Combofix log (run in Normal mode, worked now)
ComboFix 12-04-12.03 - Joa 13/04/2012 0:15.1.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.54.3082.18.1023.608 [GMT -3:00]
Running from: c:\documents and settings\Joa\Escritorio\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\archivos de programa\Hotspot Shield\hssie\HsSIe.dll
c:\windows\system32\PowerToyReadme.htm
c:\windows\WindowsUpdate.log . . . . Failed to delete
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Legacy_STEC3
-------\Service_STEC3
.
.
((((((((((((((((((((((((( Files Created from 2012-03-13 to 2012-04-13 )))))))))))))))))))))))))))))))
.
.
2012-04-11 05:16 . 2012-04-11 05:16 -------- d-----w- C:\FOUND.005
2012-04-10 04:28 . 2012-04-10 04:28 -------- d-----w- c:\documents and settings\Joa\Datos de programa\Malwarebytes
2012-04-10 04:27 . 2012-04-10 04:27 -------- d-----w- c:\documents and settings\All Users\Datos de programa\Malwarebytes
2012-04-10 04:27 . 2012-04-10 04:27 -------- d-----w- c:\archivos de programa\Malwarebytes' Anti-Malware
2012-04-10 04:27 . 2012-04-04 18:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-09 14:59 . 2012-03-07 00:01 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-04-09 14:59 . 2012-03-07 00:03 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-04-09 14:59 . 2012-03-07 00:02 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-04-09 14:59 . 2012-03-07 00:01 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-04-09 14:59 . 2012-03-07 00:03 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-04-09 14:59 . 2012-03-07 00:01 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-04-09 14:59 . 2012-03-07 00:01 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-04-09 14:59 . 2012-03-06 23:58 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-04-09 14:58 . 2012-03-07 00:15 41184 ----a-w- c:\windows\avastSS.scr
2012-04-09 14:58 . 2012-03-07 00:15 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-04-09 14:58 . 2012-04-09 14:58 -------- d-----w- c:\documents and settings\All Users\Datos de programa\AVAST Software
2012-04-09 14:58 . 2012-04-09 14:58 -------- d-----w- c:\archivos de programa\AVAST Software
2012-03-18 22:05 . 2012-03-18 22:05 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2006-05-24 18:24 . 2006-05-24 18:24 623104 ----a-w- c:\archivos de programa\hfs.exe
2005-04-19 22:25 . 2005-09-06 15:59 53323 ----a-w- c:\archivos de programa\opera\program\plugins\PlugDef.dll
2005-07-16 08:41 . 2005-06-25 01:55 41573 ----a-w- c:\archivos de programa\mozilla firefox\components\jar50.dll
2005-07-16 08:41 . 2005-06-25 01:55 160871 ----a-w- c:\archivos de programa\mozilla firefox\components\xpinstal.dll
2005-07-16 08:41 . 2005-06-25 01:55 48223 ----a-w- c:\archivos de programa\mozilla firefox\components\jsd3250.dll
2005-07-16 08:41 . 2005-08-02 16:06 150912 ----a-w- c:\archivos de programa\mozilla firefox\components\fullsoft.dll
2005-07-16 08:41 . 2005-08-02 16:06 94208 ----a-w- c:\archivos de programa\mozilla firefox\components\BrandRes.dll
2005-07-16 08:41 . 2005-08-02 16:06 8813 ----a-w- c:\archivos de programa\mozilla firefox\components\qfaservices.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-07 00:15 123536 ----a-w- c:\archivos de programa\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2005-06-15 6803456]
"nwiz"="nwiz.exe" [2005-06-15 1519616]
"NvMediaCenter"="NvMCTray.dll" [2005-06-15 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avast"="c:\archivos de programa\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menú Inicio^Programas^Inicio^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Menú Inicio\Programas\Inicio\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Joa^Menú Inicio^Programas^Inicio^Konfabulator.lnk]
path=c:\documents and settings\Joa\Menú Inicio\Programas\Inicio\Konfabulator.lnk
backup=c:\windows\pss\Konfabulator.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C-Media Mixer]
2002-10-15 21:00 1818624 ----a-w- c:\windows\mixer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-08-05 09:32 136176 ----a-w- c:\documents and settings\Joa\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 9.0]
2004-07-29 07:41 1122304 ----a-w- c:\archivos de programa\Symantec\Norton Ghost\Agent\GhostTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-03-25 07:28 144784 ----a-w- c:\archivos de programa\Java\jre1.6.0_06\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TorCP]
2005-12-11 19:51 225280 ----a-w- c:\archivos de programa\TorCP\TorCP.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"srvInetShaper"=2 (0x2)
"MDM"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Archivos de programa\\ABC\\abc.exe"=
"c:\\Archivos de programa\\Google\\Google Talk\\googletalk.exe"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Archivos de programa\\mIRC\\mirc.exe"=
"c:\\Archivos de programa\\uTorrent\\utorrent.exe"=
"c:\\Archivos de programa\\hfs.exe"=
"c:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\Joa\\Escritorio\\utorrent 182.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11297:UDP"= 11297:UDP:UDP 11297
"18377:TCP"= 18377:TCP:TCP 18377
.
R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [15/08/2005 02:02 AM 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [15/08/2005 02:02 AM 5248]
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [29/07/2004 03:33 AM 138780]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [09/04/2012 11:59 AM 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [09/04/2012 11:59 AM 337880]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [29/07/2004 04:13 AM 46779]
R2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;c:\archivos de programa\VMLaunch\BuddyVM.sys [03/12/2004 08:12 PM 15872]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [09/04/2012 11:59 AM 20696]
S3 OracleServiceXE;OracleServiceXE;c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE XE --> c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE XE [?]
S3 OracleXETNSListener;OracleXETNSListener;c:\oraclexe\app\oracle\product\10.2.0\server\BIN\TNSLSNR.EXE [02/02/2006 12:49 AM 204800]
S4 OracleJobSchedulerXE;OracleJobSchedulerXE;c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe XE --> c:\oraclexe\app\oracle\product\10.2.0\server\Bin\extjob.exe XE [?]
S4 srvInetShaper;iNet Shaper;c:\archivos de programa\iNet Shaper\Service\ins_service.exe --> c:\archivos de programa\iNet Shaper\Service\ins_service.exe [?]
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-12 c:\windows\Tasks\Winamp.job
- c:\archiv~1\Winamp\winamp.exe [2005-06-14 18:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uInternet Settings,ProxyServer = localhost:8088
IE: E&xportar a Microsoft Excel - c:\archiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: gamespot.com\www
TCP: Interfaces\{1B4E29EE-2AD8-41C3-A377-2F48FBFFA7A3}: NameServer = 192.168.1.1,8.8.8.8
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Joa\Datos de programa\Mozilla\Firefox\Profiles\3eot68cf.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://gamefaqs.com/
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-AFProg - c:\archivos de programa\Hotspot Shield\AnchorFree\ctrl\AFController.exe
MSConfigStartUp-QuickTime Task - c:\archivos de programa\QuickTime\qttask.exe
AddRemove-TorCP - c:\archivos de programa\TorCP\tor-bundle-uninstall.exe
AddRemove-Google Chrome - c:\documents and settings\Joa\Configuración local\Datos de programa\Google\Chrome\Application\5.0.375.125\Installer\setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-04-13 00:23
Windows 5.1.2600 Service Pack 2 FAT NTAPI
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2212)
c:\windows\system32\browselc.dll
c:\archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
c:\windows\system32\ODBC32.dll
c:\archivos de programa\Microsoft Office\OFFICE11\msohev.dll
c:\archivos de programa\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
c:\archivos de programa\Illustrate\dBpowerAMP\dBShell.dll
c:\windows\system32\shdoclc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\archivos de programa\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2012-04-13 00:26:14 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-13 03:26
.
Pre-Run: 15.530.688.512 bytes libres
Post-Run: 15.431.434.240 bytes libres
.
- - End Of File - - 10A212EB29947EA7C66BBE4ED0C37496