ComboFix 08-02.01.5 - ines 2008-02-01 13:55:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.322 [GMT 1:00]
Running from: C:\Documents and Settings\ines\Local Settings\Temporary Internet Hola, buenas tardes. Este es el resultado que me dió el log txt del combofix:
Files\Content.IE5\W5WXSNQB\ComboFix[1].exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible infected sites -----
hxxp://au.download.windowsupdate.com
hxxp://au.download.windowsupdateõj+|Cü¤Ì›v÷+È@™JŸ:®½‰NêGD_©½ºD˜QÄ{¶ÀzÎtçÒ»ÌHžG†.XóƵÌäùA¹O˜ÁEÁþWU Client Download S-1-5-18`€HT4?? 6ÚVwoQZC¬¬D¢HÿóMXC:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\mainwwsp1.cab„
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.
2008-01-30 22:00 . 2004-08-10 03:43 7,093,760 --a------ C:\WINDOWS\system32\space.scr
2008-01-30 22:00 . 2004-08-10 03:43 5,068,800 --a------ C:\WINDOWS\system32\davinci.scr
2008-01-30 22:00 . 2004-08-10 03:43 4,396,544 --a------ C:\WINDOWS\system32\wpgldfsh.scr
2008-01-30 22:00 . 2004-08-10 03:43 3,343,360 --a------ C:\WINDOWS\system32\nature.scr
2008-01-30 22:00 . 2004-08-10 03:43 1,742,336 --a------ C:\WINDOWS\system32\mypixdx.scr
2008-01-30 22:00 . 2004-04-22 02:07 11,452 --a------ C:\WINDOWS\system32\mypixdx.chm
2008-01-30 21:32 . 2008-01-30 21:32 <DIR> d-------- C:\Documents and Settings\ines\Application Data\Grisoft
2008-01-30 21:32 . 2008-01-30 21:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-30 21:32 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-30 21:06 . 2008-01-30 21:07 <DIR> d-------- C:\Program Files\CCleaner
2008-01-30 11:08 . 2008-01-30 11:08 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-01-30 01:38 . 2008-01-30 01:38 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-28 19:21 . 2008-01-29 12:29 <DIR> d-------- C:\Documents and Settings\ines\Application Data\SUPERAntiSpyware.com
2008-01-28 19:21 . 2008-01-28 19:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-25 23:03 . 2008-01-25 23:04 <DIR> d-------- C:\Program Files\Lexmark 1200 Series
2008-01-25 19:30 . 2008-01-25 19:31 <DIR> d-------- C:\Program Files\WinZip Self-Extractor
2008-01-25 14:34 . 2008-01-25 14:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Winferno
2008-01-25 11:08 . 2008-01-25 11:08 0 --a------ C:\VDME40.tmp
2008-01-25 11:08 . 2008-01-25 11:08 0 --a------ C:\VDME3F.tmp
2008-01-21 22:57 . 2008-01-24 14:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-20 18:02 . 2008-01-20 18:02 <DIR> d-------- C:\Documents and Settings\ines\Application Data\Anonymizer
2008-01-20 17:29 . 2008-01-20 17:29 <DIR> d-------- C:\Program Files\Anonymizer
2008-01-20 17:29 . 2008-01-20 17:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Anonymizer
2008-01-20 16:56 . 2008-01-20 17:30 <DIR> d--h----- C:\Documents and Settings\All Users\Application Data\{9E97B640-FCFE-4900-B18A-72FAE662D6B7}
2008-01-19 21:49 . 2008-02-01 10:46 4,194,354 --a------ C:\WINDOWS\pfirewall.log.old
2008-01-17 21:34 . 2008-01-17 21:34 <DIR> d-------- C:\Program Files\Calendario Menstrual
2008-01-17 21:34 . 2000-07-08 14:06 87,040 --a------ C:\WINDOWS\UnGins.exe
2008-01-17 20:52 . 2008-01-17 20:53 <DIR> d-------- C:\COCINA
2008-01-16 23:33 . 2008-01-16 23:33 <DIR> d-------- C:\Program Files\GoldEsel
2008-01-16 23:33 . 2008-01-16 23:33 <DIR> d-------- C:\Program Files\Ahead
2008-01-16 23:33 . 2008-01-16 23:33 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BVRP Software
2008-01-14 23:04 . 2008-01-14 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2008-01-13 14:28 . 2008-01-13 14:28 0 --a--c--- C:\WINDOWS\nsreg.dat
2008-01-10 11:55 . 2005-11-10 12:03 49,265 --a------ C:\WINDOWS\system32\jpicpl32.cpl
2008-01-10 11:36 . 2008-01-10 11:38 <DIR> d-------- C:\Documents and Settings\ines\Application Data\Windows Live Writer
2008-01-08 22:50 . 2008-01-23 20:27 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-01-08 22:47 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-01-08 22:46 . 2008-01-08 22:46 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-01-08 20:02 . 2008-01-08 22:41 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-05 01:11 . 2008-01-05 01:11 <DIR> d-------- C:\Program Files\Vimicro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-31 20:46 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-01-31 17:58 --------- d-----w C:\Program Files\eMule
2008-01-30 20:30 --------- d-----w C:\Program Files\Yahoo!
2008-01-29 10:37 --------- d-----w C:\Program Files\MSN Messenger
2008-01-27 11:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-25 18:07 56,946 ----a-w C:\WINDOWS\Fonts\a ver dónde esta´s.zip
2008-01-25 17:28 7,488 ----a-w C:\WINDOWS\Fonts\letras capitales..zip
2008-01-25 13:22 46,050 ----a-w C:\WINDOWS\Fonts\wet_paint.zip
2008-01-25 13:20 111,084 ----a-w C:\WINDOWS\Fonts\alpha_bizzy_bee.zip
2008-01-25 13:19 110,496 ----a-w C:\WINDOWS\Fonts\catsalphabet.zip
2008-01-25 13:18 45,013 ----a-w C:\WINDOWS\Fonts\accent_cookie_dough.zip
2008-01-25 13:18 27,112 ----a-w C:\WINDOWS\Fonts\ennobled_pet.zip
2008-01-25 13:14 218,746 ----a-w C:\WINDOWS\Fonts\porcelain.zip
2008-01-25 13:13 122,962 ----a-w C:\WINDOWS\Fonts\the_king_queen_font.zip
2008-01-25 13:12 20,014 ----a-w C:\WINDOWS\Fonts\white_christmas.zip
2008-01-25 13:11 38,475 ----a-w C:\WINDOWS\Fonts\san_remo.zip
2008-01-25 13:10 84,811 ----a-w C:\WINDOWS\Fonts\devinne_swash.zip
2008-01-25 13:04 51,389 ----a-w C:\WINDOWS\Fonts\toy_train.zip
2008-01-25 13:03 31,648 ----a-w C:\WINDOWS\Fonts\inkburrow.zip
2008-01-25 13:02 99,899 ----a-w C:\WINDOWS\Fonts\kg_abcs_dingbats.zip
2008-01-25 13:01 304,605 ----a-w C:\WINDOWS\Fonts\textbook_math.zip
2008-01-25 13:01 22,349 ----a-w C:\WINDOWS\Fonts\rainies_kids.zip
2008-01-25 13:01 142,264 ----a-w C:\WINDOWS\Fonts\crayola_kiddy_font.zip
2008-01-25 13:00 124,953 ----a-w C:\WINDOWS\Fonts\baby.zip
2008-01-25 12:51 37,575 ----a-w C:\WINDOWS\Fonts\tourist_trap.zip
2008-01-25 12:50 392,889 ----a-w C:\WINDOWS\Fonts\mckloud.zip
2008-01-25 12:50 28,287 ----a-w C:\WINDOWS\Fonts\army_beans.zip
2008-01-25 12:49 39,945 ----a-w C:\WINDOWS\Fonts\brown_bear_funk.zip
2008-01-25 12:49 34,752 ----a-w C:\WINDOWS\Fonts\ji_balloon_caps.zip
2008-01-25 12:47 35,660 ----a-w C:\WINDOWS\Fonts\mickey.zip
2008-01-25 12:47 273,082 ----a-w C:\WINDOWS\Fonts\picto_glyphs.zip
2008-01-25 12:46 66,507 ----a-w C:\WINDOWS\Fonts\veneto.zip
2008-01-25 12:46 33,932 ----a-w C:\WINDOWS\Fonts\jugend_wf.zip
2008-01-25 12:45 84,401 ----a-w C:\WINDOWS\Fonts\alpha_clouds.zip
2008-01-25 12:44 60,224 ----a-w C:\WINDOWS\Fonts\caricature.zip
2008-01-25 12:44 27,106 ----a-w C:\WINDOWS\Fonts\floralies.zip
2008-01-25 12:43 43,269 ----a-w C:\WINDOWS\Fonts\moon_star.zip
2008-01-25 12:43 316,220 ----a-w C:\WINDOWS\Fonts\abusive_pencil.zip
2008-01-25 12:38 32,092 ----a-w C:\WINDOWS\Fonts\fuente8.zip
2008-01-23 19:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-01-19 22:11 --------- d-----w C:\Documents and Settings\ines\Application Data\Skype
2008-01-14 18:41 --------- d-----w C:\Program Files\ALCATEL PC Suite
2008-01-10 14:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 10:55 --------- d-----w C:\Program Files\Java
2008-01-10 10:42 --------- d-----w C:\Program Files\Windows Live
2008-01-08 21:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-02 08:58 --------- d-----w C:\Program Files\CyberLink
2008-01-02 08:58 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-30 20:01 --------- d-----w C:\Documents and Settings\ines\Application Data\SoundSpectrum
2007-12-07 13:30 --------- d-----w C:\Documents and Settings\ines\Application Data\Ahead
2007-10-13 21:27 88 --sh--r C:\WINDOWS\system32\
06D8FEF5C5.sys
2007-10-13 20:04 56 --sh--r C:\WINDOWS\system32\C5F5FED806.sys
2006-08-25 15:45 617,472 --sha-w C:\WINDOWS\system32\comctl32.dll
2004-08-10 20:00 1,028,096 --sha-w C:\WINDOWS\system32\mfc42.dll
2004-08-10 20:00 413,696 --sha-w C:\WINDOWS\system32\msvcp60.dll
2004-08-10 20:00 343,040 --sha-w C:\WINDOWS\system32\msvcrt.dll
2004-08-10 20:00 253,952 --sha-w C:\WINDOWS\system32\msvcrt20.dll
2004-08-10 20:00 30,749 --sha-w C:\WINDOWS\system32\vbajet32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 16:25 94208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-16 19:54 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-10-21 17:31 778240]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 21:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 21:00 44032]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 13:40 413696]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2006-03-17 14:00 345088]
"Acer Empowering Technology Monitor"="C:\WINDOWS\system32\SysMonitor.exe" [2006-04-18 18:54 49152]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 05:03 221184]
"ZSMCSnap211"="C:\WINDOWS\ZSMCSnap211.exe" [2006-07-14 16:24 49152]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-09 10:11 286720]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 21:00 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-10 21:00 53760 C:\WINDOWS\system32\narrator.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
R2 AnonAswSvc;Anonymizer Anti-Spyware Service;"C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe" [2007-10-22 10:12]
R2 AnonMgmtSvc;Anonymizer Management Service;"C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe" [2007-10-22 10:12]
R3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 13:46]
R3 psdfilter;psdfilter;C:\WINDOWS\system32\Drivers\psdfilter.sys [2006-04-07 19:17]
R3 psdvdisk;psdvdisk;C:\WINDOWS\system32\Drivers\psdvdisk.sys [2006-03-08 16:10]
R3 ZSMC211;USB PC Camera (ZS211);C:\WINDOWS\system32\Drivers\ZSMC211.sys [2006-07-25 11:47]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 10:38]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-30 00:50:13 C:\WINDOWS\Tasks\rpc.job"
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-01 14:00:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe [5.01.2600.2180]
-> C:\WINDOWS\system32\imon.dll
-> C:\Program Files\Eset\pr_imon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Eset\nod32kui.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\WINDOWS\system32\SysMonitor.exe
C:\WINDOWS\ZSMCSnap211.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-02-01 14:04:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-01 13:04:14
.
2008-01-26 13:42:55 --- E O F ---
Por cierto, pasé el elistara otra vez, eliminando automáticamente esta vez todo lo que encontraba. Así con todo, las páginas siguen tardando una barbaridad en entrar, y muchas de ellas ni lo hacen( no sé si la mayoría, o casi). Lo de ver las imágenes,fotos... tampoco. La página la encuentra, pone "listo" en la barra de herramientas inferior, y está en blanco.
Tras pasar el combofix, he vuelto a dar otro paseo por el hijackthis y el log que ha dado es éste, por si le resulta útil:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:14:19, on 01/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Eset\nod32kui.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\WINDOWS\system32\SysMonitor.exe
C:\WINDOWS\ZSMCSnap211.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\Notepad.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.es/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Aplicación auxiliar de vínculos de Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 1
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ZSMCSnap211] C:\WINDOWS\ZSMCSnap211.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Upload - {FD4E2FF8-973C-4A19-89BD-8E86B3CFCFE1} - C:\WINDOWS\system32\shdocvw.dll
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=58813O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
http://downloads.ewido.net/ewidoOnlineScan.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload.adobe.com/pub/shockwave/...ash/swflash.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{0930DB48-E96C-4B2D-8FE6-CC49DFB460A2}: NameServer = 62.36.225.150,62.37.228.20
O17 - HKLM\System\CCS\Services\Tcpip\..\{6CB6AB23-2345-4F28-A5CE-2730948DD445}: NameServer = 62.36.225.150,62.37.228.20
O17 - HKLM\System\CS1\Services\Tcpip\..\{0930DB48-E96C-4B2D-8FE6-CC49DFB460A2}: NameServer = 62.36.225.150,62.37.228.20
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Anonymizer Anti-Spyware Service (AnonAswSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\AnonASW\AnonAswSvc.exe
O23 - Service: Anonymizer Management Service (AnonMgmtSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
--
End of file - 8322 bytes
Muchas gracias por todo.