . [8.00.6001.18372] . . c:\windows\ServicePackFiles\i386\wininet.dll
      [-] 2009-01-15 . 2557EC018A4FE11589415F7C26D116F1 . 1013248 . . [8.00.6001.18372] . . c:\windows\system32\wininet.dll
      [7] 2009-01-15 . 203C05A174A45270A30CDD593092D91E . 911872 . . [8.00.6001.18372] . . c:\windows\VistaMizer\old\wininet.dll
      [-] 2008-06-23 . 24207433B012CD6B3C746D245C6EBCE6 . 669184 . . [6.00.2900.5626] . . c:\windows\$hf_mig$\KB953838\SP3QFE\wininet.dll
      [-] 2008-04-21 . D273F0C482B866EF3F471E388588228E . 669184 . . [6.00.2900.5583] . . c:\windows\$hf_mig$\KB950759\SP3QFE\wininet.dll
      [7] 2007-08-13 . A4A0FC92358F39538A6494C42EF99FE9 . 818688 . . [7.00.5730.13] . . c:\windows\ie8\wininet.dll
      [-] 2006-03-02 . 80BB109560A23B9C18427855CA5305E6 . 658944 . . [6.00.2900.2180] . . c:\windows\ie7\wininet.dll

      [-] 2008-04-14 . 22DB5B3DA7005C6472D35BEF3FFDA5EC . 82432 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2_32.dll
      [-] 2008-04-14 . 22DB5B3DA7005C6472D35BEF3FFDA5EC . 82432 . . [5.1.2600.5512] . . c:\windows\system32\ws2_32.dll
      [-] 2006-03-02 . B4A90738BA4355F187BD26D6C112082B . 82944 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ws2_32.dll

      [-] 2008-04-14 . F7EE4BBFB48437EDC6F7F061DE1E8F2F . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2help.dll
      [-] 2008-04-14 . F7EE4BBFB48437EDC6F7F061DE1E8F2F . 19968 . . [5.1.2600.5512] . . c:\windows\system32\ws2help.dll
      [-] 2006-03-02 . 0EDF3501370A14BEFB27526CD06FACEE . 19968 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ws2help.dll

      [-] 2008-04-14 . 262BCE958456D31B59C30A1329CECD2B . 1554944 . . [6.00.2900.5512] . . c:\windows\explorer.exe
      [-] 2008-04-14 . 262BCE958456D31B59C30A1329CECD2B . 1554944 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
      [-] 2008-04-14 . 7522F548A84ABAD8FA516DE5AB3931EF . 1036288 . . [6.00.2900.5512] . . c:\windows\VistaMizer\old\explorer.exe
      [-] 2007-06-13 . E5CF28568CB22C37F15B12C9115F70BE . 1554432 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
      [-] 2007-06-13 . DBB6B75CC6CB2CF8EC0BAFCA08AED6BE . 1035776 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe

      [-] 2008-04-14 . 48D6DDFED47793E0F6DD77B8F2660BC3 . 1312256 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ole32.dll
      [-] 2008-04-14 . 48D6DDFED47793E0F6DD77B8F2660BC3 . 1312256 . . [5.1.2600.5512] . . c:\windows\system32\ole32.dll
      [-] 2008-04-14 . 463D57BF9FE5871208FF99399360A57D . 1287168 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ole32.dll
      [-] 2005-07-26 . 3200390606D6816D86F14AAFAB7F1A03 . 1284608 . . [5.1.2600.2726] . . c:\windows\$NtServicePackUninstall$\ole32.dll
      [-] 2005-07-26 . 1CCD86AF8968519AE6BF9729FC566F1A . 1285632 . . [5.1.2600.2726] . . c:\windows\$hf_mig$\KB902400\SP2QFE\ole32.dll
      [-] 2005-04-28 . E13ABDC8A801329203091546722B63C9 . 1286144 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\ole32.dll

      [-] 2008-04-14 . 0F30EEC6013FCF76693405EC4A7DF899 . 171520 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\srsvc.dll
      [-] 2008-04-14 . 0F30EEC6013FCF76693405EC4A7DF899 . 171520 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll
      [-] 2006-03-02 . C791D16BF25264738B14873436293BD0 . 171008 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\srsvc.dll

      [-] 2008-04-14 . B2718EC9DC738E915D4177498E92BC4D . 13824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wscntfy.exe
      [-] 2008-04-14 . B2718EC9DC738E915D4177498E92BC4D . 13824 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe
      [-] 2006-03-02 . 9C90A6DBE5D43E189F199172675D6312 . 13824 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\wscntfy.exe

      [-] 2008-04-14 . 14FDADCF05A37582399DAF1DA1DE1C7B . 129024 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\xmlprov.dll
      [-] 2008-04-14 . 14FDADCF05A37582399DAF1DA1DE1C7B . 129024 . . [5.1.2600.5512] . . c:\windows\system32\xmlprov.dll
      [-] 2006-03-02 . 843E0DB8042A8C0D749EB2B9EFA54F24 . 129536 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\xmlprov.dll

      [-] 2008-04-14 . 2744C713F0217BD8FFD13E2EF731371C . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll
      [-] 2008-04-14 . 2744C713F0217BD8FFD13E2EF731371C . 56320 . . [5.1.2600.5512] . . c:\windows\system32\eventlog.dll
      [-] 2006-03-02 . 5696DF4EF09C375CE42FB2DDE1E68AB7 . 55808 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\eventlog.dll

      [-] 2008-04-14 . 2A1E1DF559B291583903D2F9CC504522 . 1572352 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfcfiles.dll
      [-] 2008-04-14 . 2A1E1DF559B291583903D2F9CC504522 . 1572352 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
      [-] 2006-03-02 . AAFD7382D64710AE3A6F1DEE5020CF19 . 1548800 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\sfcfiles.dll

      [-] 2008-04-14 . 0787E74EE4A4BC7448DA95CC1866F83E . 25088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
      [-] 2008-04-14 . 0787E74EE4A4BC7448DA95CC1866F83E . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
      [-] 2008-04-14 . DAAE1CB1B1875B760496E7D3336DA1AD . 15360 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ctfmon.exe
      [-] 2006-03-02 . 172F37F076E17C28D63F02049A181679 . 25088 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe

      [-] 2008-04-14 . CA70EDBF32032EA53F114CB930741CB5 . 135168 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll
      [-] 2008-04-14 . CA70EDBF32032EA53F114CB930741CB5 . 135168 . . [6.00.2900.5512] . . c:\windows\system32\shsvcs.dll
      [-] 2006-12-19 . 2A7B15883836B7B44F4C9FADEEF2F187 . 134656 . . [6.00.2900.3051] . . c:\windows\$NtServicePackUninstall$\shsvcs.dll
      [-] 2006-12-19 . 00C566D725F80E77DAACB82D1FED4493 . 135168 . . [6.00.2900.3051] . . c:\windows\$hf_mig$\KB928255\SP2QFE\shsvcs.dll

      [-] 2008-04-14 . E424F05B07AC4357DC08D06218D76C7C . 59904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regsvc.dll
      [-] 2008-04-14 . E424F05B07AC4357DC08D06218D76C7C . 59904 . . [5.1.2600.5512] . . c:\windows\system32\regsvc.dll
      [-] 2006-03-02 . D025E953864EBEBAB5933086D15C4FC6 . 59904 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\regsvc.dll

      [-] 2008-04-14 . 51BE25C404D3DD344C6079DE715E4977 . 193536 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\schedsvc.dll
      [-] 2008-04-14 . 51BE25C404D3DD344C6079DE715E4977 . 193536 . . [5.1.2600.5512] . . c:\windows\system32\schedsvc.dll
      [-] 2006-03-02 . 0125649B3C00D037E07FD7BCEF7B653B . 192000 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\schedsvc.dll

      [-] 2008-04-14 . B622A432EF02895DE4AA38AC8B85FA4C . 71680 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ssdpsrv.dll
      [-] 2008-04-14 . B622A432EF02895DE4AA38AC8B85FA4C . 71680 . . [5.1.2600.5512] . . c:\windows\system32\ssdpsrv.dll
      [-] 2006-03-02 . 4AFF5EA8BF2362C3D5001295FDEB3ABD . 71680 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ssdpsrv.dll

      [-] 2008-04-14 . 288B20D56D5F0EC4BCC77FBFA5A81740 . 296960 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll
      [-] 2008-04-14 . 288B20D56D5F0EC4BCC77FBFA5A81740 . 296960 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll
      [-] 2006-03-02 . C2038466BE5A6A76EFD592FA0B459E17 . 296960 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\termsrv.dll

      [-] 2008-04-14 . 30CD42BFCDAFEFE8567B9E527DD3AE08 . 175104 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\appmgmts.dll
      [-] 2008-04-14 . 30CD42BFCDAFEFE8567B9E527DD3AE08 . 175104 . . [5.1.2600.5512] . . c:\windows\system32\appmgmts.dll
      [-] 2006-03-02 . 0CF68B185221E5B162EF1B0559428B40 . 175104 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\appmgmts.dll

      [-] 2006-03-02 . 1C905333C0B9F3D7C68DDF25E54B00F9 . 12032 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys

      [-] 2008-04-14 00:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\ServicePackFiles\i386\aec.sys
      [-] 2008-04-14 00:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\system32\drivers\aec.sys
      [-] 2006-02-15 00:30 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\$hf_mig$\KB900485\SP2QFE\aec.sys
      [-] 2006-02-15 00:22 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\$NtServicePackUninstall$\aec.sys

      [-] 2008-04-14 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\agp440.sys
      [-] 2008-04-14 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\system32\drivers\agp440.sys
      [-] 2004-08-04 . 2C428FA0C3E3A01ED93C9B2A27D8D4BB . 42368 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\agp440.sys

      [-] 2008-04-14 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ip6fw.sys
      [-] 2008-04-14 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys
      [-] 2006-03-02 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ip6fw.sys

      [-] 2008-04-14 09:48 . 27415CEEB58C8C2F92AFF8CFE2517A3C . 927504 . . [4.1.0.61] . . c:\windows\ServicePackFiles\i386\mfc40u.dll
      [-] 2008-04-14 09:48 . 27415CEEB58C8C2F92AFF8CFE2517A3C . 927504 . . [4.1.0.61] . . c:\windows\system32\mfc40u.dll
      [-] 2006-11-01 19:18 . 2B7A4915332B5DD133536E1E7E436654 . 927504 . . [4.1.0.61] . . c:\windows\$NtServicePackUninstall$\mfc40u.dll

      [-] 2008-04-14 . 047E70B04B288439245DDC8DD1A31982 . 33792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\msgsvc.dll
      [-] 2008-04-14 . 047E70B04B288439245DDC8DD1A31982 . 33792 . . [5.1.2600.5512] . . c:\windows\system32\msgsvc.dll
      [-] 2006-03-02 . CA33F6547C49E749E47FB6A0D1DBE192 . 33792 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\msgsvc.dll

      [-] 2008-04-14 02:18 . 57CF215B0250DE0C4AE36ABC8AE31BE4 . 52736 . . [9.0.1.56] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
      [-] 2006-10-18 23:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
      [-] 2006-10-18 23:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\dllcache\mspmsnsv.dll

      [-] 2008-04-14 09:48 . D60C40D71A4D874C903255E4827AFA0C . 437760 . . [5.1.2400.5512] . . c:\windows\ServicePackFiles\i386\ntmssvc.dll
      [-] 2008-04-14 09:48 . D60C40D71A4D874C903255E4827AFA0C . 437760 . . [5.1.2400.5512] . . c:\windows\system32\ntmssvc.dll
      [-] 2006-03-02 12:00 . 395948DEE2B0F534A8C70687CC6DD7CA . 437760 . . [5.1.2400.2180] . . c:\windows\$NtServicePackUninstall$\ntmssvc.dll

      [-] 2008-04-14 . 7594203F459ABDB5FE53C08D6B1BD53B . 186368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\upnphost.dll
      [-] 2008-04-14 . 7594203F459ABDB5FE53C08D6B1BD53B . 186368 . . [5.1.2600.5512] . . c:\windows\system32\upnphost.dll
      [-] 2007-02-05 . FCB8D49E28B6AB1BC09AC240B07BADFC . 185344 . . [5.1.2600.3077] . . c:\windows\$hf_mig$\KB931261\SP2QFE\upnphost.dll
      [-] 2007-02-05 . 534166BDD7664FA8590827FFB73F1B35 . 185344 . . [5.1.2600.3077] . . c:\windows\$NtServicePackUninstall$\upnphost.dll

      [-] 2008-04-14 . 9EF059A2C76BCE8DB9B0DD95EFE23A48 . 367616 . . [5.3.2600.5512] . . c:\windows\ServicePackFiles\i386\dsound.dll
      [-] 2008-04-14 . 9EF059A2C76BCE8DB9B0DD95EFE23A48 . 367616 . . [5.3.2600.5512] . . c:\windows\system32\dsound.dll
      [-] 2006-03-02 . BDE6AEDFD66768C08C42DAE5056B6779 . 367616 . . [5.3.2600.2180] . . c:\windows\$NtServicePackUninstall$\dsound.dll
      [7] 2004-07-09 07:27 . 033A45AB696EEF481707C2808C806E1A . 381952 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsound.dll
      [7] 2004-07-09 07:27 . 033A45AB696EEF481707C2808C806E1A . 381952 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\system32\dllcache\dsound.dll

      [-] 2008-04-14 . AE5DD931EFAB3687BA4DF0671F4CE078 . 1689088 . . [5.03.2600.5512] . . c:\windows\ServicePackFiles\i386\d3d9.dll
      [-] 2008-04-14 . AE5DD931EFAB3687BA4DF0671F4CE078 . 1689088 . . [5.03.2600.5512] . . c:\windows\system32\d3d9.dll
      [-] 2006-03-02 . 77A1379688F15B02D5100183A54778BB . 1689088 . . [5.03.2600.2180] . . c:\windows\$NtServicePackUninstall$\d3d9.dll

      [-] 2008-04-14 . 28D0D87445F4ADD6614155EC13F042DD . 279552 . . [5.03.2600.5512] . . c:\windows\ServicePackFiles\i386\ddraw.dll
      [-] 2008-04-14 . 28D0D87445F4ADD6614155EC13F042DD . 279552 . . [5.03.2600.5512] . . c:\windows\system32\ddraw.dll
      [-] 2006-03-02 . 285B7EA6C449DA0E08B1195FE7033A1A . 266240 . . [5.03.2600.2180] . . c:\windows\$NtServicePackUninstall$\ddraw.dll
      [7] 2004-07-09 07:27 . 90114704C17A581DA1BAE029F20932BE . 292864 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ddraw.dll
      [7] 2004-07-09 07:27 . 90114704C17A581DA1BAE029F20932BE . 292864 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\system32\dllcache\ddraw.dll

      [-] 2008-04-14 09:48 . F71CB6064DFC10DFB767B537BFA33D61 . 84992 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\olepro32.dll
      [-] 2008-04-14 09:48 . F71CB6064DFC10DFB767B537BFA33D61 . 84992 . . [5.1.2600.5512] . . c:\windows\system32\olepro32.dll
      [-] 2006-03-02 12:00 . 74A98B98FB63049B6FECC472AD09A577 . 83456 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\olepro32.dll

      [-] 2008-04-14 . 91C2A139745F2AF17E4685A1E54B4FDA . 41984 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\perfctrs.dll
      [-] 2008-04-14 . 91C2A139745F2AF17E4685A1E54B4FDA . 41984 . . [5.1.2600.5512] . . c:\windows\system32\perfctrs.dll
      [-] 2006-03-02 . AC18C8A4D842211748AAACF89EFEBF07 . 41984 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\perfctrs.dll

      [-] 2008-04-14 . F4968D88123785BCF95A31E0225C5592 . 18944 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\version.dll
      [-] 2008-04-14 . F4968D88123785BCF95A31E0225C5592 . 18944 . . [5.1.2600.5512] . . c:\windows\system32\version.dll
      [-] 2006-03-02 . 63782F8342BB8F04E0AFCAABA2B60C09 . 18944 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\version.dll
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
      2010-05-26 18:23 1385864 -c--a-w- d:\archivos de programa\Ask.com\GenericAskToolbar.dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
      "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "d:\archivos de programa\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

      [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
      [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
      [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
      [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
      "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "d:\archivos de programa\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

      [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
      [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
      [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
      [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "DAEMON Tools Lite"="d:\archivos de programa\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
      "MsnMsgr"="c:\archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
      "ares"="d:\archivos de programa\Ares\Ares.exe" [2009-03-13 3231744]
      "uTorrent"="d:\archivos de programa\uTorrent\uTorrent.exe" [2010-08-30 328568]
      "Google Update"="c:\documents and settings\Facerplast\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
      "SUPERAntiSpyware"="d:\archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-09-10 2424560]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "GrooveMonitor"="d:\archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
      "egui"="c:\archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
      "nwiz"="c:\archivos de programa\NVIDIA Corporation\nView\nwiz.exe" [2009-08-13 1657376]
      "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
      "RTHDCPL"="RTHDCPL.EXE" [2007-10-25 16855552]
      "SkyTel"="SkyTel.EXE" [2007-10-11 1826816]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 25088]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
      "NoPopUpsOnBoot"= 1 (0x1)

      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
      "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\archivos de programa\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
      2009-09-03 22:21 548352 -c--a-w- d:\archivos de programa\SUPERAntiSpyware\SASWINLO.DLL

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
      BootExecute REG_MULTI_SZ autocheck autochk /p \??\D\0autocheck autochk /k:C /k:D *

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menú Inicio^Programas^Inicio^Actualizar la licencia de ESET.lnk]
      backup=c:\windows\pss\Actualizar la licencia de ESET.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^Facerplast^Menú Inicio^Programas^Inicio^Recorte de pantalla e Inicio rápido de OneNote 2007.lnk]
      backup=c:\windows\pss\Recorte de pantalla e Inicio rápido de OneNote 2007.lnkStartup
      HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
      c:\windows\system32\dumprep 0 -k [X]

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
      2008-08-14 09:58 611712 ----a-w- c:\archivos de programa\Archivos comunes\Adobe\CS4ServiceManager\CS4ServiceManager.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
      2010-08-10 18:10 2349776 -c--a-w- d:\archivos de programa\IObit\Advanced SystemCare 3\AWC.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
      2007-07-02 10:27 219520 -c--a-w- d:\archivos de programa\Alcohol Soft\Alcohol 120\AxCmd.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileHippo.com]
      2010-04-29 12:57 248832 ----a-w- c:\archivos de programa\FileHippo.com\UpdateChecker.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
      2008-09-02 19:41 133104 ----atw- c:\documents and settings\Facerplast\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
      2004-08-20 12:00 208952 ----a-w- c:\windows\ime\imjp8_1\imjpmig.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
      2009-05-27 00:06 4351216 ----a-w- d:\archivos de programa\Yahoo!\Messenger\YahooMessenger.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MiponyAutoRun]
      2010-06-16 09:29 1234432 -c--a-w- d:\archivos de programa\MiPony\MiPony.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
      2008-04-14 09:49 1832448 ----a-w- c:\archivos de programa\Messenger\msmsgs.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
      2008-09-06 17:09 413696 ----a-w- c:\archivos de programa\QuickTime\QTTask.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
      2007-10-25 03:57 16855552 ------r- c:\windows\RTHDCPL.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
      2010-05-13 19:12 26192168 ----a-r- d:\skype\Phone\Skype.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
      2007-10-11 03:04 1826816 ------r- c:\windows\SkyTel.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
      2010-02-18 14:43 248040 ----a-w- c:\archivos de programa\Archivos comunes\Java\Java Update\jusched.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
      2008-07-29 16:45 185896 -c--a-w- c:\archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
      2010-08-30 09:40 328568 -c--a-w- d:\archivos de programa\uTorrent\uTorrent.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
      "XAMPP"=2 (0x2)
      "wampmysqld"=3 (0x3)
      "wampapache"=3 (0x3)

      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "AntiVirusOverride"=dword:00000001
      "FirewallOverride"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "c:\\Documents and Settings\\All Users\\Datos de programa\\NexonUS\\NGM\\NGM.exe"=
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Archivos de programa\\SopCast\\adv\\SopAdver.exe"=
      "d:\\Pokémon Online\\Pokemon Game.exe"=
      "d:\\Archivos de programa\\GameSpy Arcade\\Aphex.exe"=
      "c:\\Archivos de programa\\Windows Media Player\\wmplayer.exe"=
      "c:\\Archivos de programa\\Java\\jre6\\bin\\java.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\WINDOWS\\system32\\dpvsetup.exe"=
      "c:\\Documents and Settings\\Facerplast\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
      "d:\\Archivos de programa\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
      "d:\\Archivos de programa\\Microsoft Office\\Office12\\GROOVE.EXE"=
      "d:\\Archivos de programa\\Microsoft Office\\Office12\\ONENOTE.EXE"=
      "c:\\Archivos de programa\\Messenger\\msmsgs.exe"=
      "c:\\Nexon\\NEXON_EU_Downloader\\NEXON_EU_Downloader_Engine.exe"=
      "c:\\Documents and Settings\\All Users\\Datos de programa\\NexonEU\\NGM\\NGM.exe"=
      "d:\\Combat Arms\\Combat Arms EU\\NMService.exe"=
      "d:\\Archivos de programa\\Yahoo!\\Messenger\\YahooMessenger.exe"=
      "c:\\Archivos de programa\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
      "c:\\WINDOWS\\system32\\java.exe"=
      "c:\\WINDOWS\\system32\\rtcshare.exe"=
      "c:\\Archivos de programa\\NetMeeting\\conf.exe"=
      "c:\\Archivos de programa\\Java\\jre6\\bin\\javaw.exe"=
      "d:\\Documents and Settings\\Facerplast\\Escritorio\\Mauricio\\Nueva carpeta\\Xfire\\xfire.exe"=
      "d:\\Mis documentos\\Chat\\mirc32.exe"=
      "d:\\Mis documentos\\Copia de Chat\\mirc32.exe"=
      "d:\\Archivos de programa\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
      "d:\\Archivos de programa\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=
      "c:\\Archivos de programa\\Windows Live\\Messenger\\msnmsgr.exe"=
      "d:\\Mis documentos\\Chat\\Kazuma\\mirc.exe"=
      "d:\\Archivos de programa\\Garena\\Garena.exe"=
      "c:\\Archivos de programa\\Archivos comunes\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
      "d:\\Archivos de programa\\KONAMI\\Pro Evolution Soccer 2010\\pes2010.exe"=
      "c:\\KeyHoleTV.exe"=
      "c:\\Archivos de programa\\KeyHoleTV\\KeyHoleTV.exe"=
      "d:\\Archivos de programa\\uTorrent\\uTorrent.exe"=
      "d:\\server\\samp-server.exe"=
      "d:\\server 2\\samp-server.exe"=
      "d:\\Skype\\Plugin Manager\\skypePM.exe"=
      "c:\\Archivos de programa\\Opera\\opera.exe"=
      "c:\\Archivos de programa\\TeamViewer\\Version5\\TeamViewer.exe"=
      "d:\\Skype\\Phone\\Skype.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
      "8082:TCP"= 8082:TCP:Proxy
      "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
      "9014:TCP"= 9014:TCP:BitComet 9014 TCP
      "9014:UDP"= 9014:UDP:BitComet 9014 UDP
      "5353:TCP"= 5353:TCP:Adobe CSI CS4
      "67:UDP"= 67:UDP:DHCP Discovery Service

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
      "AllowInboundEchoRequest"= 1 (0x1)

      R2 Apache2.2;Apache2.2;d:\xampp\apache\bin\apache.exe [x]
      R2 GF0003;GASIA GF0003 Filter Driver;c:\windows\system32\DRIVERS\GF0003.sys [2006-04-28 9216]
      R3 CAM1690;USB 2.0 Compliance JPEG Video Camera;c:\windows\system32\Drivers\cam1690.sys [2007-07-13 152832]
      R3 cpuz130;cpuz130;c:\docume~1\FACERP~1\CONFIG~1\Temp\cpuz130\cpuz_x32.sys [x]
      R3 dump_wmimmc;dump_wmimmc;d:\archivos de programa\Lineage II\system\GameGuard\dump_wmimmc.sys [x]
      R3 FXDrv32;FXDrv32;F:\FXDrv32.sys [x]
      R3 hid7906;hid7906;c:\windows\system32\drivers\hid7906.sys [2007-12-12 34963]
      R3 hid8101;hid8101;c:\windows\system32\drivers\hid8101.sys [2007-12-03 37024]
      R3 hid8103;hid8103;c:\windows\system32\drivers\hid8103.sys [2007-11-28 34587]
      R3 LLRING0;LLRING0;d:\archivos de programa\AOG\MUruguay\MuGuard\llck1.sys [2010-05-29 3840]
      R3 MobileAdapter;Huawei Mobile Adapter USB Modem and USB Serial;c:\windows\system32\DRIVERS\hmumdm.sys [2007-09-05 101120]
      R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-04-06 23064]
      R3 zlportio;zlportio;d:\ultrastar deluxe\zlportio.sys [x]
      R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2008-10-26 717296]
      R4 XAMPP;XAMPP Service;d:\xampp\service.exe [x]
      S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
      S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2009-02-06 93336]
      S1 SASDIFSV;SASDIFSV;d:\archivos de programa\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
      S1 SASKUTIL;SASKUTIL;d:\archivos de programa\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
      S2 ekrn;ESET Service;c:\archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]

      .
      Contents of the 'Scheduled Tasks' folder

      2010-06-19 c:\windows\Tasks\AWC AutoSweep.job
      - d:\archivos de programa\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-03-19 17:11]

      2010-09-25 c:\windows\Tasks\AWC Update.job
      - d:\archivos de programa\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-03-19 14:08]

      2010-09-23 c:\windows\Tasks\OGALogon.job
      - c:\windows\system32\OGAEXEC.exe [2009-08-03 18:07]

      2010-09-27 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
      - d:\archivos de programa\Ask.com\UpdateTask.exe [2010-05-26 18:23]

      2010-09-27 c:\windows\Tasks\User_Feed_Synchronization-{168D70C3-E309-409B-BE83-4F8C3C9A3BAA}.job
      - c:\windows\system32\msfeedssync.exe [2007-08-13 04:01]

      2010-09-27 c:\windows\Tasks\User_Feed_Synchronization-{1F3174A3-472B-4BC2-A6BD-7CB0D3461CA7}.job
      - c:\windows\system32\msfeedssync.exe [2007-08-13 04:01]

      2010-09-27 c:\windows\Tasks\User_Feed_Synchronization-{61ACB603-68A1-4CC7-A2A9-04C423D56DB0}.job
      - c:\windows\system32\msfeedssync.exe [2007-08-13 04:01]
      .
      .
      ------- Supplementary Scan -------
      .
      uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2233703
      uSearchMigratedDefaultURL = hxxp://www.Google.com/
      mWindow Title =
      mSearchMigratedDefaultURL = hxxp://www.Google.com/
      uInternet Connection Wizard,ShellNext = iexplore
      mSearchURL = hxxp://www.Google.com/
      IE: &Download All using 4shared Desktop
      IE: E&xportar a Microsoft Excel - d:\archiv~1\MICROS~1\Office12\EXCEL.EXE/3000
      IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\archivos de programa\PokerStars.NET\PokerStarsUpdate.exe
      DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      FF - ProfilePath - c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\
      FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2233703&SearchSource=3&q={searchTerms}
      FF - prefs.js: browser.startup.homepage - www.google.com
      FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2438727&q=
      FF - component: c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
      FF - component: c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
      FF - component: c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
      FF - plugin: c:\archivos de programa\Google\Google Earth\plugin\npgeplugin.dll
      FF - plugin: c:\archivos de programa\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
      FF - plugin: c:\archivos de programa\Java\jre6\bin\new_plugin\npdeploytk.dll
      FF - plugin: c:\archivos de programa\Java\jre6\bin\new_plugin\npjp2.dll
      FF - plugin: c:\archivos de programa\Mozilla Firefox 3.6 Beta 3\plugins\npdeployJava1.dll
      FF - plugin: c:\archivos de programa\Mozilla Firefox 3.6 Beta 3\plugins\npFoxitReaderPlugin.dll
      FF - plugin: c:\archivos de programa\Opera\program\plugins\NPOFFICE.DLL
      FF - plugin: c:\archivos de programa\Opera\program\plugins\NPOFFICE.DLL
      FF - plugin: c:\archivos de programa\QuickTime\Plugins\npqtplugin.dll
      FF - plugin: c:\archivos de programa\QuickTime\Plugins\npqtplugin2.dll
      FF - plugin: c:\archivos de programa\QuickTime\Plugins\npqtplugin3.dll
      FF - plugin: c:\archivos de programa\QuickTime\Plugins\npqtplugin4.dll
      FF - plugin: c:\archivos de programa\QuickTime\Plugins\npqtplugin5.dll
      FF - plugin: c:\archivos de programa\QuickTime\Plugins\npqtplugin6.dll
      FF - plugin: c:\archivos de programa\QuickTime\Plugins\npqtplugin7.dll
      FF - plugin: c:\archivos de programa\Unity\WebPlayer\loader\npUnity3D32.dll
      FF - plugin: c:\archivos de programa\Windows Media Player\npdrmv2.dll
      FF - plugin: c:\archivos de programa\Windows Media Player\npdsplay.dll
      FF - plugin: c:\archivos de programa\Windows Media Player\npwmsdrm.dll
      FF - plugin: c:\archivos de programa\Yahoo!\Shared\npYState.dll
      FF - plugin: c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\npNxGameeu.dll
      FF - plugin: c:\documents and settings\All Users\Datos de programa\NexonUS\NGM\npNxGameUS.dll
      FF - plugin: c:\documents and settings\Facerplast\Datos de programa\Facebook\npfbplugin_1_0_3.dll
      FF - plugin: c:\documents and settings\Facerplast\Datos de programa\Mozilla\plugins\npcoolirisplugin.dll
      FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nppl3260.dll
      FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprjplug.dll
      FF - plugin: c:\program files\Real\RealPlayer\Netscape6\nprpjplug.dll
      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

      ---- FIREFOX POLICIES ----
      FF - user.js: browser.cache.memory.capacity - 65536
      FF - user.js: browser.chrome.favicons - false
      FF - user.js: browser.display.show_image_placeholders - true
      FF - user.js: browser.turbo.enabled - true
      FF - user.js: browser.urlbar.autocomplete.enabled - true
      FF - user.js: browser.urlbar.autofill - true
      FF - user.js: browser.xul.error_pages.enabled - true
      FF - user.js: content.interrupt.parsing - true
      FF - user.js: content.max.tokenizing.time - 3000000
      FF - user.js: content.maxtextrun - 8191
      FF - user.js: content.notify.backoffcount - 5
      FF - user.js: content.notify.interval - 750000
      FF - user.js: content.notify.ontimer - true
      FF - user.js: content.switch.threshold - 750000
      FF - user.js: network.http.max-connections - 32
      FF - user.js: network.http.max-connections-per-server - 8
      FF - user.js: network.http.max-persistent-connections-per-proxy - 8
      FF - user.js: network.http.max-persistent-connections-per-server - 4
      FF - user.js: network.http.pipelining - true
      FF - user.js: network.http.pipelining.firstrequest - true
      FF - user.js: network.http.pipelining.maxrequests - 8
      FF - user.js: network.http.proxy.pipelining - true
      FF - user.js: network.http.request.max-start-delay - 0
      FF - user.js: nglayout.initialpaint.delay - 0
      FF - user.js: plugin.expose_full_path - true
      FF - user.js: ui.submenuDelay - 0
      c:\archivos de programa\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
      c:\archivos de programa\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
      c:\archivos de programa\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
      .
      - - - - ORPHANS REMOVED - - - -

      BHO-{EB5CEE80-030A-4ED8-8E20-454E9C68380F} - (no file)
      Notify-avldr - (no file)
      MSConfigStartUp-ares - c:\archivos de programa\Ares\Ares.exe
      AddRemove-uTorrent - c:\archivos de programa\uTorrent\uTorrent.exe



      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-09-26 22:50
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      --------------------- LOCKED REGISTRY KEYS ---------------------

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
      @Denied: (A 2) (Everyone)
      @="FlashBroker"
      "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
      "Enabled"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
      @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
      @Denied: (A 2) (Everyone)
      @="IFlashBroker4"

      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
      @="{00020424-0000-0000-C000-000000000046}"

      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      "Version"="1.0"
      .
      --------------------- DLLs Loaded Under Running Processes ---------------------

      - - - - - - - > 'winlogon.exe'(628)
      c:\windows\system32\SETUPAPI.dll
      c:\windows\SYSTEM32\sfc_os.dll
      d:\archivos de programa\SUPERAntiSpyware\SASWINLO.DLL
      c:\windows\SYSTEM32\COMRes.dll
      c:\archivos de programa\Archivos comunes\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
      c:\windows\SYSTEM32\cscui.dll

      - - - - - - - > 'lsass.exe'(684)
      c:\windows\system32\setupapi.dll
      .
      Completion time: 2010-09-26 22:55:22
      ComboFix-quarantined-files.txt 2010-09-27 01:55
      ComboFix2.txt 2008-12-06 14:02

      Pre-Run: 57.757.696 bytes libres
      Post-Run: 166.531.072 bytes libres

      WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
      [operating systems]
      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
      UnsupportedDebug="do not select this" /debug
      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

      Current=16 Default=16 Failed=15 LastKnownGood=17 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17
      - - End Of File - - 0B203E89B9C01BFB307C69A21847C518

    6. #6
      Moderador Gral.
      Avatar de Damianl_77
      Registrado
      ene 2008
      Ubicación
      Argentina
      Mensajes
      22.895

      Re: Múltiples problemas, errores de .dll, pant. azules y desconexiones.

      Como para no tener tantos errores

      Tenes el CD de instalación?

      Descarga el archivo adjunto que te dejo al final del post y guardalo en "C" quedando de esta manera:

      C:\midimap.dll

      Realiza estos pasos

      * Clic en INICIO > EJECUTAR >
      o Y ahí pones notepad.exe y ACEPTAR
      o Ahora copia y pega estos archivos dentro del Notepad (menos la palabra código)




      Código:
      KillAll::
      
      
      File::
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR
      c:\windows\system32\2A6F47CBAA.sys
      
      
      Folder::
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR
      C:\documents and settings\Facerplast\Datos de programa\netz
      d:\archivos de programa\Ask.com
      
      Driver::
      2A6F47CBAA
      
      Registry::
      [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
      
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
      "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
      
      [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
      [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
      [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
      [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
      
      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
      "{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
      
      [-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
      [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
      [-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
      [-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
      
      FCopy::
      c:\midimap.dll | c:\windows\system32\midimap.dll


      * Graba este archivo con el nombre CFScript.txt y déjalo en tu escritorio.

      Antes de usar el CFScript....
      • Desactiva temporalmente el Antivirus y/o Antispyware..
      • Cierra todas las ventanas abiertas. Arrastras el block de notas al icono de ComboFix que tenes en el escritorio, como muestra la imagen de abajo.



      * ComboFix comenzará otra vez a ejecutarse, Cuando termine este generara un reporte que tendrías que pegar en este mismo mensaje.

      Espero el nuevo reporte, tu respuesta y comenta como se encuentra funcionando la PC.


      Blog | Antivirus Online | Eliminar Malwares | Antivirus Gratis


      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    7. #7
      Usuario Avatar de Freddie90
      Registrado
      oct 2008
      Ubicación
      Montevideo, Uruguay
      Mensajes
      8

      Re: Múltiples problemas, errores de .dll, pant. azules y desconexiones.

      Pues, hasta ahora el error de Opciones de Internet; svchost.exe "0x00000000"; services.msc siguen con errores :/.


      Cita Originalmente publicado por ComboFix
      ComboFix 10-09-25.07 - Facerplast 27/09/2010 1:33.3.2 - x86
      Running from: c:\documents and settings\Facerplast\Escritorio\ComboFix.exe
      Command switches used :: c:\documents and settings\Facerplast\Escritorio\CFScript.txt
      * Created a new restore point
      * Resident AV is active


      FILE ::
      "c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR"
      "c:\windows\system32\2A6F47CBAA.sys"
      .

      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\COMBOSEARCH.acs
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\connect.ico
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\dnload.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\dnloado.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\downfile\megauper.zip
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\downfile\megauper.zip27292250
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\ErrorPageTemplate.css
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\extend.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\extendi.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\extendo.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\graphred0.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\graphred0_5.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\graphred1.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\graphred1_5.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\graphred2.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\graphred2_5.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\graphred3.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\graphred3_5.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\graphred4.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\graphred4_5.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\graphred5.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\happyhour.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\happyhouri.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\happyhouro.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\help.gif
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\ie7tab3.zip
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\info.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\links.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\logo.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\logoo.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\marrow.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\megauper.exe
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\megauploadtoolbartb0500.cfg
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\powered_by_yahoo.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\search.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\searchA.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\searchAo.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\searcho.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\sinfo.txt
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\sinfo.txt21570578
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\sinfo.txt21573218
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\sinfo.txt230425390
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\sinfo.txt46153000
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\slider.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\tab_icon.png
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\tabdata.js
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\tablib.js
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\tabwelcome.html
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\upload.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\uploado.bmp
      c:\documents and settings\Facerplast\Datos de programa\MEGAUPLOADTOOLBAR\yahoo_search.gif
      c:\documents and settings\Facerplast\Datos de programa\netz
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\DataFiles\characters.txt
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\DataFiles\clan-names.txt
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\DataFiles\gear.txt
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\DataFiles\statistics-config.txt
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\DataFiles\statistics.txt
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\tessdata\ca.DangAmbigs
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\tessdata\ca.freq-dawg
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\tessdata\ca.inttemp
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\tessdata\ca.normproto
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\tessdata\ca.pffmtable
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\tessdata\ca.unicharset
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\tessdata\ca.user-words
      c:\documents and settings\Facerplast\Datos de programa\netz\CA CW Helper\1.0.3.0\tessdata\ca.word-dawg
      C:\Thumbs.db
      c:\windows\system32\2A6F47CBAA.sys
      d:\archivos de programa\Ask.com
      d:\archivos de programa\Ask.com\cobrand.ico
      d:\archivos de programa\Ask.com\config.xml
      d:\archivos de programa\Ask.com\favicon.ico
      d:\archivos de programa\Ask.com\fv_667.ico
      d:\archivos de programa\Ask.com\GenericAskToolbar.dll
      d:\archivos de programa\Ask.com\mupcfg.xml
      d:\archivos de programa\Ask.com\SaUpdate.exe
      d:\archivos de programa\Ask.com\Thumbs.db
      d:\archivos de programa\Ask.com\UpdateTask.exe

      .
      --------------- FCopy ---------------

      c:\midimap.dll --> c:\windows\system32\midimap.dll
      .
      ((((((((((((((((((((((((( Files Created from 2010-08-27 to 2010-09-27 )))))))))))))))))))))))))))))))
      .

      2010-09-27 04:30 . 2010-09-27 02:56 18944 ------w- C:\midimap.dll
      2010-09-26 23:02 . 2010-09-26 23:02 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Malwarebytes
      2010-09-26 23:01 . 2010-04-29 18:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
      2010-09-26 23:01 . 2010-09-26 23:01 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Malwarebytes
      2010-09-26 23:01 . 2010-04-29 18:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
      2010-09-26 23:01 . 2010-09-26 23:01 -------- dc----w- d:\archivos de programa\Malwarebytes' Anti-Malware
      2010-09-24 03:29 . 2010-09-24 03:29 -------- dc----w- d:\archivos de programa\Trend Micro
      2010-09-22 04:06 . 2010-09-22 04:06 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\SUPERAntiSpyware.com
      2010-09-22 04:06 . 2010-09-22 04:06 -------- d-----w- c:\documents and settings\All Users\Datos de programa\SUPERAntiSpyware.com
      2010-09-22 04:06 . 2010-09-22 04:06 -------- dc----w- d:\archivos de programa\SUPERAntiSpyware
      2010-09-22 04:06 . 2010-09-22 04:06 -------- dc----w- d:\archivos de programa\SpywareBlaster
      2010-09-21 13:48 . 2010-09-21 13:48 -------- dc----w- d:\archivos de programa\MSXML 4.0
      2010-09-21 08:39 . 2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
      2010-09-21 08:39 . 2010-09-21 08:39 -------- dc----w- d:\archivos de programa\Realtek
      2010-09-19 06:36 . 2009-11-21 15:58 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
      2010-09-19 06:34 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
      2010-09-04 23:07 . 2010-09-04 23:07 -------- dc----w- d:\archivos de programa\VID_0E8F&PID_0003
      2010-09-04 23:07 . 2006-04-28 16:33 9216 ----a-w- c:\windows\system32\drivers\GF0003.sys
      2010-09-04 23:07 . 2010-09-04 23:07 -------- d-----w- c:\archivos de programa\Archivos comunes\VID_0E8F&PID_0003
      2010-08-31 17:55 . 2010-09-25 13:27 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Spybot - Search & Destroy
      2010-08-31 17:55 . 2010-09-24 16:09 -------- dc----w- d:\archivos de programa\Spybot - Search & Destroy
      2010-08-31 13:59 . 2010-08-31 13:59 -------- d-----w- c:\documents and settings\All Users\Datos de programa\WNR
      2010-08-31 13:58 . 2010-08-31 13:58 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\WNR
      2010-08-31 01:07 . 2010-08-31 01:07 -------- dc----w- d:\archivos de programa\Microsoft Silverlight
      2010-08-30 11:34 . 2010-08-30 11:31 178176 ----a-w- c:\windows\system32\wbemdisp.dll
      2010-08-29 16:55 . 2010-08-29 16:55 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\SynthMaker
      2010-08-29 12:59 . 2010-08-30 13:27 -------- dc----w- d:\archivos de programa\Acoustica Shared Effects
      2010-08-29 12:58 . 2010-08-30 10:19 -------- dc----w- d:\archivos de programa\Acoustica Mixcraft 5

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-09-27 04:40 . 2008-08-01 05:16 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\uTorrent
      2010-09-27 04:31 . 2008-09-05 21:51 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\mIRC
      2010-09-27 02:56 . 2006-03-02 12:00 18944 ----a-w- c:\windows\system32\midimap.dll
      2010-09-26 22:54 . 2008-07-28 23:04 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Google Updater
      2010-09-24 03:29 . 2010-09-24 03:29 388096 ----a-r- c:\documents and settings\Facerplast\Datos de programa\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
      2010-09-23 18:53 . 2009-04-13 05:04 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Microsoft Help
      2010-09-23 18:49 . 2004-08-20 12:00 94648 ----a-w- c:\windows\system32\perfc00A.dat
      2010-09-23 18:49 . 2004-08-20 12:00 509142 ----a-w- c:\windows\system32\perfh00A.dat
      2010-09-23 14:15 . 2009-05-16 13:37 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\MessengerDiscovery 2
      2010-09-23 03:25 . 2008-08-30 12:09 401304 ---ha-w- c:\windows\system32\mlfcache.dat
      2010-09-22 09:24 . 2009-07-24 23:09 620664 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
      2010-09-22 04:08 . 2010-09-22 04:08 63488 ----a-w- c:\documents and settings\Facerplast\Datos de programa\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
      2010-09-22 04:08 . 2010-09-22 04:08 52224 ----a-w- c:\documents and settings\Facerplast\Datos de programa\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
      2010-09-22 04:08 . 2010-09-22 04:08 117760 ----a-w- c:\documents and settings\Facerplast\Datos de programa\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
      2010-09-22 04:05 . 2010-03-18 04:01 -------- dc----w- d:\archivos de programa\CCleaner
      2010-09-21 08:57 . 2010-04-09 17:55 -------- dc----w- d:\archivos de programa\Total Video Converter
      2010-09-21 08:57 . 2010-07-05 13:10 -------- dc----w- d:\archivos de programa\TextAloud
      2010-09-19 08:42 . 2009-12-19 12:11 -------- dc----w- d:\archivos de programa\Garena
      2010-09-19 07:54 . 2010-05-22 08:34 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Mipony
      2010-09-19 01:37 . 2010-06-18 00:04 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Facebook
      2010-09-19 01:34 . 2010-01-03 11:36 -------- dc----w- d:\archivos de programa\Rockstar
      2010-09-19 01:34 . 2010-02-10 03:58 -------- dc----w- d:\archivos de programa\CamStudio
      2010-09-19 01:34 . 2010-03-28 04:33 -------- dc----w- d:\archivos de programa\Avi
      2010-09-19 01:34 . 2008-12-03 20:13 -------- d-----w- d:\archivos de programa\GameSpy Arcade
      2010-09-19 01:34 . 2010-07-06 11:03 -------- dc----w- d:\archivos de programa\AV Vcs 6.0 DIAMOND
      2010-09-19 01:30 . 2009-11-10 05:22 -------- dc----w- d:\archivos de programa\Inkscape
      2010-09-17 17:31 . 2009-06-13 22:54 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Winamp
      2010-09-14 22:05 . 2009-11-16 14:28 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Rosetta Stone
      2010-09-12 20:40 . 2010-06-04 14:15 -------- dc----w- d:\archivos de programa\wamp
      2010-09-12 10:09 . 2008-09-03 18:03 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Skype
      2010-09-12 06:11 . 2008-09-03 18:04 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\skypePM
      2010-09-08 14:04 . 2010-09-18 03:20 114360 ----a-w- c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
      2010-09-06 06:46 . 2009-05-15 22:03 81920 ----a-w- c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\npNxGameeu.dll
      2010-09-06 06:46 . 2009-05-15 22:03 98304 -c--a-w- c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\nxgameeu.dll
      2010-09-06 06:46 . 2009-05-15 22:03 331776 ----a-w- c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\NGMResource.dll
      2010-09-06 06:46 . 2009-05-15 22:03 258352 -c--a-w- c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\unicows.dll
      2010-09-06 06:46 . 2009-05-15 22:02 532480 ----a-w- c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\NGMDll.dll
      2010-09-06 06:46 . 2009-05-15 22:02 155648 ----a-w- c:\documents and settings\All Users\Datos de programa\NexonEU\NGM\NGM.exe
      2010-09-06 06:45 . 2009-05-15 14:23 421888 -c--a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe
      2010-09-04 23:07 . 2010-06-24 02:47 -------- dc-h--w- d:\archivos de programa\InstallShield Installation Information
      2010-08-30 10:19 . 2010-08-09 04:18 -------- dc----w- d:\archivos de programa\Livestream Procaster
      2010-08-30 10:19 . 2010-07-21 08:08 -------- dc----w- d:\archivos de programa\Chess3D
      2010-08-30 10:19 . 2010-02-05 00:08 -------- dc----w- d:\archivos de programa\Metin2
      2010-08-30 10:19 . 2010-06-20 03:47 -------- dc----w- d:\archivos de programa\TrucoTec 2008 V400
      2010-08-30 10:19 . 2010-03-29 04:40 -------- dc----w- d:\archivos de programa\uTorrent
      2010-08-29 16:36 . 2009-08-06 19:33 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Acoustica
      2010-08-29 13:01 . 2009-08-06 19:34 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Acoustica
      2010-08-27 20:17 . 2008-08-01 02:01 -------- d---a-w- c:\documents and settings\All Users\Datos de programa\TEMP
      2010-08-26 14:35 . 2009-06-12 19:42 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\gtk-2.0
      2010-08-20 18:23 . 2010-08-20 17:55 848 --sha-w- c:\windows\system32\KGyGaAvL.sys
      2010-08-17 13:17 . 2006-03-02 12:00 58880 ----a-w- c:\windows\system32\spoolsv.exe
      2010-08-17 07:42 . 2010-08-17 07:42 -------- dc----w- d:\archivos de programa\Enterbrain
      2010-08-04 13:50 . 2008-10-04 12:28 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\Anvil Studio
      2010-08-03 21:32 . 2010-08-03 21:03 -------- dc----w- d:\archivos de programa\SynthFont
      2010-08-03 21:03 . 2010-08-03 21:03 -------- d-----w- c:\documents and settings\Facerplast\Datos de programa\SynthFont
      2010-08-03 20:30 . 2010-08-03 20:30 -------- dc----w- d:\archivos de programa\VST
      2010-08-03 20:11 . 2009-06-01 05:41 -------- d-----w- d:\archivos de programa\Image-Line
      2010-07-30 14:37 . 2010-09-12 18:35 3184800 ----a-w- c:\documents and settings\Facerplast\Datos de programa\mIRC\mirc.exe
      2010-07-22 15:46 . 2006-03-02 12:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll
      2010-07-22 06:19 . 2008-05-05 10:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
      2010-07-14 19:58 . 2010-07-14 19:58 10806 ----a-r- c:\documents and settings\Facerplast\Datos de programa\Microsoft\Installer\{9F83E009-A168-4E65-A6CF-8FFB2F4E0C7B}\_68FD413B433F3D7874F6ED.exe
      2010-07-14 19:58 . 2010-07-14 19:58 10806 ----a-r- c:\documents and settings\Facerplast\Datos de programa\Microsoft\Installer\{9F83E009-A168-4E65-A6CF-8FFB2F4E0C7B}\_44C63FAA304844377BFF37.exe
      2010-07-06 08:25 . 2008-09-10 08:45 711 -c--a-w- c:\windows\eReg.dat
      2010-07-04 07:25 . 2010-06-20 03:48 22 ----a-w- c:\windows\Fonts\Times.txt
      2010-06-30 12:32 . 2006-03-02 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
      2010-06-30 03:13 . 2010-09-23 22:20 52224 ----a-w- c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
      2010-06-30 03:13 . 2010-09-23 22:20 101376 ----a-w- c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
      2010-06-29 21:36 . 2010-06-29 21:35 2167292 ----a-w- c:\documents and settings\Facerplast\Datos de programa\MessengerDiscovery 2\0\Update.exe
      .

      ------- Sigcheck -------

      [-] 2008-04-14 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\atapi.sys
      [-] 2008-04-14 . 9F3A2F5AA6875C72BF062C712CFA2674 . 96512 . . [5.1.2600.5512] . . c:\windows\system32\drivers\atapi.sys
      [-] 2006-03-02 . CDFE4411A69C224BD1D11B2DA92DAC51 . 95360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\atapi.sys

      [-] 2008-04-14 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\asyncmac.sys
      [-] 2008-04-14 . B153AFFAC761E7F5FCFA822B9C4E97BC . 14336 . . [5.1.2600.5512] . . c:\windows\system32\drivers\asyncmac.sys
      [-] 2006-03-02 . 02000ABF34AF4C218C35D257024807D6 . 14336 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\asyncmac.sys

      [-] 2006-03-02 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\dllcache\beep.sys
      [-] 2006-03-02 . DA1F27D85E0D1525F6621372E7B685E9 . 4224 . . [5.1.2600.0] . . c:\windows\system32\drivers\beep.sys

      [-] 2008-04-14 . 188DDD286BC0DAEA6984858C6A4D7BBF . 25088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\kbdclass.sys
      [-] 2008-04-14 . 188DDD286BC0DAEA6984858C6A4D7BBF . 25088 . . [5.1.2600.5512] . . c:\windows\system32\drivers\kbdclass.sys
      [-] 2006-03-02 . 71BFDDA7B3006B45B18D8BAC92BC9993 . 25088 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\kbdclass.sys

      [-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ndis.sys
      [-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D . 182656 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ndis.sys
      [-] 2006-03-02 . 558635D3AF1C7546D26067D5D9B6959E . 182912 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ndis.sys

      [-] 2008-04-14 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ntfs.sys
      [-] 2008-04-14 . 78A08DD6A8D65E697C18E1DB01C5CDCA . 574976 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ntfs.sys
      [-] 2007-02-09 . 05AB81909514BFD69CBB1F2C147CF6B9 . 574976 . . [5.1.2600.3081] . . c:\windows\$hf_mig$\KB930916\SP2QFE\ntfs.sys
      [-] 2007-02-09 . 19A811EF5F1ED5C926A028CE107FF1AF . 574464 . . [5.1.2600.3081] . . c:\windows\$NtServicePackUninstall$\ntfs.sys

      [-] 2006-03-02 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\dllcache\null.sys
      [-] 2006-03-02 . 73C1E1F395918BC2C6DD67AF7591A3AD . 2944 . . [5.1.2600.0] . . c:\windows\system32\drivers\null.sys

      [-] 2008-04-14 . E28818BD591F8AF8FBE9897472B9665E . 77824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\browser.dll
      [-] 2008-04-14 . E28818BD591F8AF8FBE9897472B9665E . 77824 . . [5.1.2600.5512] . . c:\windows\system32\browser.dll
      [-] 2006-03-02 . D01CFCC753B09E70F5B7622501FF5383 . 77312 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\browser.dll

      [-] 2008-04-14 . 671ACA589DA3733FAC878A751C5BF0ED . 13312 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lsass.exe
      [-] 2008-04-14 . 671ACA589DA3733FAC878A751C5BF0ED . 13312 . . [5.1.2600.5512] . . c:\windows\system32\lsass.exe
      [-] 2006-03-02 . 2B0B88652C9F6714FD4886839B3B0442 . 13312 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\lsass.exe

      [-] 2008-04-14 . A48884C9359EE9F1FC8F3F0D93FB1D95 . 198144 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netman.dll
      [-] 2008-04-14 . A48884C9359EE9F1FC8F3F0D93FB1D95 . 198144 . . [5.1.2600.5512] . . c:\windows\system32\netman.dll
      [-] 2005-08-22 . 7BDB3A1B78A33455F3704AA12B9A0FE1 . 197632 . . [5.1.2600.2743] . . c:\windows\$NtServicePackUninstall$\netman.dll
      [-] 2005-08-22 . 157B6FCB58270E3DF3ED67D316DCECE0 . 197632 . . [5.1.2600.2743] . . c:\windows\$hf_mig$\KB905414\SP2QFE\netman.dll

      [-] 2008-04-14 . 8EE9639C01B92490E09638CAA1B16C3C . 409088 . . [6.7.2600.5512] . . c:\windows\ServicePackFiles\i386\qmgr.dll
      [-] 2008-04-14 . 8EE9639C01B92490E09638CAA1B16C3C . 409088 . . [6.7.2600.5512] . . c:\windows\system32\qmgr.dll
      [-] 2008-04-14 . 8EE9639C01B92490E09638CAA1B16C3C . 409088 . . [6.7.2600.5512] . . c:\windows\system32\bits\qmgr.dll
      [-] 2006-03-02 . 02451268DC47E4DC228210DA0E3C3274 . 382464 . . [6.6.2600.2180] . . c:\windows\$NtServicePackUninstall$\qmgr.dll

      [-] 2008-04-14 . 3F5B7DD84DB17717502FB9F9954C17A7 . 550400 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
      [-] 2008-04-14 . 3F5B7DD84DB17717502FB9F9954C17A7 . 550400 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe
      [-] 2008-04-14 . 213C80D912880BBF04453D09FFCCB28C . 510976 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\winlogon.exe
      [-] 2006-03-02 . B7D1DE4D0BBC5E6B920C31951FC9F4C7 . 544768 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe

      [-] 2008-04-14 . 1D6969BDDFC5DE38F92572FF286330FB . 724992 . . [5.82] . . c:\windows\ServicePackFiles\i386\comctl32.dll
      [-] 2008-04-14 . 1D6969BDDFC5DE38F92572FF286330FB . 724992 . . [5.82] . . c:\windows\system32\comctl32.dll
      [-] 2008-04-14 . 618A4C7A7C0CA86DA884C8C0FACAD8C2 . 617472 . . [5.82] . . c:\windows\VistaMizer\old\comctl32.dll
      [-] 2006-08-25 . 3567E0A82689A55907F8D9D70B58F88E . 724992 . . [5.82] . . c:\windows\$NtServicePackUninstall$\comctl32.dll

      [-] 2008-04-14 . E423C9C1946C656E0E4840210A0A8681 . 62464 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\cryptsvc.dll
      [-] 2008-04-14 . E423C9C1946C656E0E4840210A0A8681 . 62464 . . [5.1.2600.5512] . . c:\windows\system32\cryptsvc.dll
      [-] 2006-03-02 . 149CFFBF77CC1306FC535557CF513B91 . 60416 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\cryptsvc.dll

      [-] 2008-04-14 . 95DF6A7520912B1040F748A287EA382A . 110080 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\imm32.dll
      [-] 2008-04-14 . 95DF6A7520912B1040F748A287EA382A . 110080 . . [5.1.2600.5512] . . c:\windows\system32\imm32.dll
      [-] 2006-03-02 . BE2282FBEAFBB76577D47B06071139BB . 110080 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\imm32.dll

      [-] 2008-04-14 . FB67F1E092AB9967D0CD17300D751874 . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\linkinfo.dll
      [-] 2008-04-14 . FB67F1E092AB9967D0CD17300D751874 . 19968 . . [5.1.2600.5512] . . c:\windows\system32\linkinfo.dll
      [-] 2005-09-01 . C4E7CEFD3802415865E631BE3AB6AC3B . 19968 . . [5.1.2600.2751] . . c:\windows\$hf_mig$\KB900725\SP2QFE\linkinfo.dll
      [-] 2005-09-01 . EB7A3E05F297799847AACFA00B4B9218 . 19968 . . [5.1.2600.2751] . . c:\windows\$NtServicePackUninstall$\linkinfo.dll

      [-] 2008-04-14 . 87F15A88AA3376B48F75D7D176B312A0 . 22016 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lpk.dll
      [-] 2008-04-14 . 87F15A88AA3376B48F75D7D176B312A0 . 22016 . . [5.1.2600.5512] . . c:\windows\system32\lpk.dll
      [-] 2006-03-02 . 24B2A5D3EE366A3E9C1E0941363618C7 . 22016 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\lpk.dll

      [-] 2008-04-14 . 0F021B29E0C2C9D897258399FB2149CD . 343040 . . [7.0.2600.5512] . . c:\windows\ServicePackFiles\i386\msvcrt.dll
      [-] 2008-04-14 . 0F021B29E0C2C9D897258399FB2149CD . 343040 . . [7.0.2600.5512] . . c:\windows\system32\msvcrt.dll
      [-] 2006-03-02 . 3CDD949F8340F06FD99667B4F75409D0 . 343040 . . [7.0.2600.2180] . . c:\windows\$NtServicePackUninstall$\msvcrt.dll

      [-] 2008-04-14 . CD2BBB52DFAAB666B812A51B1E96F2A0 . 407040 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\netlogon.dll
      [-] 2008-04-14 . CD2BBB52DFAAB666B812A51B1E96F2A0 . 407040 . . [5.1.2600.5512] . . c:\windows\system32\netlogon.dll
      [-] 2006-03-02 . 7FD182B1B80117C353983565D60B1CAF . 407040 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\netlogon.dll

      [-] 2008-04-14 . 56DE6FD410B277C4345D7A2C3414DB64 . 17408 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\powrprof.dll
      [-] 2008-04-14 . 56DE6FD410B277C4345D7A2C3414DB64 . 17408 . . [6.00.2900.5512] . . c:\windows\system32\powrprof.dll
      [-] 2006-03-02 . 75EFF6383C2F9BC1198C5351754D27AC . 17408 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\powrprof.dll

      [-] 2008-04-14 . B6BE3C96CD33336A551DB3F2299A8E69 . 185856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\scecli.dll
      [-] 2008-04-14 . B6BE3C96CD33336A551DB3F2299A8E69 . 185856 . . [5.1.2600.5512] . . c:\windows\system32\scecli.dll
      [-] 2006-03-02 . C6347748F2E9F310EA1E1915482ABFEF . 184832 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\scecli.dll

      [-] 2008-04-14 . D5AC9FA63EBEFD7AACCB14BA0DB1BAC3 . 5120 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfc.dll
      [-] 2008-04-14 . D5AC9FA63EBEFD7AACCB14BA0DB1BAC3 . 5120 . . [5.1.2600.5512] . . c:\windows\system32\sfc.dll
      [-] 2006-03-02 . CA557E5E31C7BCFC2CB61CCFE9F6C945 . 5120 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\sfc.dll

      [-] 2008-04-14 . 4F2340F0BD5B6365C38E74DD391919A8 . 14336 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\svchost.exe
      [-] 2008-04-14 . 4F2340F0BD5B6365C38E74DD391919A8 . 14336 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe
      [-] 2006-03-02 . FA03E1FC17F38FBDBA81470D08B3E416 . 14336 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\svchost.exe

      [-] 2008-04-14 . 04A5B8EA326951DB27DF60A14F2999FF . 249856 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tapisrv.dll
      [-] 2008-04-14 . 04A5B8EA326951DB27DF60A14F2999FF . 249856 . . [5.1.2600.5512] . . c:\windows\system32\tapisrv.dll
      [-] 2005-07-08 . 861E25215BA370D4CA9337C2BC0E647F . 249344 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
      [-] 2005-07-08 . FB0794BE642E50D2284A8841043B5867 . 249344 . . [5.1.2600.2716] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll

      [-] 2008-04-14 . BCEAB836D3EF27938B90D5FF88C0FE26 . 588288 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\user32.dll
      [-] 2008-04-14 . BCEAB836D3EF27938B90D5FF88C0FE26 . 588288 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll
      [-] 2008-04-14 . DA8898129E0075C7DE4DEE457514A73C . 579584 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\user32.dll
      [-] 2007-03-08 . 237FB93C6B4330D8EE7D2448CF71C5ED . 579072 . . [5.1.2600.3099] . . c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
      [-] 2007-03-08 . FED9881C07A301271F52B51389A028C9 . 578560 . . [5.1.2600.3099] . . c:\windows\$NtServicePackUninstall$\user32.dll
      [-] 2005-03-02 . 37CE819E8ECB3517B9981A886876EF72 . 578048 . . [5.1.2600.2622] . . c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll

      [-] 2008-04-14 . F5B8745B9A90EAF17E30C0574E049AA3 . 26624 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe
      [-] 2008-04-14 . F5B8745B9A90EAF17E30C0574E049AA3 . 26624 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe
      [-] 2006-03-02 . 7B30B4D55B4562C733A5DDF6D6F72B3F . 25088 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\userinit.exe

      [-] 2009-01-15 . 2557EC018A4FE11589415F7C26D116F1 . 1013248 . . [8.00.6001.18372] . . c:\windows\ServicePackFiles\i386\wininet.dll
      [-] 2009-01-15 . 2557EC018A4FE11589415F7C26D116F1 . 1013248 . . [8.00.6001.18372] . . c:\windows\system32\wininet.dll
      [7] 2009-01-15 . 203C05A174A45270A30CDD593092D91E . 911872 . . [8.00.6001.18372] . . c:\windows\VistaMizer\old\wininet.dll
      [-] 2008-06-23 . 24207433B012CD6B3C746D245C6EBCE6 . 669184 . . [6.00.2900.5626] . . c:\windows\$hf_mig$\KB953838\SP3QFE\wininet.dll
      [-] 2008-04-21 . D273F0C482B866EF3F471E388588228E . 669184 . . [6.00.2900.5583] . . c:\windows\$hf_mig$\KB950759\SP3QFE\wininet.dll
      [7] 2007-08-13 . A4A0FC92358F39538A6494C42EF99FE9 . 818688 . . [7.00.5730.13] . . c:\windows\ie8\wininet.dll
      [-] 2006-03-02 . 80BB109560A23B9C18427855CA5305E6 . 658944 . . [6.00.2900.2180] . . c:\windows\ie7\wininet.dll

      [-] 2008-04-14 . 22DB5B3DA7005C6472D35BEF3FFDA5EC . 82432 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2_32.dll
      [-] 2008-04-14 . 22DB5B3DA7005C6472D35BEF3FFDA5EC . 82432 . . [5.1.2600.5512] . . c:\windows\system32\ws2_32.dll
      [-] 2006-03-02 . B4A90738BA4355F187BD26D6C112082B . 82944 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ws2_32.dll

      [-] 2008-04-14 . F7EE4BBFB48437EDC6F7F061DE1E8F2F . 19968 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ws2help.dll
      [-] 2008-04-14 . F7EE4BBFB48437EDC6F7F061DE1E8F2F . 19968 . . [5.1.2600.5512] . . c:\windows\system32\ws2help.dll
      [-] 2006-03-02 . 0EDF3501370A14BEFB27526CD06FACEE . 19968 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ws2help.dll

      [-] 2008-04-14 . 262BCE958456D31B59C30A1329CECD2B . 1554944 . . [6.00.2900.5512] . . c:\windows\explorer.exe
      [-] 2008-04-14 . 262BCE958456D31B59C30A1329CECD2B . 1554944 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
      [-] 2008-04-14 . 7522F548A84ABAD8FA516DE5AB3931EF . 1036288 . . [6.00.2900.5512] . . c:\windows\VistaMizer\old\explorer.exe
      [-] 2007-06-13 . E5CF28568CB22C37F15B12C9115F70BE . 1554432 . . [6.00.2900.3156] . . c:\windows\$NtServicePackUninstall$\explorer.exe
      [-] 2007-06-13 . DBB6B75CC6CB2CF8EC0BAFCA08AED6BE . 1035776 . . [6.00.2900.3156] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe

      [-] 2008-04-14 . 48D6DDFED47793E0F6DD77B8F2660BC3 . 1312256 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ole32.dll
      [-] 2008-04-14 . 48D6DDFED47793E0F6DD77B8F2660BC3 . 1312256 . . [5.1.2600.5512] . . c:\windows\system32\ole32.dll
      [-] 2008-04-14 . 463D57BF9FE5871208FF99399360A57D . 1287168 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ole32.dll
      [-] 2005-07-26 . 3200390606D6816D86F14AAFAB7F1A03 . 1284608 . . [5.1.2600.2726] . . c:\windows\$NtServicePackUninstall$\ole32.dll
      [-] 2005-07-26 . 1CCD86AF8968519AE6BF9729FC566F1A . 1285632 . . [5.1.2600.2726] . . c:\windows\$hf_mig$\KB902400\SP2QFE\ole32.dll
      [-] 2005-04-28 . E13ABDC8A801329203091546722B63C9 . 1286144 . . [5.1.2600.2665] . . c:\windows\$hf_mig$\KB894391\SP2QFE\ole32.dll

      [-] 2008-04-14 . 0F30EEC6013FCF76693405EC4A7DF899 . 171520 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\srsvc.dll
      [-] 2008-04-14 . 0F30EEC6013FCF76693405EC4A7DF899 . 171520 . . [5.1.2600.5512] . . c:\windows\system32\srsvc.dll
      [-] 2006-03-02 . C791D16BF25264738B14873436293BD0 . 171008 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\srsvc.dll

      [-] 2008-04-14 . B2718EC9DC738E915D4177498E92BC4D . 13824 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wscntfy.exe
      [-] 2008-04-14 . B2718EC9DC738E915D4177498E92BC4D . 13824 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe
      [-] 2006-03-02 . 9C90A6DBE5D43E189F199172675D6312 . 13824 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\wscntfy.exe

      [-] 2008-04-14 . 14FDADCF05A37582399DAF1DA1DE1C7B . 129024 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\xmlprov.dll
      [-] 2008-04-14 . 14FDADCF05A37582399DAF1DA1DE1C7B . 129024 . . [5.1.2600.5512] . . c:\windows\system32\xmlprov.dll
      [-] 2006-03-02 . 843E0DB8042A8C0D749EB2B9EFA54F24 . 129536 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\xmlprov.dll

      [-] 2008-04-14 . 2744C713F0217BD8FFD13E2EF731371C . 56320 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\eventlog.dll
      [-] 2008-04-14 . 2744C713F0217BD8FFD13E2EF731371C . 56320 . . [5.1.2600.5512] . . c:\windows\system32\eventlog.dll
      [-] 2006-03-02 . 5696DF4EF09C375CE42FB2DDE1E68AB7 . 55808 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\eventlog.dll

      [-] 2008-04-14 . 2A1E1DF559B291583903D2F9CC504522 . 1572352 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfcfiles.dll
      [-] 2008-04-14 . 2A1E1DF559B291583903D2F9CC504522 . 1572352 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
      [-] 2006-03-02 . AAFD7382D64710AE3A6F1DEE5020CF19 . 1548800 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\sfcfiles.dll

      [-] 2008-04-14 . 0787E74EE4A4BC7448DA95CC1866F83E . 25088 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
      [-] 2008-04-14 . 0787E74EE4A4BC7448DA95CC1866F83E . 25088 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
      [-] 2008-04-14 . DAAE1CB1B1875B760496E7D3336DA1AD . 15360 . . [5.1.2600.5512] . . c:\windows\VistaMizer\old\ctfmon.exe
      [-] 2006-03-02 . 172F37F076E17C28D63F02049A181679 . 25088 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe

      [-] 2008-04-14 . CA70EDBF32032EA53F114CB930741CB5 . 135168 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\shsvcs.dll
      [-] 2008-04-14 . CA70EDBF32032EA53F114CB930741CB5 . 135168 . . [6.00.2900.5512] . . c:\windows\system32\shsvcs.dll
      [-] 2006-12-19 . 2A7B15883836B7B44F4C9FADEEF2F187 . 134656 . . [6.00.2900.3051] . . c:\windows\$NtServicePackUninstall$\shsvcs.dll
      [-] 2006-12-19 . 00C566D725F80E77DAACB82D1FED4493 . 135168 . . [6.00.2900.3051] . . c:\windows\$hf_mig$\KB928255\SP2QFE\shsvcs.dll

      [-] 2008-04-14 . E424F05B07AC4357DC08D06218D76C7C . 59904 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regsvc.dll
      [-] 2008-04-14 . E424F05B07AC4357DC08D06218D76C7C . 59904 . . [5.1.2600.5512] . . c:\windows\system32\regsvc.dll
      [-] 2006-03-02 . D025E953864EBEBAB5933086D15C4FC6 . 59904 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\regsvc.dll

      [-] 2008-04-14 . 51BE25C404D3DD344C6079DE715E4977 . 193536 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\schedsvc.dll
      [-] 2008-04-14 . 51BE25C404D3DD344C6079DE715E4977 . 193536 . . [5.1.2600.5512] . . c:\windows\system32\schedsvc.dll
      [-] 2006-03-02 . 0125649B3C00D037E07FD7BCEF7B653B . 192000 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\schedsvc.dll

      [-] 2008-04-14 . B622A432EF02895DE4AA38AC8B85FA4C . 71680 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ssdpsrv.dll
      [-] 2008-04-14 . B622A432EF02895DE4AA38AC8B85FA4C . 71680 . . [5.1.2600.5512] . . c:\windows\system32\ssdpsrv.dll
      [-] 2006-03-02 . 4AFF5EA8BF2362C3D5001295FDEB3ABD . 71680 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ssdpsrv.dll

      [-] 2008-04-14 . 288B20D56D5F0EC4BCC77FBFA5A81740 . 296960 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\termsrv.dll
      [-] 2008-04-14 . 288B20D56D5F0EC4BCC77FBFA5A81740 . 296960 . . [5.1.2600.5512] . . c:\windows\system32\termsrv.dll
      [-] 2006-03-02 . C2038466BE5A6A76EFD592FA0B459E17 . 296960 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\termsrv.dll

      [-] 2008-04-14 . 30CD42BFCDAFEFE8567B9E527DD3AE08 . 175104 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\appmgmts.dll
      [-] 2008-04-14 . 30CD42BFCDAFEFE8567B9E527DD3AE08 . 175104 . . [5.1.2600.5512] . . c:\windows\system32\appmgmts.dll
      [-] 2006-03-02 . 0CF68B185221E5B162EF1B0559428B40 . 175104 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\appmgmts.dll

      [-] 2006-03-02 . 1C905333C0B9F3D7C68DDF25E54B00F9 . 12032 . . [5.1.2600.0] . . c:\windows\system32\drivers\acpiec.sys

      [-] 2008-04-14 00:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\ServicePackFiles\i386\aec.sys
      [-] 2008-04-14 00:09 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . c:\windows\system32\drivers\aec.sys
      [-] 2006-02-15 00:30 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\$hf_mig$\KB900485\SP2QFE\aec.sys
      [-] 2006-02-15 00:22 . 1EE7B434BA961EF845DE136224C30FEC . 142464 . . [5.1.2601.2180] . . c:\windows\$NtServicePackUninstall$\aec.sys

      [-] 2008-04-14 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\agp440.sys
      [-] 2008-04-14 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512] . . c:\windows\system32\drivers\agp440.sys
      [-] 2004-08-04 . 2C428FA0C3E3A01ED93C9B2A27D8D4BB . 42368 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\agp440.sys

      [-] 2008-04-14 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ip6fw.sys
      [-] 2008-04-14 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\system32\drivers\ip6fw.sys
      [-] 2006-03-02 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ip6fw.sys

      [-] 2008-04-14 09:48 . 27415CEEB58C8C2F92AFF8CFE2517A3C . 927504 . . [4.1.0.61] . . c:\windows\ServicePackFiles\i386\mfc40u.dll
      [-] 2008-04-14 09:48 . 27415CEEB58C8C2F92AFF8CFE2517A3C . 927504 . . [4.1.0.61] . . c:\windows\system32\mfc40u.dll
      [-] 2006-11-01 19:18 . 2B7A4915332B5DD133536E1E7E436654 . 927504 . . [4.1.0.61] . . c:\windows\$NtServicePackUninstall$\mfc40u.dll

      [-] 2008-04-14 . 047E70B04B288439245DDC8DD1A31982 . 33792 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\msgsvc.dll
      [-] 2008-04-14 . 047E70B04B288439245DDC8DD1A31982 . 33792 . . [5.1.2600.5512] . . c:\windows\system32\msgsvc.dll
      [-] 2006-03-02 . CA33F6547C49E749E47FB6A0D1DBE192 . 33792 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\msgsvc.dll

      [-] 2008-04-14 02:18 . 57CF215B0250DE0C4AE36ABC8AE31BE4 . 52736 . . [9.0.1.56] . . c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
      [-] 2006-10-18 23:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll
      [-] 2006-10-18 23:47 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\dllcache\mspmsnsv.dll

      [-] 2008-04-14 09:48 . D60C40D71A4D874C903255E4827AFA0C . 437760 . . [5.1.2400.5512] . . c:\windows\ServicePackFiles\i386\ntmssvc.dll
      [-] 2008-04-14 09:48 . D60C40D71A4D874C903255E4827AFA0C . 437760 . . [5.1.2400.5512] . . c:\windows\system32\ntmssvc.dll
      [-] 2006-03-02 12:00 . 395948DEE2B0F534A8C70687CC6DD7CA . 437760 . . [5.1.2400.2180] . . c:\windows\$NtServicePackUninstall$\ntmssvc.dll

      [-] 2008-04-14 . 7594203F459ABDB5FE53C08D6B1BD53B . 186368 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\upnphost.dll
      [-] 2008-04-14 . 7594203F459ABDB5FE53C08D6B1BD53B . 186368 . . [5.1.2600.5512] . . c:\windows\system32\upnphost.dll
      [-] 2007-02-05 . FCB8D49E28B6AB1BC09AC240B07BADFC . 185344 . . [5.1.2600.3077] . . c:\windows\$hf_mig$\KB931261\SP2QFE\upnphost.dll
      [-] 2007-02-05 . 534166BDD7664FA8590827FFB73F1B35 . 185344 . . [5.1.2600.3077] . . c:\windows\$NtServicePackUninstall$\upnphost.dll

      [-] 2008-04-14 . 9EF059A2C76BCE8DB9B0DD95EFE23A48 . 367616 . . [5.3.2600.5512] . . c:\windows\ServicePackFiles\i386\dsound.dll
      [-] 2008-04-14 . 9EF059A2C76BCE8DB9B0DD95EFE23A48 . 367616 . . [5.3.2600.5512] . . c:\windows\system32\dsound.dll
      [-] 2006-03-02 . BDE6AEDFD66768C08C42DAE5056B6779 . 367616 . . [5.3.2600.2180] . . c:\windows\$NtServicePackUninstall$\dsound.dll
      [7] 2004-07-09 07:27 . 033A45AB696EEF481707C2808C806E1A . 381952 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\dsound.dll
      [7] 2004-07-09 07:27 . 033A45AB696EEF481707C2808C806E1A . 381952 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\system32\dllcache\dsound.dll

      [-] 2008-04-14 . AE5DD931EFAB3687BA4DF0671F4CE078 . 1689088 . . [5.03.2600.5512] . . c:\windows\ServicePackFiles\i386\d3d9.dll
      [-] 2008-04-14 . AE5DD931EFAB3687BA4DF0671F4CE078 . 1689088 . . [5.03.2600.5512] . . c:\windows\system32\d3d9.dll
      [-] 2006-03-02 . 77A1379688F15B02D5100183A54778BB . 1689088 . . [5.03.2600.2180] . . c:\windows\$NtServicePackUninstall$\d3d9.dll

      [-] 2008-04-14 . 28D0D87445F4ADD6614155EC13F042DD . 279552 . . [5.03.2600.5512] . . c:\windows\ServicePackFiles\i386\ddraw.dll
      [-] 2008-04-14 . 28D0D87445F4ADD6614155EC13F042DD . 279552 . . [5.03.2600.5512] . . c:\windows\system32\ddraw.dll
      [-] 2006-03-02 . 285B7EA6C449DA0E08B1195FE7033A1A . 266240 . . [5.03.2600.2180] . . c:\windows\$NtServicePackUninstall$\ddraw.dll
      [7] 2004-07-09 07:27 . 90114704C17A581DA1BAE029F20932BE . 292864 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\RegisteredPackages\{44BBA855-CC51-11CF-AAFA-00AA00B6015C}\ddraw.dll
      [7] 2004-07-09 07:27 . 90114704C17A581DA1BAE029F20932BE . 292864 . . [5.3.0000001.0904 built by: private/Lab06_dev(DXBLD00)] . . c:\windows\system32\dllcache\ddraw.dll

      [-] 2008-04-14 09:48 . F71CB6064DFC10DFB767B537BFA33D61 . 84992 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\olepro32.dll
      [-] 2008-04-14 09:48 . F71CB6064DFC10DFB767B537BFA33D61 . 84992 . . [5.1.2600.5512] . . c:\windows\system32\olepro32.dll
      [-] 2006-03-02 12:00 . 74A98B98FB63049B6FECC472AD09A577 . 83456 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\olepro32.dll

      [-] 2008-04-14 . 91C2A139745F2AF17E4685A1E54B4FDA . 41984 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\perfctrs.dll
      [-] 2008-04-14 . 91C2A139745F2AF17E4685A1E54B4FDA . 41984 . . [5.1.2600.5512] . . c:\windows\system32\perfctrs.dll
      [-] 2006-03-02 . AC18C8A4D842211748AAACF89EFEBF07 . 41984 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\perfctrs.dll

      [-] 2008-04-14 . F4968D88123785BCF95A31E0225C5592 . 18944 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\version.dll
      [-] 2008-04-14 . F4968D88123785BCF95A31E0225C5592 . 18944 . . [5.1.2600.5512] . . c:\windows\system32\version.dll
      [-] 2006-03-02 . 63782F8342BB8F04E0AFCAABA2B60C09 . 18944 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\version.dll
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "DAEMON Tools Lite"="d:\archivos de programa\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
      "MsnMsgr"="c:\archivos de programa\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
      "ares"="d:\archivos de programa\Ares\Ares.exe" [2009-03-13 3231744]
      "uTorrent"="d:\archivos de programa\uTorrent\uTorrent.exe" [2010-08-30 328568]
      "Google Update"="c:\documents and settings\Facerplast\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
      "SUPERAntiSpyware"="d:\archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-09-10 2424560]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
      "GrooveMonitor"="d:\archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
      "egui"="c:\archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe" [2009-02-06 2021400]
      "nwiz"="c:\archivos de programa\NVIDIA Corporation\nView\nwiz.exe" [2009-08-13 1657376]
      "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-08-17 86016]
      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
      "RTHDCPL"="RTHDCPL.EXE" [2007-10-25 16855552]
      "SkyTel"="SkyTel.EXE" [2007-10-11 1826816]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 25088]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
      "NoPopUpsOnBoot"= 1 (0x1)

      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
      "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\archivos de programa\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
      2009-09-03 22:21 548352 -c--a-w- d:\archivos de programa\SUPERAntiSpyware\SASWINLO.DLL

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
      BootExecute REG_MULTI_SZ autocheck autochk /p \??\D\0autocheck autochk /k:C /k:D *

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menú Inicio^Programas^Inicio^Actualizar la licencia de ESET.lnk]
      backup=c:\windows\pss\Actualizar la licencia de ESET.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^Facerplast^Menú Inicio^Programas^Inicio^Recorte de pantalla e Inicio rápido de OneNote 2007.lnk]
      backup=c:\windows\pss\Recorte de pantalla e Inicio rápido de OneNote 2007.lnkStartup

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
      c:\windows\system32\dumprep 0 -k [X]

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
      2008-08-14 09:58 611712 ----a-w- c:\archivos de programa\Archivos comunes\Adobe\CS4ServiceManager\CS4ServiceManager.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
      2010-08-10 18:10 2349776 -c--a-w- d:\archivos de programa\IObit\Advanced SystemCare 3\AWC.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
      2007-07-02 10:27 219520 -c--a-w- d:\archivos de programa\Alcohol Soft\Alcohol 120\AxCmd.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FileHippo.com]
      2010-04-29 12:57 248832 ----a-w- c:\archivos de programa\FileHippo.com\UpdateChecker.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
      2008-09-02 19:41 133104 ----atw- c:\documents and settings\Facerplast\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
      2004-08-20 12:00 208952 ----a-w- c:\windows\ime\imjp8_1\imjpmig.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
      2009-05-27 00:06 4351216 ----a-w- d:\archivos de programa\Yahoo!\Messenger\YahooMessenger.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MiponyAutoRun]
      2010-06-16 09:29 1234432 -c--a-w- d:\archivos de programa\MiPony\MiPony.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
      2008-04-14 09:49 1832448 ----a-w- c:\archivos de programa\Messenger\msmsgs.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
      2008-09-06 17:09 413696 ----a-w- c:\archivos de programa\QuickTime\QTTask.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
      2007-10-25 03:57 16855552 ------r- c:\windows\RTHDCPL.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
      2010-05-13 19:12 26192168 ----a-r- d:\skype\Phone\Skype.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
      2007-10-11 03:04 1826816 ------r- c:\windows\SkyTel.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
      2010-02-18 14:43 248040 ----a-w- c:\archivos de programa\Archivos comunes\Java\Java Update\jusched.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
      2008-07-29 16:45 185896 -c--a-w- c:\archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
      2010-08-30 09:40 328568 -c--a-w- d:\archivos de programa\uTorrent\uTorrent.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
      "XAMPP"=2 (0x2)
      "wampmysqld"=3 (0x3)
      "wampapache"=3 (0x3)

      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "AntiVirusOverride"=dword:00000001
      "FirewallOverride"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "c:\\Documents and Settings\\All Users\\Datos de programa\\NexonUS\\NGM\\NGM.exe"=
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Archivos de programa\\SopCast\\adv\\SopAdver.exe"=
      "d:\\Pokémon Online\\Pokemon Game.exe"=
      "d:\\Archivos de programa\\GameSpy Arcade\\Aphex.exe"=
      "c:\\Archivos de programa\\Windows Media Player\\wmplayer.exe"=
      "c:\\Archivos de programa\\Java\\jre6\\bin\\java.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\WINDOWS\\system32\\dpvsetup.exe"=
      "c:\\Documents and Settings\\Facerplast\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
      "d:\\Archivos de programa\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
      "d:\\Archivos de programa\\Microsoft Office\\Office12\\GROOVE.EXE"=
      "d:\\Archivos de programa\\Microsoft Office\\Office12\\ONENOTE.EXE"=
      "c:\\Archivos de programa\\Messenger\\msmsgs.exe"=
      "c:\\Nexon\\NEXON_EU_Downloader\\NEXON_EU_Downloader_Engine.exe"=
      "c:\\Documents and Settings\\All Users\\Datos de programa\\NexonEU\\NGM\\NGM.exe"=
      "d:\\Combat Arms\\Combat Arms EU\\NMService.exe"=
      "d:\\Archivos de programa\\Yahoo!\\Messenger\\YahooMessenger.exe"=
      "c:\\Archivos de programa\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
      "c:\\WINDOWS\\system32\\java.exe"=
      "c:\\WINDOWS\\system32\\rtcshare.exe"=
      "c:\\Archivos de programa\\NetMeeting\\conf.exe"=
      "c:\\Archivos de programa\\Java\\jre6\\bin\\javaw.exe"=
      "d:\\Documents and Settings\\Facerplast\\Escritorio\\Mauricio\\Nueva carpeta\\Xfire\\xfire.exe"=
      "d:\\Mis documentos\\Chat\\mirc32.exe"=
      "d:\\Mis documentos\\Copia de Chat\\mirc32.exe"=
      "d:\\Archivos de programa\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
      "d:\\Archivos de programa\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=
      "c:\\Archivos de programa\\Windows Live\\Messenger\\msnmsgr.exe"=
      "d:\\Mis documentos\\Chat\\Kazuma\\mirc.exe"=
      "d:\\Archivos de programa\\Garena\\Garena.exe"=
      "c:\\Archivos de programa\\Archivos comunes\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
      "d:\\Archivos de programa\\KONAMI\\Pro Evolution Soccer 2010\\pes2010.exe"=
      "c:\\KeyHoleTV.exe"=
      "c:\\Archivos de programa\\KeyHoleTV\\KeyHoleTV.exe"=
      "d:\\Archivos de programa\\uTorrent\\uTorrent.exe"=
      "d:\\server\\samp-server.exe"=
      "d:\\server 2\\samp-server.exe"=
      "d:\\Skype\\Plugin Manager\\skypePM.exe"=
      "c:\\Archivos de programa\\Opera\\opera.exe"=
      "c:\\Archivos de programa\\TeamViewer\\Version5\\TeamViewer.exe"=
      "d:\\Skype\\Phone\\Skype.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
      "8082:TCP"= 8082:TCP:Proxy
      "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
      "9014:TCP"= 9014:TCP:BitComet 9014 TCP
      "9014:UDP"= 9014:UDP:BitComet 9014 UDP
      "5353:TCP"= 5353:TCP:Adobe CSI CS4
      "67:UDP"= 67:UDP:DHCP Discovery Service

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
      "AllowInboundEchoRequest"= 1 (0x1)

      R2 Apache2.2;Apache2.2;d:\xampp\apache\bin\apache.exe [x]
      R2 GF0003;GASIA GF0003 Filter Driver;c:\windows\system32\DRIVERS\GF0003.sys [2006-04-28 9216]
      R3 CAM1690;USB 2.0 Compliance JPEG Video Camera;c:\windows\system32\Drivers\cam1690.sys [2007-07-13 152832]
      R3 cpuz130;cpuz130;c:\docume~1\FACERP~1\CONFIG~1\Temp\cpuz130\cpuz_x32.sys [x]
      R3 dump_wmimmc;dump_wmimmc;d:\archivos de programa\Lineage II\system\GameGuard\dump_wmimmc.sys [x]
      R3 FXDrv32;FXDrv32;F:\FXDrv32.sys [x]
      R3 hid7906;hid7906;c:\windows\system32\drivers\hid7906.sys [2007-12-12 34963]
      R3 hid8101;hid8101;c:\windows\system32\drivers\hid8101.sys [2007-12-03 37024]
      R3 hid8103;hid8103;c:\windows\system32\drivers\hid8103.sys [2007-11-28 34587]
      R3 LLRING0;LLRING0;d:\archivos de programa\AOG\MUruguay\MuGuard\llck1.sys [2010-05-29 3840]
      R3 MobileAdapter;Huawei Mobile Adapter USB Modem and USB Serial;c:\windows\system32\DRIVERS\hmumdm.sys [2007-09-05 101120]
      R3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-04-06 23064]
      R3 zlportio;zlportio;d:\ultrastar deluxe\zlportio.sys [x]
      R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2008-10-26 717296]
      R4 XAMPP;XAMPP Service;d:\xampp\service.exe [x]
      S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
      S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2009-02-06 93336]
      S1 SASDIFSV;SASDIFSV;d:\archivos de programa\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
      S1 SASKUTIL;SASKUTIL;d:\archivos de programa\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
      S2 ekrn;ESET Service;c:\archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe [2009-02-06 727720]

      .
      Contents of the 'Scheduled Tasks' folder

      2010-09-27 c:\windows\Tasks\AWC AutoSweep.job
      - d:\archivos de programa\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-03-19 17:11]

      2010-09-27 c:\windows\Tasks\OGALogon.job
      - c:\windows\system32\OGAEXEC.exe [2009-08-03 18:07]

      2010-09-27 c:\windows\Tasks\User_Feed_Synchronization-{168D70C3-E309-409B-BE83-4F8C3C9A3BAA}.job
      - c:\windows\system32\msfeedssync.exe [2007-08-13 04:01]

      2010-09-27 c:\windows\Tasks\User_Feed_Synchronization-{1F3174A3-472B-4BC2-A6BD-7CB0D3461CA7}.job
      - c:\windows\system32\msfeedssync.exe [2007-08-13 04:01]

      2010-09-27 c:\windows\Tasks\User_Feed_Synchronization-{61ACB603-68A1-4CC7-A2A9-04C423D56DB0}.job
      - c:\windows\system32\msfeedssync.exe [2007-08-13 04:01]
      .
      .
      ------- Supplementary Scan -------
      .
      uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2233703
      uSearchMigratedDefaultURL = hxxp://www.Google.com/
      mWindow Title =
      mSearchMigratedDefaultURL = hxxp://www.Google.com/
      uInternet Connection Wizard,ShellNext = iexplore
      mSearchURL = hxxp://www.Google.com/
      IE: &Download All using 4shared Desktop
      IE: E&xportar a Microsoft Excel - d:\archiv~1\MICROS~1\Office12\EXCEL.EXE/3000
      IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\archivos de programa\PokerStars.NET\PokerStarsUpdate.exe
      DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      FF - ProfilePath - c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\
      FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2233703&SearchSource=3&q={searchTerms}
      FF - prefs.js: browser.startup.homepage - www.google.com
      FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2438727&q=
      FF - component: c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
      FF - component: c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
      FF - component: c:\documents and settings\Facerplast\Datos de programa\Mozilla\Firefox\Profiles\g23w4jng.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

      ---- FIREFOX POLICIES ----
      FF - user.js: browser.cache.memory.capacity - 65536
      FF - user.js: browser.chrome.favicons - false
      FF - user.js: browser.display.show_image_placeholders - true
      FF - user.js: browser.turbo.enabled - true
      FF - user.js: browser.urlbar.autocomplete.enabled - true
      FF - user.js: browser.urlbar.autofill - true
      FF - user.js: browser.xul.error_pages.enabled - true
      FF - user.js: content.interrupt.parsing - true
      FF - user.js: content.max.tokenizing.time - 3000000
      FF - user.js: content.maxtextrun - 8191
      FF - user.js: content.notify.backoffcount - 5
      FF - user.js: content.notify.interval - 750000
      FF - user.js: content.notify.ontimer - true
      FF - user.js: content.switch.threshold - 750000
      FF - user.js: network.http.max-connections - 32
      FF - user.js: network.http.max-connections-per-server - 8
      FF - user.js: network.http.max-persistent-connections-per-proxy - 8
      FF - user.js: network.http.max-persistent-connections-per-server - 4
      FF - user.js: network.http.pipelining - true
      FF - user.js: network.http.pipelining.firstrequest - true
      FF - user.js: network.http.pipelining.maxrequests - 8
      FF - user.js: network.http.proxy.pipelining - true
      FF - user.js: network.http.request.max-start-delay - 0
      FF - user.js: nglayout.initialpaint.delay - 0
      FF - user.js: plugin.expose_full_path - true
      FF - user.js: ui.submenuDelay - 0
      c:\archivos de programa\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
      c:\archivos de programa\Mozilla Firefox 3.6 Beta 3\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
      c:\archivos de programa\Mozilla Firefox 3.6 Beta 3\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
      .

      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-09-27 01:42
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden autostart entries ...

      scanning hidden files ...

      scan completed successfully
      hidden files: 0

      **************************************************************************
      .
      --------------------- DLLs Loaded Under Running Processes ---------------------

      - - - - - - - > 'winlogon.exe'(632)
      c:\windows\system32\SETUPAPI.dll
      c:\windows\system32\sfc_os.dll
      d:\archivos de programa\SUPERAntiSpyware\SASWINLO.DLL
      c:\windows\system32\COMRes.dll
      c:\archivos de programa\Archivos comunes\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
      c:\windows\system32\cscui.dll
      c:\windows\system32\midimap.dll

      - - - - - - - > 'lsass.exe'(688)
      c:\windows\system32\setupapi.dll

      - - - - - - - > 'explorer.exe'(4004)
      c:\windows\system32\SHDOCVW.dll
      c:\windows\system32\COMRes.dll
      c:\windows\System32\cscui.dll
      c:\windows\system32\LINKINFO.dll
      c:\windows\system32\ntshrui.dll
      c:\windows\system32\SETUPAPI.dll
      c:\windows\system32\ieframe.dll
      c:\windows\system32\NETSHELL.dll
      c:\windows\system32\credui.dll
      c:\windows\system32\MSVCP60.dll
      c:\windows\system32\webcheck.dll
      c:\windows\system32\stobject.dll
      c:\windows\system32\WPDShServiceObj.dll
      c:\windows\system32\PortableDeviceTypes.dll
      c:\windows\system32\PortableDeviceApi.dll
      c:\archivos de programa\Archivos comunes\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
      .
      ------------------------ Other Running Processes ------------------------
      .
      c:\windows\system32\nvsvc32.exe
      c:\windows\system32\RUNDLL32.EXE
      c:\documents and settings\Facerplast\Configuración local\Datos de programa\Google\Update\1.2.183.29\GoogleCrashHandler.exe
      c:\archivos de programa\Java\jre6\bin\jqs.exe
      c:\archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
      c:\windows\system32\PnkBstrA.exe
      c:\windows\system32\PnkBstrB.exe
      c:\windows\System32\snmp.exe
      d:\archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
      c:\windows\system32\wbem\wmiapsrv.exe
      .
      **************************************************************************
      .
      Completion time: 2010-09-27 01:49:30 - machine was rebooted
      ComboFix-quarantined-files.txt 2010-09-27 04:49
      ComboFix2.txt 2010-09-27 01:55
      ComboFix3.txt 2008-12-06 14:02

      Pre-Run: 152.821.760 bytes libres
      Post-Run: 110.821.376 bytes libres

      Current=16 Default=16 Failed=15 LastKnownGood=17 Sets=1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17
      - - End Of File - - D60E18410DCDCD43E4FD600577880A85

    8. #8
      Moderador Gral.
      Avatar de Damianl_77
      Registrado
      ene 2008
      Ubicación
      Argentina
      Mensajes
      22.895

      Re: Múltiples problemas, errores de .dll, pant. azules y desconexiones.

      No me respondiste lo mas importante

      Tenes el CD de instalación del sistema operativo? (XP)

      Blog | Antivirus Online | Eliminar Malwares | Antivirus Gratis


      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    9. #9
      Usuario Avatar de Freddie90
      Registrado
      oct 2008
      Ubicación
      Montevideo, Uruguay
      Mensajes
      8

      Re: Múltiples problemas, errores de .dll, pant. azules y desconexiones.

      Cierto, perdón, me olvidé :P.

      Sí, sí lo tengo (original y todo).

      (Nuevos errores:

      * svchost.exe, La instrucción en "0x7c9200e8" hace referencia a la memoria en "0x00000010". La memoria no se puede "read".

      * Generic Host Process for Win32 Services ha detectado un problema...

      * DAEMON Tools Lite - Initialization error 2. This program requires at least Windows 2000 with SPTD 1.53 or higher. Kernel debugger must be deactivated.

      * Al presionar el botón de apagado, la PC se queda igual.)

    10. #10
      Moderador Gral.
      Avatar de Damianl_77
      Registrado
      ene 2008
      Ubicación
      Argentina
      Mensajes
      22.895

      Re: Múltiples problemas, errores de .dll, pant. azules y desconexiones.

      Usa el CD para reparar el sistema, ya que los errores son provocados por los archivos dañados. tenes la mayoría de los archivos del sistema con algún daño.
      Reparr el sistema con el CD de instalación

      Mira el manual con detenimiento y comentas como te fue

      Blog | Antivirus Online | Eliminar Malwares | Antivirus Gratis


      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    Página 1 de 2 12 ÚltimoÚltimo