ComboFix 08-05-09.1 - Jessiem 2008-05-10 15:50:48.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.1.3082.18.134 [GMT -7:00]Se ejecuta desde: C:\Users\Jessiem\Desktop\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Otras eliminaciones )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\cfg32r.dll
C:\Windows\cfg32s.dll
C:\Windows\cs_cache.ini
C:\Windows\dat.txt
C:\Windows\Downloaded Program Files\setup.inf
C:\Windows\inf\svchost.exe
C:\Windows\system32\o06PrEz
C:\Windows\system32\S0
C:\Windows\system32\S1
C:\Windows\system32\S4
C:\Windows\system32\S6
C:\Windows\system32\S7
C:\Windows\system32\win
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TNIDRIVER
(((((((((((((((((( Archivos creados desde 2008-04-10 - 2008-05-10 )))))))))))))))))))))))))))))))))
.
Ning£n archivo ha sido creado durante este intervalo de tiempo
.
(((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-10 00:07 --------- d-----w C:\Program Files\Trend Micro
2008-05-09 13:11 --------- d-----w C:\Program Files\Windows Sidebar
2008-05-09 13:10 74,653,651 ----a-w C:\Windows\DUMP44d9.tmp
2008-05-09 13:10 --------- d-----w C:\Program Files\Windows Mail
2008-05-09 13:10 --------- d-----w C:\Program Files\Windows Calendar
2008-05-09 12:36 82,341,843 ----a-w C:\Windows\DUMP41ac.tmp
2008-05-01 05:31 --------- d-----w C:\Program Files\LimeWire
2008-05-01 02:54 --------- d-----w C:\Users\Jessiem\AppData\Roaming\LimeWire
2008-04-23 03:00 --------- d-----w C:\ProgramData\Kaspersky Lab
2008-04-18 07:38 --------- d-----w C:\Program Files\CamStudio
2008-04-11 07:03 --------- d-----w C:\Program Files\Xara
2008-04-05 05:47 --------- d-----w C:\Users\Jessiem\AppData\Roaming\Grisoft
2008-03-20 17:31 --------- d-----w C:\ProgramData\Zylom
2008-03-15 05:55 --------- d-----w C:\Users\Jessiem\AppData\Roaming\U3
2008-03-14 21:25 --------- d-----w C:\Program Files\Java
2007-10-01 21:57 174 --sha-w C:\Program Files\desktop.ini
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((( Cargando Puntos Reg ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* entradas vac¡as & entradas leg¡timas predeterminadas no son mostradas
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-10-05 00:42 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25 6731312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{32928462-6441-4F84-83D9-4872A51ACAFA}C:\\program files\\kaspersky lab\\kaspersky anti-virus 6.0\\avp.exe"= UDP:C:\program files\kaspersky lab\kaspersky anti-virus 6.0\avp.exe:Kaspersky Anti-Virus
"UDP Query User{8366955E-37F2-49B6-8293-549702B7EFC4}C:\\program files\\kaspersky lab\\kaspersky anti-virus 6.0\\avp.exe"= TCP:C:\program files\kaspersky lab\kaspersky anti-virus 6.0\avp.exe:Kaspersky Anti-Virus
"{8372A07C-C88C-410E-B8FA-95CF1E480BA7}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{1C001ED0-D973-4EC2-84B1-512D3E396AC6}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{C66518A6-BF31-43E2-BA43-4B5AB4D0FAD9}C:\\program files\\yahoo! games\\yahoo! ten pin championship bowling\\yahoo ten pin championship bowling.exe"= UDP:C:\program files\yahoo! games\yahoo! ten pin championship bowling\yahoo ten pin championship bowling.exe:Skyworks Ten Pin Championship Bowling
"UDP Query User{2C5C540C-D404-469F-B9B2-C610CAACBD0D}C:\\program files\\yahoo! games\\yahoo! ten pin championship bowling\\yahoo ten pin championship bowling.exe"= TCP:C:\program files\yahoo! games\yahoo! ten pin championship bowling\yahoo ten pin championship bowling.exe:Skyworks Ten Pin Championship Bowling
"{CADD3FF7-D782-4C62-BF39-873151DA9F7D}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{8242658C-FA50-4572-B0CA-F0039166F2C1}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{EFD7EA95-ECBC-482D-88C8-FA3683DD3EA4}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:Windows Live Messenger 8.0
"{723EBFE4-26B3-4820-BB85-C7A99902CA60}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:Windows Live Messenger 8.0
"{F9B75228-6F49-48D6-ACD8-87B6495AEBAB}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:Windows Live Messenger 8.0
"{97D48971-F389-4021-9AE2-C0C31DF6EDF8}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:Windows Live Messenger 8.0
"{A2E606E3-190B-495D-B2BC-73FCD4122D95}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:Windows Live Messenger 8.0
"{82FE707C-23DF-48A6-9BB4-0AAB7B454200}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:Windows Live Messenger 8.0
"{5DFACC57-F6EE-41FE-B00D-5C08A5642524}"= UDP:C:\Program Files\MSN Messenger\msncall.exe:Windows Live Messenger 8.0 (Phone)
"{2E15BE23-C8B1-4839-BF31-71D019BF5565}"= TCP:C:\Program Files\MSN Messenger\msncall.exe:Windows Live Messenger 8.0 (Phone)
"{9A04F012-7E10-4CB1-8B0C-525064361398}"= UDP:C:\Program Files\MSN Messenger\msncall.exe:Windows Live Messenger 8.0 (Phone)
"{BCF89A14-CB79-46C1-B6AD-657175FE85B9}"= TCP:C:\Program Files\MSN Messenger\msncall.exe:Windows Live Messenger 8.0 (Phone)
"{69728AC0-55B8-4BB3-8578-CBEC08C8F621}"= UDP:C:\Program Files\MSN Messenger\msncall.exe:Windows Live Messenger 8.0 (Phone)
"{B7A89305-3BAE-4B54-A29E-0B099CBBBF3F}"= TCP:C:\Program Files\MSN Messenger\msncall.exe:Windows Live Messenger 8.0 (Phone)
"{124399F6-1337-49EA-9BA6-8C11CFEB4D22}"= Disabled:UDP:C:\Windows\System32\lxcgcoms.exe:2300 Series
"{6E4C2423-FCBF-4486-92B4-E09060188DA7}"= Disabled:TCP:C:\Windows\System32\lxcgcoms.exe:2300 Series
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DisableNotifications"= 1 (0x1)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL D:\Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{13e6c64e-e8a8-11dc-a9b5-bf8637c71753}]
\shell\AutoRun\command - J:\kypdcrkh.exe
\shell\explore\Command - J:\kypdcrkh.exe
\shell\open\Command - J:\kypdcrkh.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{73777684-bb11-11dc-acba-a8c96a822d8c}]
\shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{971a3ffa-ea80-11db-b30a-806e6f6e6963}]
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL D:\Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bc69e0c8-16f0-11dd-9cb7-c7adb9ad4799}]
\shell\AutoRun\command - J:\fadqhvul.exe
\shell\explore\Command - J:\fadqhvul.exe
\shell\open\Command - J:\fadqhvul.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d01e391b-0895-11dc-9649-0013d4e77f78}]
\shell\AutoRun\command - J:\sgdrcsjf.exe
\shell\explore\Command - J:\sgdrcsjf.exe
\shell\open\Command - J:\sgdrcsjf.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-10 16:02:14
Windows 6.0.6000 NTFS
escaneando procesos ocultos ...
escaneando entradas ocultas de autostart ...
escaneando archivos ocultos ...
el escaneo se completo con exito
archivos ocultos: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Novatel Wireless\Sprint\Sprint PCS Connection Manager\OSCMUtilityService.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Windows\System32\WUDFHost.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Tiempo completado: 2008-05-10 16:20:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-10 23:20:12
El sistema no puede encontrar el texto del mensaje para el mensaje número 0x2379 en el archivo de mensajes para Application.
El sistema no puede encontrar el texto del mensaje para el mensaje n£mero 0x2379 en el archivo de mensajes para Application.
141 --- E O F --- 2008-05-10 01:24:50