funciono igual en vista jejej
ComboFix 08-06-20.4 - Roque 2008-06-25 16:00:02.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.3082.18.1230 [GMT -4:00]
Se ejecuta desde: C:\Users\Roque\Desktop\ComboFix.exe
* Creado un nuevo punto de restauración
* Resident AV is active
.
(((((((((((((((((((((((((((((((((((( Otras eliminaciones )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\x64
.
(((((((((((((((((( Archivos creados desde 2008-05-25 - 2008-06-25 )))))))))))))))))))))))))))))))))
.
Ningún archivo ha sido creado durante este intervalo de tiempo
.
(((((((((((((((((((((((((((((((((((((( Reporte Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-24 23:31 --------- d-----w C:\Users\Roque\AppData\Roaming\Sony Corporation
2008-06-23 06:41 --------- d-----w C:\Users\Roque\AppData\Roaming\Uniblue
2008-06-23 06:40 --------- d-----w C:\Program Files\Uniblue
2008-06-23 04:21 --------- d-----w C:\Users\Roque\AppData\Roaming\Malwarebytes
2008-06-23 04:21 --------- d-----w C:\ProgramData\Malwarebytes
2008-06-23 04:21 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-06-22 22:00 --------- d-----w C:\Program Files\Norton Security Scan
2008-06-22 03:33 --------- d-----w C:\Program Files\CCleaner
2008-06-22 02:53 --------- d-----w C:\Program Files\Trend Micro
2008-06-20 04:27 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-06-20 03:56 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-19 21:48 34,296 ----a-w C:\Windows\system32\drivers\mbamcatchme.sys
2008-06-19 21:47 17,144 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-06-12 04:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-06-11 09:19 --------- d-----w C:\Program Files\Windows Mail
2008-06-06 06:37 --------- d-----w C:\Users\Roque\AppData\Roaming\Winamp
2008-06-04 22:18 --------- d-----w C:\ProgramData\Symantec
2008-06-03 22:50 --------- d-----w C:\Program Files\Winamp
2008-06-03 05:52 --------- d-----w C:\Program Files\ESET
2008-06-03 03:10 --------- d-----w C:\ProgramData\Kaspersky Lab Setup Files
2008-06-01 06:05 --------- d-----w C:\Users\Roque\AppData\Roaming\InterVideo
2008-05-14 03:39 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-14 02:35 --------- d-----w C:\Program Files\Google
2008-05-10 03:30 14,848 ----a-w C:\Windows\System32\wshrm.dll
2008-05-10 01:21 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys
2008-05-04 21:55 --------- d--h--w C:\ProgramData\CanonBJ
2008-05-03 22:10 --------- d-----w C:\ProgramData\FLEXnet
2008-04-28 12:41 --------- d-----w C:\Program Files\Windows Live
2008-04-28 12:32 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-28 12:31 --------- d-----w C:\ProgramData\WLInstaller
2008-04-28 02:39 --------- d-----w C:\Program Files\Windows Sidebar
2008-04-27 23:55 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-04-27 23:55 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-04-27 23:54 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys
2008-04-27 23:54 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
2008-04-27 23:54 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-04-27 23:52 2,027,008 ----a-w C:\Windows\System32\win32k.sys
2008-04-27 23:50 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-04-27 23:48 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2008-04-27 23:48 83,968 ----a-w C:\Windows\System32\dnsrslvr.dll
2008-04-27 23:48 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2008-04-27 23:48 24,576 ----a-w C:\Windows\System32\dnscacheugc.exe
2008-04-27 23:48 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
2008-04-27 23:48 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
2008-04-27 23:46 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-04-27 23:28 --------- d-----w C:\Program Files\MSN Messenger
2008-04-27 05:25 53,080 ----a-w C:\Windows\System32\wuauclt.exe
2008-04-27 05:25 43,352 ----a-w C:\Windows\System32\wups2.dll
2008-04-27 05:25 1,712,984 ----a-w C:\Windows\System32\wuaueng.dll
2008-04-27 05:25 1,524,224 ----a-w C:\Windows\System32\wucltux.dll
2008-04-27 05:24 80,896 ----a-w C:\Windows\System32\wudriver.dll
2008-04-27 05:24 549,720 ----a-w C:\Windows\System32\wuapi.dll
2008-04-27 05:24 33,624 ----a-w C:\Windows\System32\wups.dll
2008-04-27 05:24 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-04-27 05:24 163,000 ----a-w C:\Windows\System32\wuwebv.dll
2008-04-26 08:02 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-04-25 04:23 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-04-25 04:23 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-04-25 04:23 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-04-25 04:22 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-04-23 04:27 428,032 ----a-w C:\Windows\System32\EncDec.dll
2008-04-23 04:27 292,352 ----a-w C:\Windows\System32\psisdecd.dll
2008-04-23 04:27 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-28 20:24 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Cargando Puntos Reg ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* entradas vacías & entradas legítimas predeterminadas no son mostradas
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-04-27 19:50 1232896]
"NSUFloatingUI"="C:\Program Files\Sony\Network Utility\LANUtil.exe" [2007-11-26 12:50 253952]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 08:35 125440]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"Uniblue RegistryBooster 2"="c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe" [2008-05-05 12:22 99608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-08-24 20:06 4669440 C:\Windows\RtHDVCpl.exe]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-09-19 20:06 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-09-19 20:03 154136]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-09-19 20:04 137752]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2007-06-09 20:12 118784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 05:06 40048]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2007-09-19 13:09 311296]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-11-28 18:12 77824]
"VAIOSurvey"="C:\Program Files\Sony\VAIO Survey\Vista VAIO Survey.exe" [2007-07-20 17:30 577536]
"Unattend0000000001{CD700DA0-8EC6-402F-9CAC-00EB11D240B2}"="C:\Program Files\Sony\First Experience\VAIOWelcome.exe" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2008-04-26 16:39 6731312]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-29 14:54 1443072]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2007-08-14 22:05 98304 C:\Windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{EFE3E742-676E-4D9F-BA24-A567FB1690DD}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{12566EA0-DAC6-4172-827A-045A85C82A49}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{DA25080F-53E9-47CB-8610-7B868FFAA15F}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{A1F2505B-B9E6-4204-9731-CCEAD1E8D428}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{B9A7E2F6-529C-42C0-AD52-24E3495AA9BB}"= Disabled:UDP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{3BD35F8E-84E5-4B6D-8379-56F8D66C044F}"= Disabled:TCP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{9F62E6EC-B31F-4D93-9F15-315A94CB4F84}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R1 epfwtdir;epfwtdir;C:\Windows\system32\DRIVERS\epfwtdir.sys [2008-02-29 14:56]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 02:45]
R2 NSUService;NSUService;"C:\Program Files\Sony\Network Utility\NSUService.exe" [2007-11-26 12:50]
R2 regi;regi;C:\Windows\system32\drivers\regi.sys [2007-04-17 22:09]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-09-19 20:04]
R3 SFEP;Sony Firmware Extension Parser;C:\Windows\system32\DRIVERS\SFEP.sys [2007-08-28 21:58]
R3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2007-06-05 20:00]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-09-19 20:16]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-10 18:51]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);"C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-UCLS-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\UCLS\HTTP" []
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-06-20 17:34]
S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;"C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe" [2007-09-28 23:11]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;"C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe" [2007-09-20 20:52]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eae7cb5c-0982-11dd-9154-001a80b7becb}]
\shell\AutoRun\command - G:\AutoTransfer.exe
*Newly Created Service* - CATCHME
.
Contenido de carpeta 'Tareas Programadas'
"2008-06-22 22:00:15 C:\Windows\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-25 16:03:09
Windows 6.0.6000 NTFS
escaneando procesos ocultos ...
escaneando entradas ocultas de autostart ...
escaneando archivos ocultos ...
el escaneo se completo con exito
archivos ocultos: 0
**************************************************************************
.
Tiempo completado: 2008-06-25 16:04:00
ComboFix-quarantined-files.txt 2008-06-25 20:03:56
El sistema no puede encontrar el texto del mensaje para el mensaje número 0x2379 en el archivo de mensajes para Application.
El sistema no puede encontrar el texto del mensaje para el mensaje número 0x2379 en el archivo de mensajes para Application.
165 --- E O F --- 2008-06-15 05:48:12