j'envoie le log de trojan remover fait vers 23h :
***** THE SYSTEM HAS BEEN RESTARTED *****
25/11/2008 23:43:48: Trojan Remover has been restarted
=======================================================
Removing the following registry keys:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\WgaLogon - already removed (or did not exist)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dotnet3.exe - already removed (or did not exist)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dotnet3[1].exe - already removed (or did not exist)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dotnet3[2].exe - already removed (or did not exist)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dotnetfx.exe - already removed (or did not exist)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dotnetfx3.exe - already removed (or did not exist)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dotnetfx30SP1setup.exe - already removed (or did not exist)
=======================================================
25/11/2008 23:43:48: Trojan Remover closed
************************************************************
***** NORMAL SCAN FOR ACTIVE MALWARE *****
Trojan Remover Ver 6.7.4.2553. For information, email
support@simplysup1.com
[Unregistered version]
Scan started at: 23:06:41 25 nov 2008
Using Database v7210
Operating System: Windows XP SP2 [Windows XP Professional Service Pack 2 (Build 2600)]
File System: NTFS
Data directory: C:\Documents and Settings\JM\Datos de programa\Simply Super Software\Trojan Remover\
Database directory: C:\Archivos de programa\Trojan Remover\
Logfile directory: C:\Documents and Settings\JM\Mis documentos\Simply Super Software\Trojan Remover Logfiles\
Program directory: C:\Archivos de programa\Trojan Remover\
Running with Administrator privileges
************************************************************
The following Anti-Malware program(s) are loaded:
Avira AntiVir
************************************************************
************************************************************
23:06:41: Scanning ----------WIN.INI-----------
WIN.INI found in C:\WINDOWS
************************************************************
23:06:41: Scanning --------SYSTEM.INI---------
SYSTEM.INI found in C:\WINDOWS
************************************************************
23:06:41: ----- SCANNING FOR ROOTKIT SERVICES -----
No hidden Services were detected.
************************************************************
23:06:41: Scanning -----WINDOWS REGISTRY-----
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
This key's "Shell" value calls the following program(s):
File: Explorer.exe
C:\WINDOWS\Explorer.exe
1034752 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
----------
This key's "Userinit" value calls the following program(s):
File: C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
25088 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
----------
This key's "System" value appears to be blank
----------
This key's "UIHost" value calls the following program:
File: logonui.exe
C:\WINDOWS\system32\logonui.exe
515584 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
----------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Value Name: load
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvCplDaemon
Value Data: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
C:\WINDOWS\system32\NvCpl.dll
8523776 bytes
Created: 09/01/2008
Modified: 09/01/2008
Company: NVIDIA Corporation
--------------------
Value Name: nwiz
Value Data: nwiz.exe /install
C:\WINDOWS\system32\nwiz.exe
1626112 bytes
Created: 09/01/2008
Modified: 09/01/2008
Company:
--------------------
Value Name: NvMediaCenter
Value Data: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
C:\WINDOWS\system32\NvMcTray.dll
81920 bytes
Created: 09/01/2008
Modified: 09/01/2008
Company: NVIDIA Corporation
--------------------
Value Name: RTHDCPL
Value Data: RTHDCPL.EXE
C:\WINDOWS\RTHDCPL.EXE
16862720 bytes
Created: 24/10/2008
Modified: 16/05/2008
Company: Realtek Semiconductor Corp.
--------------------
Value Name: BigDogPath
Value Data: C:\WINDOWS\VM_STI.EXE Philips SPC 200NC PC Camera
C:\WINDOWS\VM_STI.EXE
40960 bytes
Created: 25/10/2008
Modified: 09/06/2004
Company: BIGDOG
--------------------
Value Name: Logitech Hardware Abstraction Layer
Value Data: KHALMNPR.EXE
C:\WINDOWS\KHALMNPR.EXE
28160 bytes
Created: 26/10/2008
Modified: 22/07/2005
Company: Logitech Inc.
--------------------
Value Name: avgnt
Value Data: "C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgnt.exe
266497 bytes
Created: 24/11/2008
Modified: 12/06/2008
Company: Avira GmbH
--------------------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value Name: MSMSGS
Value Data: "C:\Archivos de programa\Messenger\msmsgs.exe" /background
C:\Archivos de programa\Messenger\msmsgs.exe
1695232 bytes
Created: 14/04/2008
Modified: 14/04/2008
Company: Microsoft Corporation
--------------------
Value Name: Skype
Value Data: "C:\Archivos de programa\Skype\Phone\Skype.exe" /nosplash /minimized
C:\Archivos de programa\Skype\Phone\Skype.exe
-R- 21755688 bytes
Created: 29/09/2008
Modified: 29/09/2008
Company: Skype Technologies S.A.
--------------------
Value Name: TClockEx
Value Data: C:\Archivos de programa\TClockEx\TCLOCKEX.EXE
C:\Archivos de programa\TClockEx\TCLOCKEX.EXE
89088 bytes
Created: 09/03/2000
Modified: 09/03/2000
Company: Dale Nurden
--------------------
Value Name:
Value Data:
Blank entry: []
--------------------
Value Name: ctfmon.exe
Value Data: C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
15360 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
--------------------
Value Name: Uniblue RegistryBooster 2009
Value Data: C:\Archivos de programa\Uniblue\RegistryBooster\RegistryBooster.exe /S
C:\Archivos de programa\Uniblue\RegistryBooster\RegistryBooster.exe
2019624 bytes
Created: 26/08/2008
Modified: 26/08/2008
Company: Uniblue Software
--------------------
Value Name: DAEMON Tools Lite
Value Data: "C:\Archivos de programa\DAEMON Tools Lite\daemon.exe" -autorun
C:\Archivos de programa\DAEMON Tools Lite\daemon.exe
490952 bytes
Created: 24/07/2008
Modified: 24/07/2008
Company: DT Soft Ltd
--------------------
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
This Registry Key appears to be empty
************************************************************
23:06:44: Scanning -----SHELLEXECUTEHOOKS-----
ValueName: {AEB6717E-7E19-11d0-97EE-00C04FD91972}
File: shell32.dll - this file is expected and has been left in place
----------
************************************************************
23:06:44: Scanning -----HIDDEN REGISTRY ENTRIES-----
Taskdir check completed
----------
No Hidden File-loading Registry Entries found
----------
************************************************************
23:06:44: Scanning -----ACTIVE SCREENSAVER-----
No active ScreenSaver found to scan.
************************************************************
23:06:44: Scanning ----- REGISTRY ACTIVE SETUP KEYS -----
Key: {22d6f312-b0f6-11d0-94ab-0080c74c7e95}
Path: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\mplayer2.inf,PerUserStub.NT
C:\WINDOWS\INF\mplayer2.inf
51761 bytes
Created: 19/08/2004
Modified: 02/09/1998
Company:
----------
Key: {44BBA840-CC51-11CF-AAFA-00AA00B6015C}
Path: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
C:\Archivos de programa\Outlook Express\setup50.exe
73728 bytes
Created: 24/10/2008
Modified: 19/08/2004
Company: Microsoft Corporation
----------
Key: {7790769C-0471-11d2-AF11-00C04FA35D02}
Path: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
C:\Archivos de programa\Outlook Express\setup50.exe
73728 bytes
Created: 24/10/2008
Modified: 19/08/2004
Company: Microsoft Corporation
----------
************************************************************
23:06:44: Scanning ----- SERVICEDLL REGISTRY KEYS -----
Key: UxTuneUp
Path: %SystemRoot%\System32\uxtuneup.dll
C:\WINDOWS\System32\uxtuneup.dll
28416 bytes
Created: 09/11/2008
Modified: 04/04/2008
Company: TuneUp Software GmbH
--------------------
************************************************************
23:06:45: Scanning ----- SERVICES REGISTRY KEYS -----
Key: antivirscheduler
ImagePath: "C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\sched.exe"
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\sched.exe
68865 bytes
Created: 24/11/2008
Modified: 24/11/2008
Company: Avira GmbH
----------
Key: antivirservice
ImagePath: "C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avguard.exe"
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avguard.exe
151297 bytes
Created: 24/11/2008
Modified: 24/11/2008
Company: Avira GmbH
----------
Key: AtcL001
ImagePath: system32\DRIVERS\l151x86.sys
C:\WINDOWS\system32\DRIVERS\l151x86.sys
37376 bytes
Created: 24/10/2008
Modified: 24/02/2008
Company: Atheros Communications, Inc.
----------
Key: avgio
ImagePath: \??\C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgio.sys
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgio.sys
11840 bytes
Created: 24/11/2008
Modified: 27/02/2007
Company: Avira GmbH
----------
Key: avgntflt
ImagePath: \??\C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgntflt.sys
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgntflt.sys
52032 bytes
Created: 24/11/2008
Modified: 20/05/2008
Company: Avira GmbH
----------
Key: avipbb
ImagePath: system32\DRIVERS\avipbb.sys
C:\WINDOWS\system32\DRIVERS\avipbb.sys
75072 bytes
Created: 24/11/2008
Modified: 25/11/2008
Company: Avira GmbH
----------
Key: C-DillaCdaC11BA
ImagePath: C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
54784 bytes
Created: 25/10/2008
Modified: 25/10/2008
Company: Macrovision
----------
Key: CdaC15BA
ImagePath: \??\C:\WINDOWS\system32\drivers\CDAC15BA.SYS
C:\WINDOWS\system32\drivers\CDAC15BA.SYS
12464 bytes
Created: 25/10/2008
Modified: 25/10/2008
Company: Macrovision Europe Ltd
----------
Key: CTSYN
ImagePath: \SystemRoot\System32\drivers\CTSYN.SYS
C:\WINDOWS\System32\drivers\CTSYN.SYS
160832 bytes
Created: 25/10/2008
Modified: 16/06/1999
Company: Creative Technology Ltd.
----------
Key: dmadmin
ImagePath: %SystemRoot%\System32\dmadmin.exe /com
C:\WINDOWS\System32\dmadmin.exe
225792 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corp., VERITAS Software
----------
Key: EMU10K1
ImagePath: \SystemRoot\System32\drivers\EMU10K1.SYS
C:\WINDOWS\System32\drivers\EMU10K1.SYS
219520 bytes
Created: 25/10/2008
Modified: 15/07/1999
Company: Creative Technology Ltd.
----------
Key: FontCache3.0.0.0
ImagePath: C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
46104 bytes
Created: 29/07/2008
Modified: 29/07/2008
Company: Microsoft Corporation
----------
Key: HDAudBus
ImagePath: system32\DRIVERS\HDAudBus.sys
C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
138752 bytes
Created: 07/01/2005
Modified: 07/01/2005
Company: Windows (R) Server 2003 DDK provider
----------
Key: idrivert
ImagePath: "C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe"
C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
69632 bytes
Created: 04/04/2005
Modified: 04/04/2005
Company: Macrovision Corporation
----------
Key: IntcAzAudAddService
ImagePath: system32\drivers\RtkHDAud.sys
C:\WINDOWS\system32\drivers\RtkHDAud.sys
4800000 bytes
Created: 24/10/2008
Modified: 20/05/2008
Company: Realtek Semiconductor Corp.
----------
Key: JavaQuickStarterService
ImagePath: "C:\Archivos de programa\Java\jre6\bin\jqs.exe" -service -config "C:\Archivos de programa\Java\jre6\lib\deploy\jqs\jqs.conf"
C:\Archivos de programa\Java\jre6\bin\jqs.exe
152984 bytes
Created: 30/10/2008
Modified: 30/10/2008
Company: Sun Microsystems, Inc.
----------
Key: L8042mou
ImagePath: system32\DRIVERS\L8042mou.Sys
C:\WINDOWS\system32\DRIVERS\L8042mou.Sys
55040 bytes
Created: 26/10/2008
Modified: 22/07/2005
Company: Logitech, Inc.
----------
Key: LHidKe
ImagePath: system32\DRIVERS\LHidKE.Sys
C:\WINDOWS\system32\DRIVERS\LHidKE.Sys
26112 bytes
Created: 26/10/2008
Modified: 22/07/2005
Company: Logitech, Inc.
----------
Key: LMouKE
ImagePath: system32\DRIVERS\LMouKE.Sys
C:\WINDOWS\system32\DRIVERS\LMouKE.Sys
68864 bytes
Created: 26/10/2008
Modified: 22/07/2005
Company: Logitech, Inc.
----------
Key: MTsensor
ImagePath: system32\DRIVERS\ASACPI.sys
C:\WINDOWS\system32\DRIVERS\ASACPI.sys
-R- 5810 bytes
Created: 24/10/2008
Modified: 13/08/2004
Company:
----------
Key: nero backitup scheduler 4.0
ImagePath: C:\Archivos de programa\Archivos comunes\Nero\Nero BackItUp 4\NBService.exe
C:\Archivos de programa\Archivos comunes\Nero\Nero BackItUp 4\NBService.exe
935208 bytes
Created: 24/09/2008
Modified: 24/09/2008
Company: Nero AG
----------
Key: plflash deviceiocontrol service
ImagePath: C:\Archivos de programa\Nero\Nero BackItUp 4\IoctlSvc.exe
C:\Archivos de programa\Nero\Nero BackItUp 4\IoctlSvc.exe
81920 bytes
Created: 24/09/2008
Modified: 24/09/2008
Company: Prolific Technology Inc.
----------
Key: RTL8187B
ImagePath: system32\DRIVERS\RTL8187B.sys
C:\WINDOWS\system32\DRIVERS\RTL8187B.sys
-R- 264576 bytes
Created: 24/10/2008
Modified: 18/07/2007
Company: Realtek Semiconductor Corporation
----------
Key: Secdrv
ImagePath: system32\DRIVERS\secdrv.sys
C:\WINDOWS\system32\DRIVERS\secdrv.sys
27440 bytes
Created: 17/07/2004
Modified: 17/07/2004
Company:
----------
Key: SFMAN
ImagePath: \SystemRoot\System32\drivers\SFMAN.SYS
C:\WINDOWS\System32\drivers\SFMAN.SYS
27264 bytes
Created: 25/10/2008
Modified: 09/02/1999
Company: Creative Technology Ltd.
----------
Key: sptd
ImagePath: System32\Drivers\sptd.sys - this file is globally excluded
----------
Key: ssmdrv
ImagePath: system32\DRIVERS\ssmdrv.sys
C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
28352 bytes
Created: 24/11/2008
Modified: 01/03/2007
Company: Avira GmbH
----------
Key: SwPrv
ImagePath: C:\WINDOWS\system32\dllhost.exe /Processid:{D7302D89-876C-42DA-A580-373B6B4B8A6E}
C:\WINDOWS\system32\dllhost.exe
5120 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
----------
Key: tmcomm
ImagePath: \??\C:\WINDOWS\system32\drivers\tmcomm.sys
C:\WINDOWS\system32\drivers\tmcomm.sys
102664 bytes
Created: 30/10/2008
Modified: 30/10/2008
Company: Trend Micro Inc.
----------
Key: TuneUp.Defrag
ImagePath: %SystemRoot%\System32\TuneUpDefragService.exe
C:\WINDOWS\System32\TuneUpDefragService.exe
354560 bytes
Created: 09/11/2008
Modified: 09/11/2008
Company: TuneUp Software GmbH
----------
Key: tvtool
ImagePath: \??\C:\Archivos de programa\TVTool\tvtool.sys
C:\Archivos de programa\TVTool\tvtool.sys
5248 bytes
Created: 03/04/1996
Modified: 03/04/1996
Company:
----------
Key: ZSMC301b
ImagePath: System32\Drivers\usbVM31b.sys
C:\WINDOWS\System32\Drivers\usbVM31b.sys
93319 bytes
Created: 25/10/2008
Modified: 16/12/2004
Company: VM
----------
************************************************************
23:06:47: Scanning -----VXD ENTRIES-----
************************************************************
23:06:47: Scanning ----- WINLOGON\NOTIFY DLLS -----
Key : WgaLogon
DLLName: WgaLogon.dll
WgaLogon.dll - this reference has been removed [file not found to scan]
----------
************************************************************
23:07:41: Scanning ----- CONTEXTMENUHANDLERS -----
Key: cover designer
CLSID: {73FCA462-9BD5-4065-A73F-A8E5F6904EF7}
Path: C:\Archivos de programa\Nero\Nero 9\Nero CoverDesigner\CoverEdExtension.dll
C:\Archivos de programa\Nero\Nero 9\Nero CoverDesigner\CoverEdExtension.dll
2135336 bytes
Created: 19/09/2008
Modified: 19/09/2008
Company: Nero AG
----------
Key: shell extension for malware scanning
CLSID: {45AC2688-0253-4ED8-97DE-B5370FA7D48A}
Path: C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\shlext.dll
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\shlext.dll
65793 bytes
Created: 24/11/2008
Modified: 12/06/2008
Company: Avira GmbH
----------
Key: trojan remover
CLSID: {52B87208-9CCF-42C9-B88E-069281105805}
Path: C:\ARCHIV~1\Trojan Remover\Trshlex.dll
C:\ARCHIV~1\Trojan Remover\Trshlex.dll
467552 bytes
Created: 25/11/2008
Modified: 05/02/2007
Company: Simply Super Software
----------
Key: TuneUp Shredder Shell Extension
CLSID: {4858E7D9-8E12-45a3-B6A3-1CD128C9D403}
Path: C:\ARCHIV~1\TuneUp Utilities 2008\SDShelEx-win32.dll
C:\ARCHIV~1\TuneUp Utilities 2008\SDShelEx-win32.dll
27656 bytes
Created: 04/09/2007
Modified: 04/09/2007
Company: TuneUp Software GmbH
----------
Key: WinRAR
CLSID: {B41DB860-8EE4-11D2-9906-E49FADC173CA}
Path: C:\Archivos de programa\WinRAR\rarext.dll
C:\Archivos de programa\WinRAR\rarext.dll
126464 bytes
Created: 24/10/2008
Modified: 03/12/2006
Company:
----------
Key: {7759105c-e384-4a1f-9315-eb695369ca76}
Path: C:\Archivos de programa\Nero\Nero BackItUp 4\NBShell.dll
C:\Archivos de programa\Nero\Nero BackItUp 4\NBShell.dll
283944 bytes
Created: 24/09/2008
Modified: 24/09/2008
Company: Nero AG
----------
************************************************************
23:07:41: Scanning ----- FOLDER\COLUMNHANDLERS -----
Key: {c9e60ed7-feae-477b-b6a6-7d62103a0c6b}
File: C:\Archivos de programa\Archivos comunes\Nero\SMC\NeroDigitalExt.dll
C:\Archivos de programa\Archivos comunes\Nero\SMC\NeroDigitalExt.dll
2061608 bytes
Created: 19/09/2008
Modified: 19/09/2008
Company: Nero AG
----------
Key: {F9DB5320-233E-11D1-9F84-707F02C10627}
File: C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\PDFShell.dll
C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\PDFShell.dll
378200 bytes
Created: 11/06/2008
Modified: 11/06/2008
Company: Adobe Systems, Inc.
----------
************************************************************
23:07:41: Scanning ----- BROWSER HELPER OBJECTS -----
Key: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
BHO: C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
61816 bytes
Created: 11/06/2008
Modified: 11/06/2008
Company: Adobe Systems Incorporated
----------
Key: {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
BHO: C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
75128 bytes
Created: 11/06/2008
Modified: 11/06/2008
Company: Adobe Systems Incorporated
----------
Key: {53707962-6F74-2D53-2644-206D7942484F}
BHO: C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
C:\ARCHIV~1\SPYBOT~1\SDHelper.dll - file is excluded from scanning [SPYBOT S&D file]
----------
Key: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
BHO: C:\Archivos de programa\Java\jre6\bin\ssv.dll
C:\Archivos de programa\Java\jre6\bin\ssv.dll
320920 bytes
Created: 30/10/2008
Modified: 30/10/2008
Company: Sun Microsystems, Inc.
----------
Key: {9cb65201-89c4-402c-ba80-02d8c59f9b1d}
BHO: C:\Archivos de programa\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
C:\Archivos de programa\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
57344 bytes
Created: 11/11/2008
Modified: 11/11/2008
Company: Ask.com
----------
Key: {DBC80044-A445-435b-BC74-9C25C1C588A9}
BHO: C:\Archivos de programa\Java\jre6\bin\jp2ssv.dll
C:\Archivos de programa\Java\jre6\bin\jp2ssv.dll
34816 bytes
Created: 30/10/2008
Modified: 30/10/2008
Company: Sun Microsystems, Inc.
----------
Key: {E7E6F031-17CE-4C07-BC86-EABFE594F69C}
BHO: C:\Archivos de programa\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
C:\Archivos de programa\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
73728 bytes
Created: 30/10/2008
Modified: 30/10/2008
Company: Sun Microsystems, Inc.
----------
Key: {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}
BHO: C:\Archivos de programa\AskSBar\bar\1.bin\ASKSBAR.DLL
C:\Archivos de programa\AskSBar\bar\1.bin\ASKSBAR.DLL
262144 bytes
Created: 09/11/2008
Modified: 09/11/2008
Company: Ask.com
----------
Key: {fe063db1-4ec0-403e-8dd8-394c54984b2c}
BHO: C:\Archivos de programa\AskTBar\bar\1.bin\ASKTBAR.DLL
C:\Archivos de programa\AskTBar\bar\1.bin\ASKTBAR.DLL
245760 bytes
Created: 11/11/2008
Modified: 11/11/2008
Company: Ask.com
----------
************************************************************
23:07:41: Scanning ----- SHELLSERVICEOBJECTS -----
************************************************************
23:07:41: Scanning ----- SHAREDTASKSCHEDULER ENTRIES -----
************************************************************
23:07:41: Scanning ----- IMAGEFILE DEBUGGERS -----
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe
173080 bytes
Created: 30/07/2008
Modified: 30/07/2008
Company: Microsoft Corporation
Key = dotnet3.exe
Debugger file = C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - this entry has been removed
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - process is either not running or could not be terminated
This Debugger entry has been renamed to: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe.vir
----------
Key = dotnet3[1].exe
Debugger file = C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - this entry has been removed [file not found to scan]
----------
Key = dotnet3[2].exe
Debugger file = C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - this entry has been removed [file not found to scan]
----------
Key = dotnetfx.exe
Debugger file = C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - this entry has been removed [file not found to scan]
----------
Key = dotnetfx3.exe
Debugger file = C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - this entry has been removed [file not found to scan]
----------
Key = dotnetfx30SP1setup.exe
Debugger file = C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - this entry has been removed [file not found to scan]
----------
Key = dotnetfx30SP1setup[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - this Debugger entry has been left in place [file not found to scan]
----------
Key = dotnetfx30SP1setup[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - this Debugger entry has been left in place [file not found to scan]
----------
Key = dotnetfx35.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - this Debugger entry has been left in place [file not found to scan]
----------
Key = dotnetfx35setup.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx35setup[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx35setup[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx35[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx35[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx3setup.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx3setup[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx3setup[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx3[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx3[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx3_ia64.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx3_ia64[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx3_ia64[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx3_x64.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx3_x64[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx3_x64[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = dotnetfx[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP1_ia64.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP1_ia64[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP1_ia64[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP1_x64.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP1_x64[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP1_x64[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP1_x86.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP1_x86[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP1_x86[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP2_ia64.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP2_ia64[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP2_ia64[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP2_x64.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP2_x64[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP2_x64[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP2_x86.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP2_x86[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx20SP2_x86[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx30SP1_x64.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx30SP1_x64[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx30SP1_x64[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx30SP1_x86.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx30SP1_x86[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx30SP1_x86[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx35_ia64.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx35_ia64[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx35_ia64[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx35_x64.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx35_x64[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx35_x64[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx35_x86.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx35_x86[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx35_x86[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx64.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx64[1].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
Key = NetFx64[2].exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\DotNetFxInstallBlock.exe - Debugger entry has been excluded from scanning
----------
************************************************************
23:18:04: Scanning ----- APPINIT_DLLS -----
The AppInit_DLLs value is blank or does not exist
************************************************************
23:18:04: Scanning ----- SECURITY PROVIDER DLLS -----
************************************************************
23:18:04: Scanning ------ USER STARTUP GROUPS ------
Checking Startup Group for All Users
[C:\WINDOWS\Profiles\All Users\Start Menu\Programs\StartUp]
No Startup files for All Users were located to check
************************************************************
23:18:04: Scanning ------ COMMON STARTUP GROUP ------
[C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio]
The Common Startup Group attempts to load the following file(s) at boot time:
C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio\desktop.ini
-HS- 84 bytes
Created: 24/10/2008
Modified: 24/10/2008
Company:
--------------------
C:\WINDOWS\Installer\{DBA5E973-660D-4CBE-A469-F5C37FBF0CE4}\_C1A9BF9D98647632ED5172.exe
-R- 29926 bytes
Created: 10/11/2008
Modified: 10/11/2008
Company:
DesktopEarth AutoStart.lnk - links to C:\WINDOWS\Installer\{DBA5E973-660D-4CBE-A469-F5C37FBF0CE4}\_C1A9BF9D98647632ED5172.exe
--------------------
************************************************************
No User Startup Groups were located to check
************************************************************
23:18:04: Scanning ----- SCHEDULED TASKS -----
Taskname: Uniblue SpyEraser Nag.job
File: F:\Archivos de programa\Uniblue\SpyEraser\SpyEraser.exe
Parameters: -ynag
Next Run Time: 29/11/2008 20:50:00
Status: La tarea está preparada para ejecutarse a la próxima hora programada
Creator: JM
Comments: [blank]
F:\Archivos de programa\Uniblue\SpyEraser\SpyEraser.exe [file not found to scan]
----------
Taskname: Uniblue SpyEraser.job
File: F:\Archivos de programa\Uniblue\SpyEraser\SpyEraser.exe
Parameters: -s
Next Run Time: Never
Status: No se ha establecido una o más propiedades necesarias para ejecutar de forma programada esta tarea
Creator: JM
Comments: Uniblue SpyEraser Scheduler
F:\Archivos de programa\Uniblue\SpyEraser\SpyEraser.exe [file not found to scan]
----------
************************************************************
23:18:04: Scanning ----- SHELLICONOVERLAYIDENTIFIERS -----
Key: AutoCAD Digital Signatures Icon Overlay Handler
CLSID: {36A21736-36C2-4C11-8ACB-D4136F2B57BD}
File: C:\WINDOWS\system32\AcSignIcon.dll
C:\WINDOWS\system32\AcSignIcon.dll
136352 bytes
Created: 14/02/2003
Modified: 14/02/2003
Company: Autodesk
----------
************************************************************
23:18:05: ----- ADDITIONAL CHECKS -----
PE386 rootkit checks completed
----------
Hidden or inaccessible Services entry: [81649e3e]
C:\WINDOWS\system32\drivers\81649e3e.sys
101586 bytes
Created: 11/11/2008
Modified: 25/11/2008
Company:
C:\WINDOWS\system32\drivers\81649e3e.sys appears to be in-use/locked
C:\WINDOWS\system32\drivers\81649e3e.sys - no action requested on this file
----------
Winlogon registry rootkit checks completed
----------
Heuristic checks for hidden files/drivers completed
----------
Layered Service Provider entries checks completed
----------
Windows Explorer Policies checks completed
----------
Desktop Wallpaper entry is blank
----------
Web Desktop Wallpaper entry is blank
----------
Checking Drivers32 entries:
Value Name: midi4
File: ctmm32.dll
C:\WINDOWS\system32\ctmm32.dll
18432 bytes
Created: 25/10/2008
Modified: 29/04/1999
Company: Creative Technology Ltd.
----------
Value Name: midi5
File: ctsyn32.dll
C:\WINDOWS\system32\ctsyn32.dll
19456 bytes
Created: 25/10/2008
Modified: 17/06/1999
Company: Creative Technology Ltd.
----------
--------------------
Additional checks completed
************************************************************
23:42:08: Scanning ----- RUNNING PROCESSES -----
C:\WINDOWS\System32\smss.exe
--------------------
C:\WINDOWS\system32\csrss.exe
--------------------
C:\WINDOWS\system32\winlogon.exe
--------------------
C:\WINDOWS\system32\services.exe
--------------------
C:\WINDOWS\system32\lsass.exe
--------------------
C:\WINDOWS\system32\svchost.exe
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
--------------------
C:\WINDOWS\System32\svchost.exe - file already scanned
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
--------------------
C:\WINDOWS\system32\spoolsv.exe
--------------------
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\sched.exe - file already scanned
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
--------------------
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avguard.exe - file already scanned
--------------------
C:\WINDOWS\system32\drivers\CDAC11BA.EXE - file already scanned
--------------------
C:\WINDOWS\Explorer.EXE - file already scanned
--------------------
C:\Archivos de programa\Java\jre6\bin\jqs.exe - file already scanned
--------------------
C:\Archivos de programa\Archivos comunes\Nero\Nero BackItUp 4\NBService.exe - file already scanned
--------------------
C:\WINDOWS\system32\nvsvc32.exe
--------------------
C:\Archivos de programa\Nero\Nero BackItUp 4\IoctlSvc.exe - file already scanned
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
--------------------
C:\WINDOWS\system32\wdfmgr.exe
--------------------
C:\WINDOWS\system32\rundll32.exe
--------------------
C:\WINDOWS\system32\RUNDLL32.EXE
--------------------
C:\WINDOWS\RTHDCPL.EXE - file already scanned
--------------------
C:\WINDOWS\VM_STI.EXE - file already scanned
--------------------
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgnt.exe - file already scanned
--------------------
C:\Archivos de programa\Messenger\msmsgs.exe - file already scanned
--------------------
C:\Archivos de programa\Skype\Phone\Skype.exe - file already scanned
--------------------
C:\WINDOWS\system32\ctfmon.exe - file already scanned
--------------------
C:\WINDOWS\System32\alg.exe
--------------------
C:\Archivos de programa\Uniblue\RegistryBooster\RegistryBooster.exe - file already scanned
--------------------
C:\Archivos de programa\DAEMON Tools Lite\daemon.exe - file already scanned
--------------------
C:\Archivos de programa\DesktopEarth\DesktopEarth.exe
--------------------
C:\WINDOWS\system32\wbem\wmiprvse.exe
--------------------
C:\Archivos de programa\Skype\Plugin Manager\skypePM.exe
--------------------
C:\WINDOWS\system32\wuauclt.exe
--------------------
C:\WINDOWS\system32\spider.exe
--------------------
C:\Documents and Settings\JM\Datos de programa\Simply Super Software\Trojan Remover\lhh4.exe
FileSize: 2884472
[This is a Trojan Remover component]
--------------------
C:\WINDOWS\system32\SNDVOL32.EXE
--------------------
C:\Archivos de programa\Mozilla Firefox\firefox.exe
--------------------
************************************************************
23:42:10: Checking AUTOEXEC.BAT file
AUTOEXEC.BAT found in C:\
No malicious entries were found in the AUTOEXEC.BAT file
************************************************************
23:42:10: Checking AUTOEXEC.NT file
AUTOEXEC.NT found in C:\WINDOWS\system32
No malicious entries were found in the AUTOEXEC.NT file
************************************************************
23:42:10: Checking HOSTS file
No malicious entries were found in the HOSTS file
************************************************************
------ INTERNET EXPLORER HOME/START/SEARCH SETTINGS ------
HKLM\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\Software\Microsoft\Internet Explorer\Main\"Local Page":
%SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
http://go.microsoft.com/fwlink/?LinkId=69157
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Search_URL":
http://go.microsoft.com/fwlink/?LinkId=54896
HKLM\Software\Microsoft\Internet Explorer\Search\"CustomizeSearch":
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\Software\Microsoft\Internet Explorer\Search\"SearchAssistant":
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKCU\Software\Microsoft\Internet Explorer\Main\"Start Page":
about:blank
HKCU\Software\Microsoft\Internet Explorer\Main\"Local Page":
C:\WINDOWS\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
************************************************************
=== CHANGES WERE MADE TO THE WINDOWS REGISTRY ===
=== ONE OR MORE FILES WERE RENAMED OR REMOVED ===
Scan completed at: 23:42:10 25 nov 2008
Total Scan time: 00:35:29
-------------------------------------------------------------------------
One or more files could not be moved or renamed as requested.
They may be in use by Windows, so Trojan Remover needs
to restart the system in order to deal with these files.
25/11/2008 23:42:20: restart commenced
************************************************************
***** INDIVIDUAL FILE SCAN *****
Trojan Remover Ver 6.7.4.2553. For information, email
support@simplysup1.com
[Unregistered version]
Scan started at: 17:25:09 25 nov 2008
Using Database v7209
Operating System: Windows XP SP2 [Windows XP Professional Service Pack 2 (Build 2600)]
File System: NTFS
Data directory: C:\Documents and Settings\JM\Datos de programa\Simply Super Software\Trojan Remover\
Database directory: C:\Archivos de programa\Trojan Remover\
Logfile directory: C:\Documents and Settings\JM\Mis documentos\Simply Super Software\Trojan Remover Logfiles\
Program directory: C:\Archivos de programa\Trojan Remover\
Running with Administrator privileges
************************************************************
The following Anti-Malware program(s) are loaded:
Avira AntiVir
************************************************************
Carrying out individual file scan on C:\Documents and Settings\JM\Escritorio\NIS09EN.exe
This file appears to be OK
************************************************************
***** NORMAL SCAN FOR ACTIVE MALWARE *****
Trojan Remover Ver 6.7.4.2553. For information, email
support@simplysup1.com
[Unregistered version]
Scan started at: 2:35:41 25 nov 2008
Using Database v7209
Operating System: Windows XP SP2 [Windows XP Professional Service Pack 2 (Build 2600)]
File System: NTFS
Data directory: C:\Documents and Settings\JM\Datos de programa\Simply Super Software\Trojan Remover\
Database directory: C:\Archivos de programa\Trojan Remover\
Logfile directory: C:\Documents and Settings\JM\Mis documentos\Simply Super Software\Trojan Remover Logfiles\
Program directory: C:\Archivos de programa\Trojan Remover\
Running with Administrator privileges
************************************************************
The following Anti-Malware program(s) are loaded:
Avira AntiVir
************************************************************
************************************************************
2:35:41: Scanning ----------WIN.INI-----------
WIN.INI found in C:\WINDOWS
************************************************************
2:35:41: Scanning --------SYSTEM.INI---------
SYSTEM.INI found in C:\WINDOWS
************************************************************
2:35:41: ----- SCANNING FOR ROOTKIT SERVICES -----
No hidden Services were detected.
************************************************************
2:35:41: Scanning -----WINDOWS REGISTRY-----
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
This key's "Shell" value calls the following program(s):
File: Explorer.exe
C:\WINDOWS\Explorer.exe
1034752 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
----------
This key's "Userinit" value calls the following program(s):
File: C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
25088 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
----------
This key's "System" value appears to be blank
----------
This key's "UIHost" value calls the following program:
File: logonui.exe
C:\WINDOWS\system32\logonui.exe
515584 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
----------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Value Name: load
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvCplDaemon
Value Data: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
C:\WINDOWS\system32\NvCpl.dll
8523776 bytes
Created: 09/01/2008
Modified: 09/01/2008
Company: NVIDIA Corporation
--------------------
Value Name: nwiz
Value Data: nwiz.exe /install
C:\WINDOWS\system32\nwiz.exe
1626112 bytes
Created: 09/01/2008
Modified: 09/01/2008
Company:
--------------------
Value Name: NvMediaCenter
Value Data: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
C:\WINDOWS\system32\NvMcTray.dll
81920 bytes
Created: 09/01/2008
Modified: 09/01/2008
Company: NVIDIA Corporation
--------------------
Value Name: RTHDCPL
Value Data: RTHDCPL.EXE
C:\WINDOWS\RTHDCPL.EXE
16862720 bytes
Created: 24/10/2008
Modified: 16/05/2008
Company: Realtek Semiconductor Corp.
--------------------
Value Name: BigDogPath
Value Data: C:\WINDOWS\VM_STI.EXE Philips SPC 200NC PC Camera
C:\WINDOWS\VM_STI.EXE
40960 bytes
Created: 25/10/2008
Modified: 09/06/2004
Company: BIGDOG
--------------------
Value Name: Logitech Hardware Abstraction Layer
Value Data: KHALMNPR.EXE
C:\WINDOWS\KHALMNPR.EXE
28160 bytes
Created: 26/10/2008
Modified: 22/07/2005
Company: Logitech Inc.
--------------------
Value Name: avgnt
Value Data: "C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgnt.exe
266497 bytes
Created: 24/11/2008
Modified: 12/06/2008
Company: Avira GmbH
--------------------
Value Name: TrojanScanner
Value Data: C:\Archivos de programa\Trojan Remover\Trjscan.exe /boot
C:\Archivos de programa\Trojan Remover\Trjscan.exe
1231240 bytes
Created: 25/11/2008
Modified: 22/11/2008
Company: Simply Super Software
--------------------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value Name: MSMSGS
Value Data: "C:\Archivos de programa\Messenger\msmsgs.exe" /background
C:\Archivos de programa\Messenger\msmsgs.exe
1695232 bytes
Created: 14/04/2008
Modified: 14/04/2008
Company: Microsoft Corporation
--------------------
Value Name: Skype
Value Data: "C:\Archivos de programa\Skype\Phone\Skype.exe" /nosplash /minimized
C:\Archivos de programa\Skype\Phone\Skype.exe
-R- 21755688 bytes
Created: 29/09/2008
Modified: 29/09/2008
Company: Skype Technologies S.A.
--------------------
Value Name: TClockEx
Value Data: C:\Archivos de programa\TClockEx\TCLOCKEX.EXE
C:\Archivos de programa\TClockEx\TCLOCKEX.EXE
89088 bytes
Created: 09/03/2000
Modified: 09/03/2000
Company: Dale Nurden
--------------------
Value Name:
Value Data:
Blank entry: []
--------------------
Value Name: Uniblue RegistryBooster 2009
Value Data: C:\Archivos de programa\Uniblue\RegistryBooster\RegistryBooster.exe /S
C:\Archivos de programa\Uniblue\RegistryBooster\RegistryBooster.exe
2019624 bytes
Created: 26/08/2008
Modified: 26/08/2008
Company: Uniblue Software
--------------------
Value Name: ctfmon.exe
Value Data: C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
15360 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
--------------------
Value Name: DAEMON Tools Lite
Value Data: "C:\Archivos de programa\DAEMON Tools Lite\daemon.exe" -autorun
C:\Archivos de programa\DAEMON Tools Lite\daemon.exe
490952 bytes
Created: 24/07/2008
Modified: 24/07/2008
Company: DT Soft Ltd
--------------------
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
This Registry Key appears to be empty
************************************************************
2:35:43: Scanning -----SHELLEXECUTEHOOKS-----
ValueName: {AEB6717E-7E19-11d0-97EE-00C04FD91972}
File: shell32.dll - this file is expected and has been left in place
----------
************************************************************
2:35:43: Scanning -----HIDDEN REGISTRY ENTRIES-----
Taskdir check completed
----------
No Hidden File-loading Registry Entries found
----------
************************************************************
2:35:44: Scanning -----ACTIVE SCREENSAVER-----
No active ScreenSaver found to scan.
************************************************************
2:35:44: Scanning ----- REGISTRY ACTIVE SETUP KEYS -----
Key: {22d6f312-b0f6-11d0-94ab-0080c74c7e95}
Path: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\mplayer2.inf,PerUserStub.NT
C:\WINDOWS\INF\mplayer2.inf
51761 bytes
Created: 19/08/2004
Modified: 02/09/1998
Company:
----------
Key: {44BBA840-CC51-11CF-AAFA-00AA00B6015C}
Path: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
C:\Archivos de programa\Outlook Express\setup50.exe
73728 bytes
Created: 24/10/2008
Modified: 19/08/2004
Company: Microsoft Corporation
----------
Key: {7790769C-0471-11d2-AF11-00C04FA35D02}
Path: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
C:\Archivos de programa\Outlook Express\setup50.exe
73728 bytes
Created: 24/10/2008
Modified: 19/08/2004
Company: Microsoft Corporation
----------
************************************************************
2:35:44: Scanning ----- SERVICEDLL REGISTRY KEYS -----
Key: UxTuneUp
Path: %SystemRoot%\System32\uxtuneup.dll
C:\WINDOWS\System32\uxtuneup.dll
28416 bytes
Created: 09/11/2008
Modified: 04/04/2008
Company: TuneUp Software GmbH
--------------------
************************************************************
2:35:44: Scanning ----- SERVICES REGISTRY KEYS -----
Key: .norton2009reset
ImagePath: C:\Archivos de programa\Norton2009Reset.exe
C:\Archivos de programa\Norton2009Reset.exe
-RHS- 549159 bytes
Created: 17/09/2008
Modified: 17/09/2008
Company:
----------
Services registry keys scan stopped at user request.
The VxD Entries were not scanned.
The Winlogon\Notify DLLs were not scanned.
The ContextMenuHandlers were not scanned.
The Browser Helper Objects were not scanned.
The Global Startup Group was not scanned.
The User Startup Groups were not scanned.
The Scheduled Tasks were not scanned.
The ShellIconOverylayIdentifiers were not scanned.
Running Processes were not scanned.
The Windows Services file was not checked.
The AUTOEXEC files were not checked.
The HOSTS file was not checked.
The check on Explorer.exe was not carried out.
Internet Explorer settings were not checked.
************************************************************
=== NO CHANGES HAVE BEEN MADE TO YOUR SYSTEM FILES ===
Scan completed at: 3:40:57 25 nov 2008
Total Scan time: 01:05:15
************************************************************
***** NORMAL SCAN FOR ACTIVE MALWARE *****
Trojan Remover Ver 6.7.4.2553. For information, email
support@simplysup1.com
[Unregistered version]
Scan started at: 2:26:12 25 nov 2008
Using Database v7209
Operating System: Windows XP SP2 [Windows XP Professional Service Pack 2 (Build 2600)]
File System: NTFS
Data directory: C:\Documents and Settings\JM\Datos de programa\Simply Super Software\Trojan Remover\
Database directory: C:\Archivos de programa\Trojan Remover\
Logfile directory: C:\Documents and Settings\JM\Mis documentos\Simply Super Software\Trojan Remover Logfiles\
Program directory: C:\Archivos de programa\Trojan Remover\
Running with Administrator privileges
************************************************************
The following Anti-Malware program(s) are loaded:
Avira AntiVir
************************************************************
************************************************************
2:26:12: Scanning ----------WIN.INI-----------
WIN.INI found in C:\WINDOWS
************************************************************
2:26:12: Scanning --------SYSTEM.INI---------
SYSTEM.INI found in C:\WINDOWS
************************************************************
2:26:12: ----- SCANNING FOR ROOTKIT SERVICES -----
No hidden Services were detected.
************************************************************
2:26:13: Scanning -----WINDOWS REGISTRY-----
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
This key's "Shell" value calls the following program(s):
File: Explorer.exe
C:\WINDOWS\Explorer.exe
1034752 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
----------
This key's "Userinit" value calls the following program(s):
File: C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
25088 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
----------
This key's "System" value appears to be blank
----------
This key's "UIHost" value calls the following program:
File: logonui.exe
C:\WINDOWS\system32\logonui.exe
515584 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
----------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Value Name: load
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: NvCplDaemon
Value Data: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
C:\WINDOWS\system32\NvCpl.dll
8523776 bytes
Created: 09/01/2008
Modified: 09/01/2008
Company: NVIDIA Corporation
--------------------
Value Name: nwiz
Value Data: nwiz.exe /install
C:\WINDOWS\system32\nwiz.exe
1626112 bytes
Created: 09/01/2008
Modified: 09/01/2008
Company:
--------------------
Value Name: NvMediaCenter
Value Data: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
C:\WINDOWS\system32\NvMcTray.dll
81920 bytes
Created: 09/01/2008
Modified: 09/01/2008
Company: NVIDIA Corporation
--------------------
Value Name: RTHDCPL
Value Data: RTHDCPL.EXE
C:\WINDOWS\RTHDCPL.EXE
16862720 bytes
Created: 24/10/2008
Modified: 16/05/2008
Company: Realtek Semiconductor Corp.
--------------------
Value Name: BigDogPath
Value Data: C:\WINDOWS\VM_STI.EXE Philips SPC 200NC PC Camera
C:\WINDOWS\VM_STI.EXE
40960 bytes
Created: 25/10/2008
Modified: 09/06/2004
Company: BIGDOG
--------------------
Value Name: Logitech Hardware Abstraction Layer
Value Data: KHALMNPR.EXE
C:\WINDOWS\KHALMNPR.EXE
28160 bytes
Created: 26/10/2008
Modified: 22/07/2005
Company: Logitech Inc.
--------------------
Value Name: avgnt
Value Data: "C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
C:\Archivos de programa\Avira\AntiVir PersonalEdition Classic\avgnt.exe
266497 bytes
Created: 24/11/2008
Modified: 12/06/2008
Company: Avira GmbH
--------------------
Value Name: TrojanScanner
Value Data: C:\Archivos de programa\Trojan Remover\Trjscan.exe /boot
C:\Archivos de programa\Trojan Remover\Trjscan.exe
1231240 bytes
Created: 25/11/2008
Modified: 22/11/2008
Company: Simply Super Software
--------------------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value Name: MSMSGS
Value Data: "C:\Archivos de programa\Messenger\msmsgs.exe" /background
C:\Archivos de programa\Messenger\msmsgs.exe
1695232 bytes
Created: 14/04/2008
Modified: 14/04/2008
Company: Microsoft Corporation
--------------------
Value Name: Skype
Value Data: "C:\Archivos de programa\Skype\Phone\Skype.exe" /nosplash /minimized
C:\Archivos de programa\Skype\Phone\Skype.exe
-R- 21755688 bytes
Created: 29/09/2008
Modified: 29/09/2008
Company: Skype Technologies S.A.
--------------------
Value Name: TClockEx
Value Data: C:\Archivos de programa\TClockEx\TCLOCKEX.EXE
C:\Archivos de programa\TClockEx\TCLOCKEX.EXE
89088 bytes
Created: 09/03/2000
Modified: 09/03/2000
Company: Dale Nurden
--------------------
Value Name:
Value Data:
Blank entry: []
--------------------
Value Name: Uniblue RegistryBooster 2009
Value Data: C:\Archivos de programa\Uniblue\RegistryBooster\RegistryBooster.exe /S
C:\Archivos de programa\Uniblue\RegistryBooster\RegistryBooster.exe
2019624 bytes
Created: 26/08/2008
Modified: 26/08/2008
Company: Uniblue Software
--------------------
Value Name: ctfmon.exe
Value Data: C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
15360 bytes
Created: 19/08/2004
Modified: 19/08/2004
Company: Microsoft Corporation
--------------------
Value Name: DAEMON Tools Lite
Value Data: "C:\Archivos de programa\DAEMON Tools Lite\daemon.exe" -autorun
C:\Archivos de programa\DAEMON Tools Lite\daemon.exe
490952 bytes
Created: 24/07/2008
Modified: 24/07/2008
Company: DT Soft Ltd
--------------------
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
This Registry Key appears to be empty
************************************************************
2:26:17: Scanning -----SHELLEXECUTEHOOKS-----
ValueName: {AEB6717E-7E19-11d0-97EE-00C04FD91972}
File: shell32.dll - this file is expected and has been left in place
----------
************************************************************
2:26:17: Scanning -----HIDDEN REGISTRY ENTRIES-----
Taskdir check completed
----------
No Hidden File-loading Registry Entries found
----------
************************************************************
2:26:17: Scanning -----ACTIVE SCREENSAVER-----
No active ScreenSaver found to scan.
************************************************************
2:26:17: Scanning ----- REGISTRY ACTIVE SETUP KEYS -----
Key: {22d6f312-b0f6-11d0-94ab-0080c74c7e95}
Path: rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\mplayer2.inf,PerUserStub.NT
C:\WINDOWS\INF\mplayer2.inf
51761 bytes
Created: 19/08/2004
Modified: 02/09/1998
Company:
----------
Key: {44BBA840-CC51-11CF-AAFA-00AA00B6015C}
Path: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
C:\Archivos de programa\Outlook Express\setup50.exe
73728 bytes
Created: 24/10/2008
Modified: 19/08/2004
Company: Microsoft Corporation
----------
Key: {7790769C-0471-11d2-AF11-00C04FA35D02}
Path: "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
C:\Archivos de programa\Outlook Express\setup50.exe
73728 bytes
Created: 24/10/2008
Modified: 19/08/2004
Company: Microsoft Corporation
----------
************************************************************
2:26:18: Scanning ----- SERVICEDLL REGISTRY KEYS -----
Key: UxTuneUp
Path: %SystemRoot%\System32\uxtuneup.dll
C:\WINDOWS\System32\uxtuneup.dll
28416 bytes
Created: 09/11/2008
Modified: 04/04/2008
Company: TuneUp Software GmbH
--------------------
************************************************************
2:26:20: Scanning ----- SERVICES REGISTRY KEYS -----
Key: .norton2009reset
ImagePath: C:\Archivos de programa\Norton2009Reset.exe
C:\Archivos de programa\Norton2009Reset.exe
-RHS- 549159 bytes
Created: 17/09/2008
Modified: 17/09/2008
Company:
----------
Services registry keys scan stopped at user request.
The VxD Entries were not scanned.
The Winlogon\Notify DLLs were not scanned.
The ContextMenuHandlers were not scanned.
The Browser Helper Objects w