• Registrarse
  • Iniciar sesión


  • Página 7 de 7 PrimeroPrimero ... 34567
    Resultados 61 al 65 de 65

    ventanas emergentes, de google

    el report del combo: a que te refieres con lo de etiquetas code ni html? ComboFix 13-02-24.01 - Usuario 24/02/2013 21:00:51.2.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.34.3082.18.4060.2410 [GMT 1:00] Running from: c:\users\Usuario\Desktop\ComboFix.exe AV: ...

    1. #61
      Usuario Avatar de natpo
      Registrado
      ago 2009
      Ubicación
      galicia
      Mensajes
      137

      Re: ventanas emergentes, de google

      el report del combo:


      a que te refieres con lo de etiquetas code ni html?

      ComboFix 13-02-24.01 - Usuario 24/02/2013 21:00:51.2.4 - x64
      Microsoft Windows 7 Home Premium 6.1.7601.1.1252.34.3082.18.4060.2410 [GMT 1:00]
      Running from: c:\users\Usuario\Desktop\ComboFix.exe
      AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
      SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
      SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      .
      .
      ((((((((((((((((((((((((( Files Created from 2013-01-24 to 2013-02-24 )))))))))))))))))))))))))))))))
      .
      .
      2013-02-24 20:24 . 2013-02-24 20:24 -------- d-----w- c:\users\Public\AppData\Local\temp
      2013-02-24 20:24 . 2013-02-24 20:24 -------- d-----w- c:\users\Default\AppData\Local\temp
      2013-02-24 13:20 . 2013-02-08 00:28 9162192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{CD095C4E-8EE1-4766-A9F5-C6A76BC38355}\mpengine.dll
      2013-01-29 17:42 . 2013-01-29 17:42 -------- d-----w- C:\SkyDriveTemp
      .
      .
      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2013-02-24 19:53 . 2010-10-04 10:26 25640 ----a-w- c:\windows\gdrv.sys
      2013-02-19 00:51 . 2010-10-04 11:32 70004024 ----a-w- c:\windows\system32\MRT.exe
      2013-01-17 00:28 . 2010-10-04 11:31 273840 ------w- c:\windows\system32\MpSigStub.exe
      2013-01-09 20:16 . 2012-04-15 12:27 697864 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
      2013-01-09 20:16 . 2011-11-17 21:24 74248 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
      2013-01-04 04:43 . 2013-02-18 18:04 44032 ----a-w- c:\windows\apppatch\acwow64.dll
      2012-12-16 17:11 . 2012-12-27 23:58 46080 ----a-w- c:\windows\system32\atmlib.dll
      2012-12-16 14:45 . 2012-12-27 23:58 367616 ----a-w- c:\windows\system32\atmfd.dll
      2012-12-16 14:13 . 2012-12-27 23:58 295424 ----a-w- c:\windows\SysWow64\atmfd.dll
      2012-12-16 14:13 . 2012-12-27 23:58 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
      2012-12-14 15:49 . 2012-10-15 19:22 24176 ----a-w- c:\windows\system32\drivers\mbam.sys
      2012-12-07 13:20 . 2013-01-10 18:23 441856 ----a-w- c:\windows\system32\Wpc.dll
      2012-12-07 13:15 . 2013-01-10 18:23 2746368 ----a-w- c:\windows\system32\gameux.dll
      2012-12-07 12:26 . 2013-01-10 18:23 308736 ----a-w- c:\windows\SysWow64\Wpc.dll
      2012-12-07 12:20 . 2013-01-10 18:23 2576384 ----a-w- c:\windows\SysWow64\gameux.dll
      2012-12-07 11:20 . 2013-01-10 18:23 30720 ----a-w- c:\windows\system32\usk.rs
      2012-12-07 11:20 . 2013-01-10 18:23 43520 ----a-w- c:\windows\system32\csrr.rs
      2012-12-07 11:20 . 2013-01-10 18:23 23552 ----a-w- c:\windows\system32\oflc.rs
      2012-12-07 11:20 . 2013-01-10 18:23 45568 ----a-w- c:\windows\system32\oflc-nz.rs
      2012-12-07 11:20 . 2013-01-10 18:23 44544 ----a-w- c:\windows\system32\pegibbfc.rs
      2012-12-07 11:20 . 2013-01-10 18:23 20480 ----a-w- c:\windows\system32\pegi-fi.rs
      2012-12-07 11:20 . 2013-01-10 18:23 20480 ----a-w- c:\windows\system32\pegi-pt.rs
      2012-12-07 11:19 . 2013-01-10 18:23 20480 ----a-w- c:\windows\system32\pegi.rs
      2012-12-07 11:19 . 2013-01-10 18:23 46592 ----a-w- c:\windows\system32\fpb.rs
      2012-12-07 11:19 . 2013-01-10 18:23 40960 ----a-w- c:\windows\system32\cob-au.rs
      2012-12-07 11:19 . 2013-01-10 18:23 21504 ----a-w- c:\windows\system32\grb.rs
      2012-12-07 11:19 . 2013-01-10 18:23 15360 ----a-w- c:\windows\system32\djctq.rs
      2012-12-07 11:19 . 2013-01-10 18:23 55296 ----a-w- c:\windows\system32\cero.rs
      2012-12-07 11:19 . 2013-01-10 18:23 51712 ----a-w- c:\windows\system32\esrb.rs
      2012-12-07 10:46 . 2013-01-10 18:23 43520 ----a-w- c:\windows\SysWow64\csrr.rs
      2012-12-07 10:46 . 2013-01-10 18:23 30720 ----a-w- c:\windows\SysWow64\usk.rs
      2012-12-07 10:46 . 2013-01-10 18:23 45568 ----a-w- c:\windows\SysWow64\oflc-nz.rs
      2012-12-07 10:46 . 2013-01-10 18:23 44544 ----a-w- c:\windows\SysWow64\pegibbfc.rs
      2012-12-07 10:46 . 2013-01-10 18:23 20480 ----a-w- c:\windows\SysWow64\pegi-pt.rs
      2012-12-07 10:46 . 2013-01-10 18:23 23552 ----a-w- c:\windows\SysWow64\oflc.rs
      2012-12-07 10:46 . 2013-01-10 18:23 20480 ----a-w- c:\windows\SysWow64\pegi-fi.rs
      2012-12-07 10:46 . 2013-01-10 18:23 46592 ----a-w- c:\windows\SysWow64\fpb.rs
      2012-12-07 10:46 . 2013-01-10 18:23 20480 ----a-w- c:\windows\SysWow64\pegi.rs
      2012-12-07 10:46 . 2013-01-10 18:23 21504 ----a-w- c:\windows\SysWow64\grb.rs
      2012-12-07 10:46 . 2013-01-10 18:23 40960 ----a-w- c:\windows\SysWow64\cob-au.rs
      2012-12-07 10:46 . 2013-01-10 18:23 15360 ----a-w- c:\windows\SysWow64\djctq.rs
      2012-12-07 10:46 . 2013-01-10 18:23 55296 ----a-w- c:\windows\SysWow64\cero.rs
      2012-12-07 10:46 . 2013-01-10 18:23 51712 ----a-w- c:\windows\SysWow64\esrb.rs
      2012-11-30 05:45 . 2013-01-10 18:23 362496 ----a-w- c:\windows\system32\wow64win.dll
      2012-11-30 05:45 . 2013-01-10 18:23 243200 ----a-w- c:\windows\system32\wow64.dll
      2012-11-30 05:45 . 2013-01-10 18:23 13312 ----a-w- c:\windows\system32\wow64cpu.dll
      2012-11-30 05:43 . 2013-01-10 18:23 16384 ----a-w- c:\windows\system32\ntvdm64.dll
      2012-11-30 05:41 . 2013-01-10 18:23 424448 ----a-w- c:\windows\system32\KernelBase.dll
      2012-11-30 05:41 . 2013-01-10 18:23 1161216 ----a-w- c:\windows\system32\kernel32.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-string-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 4096 ---ha-w- c:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 4096 ---ha-w- c:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 4608 ---ha-w- c:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 5120 ---ha-w- c:\windows\system32\api-ms-win-core-file-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-io-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
      2012-11-30 05:38 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
      2012-11-30 04:53 . 2013-01-10 18:23 274944 ----a-w- c:\windows\SysWow64\KernelBase.dll
      2012-11-30 04:45 . 2013-01-10 18:23 4608 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 5120 ---ha-w- c:\windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
      2012-11-30 04:45 . 2013-01-10 18:23 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
      .
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{6e47d688-85ec-465a-9946-ec58220f14fc}]
      2012-09-24 22:12 89288 ----a-w- c:\progra~2\BEARSH~1\Mediabar\Datamngr\SRTOOL~1\searchresultsDx.dll
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{B939CF93-F2CB-443d-956C-DC523D85C9DB}]
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
      "{6e47d688-85ec-465a-9946-ec58220f14fc}"= "c:\progra~2\BEARSH~1\Mediabar\Datamngr\SRTOOL~1\searchresultsDx.dll" [2012-09-24 89288]
      .
      [HKEY_CLASSES_ROOT\clsid\{6e47d688-85ec-465a-9946-ec58220f14fc}]
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
      @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
      [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
      2012-07-06 15:11 208608 ----a-w- c:\users\Usuario\AppData\Local\Microsoft\SkyDrive\16.4.4111.0525\SkyDriveShell.dll
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
      @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
      [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
      2012-07-06 15:11 208608 ----a-w- c:\users\Usuario\AppData\Local\Microsoft\SkyDrive\16.4.4111.0525\SkyDriveShell.dll
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
      @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
      [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
      2012-07-06 15:11 208608 ----a-w- c:\users\Usuario\AppData\Local\Microsoft\SkyDrive\16.4.4111.0525\SkyDriveShell.dll
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
      @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 129272 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
      @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 129272 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
      @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 129272 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
      .
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-11-01 5629312]
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
      "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "ConsentPromptBehaviorAdmin"= 5 (0x5)
      "ConsentPromptBehaviorUser"= 3 (0x3)
      "EnableUIADesktopToggle"= 0 (0x0)
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
      "LoadAppInit_DLLs"=1 (0x1)
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
      "aux"=wdmaud.drv
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
      @=""
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
      @="FSFilter System Recovery"
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
      "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
      "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
      .
      R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
      R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
      R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
      R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2010-03-25 246224]
      R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [2010-03-25 114304]
      R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [2010-07-28 29720]
      R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
      R3 S3XXx64;SCR3xx USB SmartCardReader64;c:\windows\system32\DRIVERS\S3XXx64.sys [2010-11-11 69376]
      R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
      R3 WatAdminSvc;Servicio de tecnologías de activación de Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-04 1255736]
      S1 aswSnx;aswSnx; [x]
      S1 aswSP;aswSP; [x]
      S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
      S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
      S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2012-07-11 140672]
      S2 aswFsBlk;aswFsBlk; [x]
      S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
      S2 GEST Service;GEST Service for program management.;c:\program files (x86)\GIGABYTE\EnergySaver\GSvr.exe [2009-07-30 68136]
      S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
      S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
      S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-05-25 138752]
      S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]
      S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-07-30 236544]
      S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-03-09 676864]
      .
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
      2013-02-18 17:56 1607120 ----a-w- c:\program files (x86)\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe
      .
      Contents of the 'Scheduled Tasks' folder
      .
      2013-01-18 c:\windows\Tasks\Adobe Flash Player Updater.job
      - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 20:16]
      .
      2013-02-24 c:\windows\Tasks\GlaryInitialize.job
      - c:\program files (x86)\Glary Utilities\initialize.exe [2013-01-19 23:26]
      .
      2013-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
      - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-27 17:25]
      .
      2013-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
      - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-27 17:25]
      .
      2013-01-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2997284614-1332722331-2720000673-1000Core.job
      - c:\users\Usuario\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-02 15:29]
      .
      2013-01-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2997284614-1332722331-2720000673-1000UA.job
      - c:\users\Usuario\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-02 15:29]
      .
      .
      --------- X64 Entries -----------
      .
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
      @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
      [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
      2012-07-06 15:11 232672 ----a-w- c:\users\Usuario\AppData\Local\Microsoft\SkyDrive\16.4.4111.0525\amd64\SkyDriveShell64.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
      @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
      [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
      2012-07-06 15:11 232672 ----a-w- c:\users\Usuario\AppData\Local\Microsoft\SkyDrive\16.4.4111.0525\amd64\SkyDriveShell64.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
      @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
      [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
      2012-07-06 15:11 232672 ----a-w- c:\users\Usuario\AppData\Local\Microsoft\SkyDrive\16.4.4111.0525\amd64\SkyDriveShell64.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
      @="{472083B0-C522-11CF-8763-00608CC02F24}"
      [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
      2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
      @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 162552 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
      @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 162552 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
      @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 162552 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
      @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 162552 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=c:\progra~2\BEARSH~1\Mediabar\Datamngr\x64\datamngr.dll c:\progra~2\BEARSH~1\Mediabar\Datamngr\x64\IEBHO.dll
      .
      ------- Supplementary Scan -------
      .
      uLocal Page = c:\windows\system32\blank.htm
      uStart Page = hxxp://www.google.es/
      mStart Page = Google
      mLocal Page = c:\windows\SysWOW64\blank.htm
      mSearchAssistant = hxxp://start.facemoods.com/?a=tweak&s={searchTerms}&f=4
      TCP: DhcpNameServer = 80.58.61.250 80.58.61.254
      .
      - - - - ORPHANS REMOVED - - - -
      .
      Toolbar-10 - (no file)
      HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
      WebBrowser-{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file)
      AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
      AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
      AddRemove-{56582EEA-3AEF-4D84-8B9D-C87A3CD9250F} - h:\getdataback for ntfs\Uninstall.exe
      .
      .
      .
      --------------------- LOCKED REGISTRY KEYS ---------------------
      .
      [HKEY_USERS\S-1-5-21-2997284614-1332722331-2720000673-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
      @Denied: (2) (LocalSystem)
      "Progid"="WindowsLiveMail.Email.1"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="FlashBroker"
      "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe,-101"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
      "Enabled"=dword:00000001
      .
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
      @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_146_ActiveX.exe"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="IFlashBroker5"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
      @="{00020424-0000-0000-C000-000000000046}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      "Version"="1.0"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="FlashBroker"
      "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe,-101"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
      "Enabled"=dword:00000001
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
      @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_146_ActiveX.exe"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
      @Denied: (A 2) (Everyone)
      @="Shockwave Flash Object"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
      @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
      "ThreadingModel"="Apartment"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
      @="0"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
      @="ShockwaveFlash.ShockwaveFlash.11"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
      @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
      @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
      @="1.0"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
      @="ShockwaveFlash.ShockwaveFlash"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
      @Denied: (A 2) (Everyone)
      @="Macromedia Flash Factory Object"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
      @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx"
      "ThreadingModel"="Apartment"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
      @="FlashFactory.FlashFactory.1"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
      @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_146.ocx, 1"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
      @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
      @="1.0"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
      @="FlashFactory.FlashFactory"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="IFlashBroker5"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
      @="{00020424-0000-0000-C000-000000000046}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      "Version"="1.0"
      .
      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
      @Denied: (A) (Users)
      @Denied: (A) (Everyone)
      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
      "BlindDial"=dword:00000000
      .
      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
      @Denied: (A) (Users)
      @Denied: (A) (Everyone)
      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
      "BlindDial"=dword:00000000
      .
      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
      @Denied: (Full) (Everyone)
      .
      Completion time: 2013-02-24 21:33:38
      ComboFix-quarantined-files.txt 2013-02-24 20:33
      ComboFix2.txt 2012-11-24 14:35
      .
      Pre-Run: 23.481.372.672 bytes libres
      Post-Run: 23.257.059.328 bytes libres
      .
      - - End Of File - - 89CB3B6B47984E88E899A9EC44A4DA26

    2. #62
      Usuario Avatar de natpo
      Registrado
      ago 2009
      Ubicación
      galicia
      Mensajes
      137

      Re: ventanas emergentes, de google

      ...joer...y va con 5 meses y sigue ....hay días que lo enciendo y en menos de un minuto me empiezan a salir un montón de ventanas, hasta que desisto y apago el pc.
      Otras veces...parece qu eva tranquilo el pc..y de repente me vuelve a la pagína de google sin previo aviso.....
      y así,.,,que me sigue puteando

      que coño ess??...un virús, malware? alguien que me lo maneja??


    3. #63
      Usuario Avatar de natpo
      Registrado
      ago 2009
      Ubicación
      galicia
      Mensajes
      137

      Re: ventanas emergentes, de google

      Hay alguna posibilidad de qeu alguien este hackeando mi pc...y hoy me hayan bloquedo mi cuenta de correo hotmail??Intento recuperarla en microsoft y aún no he podido!

    4. #64
      Usuario Avatar de natpo
      Registrado
      ago 2009
      Ubicación
      galicia
      Mensajes
      137

      Re: ventanas emergentes, de google

      me he quedado sin cuenta de hotmail, la de toda la vida....no sé si tiene esto que ver o no...pero normalmente cuendo le daba a l apágina de hotmail..esta era la primera que me desaparecía para ponerme la de google.. :(

    5. #65
      Usuario Avatar de natpo
      Registrado
      ago 2009
      Ubicación
      galicia
      Mensajes
      137

      Re: ventanas emergentes, de google

      ComboFix 13-04-02.01 - Usuario 02/04/2013 20:45:35.3.4 - x64
      Microsoft Windows 7 Home Premium 6.1.7601.1.1252.34.3082.18.4060.2564 [GMT 2:00]
      Running from: c:\users\Usuario\Downloads\ComboFix.exe
      AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
      SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
      SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
      * Created a new restore point
      .
      .
      ((((((((((((((((((((((((( Files Created from 2013-03-02 to 2013-04-02 )))))))))))))))))))))))))))))))
      .
      .
      2013-04-02 18:51 . 2013-04-02 18:51 -------- d-----w- c:\users\Public\AppData\Local\temp
      2013-04-02 18:51 . 2013-04-02 18:51 -------- d-----w- c:\users\Default\AppData\Local\temp
      2013-04-02 17:10 . 2013-04-02 17:10 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1CF9B605-AA05-454A-8767-59C1111708B2}\offreg.dll
      2013-03-23 20:19 . 2013-03-15 06:28 9311288 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1CF9B605-AA05-454A-8767-59C1111708B2}\mpengine.dll
      2013-03-15 15:55 . 2013-02-12 04:12 19968 ----a-w- c:\windows\system32\drivers\usb8023x.sys
      2013-03-15 15:55 . 2013-02-12 04:12 19968 ----a-w- c:\windows\system32\drivers\usb8023.sys
      2013-03-06 19:11 . 2013-04-02 16:58 -------- d-----w- c:\users\Usuario\AppData\Local\Htc
      2013-03-06 19:04 . 2013-03-06 19:11 -------- d-----w- c:\users\Usuario\AppData\Roaming\HTC
      2013-03-06 19:02 . 2013-03-06 19:08 -------- d-----w- c:\users\Usuario\AppData\Local\Downloaded Installations
      2013-03-06 19:02 . 2013-03-06 19:02 -------- d-----w- c:\program files (x86)\Spirent Communications
      2013-03-06 19:02 . 2013-03-06 19:04 -------- d-----w- c:\program files (x86)\HTC
      2013-03-06 19:02 . 2013-03-06 19:08 -------- d-----w- c:\program files (x86)\Common Files\Adobe AIR
      2013-03-06 19:02 . 2013-03-06 19:02 -------- d-----w- c:\program files (x86)\MSXML 4.0
      2013-03-06 18:47 . 2013-03-06 18:47 -------- d-----w- c:\windows\SysWow64\wbem\en-US
      2013-03-06 18:47 . 2013-03-06 18:47 -------- d-----w- c:\windows\system32\wbem\en-US
      2013-03-06 18:43 . 2012-08-23 15:25 3584 ----a-w- c:\windows\system32\drivers\es-ES\tsusbflt.sys.mui
      2013-03-06 18:43 . 2012-08-23 13:41 13312 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe
      2013-03-06 18:43 . 2012-08-23 13:40 13312 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
      2013-03-06 18:43 . 2012-08-23 13:24 15360 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
      2013-03-06 18:43 . 2012-08-23 14:10 19456 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys
      2013-03-06 18:43 . 2012-08-23 14:07 57856 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys
      .
      .
      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2013-04-02 16:57 . 2010-10-04 10:26 25640 ----a-w- c:\windows\gdrv.sys
      2013-03-15 15:56 . 2012-04-15 12:27 693976 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
      2013-03-15 15:56 . 2011-11-17 21:24 73432 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
      2013-03-13 20:19 . 2010-10-04 11:32 72013344 ----a-w- c:\windows\system32\MRT.exe
      2013-02-12 05:45 . 2013-03-13 16:40 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
      2013-02-12 05:45 . 2013-03-13 16:40 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
      2013-02-12 05:45 . 2013-03-13 16:40 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
      2013-02-12 05:45 . 2013-03-13 16:40 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
      2013-02-12 04:48 . 2013-03-13 16:40 474112 ----a-w- c:\windows\apppatch\AcSpecfc.dll
      2013-02-12 04:48 . 2013-03-13 16:40 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
      2013-01-17 00:28 . 2010-10-04 11:31 273840 ------w- c:\windows\system32\MpSigStub.exe
      2013-01-13 21:17 . 2013-02-27 23:01 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
      2013-01-13 21:17 . 2013-02-27 23:01 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
      2013-01-13 21:16 . 2013-02-27 23:01 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
      2013-01-13 21:12 . 2013-02-27 23:01 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
      2013-01-13 21:11 . 2013-02-27 23:01 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
      2013-01-13 21:11 . 2013-02-27 23:01 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
      2013-01-13 21:11 . 2013-02-27 23:01 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
      2013-01-13 21:11 . 2013-02-27 23:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
      2013-01-13 21:11 . 2013-02-27 23:01 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
      2013-01-13 20:35 . 2013-02-27 23:01 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
      2013-01-13 20:35 . 2013-02-27 23:01 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
      2013-01-13 20:35 . 2013-02-27 23:01 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
      2013-01-13 20:32 . 2013-02-27 23:01 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
      2013-01-13 20:31 . 2013-02-27 23:01 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
      2013-01-13 20:31 . 2013-02-27 23:01 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
      2013-01-13 20:31 . 2013-02-27 23:01 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
      2013-01-13 20:31 . 2013-02-27 23:01 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
      2013-01-13 20:31 . 2013-02-27 23:01 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
      2013-01-13 20:31 . 2013-02-27 23:01 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
      2013-01-13 20:22 . 2013-02-27 23:01 1988096 ----a-w- c:\windows\SysWow64\d3d10warp.dll
      2013-01-13 20:20 . 2013-02-27 23:01 293376 ----a-w- c:\windows\SysWow64\dxgi.dll
      2013-01-13 20:09 . 2013-02-27 23:01 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
      2013-01-13 20:08 . 2013-02-27 23:01 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll
      2013-01-13 20:08 . 2013-02-27 23:01 1504768 ----a-w- c:\windows\SysWow64\d3d11.dll
      2013-01-13 19:59 . 2013-02-27 23:01 1643520 ----a-w- c:\windows\system32\DWrite.dll
      2013-01-13 19:58 . 2013-02-27 23:01 1175552 ----a-w- c:\windows\system32\FntCache.dll
      2013-01-13 19:54 . 2013-02-27 23:01 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll
      2013-01-13 19:53 . 2013-02-27 23:01 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll
      2013-01-13 19:53 . 2013-02-27 23:01 187392 ----a-w- c:\windows\SysWow64\UIAnimation.dll
      2013-01-13 19:51 . 2013-02-27 23:01 2565120 ----a-w- c:\windows\system32\d3d10warp.dll
      2013-01-13 19:49 . 2013-02-27 23:01 363008 ----a-w- c:\windows\system32\dxgi.dll
      2013-01-13 19:48 . 2013-02-27 23:01 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
      2013-01-13 19:46 . 2013-02-27 23:01 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll
      2013-01-13 19:43 . 2013-02-27 23:01 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
      2013-01-13 19:38 . 2013-02-27 23:01 333312 ----a-w- c:\windows\system32\d3d10_1core.dll
      2013-01-13 19:38 . 2013-02-27 23:01 1887232 ----a-w- c:\windows\system32\d3d11.dll
      2013-01-13 19:38 . 2013-02-27 23:01 296960 ----a-w- c:\windows\system32\d3d10core.dll
      2013-01-13 19:37 . 2013-02-27 23:01 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll
      2013-01-13 19:25 . 2013-02-27 23:01 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
      2013-01-13 19:24 . 2013-02-27 23:01 648192 ----a-w- c:\windows\system32\d3d10level9.dll
      2013-01-13 19:24 . 2013-02-27 23:01 221184 ----a-w- c:\windows\system32\UIAnimation.dll
      2013-01-13 19:20 . 2013-02-27 23:01 194560 ----a-w- c:\windows\system32\d3d10_1.dll
      2013-01-13 19:20 . 2013-02-27 23:01 1238528 ----a-w- c:\windows\system32\d3d10.dll
      2013-01-13 19:15 . 2013-02-27 23:01 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
      2013-01-13 19:10 . 2013-02-27 23:01 3928064 ----a-w- c:\windows\system32\d2d1.dll
      2013-01-13 19:02 . 2013-02-27 23:01 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll
      2013-01-13 18:34 . 2013-02-27 23:01 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
      2013-01-13 18:32 . 2013-02-27 23:01 465920 ----a-w- c:\windows\system32\WMPhoto.dll
      2013-01-13 18:09 . 2013-02-27 23:01 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll
      2013-01-13 17:26 . 2013-02-27 23:01 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll
      2013-01-13 17:05 . 2013-02-27 23:01 1682432 ----a-w- c:\windows\system32\XpsPrint.dll
      2013-01-05 05:53 . 2013-02-18 18:04 5553512 ----a-w- c:\windows\system32\ntoskrnl.exe
      2013-01-05 05:00 . 2013-02-18 18:04 3967848 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
      2013-01-05 05:00 . 2013-02-18 18:04 3913064 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
      2013-01-04 06:11 . 2013-02-27 23:01 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll
      2013-01-04 06:11 . 2013-02-27 23:01 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll
      2013-01-04 05:46 . 2013-02-18 18:04 215040 ----a-w- c:\windows\system32\winsrv.dll
      2013-01-04 04:51 . 2013-02-18 18:04 5120 ----a-w- c:\windows\SysWow64\wow32.dll
      2013-01-04 04:43 . 2013-02-18 18:04 44032 ----a-w- c:\windows\apppatch\acwow64.dll
      2013-01-04 03:26 . 2013-02-18 18:04 3153408 ----a-w- c:\windows\system32\win32k.sys
      2013-01-04 02:47 . 2013-02-18 18:04 25600 ----a-w- c:\windows\SysWow64\setup16.exe
      2013-01-04 02:47 . 2013-02-18 18:04 7680 ----a-w- c:\windows\SysWow64\instnm.exe
      2013-01-04 02:47 . 2013-02-18 18:04 2048 ----a-w- c:\windows\SysWow64\user.exe
      2013-01-04 02:47 . 2013-02-18 18:04 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll
      2013-01-03 06:00 . 2013-02-18 18:04 1913192 ----a-w- c:\windows\system32\drivers\tcpip.sys
      2013-01-03 06:00 . 2013-02-18 18:04 288088 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
      2002-08-08 13:18 . 2010-11-15 00:28 15664 ----a-w- c:\program files\vfwwdm.drv
      2002-08-08 13:18 . 2010-11-15 00:28 15664 ----a-w- c:\program files (x86)\vfwwdm.drv
      .
      .
      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{6e47d688-85ec-465a-9946-ec58220f14fc}]
      2012-09-24 22:12 89288 ----a-w- c:\progra~2\BEARSH~1\Mediabar\Datamngr\SRTOOL~1\searchresultsDx.dll
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{B939CF93-F2CB-443d-956C-DC523D85C9DB}]
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
      "{6e47d688-85ec-465a-9946-ec58220f14fc}"= "c:\progra~2\BEARSH~1\Mediabar\Datamngr\SRTOOL~1\searchresultsDx.dll" [2012-09-24 89288]
      .
      [HKEY_CLASSES_ROOT\clsid\{6e47d688-85ec-465a-9946-ec58220f14fc}]
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
      @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
      [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
      2012-07-06 15:11 208608 ----a-w- c:\users\Usuario\AppData\Local\Microsoft\SkyDrive\16.4.4111.0525\SkyDriveShell.dll
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
      @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
      [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
      2012-07-06 15:11 208608 ----a-w- c:\users\Usuario\AppData\Local\Microsoft\SkyDrive\16.4.4111.0525\SkyDriveShell.dll
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
      @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
      [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
      2012-07-06 15:11 208608 ----a-w- c:\users\Usuario\AppData\Local\Microsoft\SkyDrive\16.4.4111.0525\SkyDriveShell.dll
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
      @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 129272 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
      @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 129272 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
      @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 129272 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt.17.dll
      .
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
      "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
      "HTC Sync Loader"="c:\program files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2012-04-17 651264]
      .
      c:\users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
      Dropbox.lnk - c:\users\Usuario\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-1-20 28539272]
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "ConsentPromptBehaviorAdmin"= 5 (0x5)
      "ConsentPromptBehaviorUser"= 3 (0x3)
      "EnableUIADesktopToggle"= 0 (0x0)
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
      "LoadAppInit_DLLs"=1 (0x1)
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
      "aux"=wdmaud.drv
      .
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
      @="FSFilter System Recovery"
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
      "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      "DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
      "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
      .
      R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
      R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-08-13 3064000]
      R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2012-07-13 160944]
      R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2010-03-25 246224]
      R3 HTCAND64;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-11-01 33736]
      R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2010-06-25 36928]
      R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [2010-03-25 114304]
      R3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\DRIVERS\ivusb.sys [2010-07-28 29720]
      R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
      R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
      R3 S3XXx64;SCR3xx USB SmartCardReader64;c:\windows\system32\DRIVERS\S3XXx64.sys [2010-11-11 69376]
      R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
      R3 WatAdminSvc;Servicio de tecnologías de activación de Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-10-04 1255736]
      S1 aswSnx;aswSnx; [x]
      S1 aswSP;aswSP; [x]
      S2 aswFsBlk;aswFsBlk; [x]
      S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-30 71600]
      S2 GEST Service;GEST Service for program management.;c:\program files (x86)\GIGABYTE\EnergySaver\GSvr.exe [2009-07-30 68136]
      S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-12-14 398184]
      S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-12-14 682344]
      S2 PassThru Service;Internet Pass-Through Service;c:\program files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [2012-03-23 87040]
      S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-05-25 138752]
      S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-14 24176]
      S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-07-30 236544]
      S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [2010-11-25 694888]
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{2D46B6DC-2207-486B-B523-A557E6D54B47}]
      start [BU]
      .
      [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
      2013-03-13 16:35 1629648 ----a-w- c:\program files (x86)\Google\Chrome\Application\25.0.1364.172\Installer\chrmstp.exe
      .
      Contents of the 'Scheduled Tasks' folder
      .
      2013-03-17 c:\windows\Tasks\Adobe Flash Player Updater.job
      - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-15 15:56]
      .
      2013-04-02 c:\windows\Tasks\GlaryInitialize.job
      - c:\program files (x86)\Glary Utilities\initialize.exe [2013-01-19 23:26]
      .
      2013-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
      - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-27 17:25]
      .
      2013-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
      - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-12-27 17:25]
      .
      2013-01-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2997284614-1332722331-2720000673-1000Core.job
      - c:\users\Usuario\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-02 15:29]
      .
      2013-01-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2997284614-1332722331-2720000673-1000UA.job
      - c:\users\Usuario\AppData\Local\Google\Update\GoogleUpdate.exe [2012-09-02 15:29]
      .
      .
      --------- X64 Entries -----------
      .
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
      @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
      [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
      2012-07-06 15:11 232672 ----a-w- c:\users\Usuario\AppData\Local\Microsoft\SkyDrive\16.4.4111.0525\amd64\SkyDriveShell64.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
      @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
      [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
      2012-07-06 15:11 232672 ----a-w- c:\users\Usuario\AppData\Local\Microsoft\SkyDrive\16.4.4111.0525\amd64\SkyDriveShell64.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
      @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
      [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
      2012-07-06 15:11 232672 ----a-w- c:\users\Usuario\AppData\Local\Microsoft\SkyDrive\16.4.4111.0525\amd64\SkyDriveShell64.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
      @="{472083B0-C522-11CF-8763-00608CC02F24}"
      [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
      2012-10-30 22:50 133400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
      @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 162552 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
      @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 162552 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
      @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 162552 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
      .
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
      @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
      [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
      2012-11-13 23:32 162552 ----a-w- c:\users\Usuario\AppData\Roaming\Dropbox\bin\DropboxExt64.17.dll
      .
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=c:\progra~2\BEARSH~1\Mediabar\Datamngr\x64\datamngr.dll c:\progra~2\BEARSH~1\Mediabar\Datamngr\x64\IEBHO.dll
      .
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
      FontCache
      .
      ------- Supplementary Scan -------
      .
      uLocal Page = c:\windows\system32\blank.htm
      uStart Page = hxxp://www.google.es/
      mLocal Page = c:\windows\SysWOW64\blank.htm
      mSearchAssistant = hxxp://start.facemoods.com/?a=tweak&s={searchTerms}&f=4
      TCP: DhcpNameServer = 80.58.61.250 80.58.61.254
      .
      - - - - ORPHANS REMOVED - - - -
      .
      Toolbar-10 - (no file)
      WebBrowser-{977AE9CC-AF83-45E8-9E03-E2798216E2D5} - (no file)
      AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe
      AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
      AddRemove-{56582EEA-3AEF-4D84-8B9D-C87A3CD9250F} - h:\getdataback for ntfs\Uninstall.exe
      .
      .
      .
      --------------------- LOCKED REGISTRY KEYS ---------------------
      .
      [HKEY_USERS\S-1-5-21-2997284614-1332722331-2720000673-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
      @Denied: (2) (LocalSystem)
      "Progid"="WindowsLiveMail.Email.1"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="FlashBroker"
      "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
      "Enabled"=dword:00000001
      .
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
      @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="IFlashBroker5"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
      @="{00020424-0000-0000-C000-000000000046}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      "Version"="1.0"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="FlashBroker"
      "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
      "Enabled"=dword:00000001
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
      @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
      @Denied: (A 2) (Everyone)
      @="Shockwave Flash Object"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
      @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
      "ThreadingModel"="Apartment"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
      @="0"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
      @="ShockwaveFlash.ShockwaveFlash.11"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
      @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
      @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
      @="1.0"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
      @="ShockwaveFlash.ShockwaveFlash"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
      @Denied: (A 2) (Everyone)
      @="Macromedia Flash Factory Object"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
      @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx"
      "ThreadingModel"="Apartment"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
      @="FlashFactory.FlashFactory.1"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
      @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
      @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
      @="1.0"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
      @="FlashFactory.FlashFactory"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
      @Denied: (A 2) (Everyone)
      @="IFlashBroker5"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
      @="{00020424-0000-0000-C000-000000000046}"
      .
      [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
      "Version"="1.0"
      .
      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
      @Denied: (A) (Users)
      @Denied: (A) (Everyone)
      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
      "BlindDial"=dword:00000000
      .
      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
      @Denied: (A) (Users)
      @Denied: (A) (Everyone)
      @Allowed: (B 1 2 3 4 5) (S-1-5-20)
      "BlindDial"=dword:00000000
      .
      [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
      @Denied: (Full) (Everyone)
      .
      Completion time: 2013-04-02 20:52:55
      ComboFix-quarantined-files.txt 2013-04-02 18:52
      ComboFix2.txt 2013-02-24 20:33
      ComboFix3.txt 2012-11-24 14:35
      .
      Pre-Run: 22.720.483.328 bytes libres
      Post-Run: 22.633.443.328 bytes libres
      .
      - - End Of File - - 4D086402914086DC280609984E2D35ED

    Página 7 de 7 PrimeroPrimero ... 34567