Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.2039.1491 [GMT -5:
00]
Running from: c:\documents and settings\INTERNET III MARIAS\Escritorio\ComboFix.
exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
------- Sigcheck ------Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-14 . 9F3A2F5AA6875C72BF062C712CFA2674 .
. c:\windows\ServicePackFiles\i386\atapi.sys
[-] 2008-04-14 . 9F3A2F5AA6875C72BF062C712CFA2674 .
. c:\windows\system32\drivers\atapi.sys
[-] 2006-03-02 . CDFE4411A69C224BD1D11B2DA92DAC51 .
. c:\windows\$NtServicePackUninstall$\atapi.sys
.
[-] 2008-04-14 . B153AFFAC761E7F5FCFA822B9C4E97BC .
. c:\windows\ServicePackFiles\i386\asyncmac.sys
[-] 2008-04-14 . B153AFFAC761E7F5FCFA822B9C4E97BC .
. c:\windows\system32\drivers\asyncmac.sys
[-] 2006-03-02 . 02000ABF34AF4C218C35D257024807D6 .
. c:\windows\$NtServicePackUninstall$\asyncmac.sys
.
[-] 2012-01-15 . DA1F27D85E0D1525F6621372E7B685E9 .
\windows\system32\dllcache\beep.sys
[-] 2012-01-15 . DA1F27D85E0D1525F6621372E7B685E9 .
\windows\system32\drivers\beep.sys
.
[-] 2008-04-14 . 188DDD286BC0DAEA6984858C6A4D7BBF .
. c:\windows\ServicePackFiles\i386\kbdclass.sys
[-] 2008-04-14 . 188DDD286BC0DAEA6984858C6A4D7BBF .
. c:\windows\system32\drivers\kbdclass.sys
[-] 2006-03-02 . 71BFDDA7B3006B45B18D8BAC92BC9993 .
. c:\windows\$NtServicePackUninstall$\kbdclass.sys
.
[-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D .
. c:\windows\ServicePackFiles\i386\ndis.sys
[-] 2008-04-14 . 1DF7F42665C94B825322FAE71721130D .
. c:\windows\system32\drivers\ndis.sys
[-] 2006-03-02 . 558635D3AF1C7546D26067D5D9B6959E .
. c:\windows\$NtServicePackUninstall$\ndis.sys
.
[-] 2008-04-14 . 78A08DD6A8D65E697C18E1DB01C5CDCA .
. c:\windows\ServicePackFiles\i386\ntfs.sys
[-] 2008-04-14 . 78A08DD6A8D65E697C18E1DB01C5CDCA .
. c:\windows\system32\drivers\ntfs.sys
[-] 2006-03-02 . B78BE402C3F63DD55521F73876951CDD .
. c:\windows\$NtServicePackUninstall$\ntfs.sys
.
[-] 2006-03-02 . 73C1E1F395918BC2C6DD67AF7591A3AD .
\windows\system32\dllcache\null.sys
[-] 2006-03-02 . 73C1E1F395918BC2C6DD67AF7591A3AD .
\windows\system32\drivers\null.sys
.
[-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E .
. c:\windows\$hf_mig$\KB2509553\SP3QFE\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D .
. c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D .
96512 . . [5.1.2600.5512] .
96512 . . [5.1.2600.5512] .
95360 . . [5.1.2600.2180] .
14336 . . [5.1.2600.5512] .
14336 . . [5.1.2600.5512] .
14336 . . [5.1.2600.2180] .
4224 . . [5.1.2600.0] . . c:
4224 . . [5.1.2600.0] . . c:
25088 . . [5.1.2600.5512] .
25088 . . [5.1.2600.5512] .
25088 . . [5.1.2600.2180] .
182656 . . [5.1.2600.5512] .
182656 . . [5.1.2600.5512] .
182912 . . [5.1.2600.2180] .
574976 . . [5.1.2600.5512] .
574976 . . [5.1.2600.5512] .
574592 . . [5.1.2600.2180] .
2944 . . [5.1.2600.0] . . c:
2944 . . [5.1.2600.0] . . c:
361600 . . [5.1.2600.5625] .
361600 . . [5.1.2600.5625] .
361600 . . [5.1.2600.5625] .
. c:\windows\system32\drivers\tcpip.sys
[-] 2008-04-14 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] .
. c:\windows\$NtUninstallKB2509553$\tcpip.sys
[-] 2008-04-14 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2006-03-02 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\tcpip.sys
.
[-] 2012-07-06 . DCA0E43CB14D2390FAA5A21B9DC92274 . 78336 . . [5.1.2600.6260] .
. c:\windows\system32\browser.dll
[-] 2012-07-06 . DCA0E43CB14D2390FAA5A21B9DC92274 . 78336 . . [5.1.2600.6260] .
. c:\windows\system32\dllcache\browser.dll
[-] 2012-07-06 . 88F61096EDAF97F86128ED9007802709 . 78336 . . [5.1.2600.6260] .
. c:\windows\$hf_mig$\KB2705219-v2\SP3QFE\browser.dll
[-] 2008-04-14 . E28818BD591F8AF8FBE9897472B9665E . 77824 . . [5.1.2600.5512] .
. c:\windows\$NtUninstallKB2705219-v2$\browser.dll
[-] 2008-04-14 . E28818BD591F8AF8FBE9897472B9665E . 77824 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\browser.dll
[-] 2006-03-02 . D01CFCC753B09E70F5B7622501FF5383 . 77312 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\browser.dll
.
[-] 2008-04-14 . 671ACA589DA3733FAC878A751C5BF0ED . 13312 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\lsass.exe
[-] 2008-04-14 . 671ACA589DA3733FAC878A751C5BF0ED . 13312 . . [5.1.2600.5512] .
. c:\windows\system32\lsass.exe
[-] 2006-03-02 . 2B0B88652C9F6714FD4886839B3B0442 . 13312 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\lsass.exe
.
[-] 2008-04-14 . A48884C9359EE9F1FC8F3F0D93FB1D95 . 198144 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\netman.dll
[-] 2008-04-14 . A48884C9359EE9F1FC8F3F0D93FB1D95 . 198144 . . [5.1.2600.5512] .
. c:\windows\system32\netman.dll
[-] 2006-03-02 . 25128473F0D3FD431F74CC5BAFA123CA . 198144 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\netman.dll
.
[-] 2008-04-14 12:48 . 93F4E612C695E81512110956454E6E25 . 837120 . . [2001.12.44
14.700] . . c:\windows\ServicePackFiles\i386\comres.dll
[-] 2008-04-14 12:48 . 93F4E612C695E81512110956454E6E25 . 837120 . . [2001.12.44
14.700] . . c:\windows\system32\comres.dll
[-] 2006-03-02 10:00 . DECF5947EF11B06D716E08D0B86FC62A . 837120 . . [2001.12.44
14.258] . . c:\windows\$NtServicePackUninstall$\comres.dll
.
[-] 2008-04-14 . 8EE9639C01B92490E09638CAA1B16C3C . 409088 . . [6.7.2600.5512] .
. c:\windows\ServicePackFiles\i386\qmgr.dll
[-] 2008-04-14 . 8EE9639C01B92490E09638CAA1B16C3C . 409088 . . [6.7.2600.5512] .
. c:\windows\system32\qmgr.dll
[-] 2008-04-14 . 8EE9639C01B92490E09638CAA1B16C3C . 409088 . . [6.7.2600.5512] .
. c:\windows\system32\bits\qmgr.dll
[-] 2006-03-02 . 02451268DC47E4DC228210DA0E3C3274 . 382464 . . [6.6.2600.2180] .
. c:\windows\$NtServicePackUninstall$\qmgr.dll
.
[-] 2009-02-09 . AEF41FC6F108CC4F94F9B4E96AFA9C70 . 401408 . . [5.1.2600.5755] .
. c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
[-] 2009-02-09 . 97869C55F562B777987100EA30AD8108 . 401408 . . [5.1.2600.5755] .
. c:\windows\system32\rpcss.dll
[-] 2009-02-09 . 97869C55F562B777987100EA30AD8108 . 401408 . . [5.1.2600.5755] .
. c:\windows\system32\dllcache\rpcss.dll
[-] 2008-04-14 . 53D02EFFA72CA5C57687BEE20610ABA6 . 399360 . . [5.1.2600.5512] .
. c:\windows\$NtUninstallKB956572$\rpcss.dll
[-] 2008-04-14 . 53D02EFFA72CA5C57687BEE20610ABA6 . 399360 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\rpcss.dll
[-] 2006-03-02 . 86945706EBF0460631917E967BAB3CC4 . 395776 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\rpcss.dll
.
[-] 2009-02-09 . 953DF7327510DF0DE048B8E80E504EF9 . 111104 . . [5.1.2600.5755] .
. c:\windows\system32\services.exe
[-] 2009-02-09 . 953DF7327510DF0DE048B8E80E504EF9 . 111104 . . [5.1.2600.5755] .
. c:\windows\system32\dllcache\services.exe
[-] 2009-02-09 . AA6E1769469F9D15603A619FC1FB9E18 . 111104 . . [5.1.2600.5755] .
. c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
[-] 2008-04-14 . D658A8C2FC7B2AD53D1259741A09EE04 . 109056 . . [5.1.2600.5512] .
. c:\windows\$NtUninstallKB956572$\services.exe
[-] 2008-04-14 . D658A8C2FC7B2AD53D1259741A09EE04 . 109056 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\services.exe
[-] 2006-03-02 . F9852F505E0699BB83D5C6321917040B . 108544 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\services.exe
.
[-] 2010-08-17 . 258DD5D4283FD9F9A7166BE9AE45CE73 . 58880 . . [5.1.2600.6024] .
. c:\windows\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[-] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] .
. c:\windows\system32\spoolsv.exe
[-] 2010-08-17 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024] .
. c:\windows\system32\dllcache\spoolsv.exe
[-] 2008-04-14 . CDD2DC6AE65084481E723E746C20539A . 57856 . . [5.1.2600.5512] .
. c:\windows\$NtUninstallKB2347290$\spoolsv.exe
[-] 2008-04-14 . CDD2DC6AE65084481E723E746C20539A . 57856 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\spoolsv.exe
[-] 2006-03-02 . 1CF5AF263287CF6FEBF31539833EAF4A . 57856 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\spoolsv.exe
.
[-] 2008-04-14 . 213C80D912880BBF04453D09FFCCB28C . 510976 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\winlogon.exe
[-] 2008-04-14 . 213C80D912880BBF04453D09FFCCB28C . 510976 . . [5.1.2600.5512] .
. c:\windows\system32\winlogon.exe
[-] 2006-03-02 . FCB59D25D628B4D3181DC816D14679DD . 505344 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\winlogon.exe
.
[-] 2008-04-14 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\ipsec.sys
[-] 2008-04-14 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] .
. c:\windows\system32\drivers\ipsec.sys
[-] 2006-03-02 . 64537AA5C003A6AFEEE1DF819062D0D1 . 74752 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\ipsec.sys
.
[-] 2010-08-23 . 3DDEC846E57F668C07407F3AC3B66220 . 617472 . . [5.82] . . c:\win
dows\system32\comctl32.dll
[-] 2010-08-23 . 3DDEC846E57F668C07407F3AC3B66220 . 617472 . . [5.82] . . c:\win
dows\system32\dllcache\comctl32.dll
[-] 2010-08-23 . 24B09ED0C5B019A5198A74504179EEB0 . 1054208 . . [6.0] . . c:\win
dows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028
_x-ww_61e65202\comctl32.dll
[-] 2008-04-14 . 618A4C7A7C0CA86DA884C8C0FACAD8C2 . 617472 . . [5.82] . . c:\win
dows\$NtUninstallKB2296011$\comctl32.dll
[-] 2008-04-14 . 618A4C7A7C0CA86DA884C8C0FACAD8C2 . 617472 . . [5.82] . . c:\win
dows\ServicePackFiles\i386\comctl32.dll
[-] 2008-04-14 . 08D17A982CD6191B34D1B8C8A2E694B6 . 1054208 . . [6.0] . . c:\win
dows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512
_x-ww_35d4ce83\comctl32.dll
[-] 2006-03-02 . EDA7A1054484AF5DD29A648081E93107 . 611328 . . [5.82] . . c:\win
dows\$NtServicePackUninstall$\comctl32.dll
. . c:\windows\ie8\wininet.dll
[-] 2008-04-14 . A9A84CFC20D5F4C609E9CBF9491B8DF6 . 668672 . . [6.00.2900.5512]
. . c:\windows\ServicePackFiles\i386\wininet.dll
[-] 2006-03-02 . 80BB109560A23B9C18427855CA5305E6 . 658944 . . [6.00.2900.2180]
. . c:\windows\$NtServicePackUninstall$\wininet.dll
.
[-] 2008-04-14 . 22DB5B3DA7005C6472D35BEF3FFDA5EC . 82432 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\ws2_32.dll
[-] 2008-04-14 . 22DB5B3DA7005C6472D35BEF3FFDA5EC . 82432 . . [5.1.2600.5512] .
. c:\windows\system32\ws2_32.dll
[-] 2006-03-02 . B4A90738BA4355F187BD26D6C112082B . 82944 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\ws2_32.dll
.
[-] 2008-04-14 . F7EE4BBFB48437EDC6F7F061DE1E8F2F . 19968 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\ws2help.dll
[-] 2008-04-14 . F7EE4BBFB48437EDC6F7F061DE1E8F2F . 19968 . . [5.1.2600.5512] .
. c:\windows\system32\ws2help.dll
[-] 2006-03-02 . 0EDF3501370A14BEFB27526CD06FACEE . 19968 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\ws2help.dll
.
[-] 2008-04-14 . 7522F548A84ABAD8FA516DE5AB3931EF . 1036288 . . [6.00.2900.5512]
. . c:\windows\explorer.exe
[-] 2008-04-14 . 7522F548A84ABAD8FA516DE5AB3931EF . 1036288 . . [6.00.2900.5512]
. . c:\windows\ServicePackFiles\i386\explorer.exe
[-] 2006-03-02 . 89C8DD146CEAF482D82822766437D93F . 1034752 . . [6.00.2900.2180]
. . c:\windows\$NtServicePackUninstall$\explorer.exe
.
[-] 2008-04-14 . F4B9F9AA2F72FAD20D09C3E3FF2BE224 . 152064 . . [5.1.2600.5512] .
. c:\windows\regedit.exe
[-] 2008-04-14 . F4B9F9AA2F72FAD20D09C3E3FF2BE224 . 152064 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\regedit.exe
[-] 2006-03-02 . 2BA8F4A46C83C6D3A02E9073A304F82C . 152064 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\regedit.exe
.
[-] 2011-11-01 . 494276CFE71555AE0F3234C1B227E67A . 1288192 . . [5.1.2600.6168]
. . c:\windows\system32\ole32.dll
[-] 2011-11-01 . 494276CFE71555AE0F3234C1B227E67A . 1288192 . . [5.1.2600.6168]
. . c:\windows\system32\dllcache\ole32.dll
[-] 2011-11-01 . E8C2FA9AC16C25C0AB0677BA12D74BC1 . 1288704 . . [5.1.2600.6168]
. . c:\windows\$hf_mig$\KB2624667\SP3QFE\ole32.dll
[-] 2010-07-16 . 448FE53C1B2671DB712C8E8838E4263F . 1287680 . . [5.1.2600.6010]
. . c:\windows\$NtUninstallKB2624667$\ole32.dll
[-] 2010-07-16 . BCFEA258277FB42DD7F447EB61C34D06 . 1288704 . . [5.1.2600.6010]
. . c:\windows\$hf_mig$\KB979687\SP3QFE\ole32.dll
[-] 2008-04-14 . 463D57BF9FE5871208FF99399360A57D . 1287168 . . [5.1.2600.5512]
. . c:\windows\$NtUninstallKB979687$\ole32.dll
[-] 2008-04-14 . 463D57BF9FE5871208FF99399360A57D . 1287168 . . [5.1.2600.5512]
. . c:\windows\ServicePackFiles\i386\ole32.dll
[-] 2006-03-02 . 4284D0170197D37F0D37F55B89B3FDB7 . 1281024 . . [5.1.2600.2180]
. . c:\windows\$NtServicePackUninstall$\ole32.dll
.
[-] 2010-04-16 . A8374FF31AC6EDEBB806D2B61D44618D . 406016 . . [1.0420.2600.5969
] . . c:\windows\system32\usp10.dll
[-] 2010-04-16 . A8374FF31AC6EDEBB806D2B61D44618D . 406016 . . [1.0420.2600.5969
] . . c:\windows\system32\dllcache\usp10.dll
[-] 2010-04-16 . 964D29711065A944E1BEC7FD676E61D9 . 406016 . . [1.0420.2600.5969
] . . c:\windows\$hf_mig$\KB981322\SP3QFE\usp10.dll
[-] 2008-04-14 . D2ABEB6AF76DA414D1FFF8B409F00635 . 406016 . . [1.0420.2600.5512
] . . c:\windows\$NtUninstallKB981322$\usp10.dll
[-] 2008-04-14 . D2ABEB6AF76DA414D1FFF8B409F00635 . 406016 . . [1.0420.2600.5512
] . . c:\windows\ServicePackFiles\i386\usp10.dll
[-] 2006-03-02 . 0405987EE320AB0572E463C1E69C0121 .
] . . c:\windows\$NtServicePackUninstall$\usp10.dll
.
[-] 2008-04-14 . D9A84134776399F6BD244BC456076575 .
c:\windows\ServicePackFiles\i386\ksuser.dll
[-] 2008-04-14 . D9A84134776399F6BD244BC456076575 .
c:\windows\system32\ksuser.dll
[-] 2008-04-14 . D9A84134776399F6BD244BC456076575 .
c:\windows\system32\dllcache\ksuser.dll
.
[-] 2008-04-14 . DAAE1CB1B1875B760496E7D3336DA1AD .
. c:\windows\ServicePackFiles\i386\ctfmon.exe
[-] 2008-04-14 . DAAE1CB1B1875B760496E7D3336DA1AD .
. c:\windows\system32\ctfmon.exe
[-] 2006-03-02 . 25ECFA69AF1563FDE8DFD31F9954497A .
. c:\windows\$NtServicePackUninstall$\ctfmon.exe
.
[-] 2009-07-27 . 1F617C5A76215C380478D750CE92CC73 .
. . c:\windows\system32\shsvcs.dll
[-] 2009-07-27 . 1F617C5A76215C380478D750CE92CC73 .
. . c:\windows\system32\dllcache\shsvcs.dll
[-] 2009-07-27 . 8A34F9730A2206726B1BE4DC4209CAB9 .
. . c:\windows\$hf_mig$\KB971029\SP3QFE\shsvcs.dll
[-] 2008-04-14 . CA70EDBF32032EA53F114CB930741CB5 .
. . c:\windows\$NtUninstallKB971029$\shsvcs.dll
[-] 2008-04-14 . CA70EDBF32032EA53F114CB930741CB5 .
. . c:\windows\ServicePackFiles\i386\shsvcs.dll
[-] 2006-03-02 . DBCF824BA771A1F27E6F5124D0516358 .
. . c:\windows\$NtServicePackUninstall$\shsvcs.dll
.
[-] 2008-04-14 . B5D9EFEBE404A9A2C74EF27E1823A78B .
c:\windows\ServicePackFiles\i386\msimg32.dll
[-] 2008-04-14 . B5D9EFEBE404A9A2C74EF27E1823A78B .
c:\windows\system32\msimg32.dll
[-] 2006-03-02 . 954E6AAC31883B151A936793406D7A90 .
c:\windows\$NtServicePackUninstall$\msimg32.dll
.
[-] 2008-04-14 . 0F30EEC6013FCF76693405EC4A7DF899 .
. c:\windows\ServicePackFiles\i386\srsvc.dll
[-] 2008-04-14 . 0F30EEC6013FCF76693405EC4A7DF899 .
. c:\windows\system32\srsvc.dll
[-] 2006-03-02 . C791D16BF25264738B14873436293BD0 .
. c:\windows\$NtServicePackUninstall$\srsvc.dll
.
[-] 2008-04-14 . B2718EC9DC738E915D4177498E92BC4D .
. c:\windows\ServicePackFiles\i386\wscntfy.exe
[-] 2008-04-14 . B2718EC9DC738E915D4177498E92BC4D .
. c:\windows\system32\wscntfy.exe
[-] 2006-03-02 . 9C90A6DBE5D43E189F199172675D6312 .
. c:\windows\$NtServicePackUninstall$\wscntfy.exe
.
[-] 2008-04-14 . 14FDADCF05A37582399DAF1DA1DE1C7B .
. c:\windows\ServicePackFiles\i386\xmlprov.dll
[-] 2008-04-14 . 14FDADCF05A37582399DAF1DA1DE1C7B .
. c:\windows\system32\xmlprov.dll
[-] 2006-03-02 . 843E0DB8042A8C0D749EB2B9EFA54F24 .
. c:\windows\$NtServicePackUninstall$\xmlprov.dll
.
[-] 2010-12-09 . 48AADE1D5F48819A4C3978C09AAD1DC9 .
406528 . . [1.0420.2600.2180
4096 . . [5.3.2600.5512] . .
4096 . . [5.3.2600.5512] . .
4096 . . [5.3.2600.5512] . .
15360 . . [5.1.2600.5512] .
15360 . . [5.1.2600.5512] .
15360 . . [5.1.2600.2180] .
135168 . . [6.00.2900.5853]
135168 . . [6.00.2900.5853]
135168 . . [6.00.2900.5853]
135168 . . [6.00.2900.5512]
135168 . . [6.00.2900.5512]
134656 . . [6.00.2900.2180]
4608 . . [5.1.2600.5512] . .
4608 . . [5.1.2600.5512] . .
4608 . . [5.1.2600.2180] . .
171520 . . [5.1.2600.5512] .
171520 . . [5.1.2600.5512] .
171008 . . [5.1.2600.2180] .
13824 . . [5.1.2600.5512] .
13824 . . [5.1.2600.5512] .
13824 . . [5.1.2600.2180] .
129024 . . [5.1.2600.5512] .
129024 . . [5.1.2600.5512] .
129536 . . [5.1.2600.2180] .
742912 . . [5.1.2600.6055] .
. c:\windows\$hf_mig$\KB2393802\SP3QFE\ntdll.dll
[-] 2010-12-09 . 45B458684F0471C4F25A31A0BE4D2C70 . 742912 . . [5.1.2600.6055] .
. c:\windows\system32\ntdll.dll
[-] 2010-12-09 . 45B458684F0471C4F25A31A0BE4D2C70 . 742912 . . [5.1.2600.6055] .
. c:\windows\system32\dllcache\ntdll.dll
[-] 2009-02-09 . 6CBEC637D1B5A19A1C91F2B84E03CDE2 . 739840 . . [5.1.2600.5755] .
. c:\windows\$hf_mig$\KB956572\SP3QFE\ntdll.dll
[-] 2009-02-09 . D9B5602198F7DEE18B898298A52F684D . 739328 . . [5.1.2600.5755] .
. c:\windows\$NtUninstallKB2393802$\ntdll.dll
[-] 2008-04-14 . 91346D0D58E9FA1C75D8D0319F281745 . 730624 . . [5.1.2600.5512] .
. c:\windows\$NtUninstallKB956572$\ntdll.dll
[-] 2008-04-14 . 91346D0D58E9FA1C75D8D0319F281745 . 730624 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\ntdll.dll
[-] 2006-03-02 . 306B64DD1822BB33A7B54D203B8DB4C4 . 732672 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\ntdll.dll
.
[-] 2008-04-14 . DFE0E9229DD3C1441B93AAB15610B9B8 . 177152 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\msctfime.ime
[-] 2008-04-14 . DFE0E9229DD3C1441B93AAB15610B9B8 . 177152 . . [5.1.2600.5512] .
. c:\windows\system32\msctfime.ime
[-] 2006-03-02 . BFF509A62E57630555DAD0B7E0209573 . 177152 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\msctfime.ime
.
[-] 2008-04-14 . 2744C713F0217BD8FFD13E2EF731371C . 56320 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\eventlog.dll
[-] 2008-04-14 . 2744C713F0217BD8FFD13E2EF731371C . 56320 . . [5.1.2600.5512] .
. c:\windows\system32\eventlog.dll
[-] 2006-03-02 . 5696DF4EF09C375CE42FB2DDE1E68AB7 . 55808 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\eventlog.dll
.
[-] 2008-04-14 . 2A1E1DF559B291583903D2F9CC504522 . 1572352 . . [5.1.2600.5512]
. . c:\windows\ServicePackFiles\i386\sfcfiles.dll
[-] 2008-04-14 . 2A1E1DF559B291583903D2F9CC504522 . 1572352 . . [5.1.2600.5512]
. . c:\windows\system32\sfcfiles.dll
[-] 2006-03-02 . AAFD7382D64710AE3A6F1DEE5020CF19 . 1548800 . . [5.1.2600.2180]
. . c:\windows\$NtServicePackUninstall$\sfcfiles.dll
.
[-] 2008-04-14 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\ipsec.sys
[-] 2008-04-14 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512] .
. c:\windows\system32\drivers\ipsec.sys
[-] 2006-03-02 . 64537AA5C003A6AFEEE1DF819062D0D1 . 74752 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\ipsec.sys
.
[-] 2008-04-14 . E424F05B07AC4357DC08D06218D76C7C . 59904 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\regsvc.dll
[-] 2008-04-14 . E424F05B07AC4357DC08D06218D76C7C . 59904 . . [5.1.2600.5512] .
. c:\windows\system32\regsvc.dll
[-] 2006-03-02 . D025E953864EBEBAB5933086D15C4FC6 . 59904 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\regsvc.dll
.
[-] 2008-04-14 . 51BE25C404D3DD344C6079DE715E4977 . 193536 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\schedsvc.dll
[-] 2008-04-14 . 51BE25C404D3DD344C6079DE715E4977 . 193536 . . [5.1.2600.5512] .
. c:\windows\system32\schedsvc.dll
[-] 2006-03-02 . 0125649B3C00D037E07FD7BCEF7B653B . 192000 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\schedsvc.dll
.
[-] 2008-04-14 . B622A432EF02895DE4AA38AC8B85FA4C . 71680 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\ssdpsrv.dll
.
[-] 2008-04-14 . 047E70B04B288439245DDC8DD1A31982 . 33792 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\msgsvc.dll
[-] 2008-04-14 . 047E70B04B288439245DDC8DD1A31982 . 33792 . . [5.1.2600.5512] .
. c:\windows\system32\msgsvc.dll
[-] 2006-03-02 . CA33F6547C49E749E47FB6A0D1DBE192 . 33792 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\msgsvc.dll
.
[-] 2009-01-31 01:33 . 051B1BDECD6DEE18C771B5D5EC7F044D . 27136 . . [11.0.5721.5
262] . . c:\windows\system32\mspmsnsv.dll
[-] 2009-01-31 01:33 . 051B1BDECD6DEE18C771B5D5EC7F044D . 27136 . . [11.0.5721.5
262] . . c:\windows\system32\dllcache\mspmsnsv.dll
[-] 2008-04-14 12:48 . 57CF215B0250DE0C4AE36ABC8AE31BE4 . 52736 . . [9.0.1.56] .
. c:\windows\$NtUninstallWMFDist11$\mspmsnsv.dll
[-] 2006-03-02 10:00 . 7BB55C1143F8270467928AA843A48192 . 52736 . . [9.0.1.56] .
. c:\windows\$NtServicePackUninstall$\mspmsnsv.dll
.
[-] 2013-05-03 . 8DB7C6B7E5DC0D1E13B8D3585E3EB10C . 2072576 . . [5.1.2600.6387]
. . c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2013-05-03 . 8DB7C6B7E5DC0D1E13B8D3585E3EB10C . 2072576 . . [5.1.2600.6387]
. . c:\windows\system32\dllcache\ntkrnlpa.exe
[-] 2013-05-03 . DFF1DAA1E58ECC077DF20AF4D179F899 . 2031104 . . [5.1.2600.6387]
. . c:\windows\system32\ntkrnlpa.exe
[-] 2012-04-11 . 8D926910EA7E0419524C2A5CABFBA49D . 2029056 . . [5.1.2600.6206]
. . c:\windows\$NtUninstallKB2839229$\ntkrnlpa.exe
[-] 2012-04-11 . F3364F7432D706F7550FBA400DEC258E . 2071552 . . [5.1.2600.6206]
. . c:\windows\$hf_mig$\KB2676562\SP3QFE\ntkrnlpa.exe
[-] 2010-12-10 . 9F35605BC629F27AA34423B9DE652284 . 2071808 . . [5.1.2600.6055]
. . c:\windows\$hf_mig$\KB2393802\SP3QFE\ntkrnlpa.exe
[-] 2010-12-09 . B043D20C8CED49070DA56221BB7D6DC5 . 2029568 . . [5.1.2600.6055]
. . c:\windows\$NtUninstallKB2676562$\ntkrnlpa.exe
[-] 2009-02-09 . E1CC2E793C0A50D18BFAEB2A0C5A8762 . 2026496 . . [5.1.2600.5755]
. . c:\windows\$NtUninstallKB2393802$\ntkrnlpa.exe
[-] 2009-02-09 . 9B5E5D325CEDBB10A9A86679634A38CC . 2068608 . . [5.1.2600.5755]
. . c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[-] 2008-04-14 . B4604169BB187939CAE61D62B41E85E0 . 2026496 . . [5.1.2600.5512]
. . c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe
[-] 2008-04-14 . 2E2931A58B112CDF2A99B00B5DACDBE4 . 2068224 . . [5.1.2600.5512]
. . c:\windows\ServicePackFiles\i386\ntkrnlpa.exe
[-] 2006-03-02 . 90AA698B03FAFEE217268AB443D7B4A9 . 2017792 . . [5.1.2600.2180]
. . c:\windows\$NtServicePackUninstall$\ntkrnlpa.exe
.
[-] 2008-04-14 12:48 . D60C40D71A4D874C903255E4827AFA0C . 437760 . . [5.1.2400.5
512] . . c:\windows\ServicePackFiles\i386\ntmssvc.dll
[-] 2008-04-14 12:48 . D60C40D71A4D874C903255E4827AFA0C . 437760 . . [5.1.2400.5
512] . . c:\windows\system32\ntmssvc.dll
[-] 2006-03-02 10:00 . 395948DEE2B0F534A8C70687CC6DD7CA . 437760 . . [5.1.2400.2
180] . . c:\windows\$NtServicePackUninstall$\ntmssvc.dll
.
[-] 2008-04-14 . 7594203F459ABDB5FE53C08D6B1BD53B . 186368 . . [5.1.2600.5512] .
. c:\windows\ServicePackFiles\i386\upnphost.dll
[-] 2008-04-14 . 7594203F459ABDB5FE53C08D6B1BD53B . 186368 . . [5.1.2600.5512] .
. c:\windows\system32\upnphost.dll
[-] 2006-03-02 . 4B48358383940F6E559DA2F64753029F . 185344 . . [5.1.2600.2180] .
. c:\windows\$NtServicePackUninstall$\upnphost.dll
.
[-] 2008-04-14 . 9EF059A2C76BCE8DB9B0DD95EFE23A48 . 367616 . . [5.3.2600.5512] .
. c:\windows\ServicePackFiles\i386\dsound.dll
[-] 2008-04-14 . 9EF059A2C76BCE8DB9B0DD95EFE23A48 . 367616 . . [5.3.2600.5512] .
. c:\windows\system32\dsound.dll
.
------- Supplementary Scan ------.
uStart Page = https://www.yahoo.com?fr=hp-avast&type=avastbcl
mStart Page = https://www.yahoo.com?fr=hp-avast&type=avastbcl
mSearch Bar = https://www.yahoo.com?fr=hp-avast&type=avastbcl
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\archiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: Interfaces\{B644D154-41E6-42E3-8738-5331D5D24565}: NameServer = 200.48.225.
130,200.48.225.146
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http:/
/www.gmer.net
Rootkit scan 2014-11-19 18:27
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\archivos de programa\PDF Complete\pdfsvc.exe /startedbyscm:66B66
708-40E2BE4D-pdfcService"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SCPDFReadSpool]
"ImagePath"="c:\windows\Installer\MSIA.tmp"
.
--------------------- LOCKED REGISTRY KEYS --------------------.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F
}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_15_0_0_2
23_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F
}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F
}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_15_0_0_223_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F
}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A1082370
13BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A1082370
13BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A1082370
13BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes --------------------.
- - - - - - - > 'winlogon.exe'(764)
c:\windows\system32\l3codeca.acm
.
- - - - - - - > 'explorer.exe'(3824)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2014-11-19 18:31:25
ComboFix-quarantined-files.txt 2014-11-19 23:31
ComboFix2.txt 2014-11-16 17:47
ComboFix3.txt 2014-10-11 15:52
.
Pre-Run: 2,694,291,456 bytes libres
Post-Run: 2,691,817,472 bytes libres
.
- - End Of File - - B192C4912D76793FB02CB907F5FAA4C6
792F61657FECE3D17A9122B4EE282847