NO puedo abrir google ni facebook

Cerrado
Pcsur2014
Mensajes: 19
Registrado: 14 Ene 2015, 15:26

NO puedo abrir google ni facebook

Mensaje por Pcsur2014 » 11 May 2015, 19:52

Sera un virus? juzguelo ustedes..



http://www.imagebam.com/image/d5d9cd408046386





http://www.imagebam.com/image/2dc07b408046716



amabas imagenes muestran que no puedo ingresar ni a facebook ni a google he probado de todo.. y nada..



incluso le pase elistra....



a las tres maquinas que tienen el problema...
Adjuntos
InfoSat3.txt
elimino virus pero el problema continua
(2.14 KiB) Descargado 147 veces
InfoSat1.txt
elimino virus pero el problema continua
(4.02 KiB) Descargado 137 veces
InfoSat.txt
elimino virus pero el problema continua
(3.13 KiB) Descargado 108 veces

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Re: NO puedo abrir google ni facebook

Mensaje por msc hotline sat » 12 May 2015, 07:14

Pues lance el SPROCES , pulse en SALIR, y posteenos el contenido del fichero resultante c:/sproclog.txt



http://www.zonavirus.com/descargas/descargar-sproces.asp



Tras analizarlo, le informarmos del resultado y como proceder en consecuencia



saludos



ms, 16-5-2015

Pcsur2014
Mensajes: 19
Registrado: 14 Ene 2015, 15:26

Re: NO puedo abrir google ni facebook

Mensaje por Pcsur2014 » 13 May 2015, 19:52

aqui les tengo los archivos..
Adjuntos
SProcLog3.txt
este archivo va en conjunto con InfoSat3.txt
(9.56 KiB) Descargado 139 veces
SProcLog1.txt
este archivo va en conjunto con InfoSat1.txt
(9.17 KiB) Descargado 162 veces
SProcLog.txt
este archivo va en conjunto con InfoSat.txt
(11.26 KiB) Descargado 154 veces

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Re: NO puedo abrir google ni facebook

Mensaje por msc hotline sat » 14 May 2015, 10:35

Como que no ha posteado el contenido de los ficheros indicados, lo hacemos en esta respuesta, pero siempre se ha de postear el contenido, no indicar solo el fichero, para asi poder visionarlo a primera vista...



El primer infosat.txt:





(6-5-2015 18:03:54 (GMT))

EliStartPage v32.23 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 6 de Mayo del 2015)

--------------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-329068152-1958367476-725345543-500

Cadenas Víricas: 23873



Lista de Acciones (por Acción Directa):

Restaurado "Userinit"

[Userinit anterior] = "c:\windows\system32\userinit.exe,,c:\archivos de programa\microsoft\watermark.exe"

[Userinit actual] = "c:\windows\system32\userinit.exe,"

C:\ARCHIVOS DE PROGRAMA\DELTA\DELTA\1.8.24.6\DELTASRV.EXE --> Eliminado AdWare.DeltaSearch

C:\ARCHIVOS DE PROGRAMA\DELTA\DELTA\1.8.24.6\DELTAENG.DLL --> Eliminado AdWare.DeltaSearch

C:\ARCHIVOS DE PROGRAMA\DELTA\DELTA\1.8.24.6\DELTAAPP.DLL --> Eliminado AdWare.DeltaSearch

C:\WINDOWS\SYSTEM32\DMLCONF.DAT --> Eliminado (Fichero Complementario).

Eliminada Class, "{261DD098-8A3E-43D4-87AA-63324FA897D8}" -> "C:\Archivos de programa\Delta\delta\1.8.24.6\deltasrv.exe"

Eliminada Class, "{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}" -> C:\Archivos de programa\Delta\delta\1.8.24.6\bh\delta.dll

Eliminada Class, "{86838207-681D-469D-9511-D0DCC6F19F9B}" -> C:\Archivos de programa\Delta\delta\1.8.24.6\deltaEng.dll

Eliminada Class, "{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}" -> C:\Archivos de programa\Delta\delta\1.8.24.6\deltaApp.dll

Entrada Eliminada "LowRiskFileTypes"=".js;.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.hta;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;"

No detectado Parche MS08-067 de Microsoft instalado. (SServidor)

No detectado Parche MS10-046 de Microsoft instalado. (Exploit.CPLlink)

No detectado Parche MS14-021 de Microsoft instalado. (Seguridad IE8)

Eliminada Carpeta "C:\Documents and Settings\Administrador\Datos de programa\Delta"

Eliminada Carpeta "C:\Archivos de programa\Delta"

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE

Restaurada Clave: "SafeBoot\Minimal y Network"



(6-5-2015 18:08:45 (GMT))

EliStartPage v32.23 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 6 de Mayo del 2015)

--------------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-329068152-1958367476-725345543-500

Cadenas Víricas: 23873



Lista de Acciones (por Exploración):

Explorando "C:\"

C:\WINDOWS\system32\SRVANY.EXE --> Eliminado, RiskTool.BitCoinMiner.AM



Nº Total de Directorios: 3245

Nº Total de Ficheros: 30450

Nº de Ficheros Analizados: 11714

Nº de Ficheros Infectados: 1

Nº de Ficheros Limpiados: 1



(6-5-2015 18:10:14 (GMT))

EliStartPage v32.23 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 6 de Mayo del 2015)

--------------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-329068152-1958367476-725345543-500

Cadenas Víricas: 23873



Lista de Acciones (por Cierre):

Detectados Programas Potecialmente No Deseados (PUPs).

Ejecute el EliPUPs para proceder con su Desinstalación.

"SoftwareUpdater"





______________





El segundo infosat.txt:



(6-5-2015 18:09:15 (GMT))

EliStartPage v32.23 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 6 de Mayo del 2015)

--------------------------------------------------

Sistema Operativo: EvoLite® (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-1606980848-630328440-2146704303-500

Cadenas Víricas: 23873



Lista de Acciones (por Acción Directa):

F:\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\JWGKVSQ.VMX --> Acceso Denegado (Preparada su eliminacón en el siguiente reinicio).

C:\ARCHIVOS DE PROGRAMA\GREATSAVEE4EU\X5MGEY3DVI66QE.DLL --> Eliminado AdWare.MultiPlug(bho)

C:\ARCHIVOS DE PROGRAMA\BESTADBLOCKER\H5IKZENPVAB0WW.DLL --> Eliminado AdWare.MultiPlug(bho)

C:\ARCHIVOS DE PROGRAMA\RANDOMPRICE\EJROIKBVPBZZEN.DLL --> Eliminado AdWare.MultiPlug(bho)

C:\ARCHIVOS DE PROGRAMA\SAALEPLUS\X91X8ZELS1Z3F8.DLL --> Eliminado AdWare.MultiPlug(bho)

Eliminada Class, "{8154ab50-79f1-40c2-a449-fcce0e0caddd}" -> C:\Archivos de programa\GreatSavee4eU\X5MGey3dvi66qE.dll

Eliminada Class, "{1ba2d4a3-796a-41e9-a08f-d33117813738}" -> C:\Archivos de programa\bestadblocker\H5IkzEnPvab0wW.dll

Eliminada Class, "{25eb835d-5045-4fe1-ae09-97c93a2ef706}" -> C:\Archivos de programa\RandomPRice\EjROikbvPBzzen.dll

Eliminada Class, "{a6383432-781b-468d-b87f-f87ff76e3d19}" -> C:\Archivos de programa\SaalePlus\x91X8zeLs1z3F8.dll

Eliminada Class, "{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}" -> C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\CC88\temp\Lupa.exe

Eliminada Carpeta "C:\Archivos de programa\GreatSavee4eU"

Eliminada Carpeta "C:\Archivos de programa\bestadblocker"

Eliminada Carpeta "C:\Archivos de programa\DDIgiiSaver"

Eliminada Carpeta "C:\Archivos de programa\RandomPRice"

Eliminada Carpeta "C:\Archivos de programa\Awesome Dictionary Widget ANTP"

Eliminada Carpeta "C:\Archivos de programa\SaalePlus"

Eliminada Carpeta "C:\Archivos de programa\TransferBigFilescom Gmail Extension"

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE

Reinicie para Completar la Limpieza.



(6-5-2015 18:13:26 (GMT))

EliStartPage v32.23 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 6 de Mayo del 2015)

--------------------------------------------------

Sistema Operativo: EvoLite® (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-1606980848-630328440-2146704303-500

Cadenas Víricas: 23873



Lista de Acciones (por Exploración):

Explorando "C:\"

C:\WINDOWS\system32\CMDOW.EXE --> Eliminado, Tool-HideWindow

C:\WINDOWS\system32\SRVANY.EXE --> Eliminado, RiskTool.BitCoinMiner.AM



Nº Total de Directorios: 2100

Nº Total de Ficheros: 17043

Nº de Ficheros Analizados: 5392

Nº de Ficheros Infectados: 2

Nº de Ficheros Limpiados: 2



(6-5-2015 21:23:13 (GMT))

EliStartPage v32.23 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 6 de Mayo del 2015)

--------------------------------------------------

Sistema Operativo: EvoLite® (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-1606980848-630328440-2146704303-500

Cadenas Víricas: 23873



Lista de Acciones (por Cierre):

Detectados Programas Potecialmente No Deseados (PUPs).

Ejecute el EliPUPs para proceder con su Desinstalación.

"SuperRepair"



(7-5-2015 12:05:33 (GMT))

EliStartPage v32.23 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 6 de Mayo del 2015)

--------------------------------------------------

Sistema Operativo: EvoLite® (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-1606980848-630328440-2146704303-500

Cadenas Víricas: 23873



Lista de Acciones (por Acción Directa):



(7-5-2015 12:05:42 (GMT))

EliStartPage v32.23 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 6 de Mayo del 2015)

--------------------------------------------------

Sistema Operativo: EvoLite® (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-1606980848-630328440-2146704303-500

Cadenas Víricas: 23873



Lista de Acciones (por Cierre):

Detectados Programas Potecialmente No Deseados (PUPs).

Ejecute el EliPUPs para proceder con su Desinstalación.

"SuperRepair"



_____________





y el 3er infosat:





(18-4-2015 14:54:05 (GMT))

EliStartPage v32.07 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 14 de Abril del 2015)

--------------------------------------------------

Sistema Operativo: EvoLite® (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-1715567821-823518204-1606980848-500

Cadenas Víricas: 23696



Lista de Acciones (por Acción Directa):

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE



(18-4-2015 14:58:58 (GMT))

EliStartPage v32.07 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 14 de Abril del 2015)

--------------------------------------------------

Sistema Operativo: EvoLite® (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-1715567821-823518204-1606980848-500

Cadenas Víricas: 23696



Lista de Acciones (por Exploración):

Explorando "C:\"

C:\WINDOWS\system32\CMDOW.EXE --> Eliminado, Tool-HideWindow

C:\WINDOWS\system32\SRVANY.EXE --> Eliminado, RiskTool.BitCoinMiner.AM



Nº Total de Directorios: 1954

Nº Total de Ficheros: 16991

Nº de Ficheros Analizados: 5647

Nº de Ficheros Infectados: 2

Nº de Ficheros Limpiados: 2



(6-5-2015 18:00:40 (GMT))

EliStartPage v32.23 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 6 de Mayo del 2015)

--------------------------------------------------

Sistema Operativo: EvoLite® (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-1715567821-823518204-1606980848-500

Cadenas Víricas: 23873



Lista de Acciones (por Acción Directa):

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE



(6-5-2015 18:06:00 (GMT))

EliStartPage v32.23 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 6 de Mayo del 2015)

--------------------------------------------------

Sistema Operativo: EvoLite® (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-1715567821-823518204-1606980848-500

Cadenas Víricas: 23873



Lista de Acciones (por Exploración):

Explorando "C:\"



Nº Total de Directorios: 1982

Nº Total de Ficheros: 17634

Nº de Ficheros Analizados: 5977

Nº de Ficheros Infectados: 0

Nº de Ficheros Limpiados: 0



___________



y por lo que respecta a los logs del SPROCES:





(13-5-2015 09:16:39 GMT)

SProces v8.3 (c)2015 S.G.H. / Satinfo S.L.

-------------------------------------------

Sistema Operativo: Microsoft Windows XP (v5.1.2600) Service Pack 3

Parche MS08-067 (Servicio Servidor) NO Instalado.

Parche MS10-046 (Exploit.CPLlink) NO Instalado.

Parche MS14-021 (Seguridad IE8) NO Instalado.

Internet Explorer: (v8.0.6001.18702) 0

Equipo: WINSTALKER

Usuario: Administrador

Sesión de Usuario: Administrador



29 Procesos Activos:

C:\WINDOWS\SYSTEM32\SMSS.EXE

C:\WINDOWS\SYSTEM32\CSRSS.EXE

C:\WINDOWS\SYSTEM32\WINLOGON.EXE

C:\WINDOWS\SYSTEM32\SERVICES.EXE

C:\WINDOWS\SYSTEM32\LSASS.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\EXPLORER.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\ARCHIVOS DE PROGRAMA\ALWIL SOFTWARE\AVAST5\AVASTSVC.EXE

C:\WINDOWS\SYSTEM32\SPOOLSV.EXE

C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE

C:\ARCHIVOS DE PROGRAMA\ALWIL SOFTWARE\AVAST5\AVASTUI.EXE

C:\WINDOWS\SYSTEM32\CTFMON.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\ALG.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\WINDOWS\SYSTEM32\MMC.EXE

C:\WINDOWS\SYSTEM32\MMC.EXE

C:\ARCHIVOS DE PROGRAMA\WINRAR\WINRAR.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\ESCRITORIO\SPROCES.EXE



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

O1 - Hosts: 127.0.0.1 apps.corel.com

O1 - Hosts: 127.0.0.1 activate.adobe.com

O1 - Hosts: 127.0.0.1 practivate.adobe.com

O1 - Hosts: 127.0.0.1 ereg.adobe.com

O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com

O1 - Hosts: 127.0.0.1 wip3.adobe.com

O1 - Hosts: 127.0.0.1 3dns-3.adobe.com

O1 - Hosts: 127.0.0.1 3dns-2.adobe.com

O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com

O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com

O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com

O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com

O1 - Hosts: 127.0.0.1 activate-sea.adobe.com

O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com

O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com

O1 - Hosts: 127.0.0.1 adobeereg.com

O1 - Hosts: 127.0.0.1 http://www.adobeereg.com

O1 - Hosts: 127.0.0.1 activate.adobe.com

O1 - Hosts: 127.0.0.1 activate-sea.adobe.com

O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com

...

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre7\bin\ssv.dll

O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Archivos de programa\Alwil Software\Avast5\aswWebRepIE.dll

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Archivos de programa\Java\jre7\bin\jp2ssv.dll

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [ISUSScheduler] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [AvastUI.exe] "C:\Archivos de programa\Alwil Software\Avast5\AvastUI.exe" /nogui

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')

O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Servicio de red')

O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~1\Office12\EXCEL.EXE/3000

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~1\Office12\REFIEBAR.DLL (HKLM)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (HKLM)

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll

O20 - Winlogon Notify: DIMSNTFY - %SYSTEMROOT%\SYSTEM32\DIMSNTFY.DLL

O20 - Winlogon Notify: IGFXCUI - IGFXDEV.DLL

O20 - Winlogon Notify: RAILNOTIFICATION - WINLOGONNOTIFICATION.DLL

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O22 - SharedTaskScheduler: Precargador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - %SystemRoot%\system32\browseui.dll

O22 - SharedTaskScheduler: Demonio de caché de las categorías de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll



Información Adicional:

----------------------

Acceso Rapido ('Administrador'): Google Chrome.lnk = C:\Archivos de programa\Google\Chrome\Application\chrome.exe

Acceso Rapido ('Administrador'): Iniciar el explorador Internet Explorer.lnk = C:\Archivos de programa\Internet Explorer\iexplore.exe

Clave "HKLM\...\Image File Execution Options\notepad.exe"

"Debugger"=""C:\Archivos de programa\Notepad2\Notepad2.exe" /z"

Ext.Google Chrome. ('Administrador') Id: aohghmighlieiainnegkcijnfilokake

Ext.Google Chrome. ('Administrador') Id: apdfllckaahabafndbhieahigkjlhalf

Ext.Google Chrome. ('Administrador') Id: blpcfgokakmgnkcojhhkbfbldkacnbeo

Ext.Google Chrome. ('Administrador') Id: coobgpohoikkiipiblmjeljniedjpjpf

Ext.Google Chrome. ('Administrador') Id: gmlllbghnfkpflemihljekbapjopfjik

Ext.Google Chrome. ('Administrador') Id: lccekmodgklaepjeofjdjpbminllajkg

Ext.Google Chrome. ('Administrador') Id: mppnoffgpafgpgbaigljliadgbnhljfl

Ext.Google Chrome. ('Administrador') Id: nafaimnnclfjfedmmabolbppcngeolgf

Ext.Google Chrome. ('Administrador') Id: nmmhkkegccagdldgiimedpiccmgmieda

Ext.Google Chrome. ('Administrador') Id: pjkljhegncpnkpknbcohdijeoejaedia

Tarea Programada: C:\WINDOWS\Tasks\avast! Emergency Update.job



Listado de Servicios (Carga Automatica):

----------------------------------------

O23 - Service: avast! HardwareID (aswHwid) - AVAST Software - C:\WINDOWS\system32\drivers\aswHwid.sys

O23 - Service: aswMonFlt - AVAST Software - C:\WINDOWS\system32\drivers\aswMonFlt.sys

O23 - Service: avast! Antivirus - AVAST Software - C:\Archivos de programa\Alwil Software\Avast5\AvastSvc.exe



Listado de Servicios (Carga Manual):

------------------------------------

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: Ambfilt - Creative - C:\WINDOWS\SYSTEM32\drivers\Ambfilt.sys

**O23 - Service: Servicio del administrador de discos lógicos (dmadmin) - Microsoft Corp., VERITAS Software - C:\WINDOWS\System32\dmadmin.exe

O23 - Service: Controlador de bus de Microsoft UAA para High Definition Audio (HDAudBus) - Windows (R) Server 2003 DDK provider - C:\WINDOWS\SYSTEM32\DRIVERS\HDAudBus.sys

O23 - Service: ialm - Intel Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\igxpmp32.sys

O23 - Service: Service for Realtek HD Audio (WDM) (IntcAzAudAddService) - Realtek Semiconductor Corp. - C:\WINDOWS\SYSTEM32\drivers\RtkHDAud.sys

O23 - Service: Monfilt - Creative Technology Ltd. - C:\WINDOWS\SYSTEM32\drivers\Monfilt.sys

O23 - Service: Controlador de vínculo paralelo directo (Ptilink) - Parallel Technologies, Inc. - C:\WINDOWS\SYSTEM32\DRIVERS\ptilink.sys

O23 - Service: Realtek 10/100/1000 PCI NIC Family NDIS XP Driver (RTL8023xp) - Realtek Semiconductor Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\Rtnicxp.sys

O23 - Service: Secdrv - Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. - C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys



Listado de Servicios (Deshabilitados):

--------------------------------------

**O23 - Service: dmboot - Microsoft Corp., Veritas Software - C:\WINDOWS\SYSTEM32\drivers\dmboot.sys

O23 - Service: Google Update Servicio (gupdate) (gupdate) - Google Inc. - C:\Archivos de programa\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update Servicio (gupdatem) (gupdatem) - Google Inc. - C:\Archivos de programa\Google\Update\GoogleUpdate.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Archivos de programa\Java\jre7\bin\jqs.exe" -service -config "C:\Archivos de programa\Java\jre7\lib\deploy\jqs\jqs.con (file missing)



17 Servicios.

3 de Carga Automatica.

10 de Carga Manual.

4 Deshabilitados.



Listado de Programas Instalados:

--------------------------------

avast! Free Antivirus -> C:\Archivos de programa\Alwil Software\Avast5\Setup\Instup.exe /control_panel /instop:uninstall

Flash CS3 9.0 -> C:\Archivos de programa\Adobe\Flash CS3\Uninstall.exe

Google Chrome -> "C:\Archivos de programa\Google\Chrome\Application\42.0.2311.135\Installer\setup.exe" --uninstall --multi-install --chrome --system-level

Intel(R) Graphics Media Accelerator Driver -> C:\WINDOWS\system32\igxpun.exe -uninstall

Notepad2 (Reemplazo del Bloc de Notas) -> "C:\Archivos de programa\Notepad2\uninstall.exe"

WinRAR 5.01 (32-bit) -> C:\Archivos de programa\WinRAR\uninstall.exe

Java 7 Update 51 -> MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217051FF}

FontNav -> MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}

Adobe Flash Player 12 ActiveX -> MsiExec.exe /X{52793F88-BF4D-4AA6-8696-80E72CE758B1}

Google Update Helper -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}

CorelDRAW Graphics Suite X3 -> MsiExec.exe /I{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}

VC_CRT_x86 -> MsiExec.exe /I{8054D734-39C7-463D-B764-9C883982B8F9}

-> msiexec /package {90120000-0012-0000-0000-0000000FF1CE} /uninstall {7257E85B-FD41-4363-BF66-D8290055DF6F}

Adobe Flash Player 12 Plugin -> MsiExec.exe /X{934168C8-55AC-4593-A138-E64BA8367E6E}

Google Update Helper -> MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

Adobe Reader 9.5.0 - Español -> MsiExec.exe /I{AC76BA86-7AD7-1034-7B44-A95000000001}

VBA -> MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}

REALTEK GbE & FE Ethernet PCI-E NIC Driver -> C:\Archivos de programa\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x000a -removeonly

ES -> MsiExec.exe /I{CBFAD664-763E-4A7D-BF92-BB0E493F3C66}

Realtek High Definition Audio Driver -> RtlUpd.exe -r -m -nrg2709

Update Manager -> MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}

Adobe Shockwave Player 12.0 -> MsiExec.exe /X{FF2A5498-4EFE-430F-A138-7EB365DBEBAD}





___________





Y EL SEGUNDO:





(13-5-2015 16:51:14 GMT)

SProces v8.5 (c)2015 S.G.H. / Satinfo S.L.

-------------------------------------------

Sistema Operativo: EvoLite® (v5.1.2600) Service Pack 3

Internet Explorer: (v6.0.2900.5512) ;SP3;

Equipo: USUARIO

Usuario: Administrador

Sesión de Usuario: Administrador



22 Procesos Activos:

C:\WINDOWS\SYSTEM32\SMSS.EXE

C:\WINDOWS\SYSTEM32\CSRSS.EXE

C:\WINDOWS\SYSTEM32\WINLOGON.EXE

C:\WINDOWS\SYSTEM32\SERVICES.EXE

C:\WINDOWS\SYSTEM32\LSASS.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\EXPLORER.EXE

C:\WINDOWS\SYSTEM32\SPOOLSV.EXE

C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE

C:\WINDOWS\SYSTEM32\CTFMON.EXE

C:\ARCHIVOS DE PROGRAMA\WINZIP\WZQKPICK.EXE

C:\DOCUMENTS AND SETTINGS\ALL USERS\DATOS DE PROGRAMA\{6529EE8E-7ED3-8EDE-6529-9EE8E7EDBA39}\LUPA.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\CONFIGURACIóN LOCAL\DATOS DE PROGRAMA\GOOGLE\UPDATE\1.3.26.9\GOOGLECRASHHANDLER.EXE

C:\WINDOWS\SYSTEM32\RUNDLL32.EXE

C:\WINDOWS\SYSTEM32\ALG.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\ARCHIVOS DE PROGRAMA\WINRAR\WINRAR.EXE

C:\DOCUME~1\ADMINI~1\CONFIG~1\TEMP\RAR$EX00.156\SPROCES.EXE



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARCHIV~1\MICROS~1\Office14\GROOVEEX.DLL

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ARCHIV~1\MICROS~1\Office14\URLREDIR.DLL

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [ISUSScheduler] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\issch.exe" -start

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio Local')

O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Servicio Local')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')

O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Servicio de red')

O4 - Startup: Lupa.lnk = C:\Documents and Settings\All Users\Datos de programa\{6529ee8e-7ed3-8ede-6529-9ee8e7edba39}\Lupa.exe --startup=1

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Archivos de programa\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: &Enviar a OneNote - res://C:\ARCHIV~1\MICROS~1\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~1\Office14\EXCEL.EXE/3000

O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIE.dll (HKLM)

O9 - Extra button: Notas &vinculadas de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (HKLM)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (HKLM)

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll

O20 - Winlogon Notify: DIMSNTFY - %SYSTEMROOT%\SYSTEM32\DIMSNTFY.DLL

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - %SystemRoot%\system32\webcheck.dll

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll

O22 - SharedTaskScheduler: Precargador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - %SystemRoot%\system32\browseui.dll

O22 - SharedTaskScheduler: Demonio de caché de las categorías de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll

O22 - ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\ARCHIV~1\MICROS~1\Office14\GROOVEEX.DLL



Información Adicional:

----------------------

Acceso Rapido ('Administrador'): Google Chrome.lnk = C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe

Acceso Rapido ('Administrador'): Iniciar el explorador Internet Explorer.lnk = C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE

Ext.Google Chrome. ('Administrador') Id: aapocclcgogkmnckokdopfmhonfmgoek

Ext.Google Chrome. ('Administrador') Id: aohghmighlieiainnegkcijnfilokake

Ext.Google Chrome. ('Administrador') Id: apdfllckaahabafndbhieahigkjlhalf

Ext.Google Chrome. ('Administrador') Id: blpcfgokakmgnkcojhhkbfbldkacnbeo

Ext.Google Chrome. ('Administrador') Id: coobgpohoikkiipiblmjeljniedjpjpf

Ext.Google Chrome. ('Administrador') Id: felcaaldnbdncclmgdcncolpebgiejap

Ext.Google Chrome. ('Administrador') Id: gmlllbghnfkpflemihljekbapjopfjik

Ext.Google Chrome. ('Administrador') Id: lajnjaghjodocddaglgghffgacnoepgf

Ext.Google Chrome. ('Administrador') Id: lccekmodgklaepjeofjdjpbminllajkg

Ext.Google Chrome. ('Administrador') Id: nmmhkkegccagdldgiimedpiccmgmieda

Ext.Google Chrome. ('Administrador') Id: pjkljhegncpnkpknbcohdijeoejaedia

DataBases Google Chrome. ('Administrador'): Databases.db

DataBases Google Chrome. ('Administrador'): Databases.db-journal



Listado de Servicios (Carga Automatica):

----------------------------------------

O23 - Service: BorderlineInit (76648c07) - Unknown owner - C:\WINDOWS\system32\rundll32.exe" "c:\Archivos de programa\BorderlineInit\BorderlineInit.dll (file missing)

O23 - Service: KMService - Unknown owner - C:\WINDOWS\system32\srvany.exe (file missing)



Listado de Servicios (Carga Manual):

------------------------------------

O23 - Service: Servicio de instalación del controlador de audio (WDM) de Intel(r) 82801 (ac97intc) - Intel Corporation - C:\WINDOWS\SYSTEM32\drivers\ac97intc.sys

**O23 - Service: Servicio del administrador de discos lógicos (dmadmin) - Microsoft Corp., VERITAS Software - C:\WINDOWS\System32\dmadmin.exe

O23 - Service: 3Com 3C90X-BC Family PCI EtherLink Adapter (EL90XBC) - 3Com Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\el90xbc5.sys

O23 - Service: HpqKbFilter Driver (HpqKbFiltr) - Hewlett-Packard Development Company, L.P. - C:\WINDOWS\SYSTEM32\DRIVERS\HpqKbFiltr.sys

O23 - Service: Controlador de vínculo paralelo directo (Ptilink) - Parallel Technologies, Inc. - C:\WINDOWS\SYSTEM32\DRIVERS\ptilink.sys

O23 - Service: Secdrv - Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. - C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys



Listado de Servicios (Deshabilitados):

--------------------------------------

**O23 - Service: dmboot - Microsoft Corp., Veritas Software - C:\WINDOWS\SYSTEM32\drivers\dmboot.sys

O23 - Service: Acceso a dispositivo de interfaz humana (HidServ) - Unknown owner - %SystemRoot%\System32\svchost.exe -k netsvcs - C:\WINDOWS\System32\hidserv.dll (file missing)



10 Servicios.

2 de Carga Automatica.

6 de Carga Manual.

2 Deshabilitados.



Listado de Programas Instalados:

--------------------------------

Flash CS3 9.0 -> C:\Archivos de programa\Adobe\Flash CS3\Uninstall.exe

Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 -> "C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"

Compresor WinRAR -> C:\Archivos de programa\Winrar\uninstall.exe

SuperRepair -> "C:\WINDOWS\system32\RUNDLL32.EXE" "C:\ARCHIV~1\BORDER~1\BORDER~1.DLL",_uninstall /un

BlockIt Ad remover -> "C:\Documents and Settings\All Users\Datos de programa\BlockIt Ad remover\BlockIt Ad remover.exe" /progname=BlockIt Ad remover /progver=3.4.2 /progpub=BlockIt Ad remover /proguninstallurl=asdahjka.com /deleteappfolder=0 /deletefile2="C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Google\Chrome\Applicationupdate.dll" /deletefile3="C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Google\Chrome\Applicationchrome.dll" /VERYSILENT

FontNav -> MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}

CorelDRAW Graphics Suite X3 -> MsiExec.exe /I{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}

VBA -> MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}

ES -> MsiExec.exe /I{CBFAD664-763E-4A7D-BF92-BB0E493F3C66}

WinZip 15.0 -> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}

Update Manager -> MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}

Google Chrome -> "C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Google\Chrome\Application\42.0.2311.135\Installer\setup.exe" --uninstall --multi-install --chrome





____________



Y EL TERCERO:





(13-5-2015 16:35:42 GMT)

SProces v8.3 (c)2015 S.G.H. / Satinfo S.L.

-------------------------------------------

Sistema Operativo: EvoLite® (v5.1.2600) Service Pack 3

Internet Explorer: (v6.0.2900.5512) ;SP3;

Equipo: USUARIO1

Usuario: Administrador

Sesión de Usuario: Administrador



30 Procesos Activos:

C:\WINDOWS\SYSTEM32\SMSS.EXE

C:\WINDOWS\SYSTEM32\CSRSS.EXE

C:\WINDOWS\SYSTEM32\WINLOGON.EXE

C:\WINDOWS\SYSTEM32\SERVICES.EXE

C:\WINDOWS\SYSTEM32\LSASS.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\EXPLORER.EXE

C:\WINDOWS\SYSTEM32\SPOOLSV.EXE

C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE

C:\WINDOWS\SYSTEM32\HKCMD.EXE

C:\ARCHIVOS DE PROGRAMA\ANALOG DEVICES\CORE\SMAX4PNP.EXE

C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE

C:\WINDOWS\SYSTEM32\CTFMON.EXE

C:\ARCHIVOS DE PROGRAMA\CCLEANER\CCLEANER.EXE

C:\ARCHIVOS DE PROGRAMA\WINZIP\WZQKPICK.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\CONFIGURACIóN LOCAL\DATOS DE PROGRAMA\GOOGLE\UPDATE\1.3.26.9\GOOGLECRASHHANDLER.EXE

C:\ARCHIVOS DE PROGRAMA\BURNAWARE PRO RETAIL BY MINIMAL\NMSACCESSU.EXE

C:\WINDOWS\SYSTEM32\ALG.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\MICROSOFT SHARED\OFFICESOFTWAREPROTECTIONPLATFORM\OSPPSVC.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\CONFIGURACIóN LOCAL\DATOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\CONFIGURACIóN LOCAL\DATOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\CONFIGURACIóN LOCAL\DATOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\CONFIGURACIóN LOCAL\DATOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\WINRAR\WINRAR.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\ESCRITORIO\SPROCES.EXE



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.ve

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARCHIV~1\MICROS~1\Office14\GROOVEEX.DLL

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ARCHIV~1\MICROS~1\Office14\URLREDIR.DLL

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Archivos de programa\CCleaner\CCleaner.exe" /MONITOR

O4 - HKCU\..\Run: [CCleaner] "C:\Archivos de programa\CCleaner\CCleaner.exe" /AUTO

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe" /c

O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [SoundMAXPnP] C:\Archivos de programa\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [ISUSScheduler] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\issch.exe" -start

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio Local')

O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Servicio Local')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')

O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Servicio de red')

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Archivos de programa\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: &Enviar a OneNote - res://C:\ARCHIV~1\MICROS~1\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~1\Office14\EXCEL.EXE/3000

O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIE.dll (HKLM)

O9 - Extra button: Notas &vinculadas de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (HKLM)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (HKLM)

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll

O20 - Winlogon Notify: DIMSNTFY - %SYSTEMROOT%\SYSTEM32\DIMSNTFY.DLL

O20 - Winlogon Notify: IGFXCUI - IGFXSRVC.DLL

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - %SystemRoot%\system32\webcheck.dll

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll

O22 - SharedTaskScheduler: Precargador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - %SystemRoot%\system32\browseui.dll

O22 - SharedTaskScheduler: Demonio de caché de las categorías de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll

O22 - ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\ARCHIV~1\MICROS~1\Office14\GROOVEEX.DLL



Información Adicional:

----------------------

Acceso Rapido ('Administrador'): BurnAware Professional.lnk = C:\Archivos de programa\BurnAware Pro Retail by minimaL\burnaware.exe

Acceso Rapido ('Administrador'): Google Chrome.lnk = C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe

Acceso Rapido ('Administrador'): Iniciar el explorador Internet Explorer.lnk = C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE

Acceso Rapido ('Administrador'): Mozilla Firefox.lnk = C:\Archivos de programa\Mozilla Firefox\firefox.exe

Ext.Google Chrome. ('Administrador') Id: aohghmighlieiainnegkcijnfilokake

Ext.Google Chrome. ('Administrador') Id: gmlllbghnfkpflemihljekbapjopfjik

Ext.Google Chrome. ('Administrador') Id: lccekmodgklaepjeofjdjpbminllajkg

Ext.Google Chrome. ('Administrador') Id: nmmhkkegccagdldgiimedpiccmgmieda



Listado de Servicios (Carga Automatica):

----------------------------------------

O23 - Service: NMSAccessU - Unknown owner - C:\Archivos de programa\BurnAware Pro Retail by minimaL\nmsaccessu.exe



Listado de Servicios (Carga Manual):

------------------------------------

**O23 - Service: Servicio del administrador de discos lógicos (dmadmin) - Microsoft Corp., VERITAS Software - C:\WINDOWS\System32\dmadmin.exe

O23 - Service: Intel(R) PRO/1000 Network Connection Driver (E1000) - Intel Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\e1000325.sys

O23 - Service: ialm - Intel Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\ialmnt5.sys

O23 - Service: Controlador de vínculo paralelo directo (Ptilink) - Parallel Technologies, Inc. - C:\WINDOWS\SYSTEM32\DRIVERS\ptilink.sys

O23 - Service: Secdrv - Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. - C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys

O23 - Service: senfilt - Creative Technology Ltd. - C:\WINDOWS\SYSTEM32\drivers\senfilt.sys

O23 - Service: smwdm - Analog Devices, Inc. - C:\WINDOWS\SYSTEM32\drivers\smwdm.sys



Listado de Servicios (Deshabilitados):

--------------------------------------

**O23 - Service: dmboot - Microsoft Corp., Veritas Software - C:\WINDOWS\SYSTEM32\drivers\dmboot.sys



9 Servicios.

1 de Carga Automatica.

7 de Carga Manual.

1 Deshabilitados.



Listado de Programas Instalados:

--------------------------------

Adobe Flash Player ActiveX -> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe

Adobe Flash Player 10 Plugin -> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe

BurnAware Pro 2.3.2 Retail by minimaL -> "C:\Archivos de programa\BurnAware Pro Retail by minimaL\unins000.exe"

CCleaner -> "C:\Archivos de programa\CCleaner\uninst.exe"

Flash CS3 9.0 -> C:\Archivos de programa\Adobe\Flash CS3\Uninstall.exe

Mozilla Firefox (3.5) -> C:\Archivos de programa\Mozilla Firefox\uninstall\helper.exe

Intel(R) Network Connections Drivers -> Prounstl.exe

Compresor WinRAR -> C:\Archivos de programa\Winrar\uninstall.exe

Adobe Shockwave Player -> MsiExec.exe /X{211E8730-5681-49ED-BC6A-78C9F88E95F5}

FontNav -> MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}

CorelDRAW Graphics Suite X3 -> MsiExec.exe /I{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}

Intel(R) Extreme Graphics Driver -> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562

Adobe Reader 9 - Español -> MsiExec.exe /I{AC76BA86-7AD7-1034-7B44-A90000000001}

VBA -> MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}

ES -> MsiExec.exe /I{CBFAD664-763E-4A7D-BF92-BB0E493F3C66}

WinZip 15.0 -> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}

Update Manager -> MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}

Google Chrome -> "C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Google\Chrome\Application\42.0.2311.135\Installer\setup.exe" --uninstall --multi-install --chrome





____________



[b][color=#FF0000]RESPUESTA[/color][/b]





De entrada, EN EL PRIMER INFOSAT vemos que usa XP, sistema que ya no está soportado, y que además le faltan parches:





[i]No detectado Parche MS08-067 de Microsoft instalado. (SServidor)

No detectado Parche MS10-046 de Microsoft instalado. (Exploit.CPLlink)

No detectado Parche MS14-021 de Microsoft instalado. (Seguridad IE8)[/i]






actualicelos lanzando un windowsupdate.





Aparte, tiene PUPS que le indicamos desinstale con el ELIPUPS, si lo quiere desinstalar:



[i]Lista de Acciones (por Cierre):

Detectados Programas Potecialmente No Deseados (PUPs).

Ejecute el EliPUPs para proceder con su Desinstalación.

"SoftwareUpdater"[/i]






En el segundo infosat, aparte de eliminar otro monton de malwares, se detectan de nuevo PUPS:



[i]Lista de Acciones (por Cierre):

Detectados Programas Potecialmente No Deseados (PUPs).

Ejecute el EliPUPs para proceder con su Desinstalación.

"SuperRepair"[/i]




Pues lance el ELIPUPS y desinstalelo si no lo quiere.







Y respecto al tercer infosat, mas de lo mismo, si bien en él vemos instalado un sistema EVOLITE que es una version modificada de XP que no es oficial, la cual sugerimos desinstalar e instalar una legal, si quiere soporte del mismo:





[i] (6-5-2015 18:09:15 (GMT))

EliStartPage v32.23 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 6 de Mayo del 2015)

--------------------------------------------------

Sistema Operativo: EvoLite® (5.1.2600) SERVICE PACK 3[/i]






............





Respecto a los logs del SPROCES, en el primero vemos este ficheros sospechoso:





[b]C:\DOCUMENTS AND SETTINGS\ALL USERS\DATOS DE PROGRAMA\{6529EE8E-7ED3-8EDE-6529-9EE8E7EDBA39}\LUPA.EXE[/b]





Añadan .VIR a su extension y enviennoslo para analizar





ya que la informacion del mismo indica que puede ser peligroso, segun:



http://www.tweakmysystem.com/fixerror-exe/lupa.exe.html





E igualmente con este otro





[b]C:\WINDOWS\system32\rundll32.exe" "c:\Archivos de programa\BorderlineInit\BorderlineInit.dll

[/b]




que tambien puede ser malicioso, segun:



http://www.herdprotect.com/borderlineinit.dll-f6b2fc0e21d7e9796dbe313194caeec392948b54.aspx





Si no encontraran a primera vista alguno de los ficheros pedidos, por poder tener atributos de oculto, prueben con nuestro ELIMOVER.EXE, que si lo encuentra lo copiará en C:\muestras sin atributos, desde donde podfrá enviarnoslo facilmente



Y como que vemnos modificaciones en el HOSTS, como:



[i]O1 - Hosts: 127.0.0.1 apps.corel.com

O1 - Hosts: 127.0.0.1 activate.adobe.com

O1 - Hosts: 127.0.0.1 practivate.adobe.com

O1 - Hosts: 127.0.0.1 ereg.adobe.com

O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com

O1 - Hosts: 127.0.0.1 wip3.adobe.com

O1 - Hosts: 127.0.0.1 3dns-3.adobe.com

O1 - Hosts: 127.0.0.1 3dns-2.adobe.com

O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com

O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com

O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com

O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com

O1 - Hosts: 127.0.0.1 activate-sea.adobe.com

O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com

O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com

O1 - Hosts: 127.0.0.1 adobeereg.com

O1 - Hosts: 127.0.0.1 http://www.adobeereg.com

O1 - Hosts: 127.0.0.1 activate.adobe.com

O1 - Hosts: 127.0.0.1 activate-sea.adobe.com

O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com

...[/i]




Sugerimos que al detectar con el ELISTARA, el HOST modificado, proceder a aceptar cambiarlo por el original, no sea que alguna de las modificaciones (que no se indican en el informe), impida el acceso a las webs indicadas







Y en el segundo informe del SPROCES vemos repetido el uso del LUPA.EXE y del BorderLineInit.DLL, asi que nuestro consejo es que añadan .VIR a la extension de dichos ficheros para que no se vuelvan a cargar tras reiniciar, yy como que ya nos los habrán enviado desde el primer ordenador, ya los analizaremos y obraremos en consecuencia con ellos.





y del tercer informe, al usar sistema Sistema Operativo: EvoLite® , sin comentarios.





Quedamos pendientes de recibir las muestras pedidas y de que nos indique si tras añadir .VIR a su extension y reiniciar, se ha solucionado la anomalía, gracias



muestras pendientes de recibir:



[b]C:\DOCUMENTS AND SETTINGS\ALL USERS\DATOS DE PROGRAMA\{6529EE8E-7ED3-8EDE-6529-9EE8E7EDBA39}\LUPA.EXE.VIR



C:\WINDOWS\system32\rundll32.exe" "c:\Archivos de programa\BorderlineInit\BorderlineInit.dll.VIR[/b]






saludos



ms, 14-5-2015

Pcsur2014
Mensajes: 19
Registrado: 14 Ene 2015, 15:26

Re: NO puedo abrir google ni facebook

Mensaje por Pcsur2014 » 08 Jun 2015, 22:03

hola nuevamente...

he decido retomar el caso..

en realidad no hize lo que ustedes me dijeron

sin embargo, paso cierto tiempo...sin tocar el caso

y me halle con la sorpresa de por los menos 4

equipos tienen el mismo caso...y a su vez me detecto

unos troyanos.





aquí les dejos los que me arrojo sprocess.... y el infosat...(maquina 1)



(8-6-2015 16:59:27 GMT)

SProces v8.5 (c)2015 S.G.H. / Satinfo S.L.

-------------------------------------------

Sistema Operativo: EvoLite® (v5.1.2600) Service Pack 3

Internet Explorer: (v6.0.2900.5512) ;SP3;

Equipo: USUARIO1

Usuario: Administrador

Sesión de Usuario: Administrador



28 Procesos Activos:

C:\WINDOWS\SYSTEM32\SMSS.EXE

C:\WINDOWS\SYSTEM32\CSRSS.EXE

C:\WINDOWS\SYSTEM32\WINLOGON.EXE

C:\WINDOWS\SYSTEM32\SERVICES.EXE

C:\WINDOWS\SYSTEM32\LSASS.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SPOOLSV.EXE

C:\ARCHIVOS DE PROGRAMA\BURNAWARE PRO RETAIL BY MINIMAL\NMSACCESSU.EXE

C:\WINDOWS\EXPLORER.EXE

C:\WINDOWS\SYSTEM32\ALG.EXE

C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE

C:\WINDOWS\SYSTEM32\HKCMD.EXE

C:\ARCHIVOS DE PROGRAMA\ANALOG DEVICES\CORE\SMAX4PNP.EXE

C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\CONFIGURACIóN LOCAL\DATOS DE PROGRAMA\GOOGLE\UPDATE\1.3.27.5\GOOGLECRASHHANDLER.EXE

C:\ARCHIVOS DE PROGRAMA\WINZIP\WZQKPICK.EXE

C:\WINDOWS\SYSTEM32\WBEM\UNSECAPP.EXE

C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE

C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\MICROSOFT SHARED\OFFICESOFTWAREPROTECTIONPLATFORM\OSPPSVC.EXE

C:\ARCHIVOS DE PROGRAMA\MICROSOFT OFFICE\OFFICE14\EXCEL.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\ESCRITORIO\SPROCES (1)\SPROCES.EXE



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://45rjzas5aa8qa3h.directorio-w.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://9x882f1s9pas3g1.directorio-w.com

O1 - Hosts: 193.148.216.11 13iii.com

O1 - Hosts: 182.181.118.51 15660808.co.kr

O1 - Hosts: 185.39.100.171 2-spyware.com

O1 - Hosts: 80.165.96.116 247fixes.com

O1 - Hosts: 244.185.173.142 360.cn

O1 - Hosts: 233.218.74.182 360.com

O1 - Hosts: 47.76.57.114 360safe.cn

O1 - Hosts: 130.203.52.59 360safe.com

O1 - Hosts: 106.154.129.18 45pounds.com

O1 - Hosts: 95.187.30.125 51nb.com

O1 - Hosts: 97.45.201.245 9down.com

O1 - Hosts: 248.240.8.191 a-2.org

O1 - Hosts: 156.192.85.149 a188.x.akamai.net

O1 - Hosts: 145.225.243.0 abuse.ch

O1 - Hosts: 215.82.157.121 acs.pandasoftware.com

O1 - Hosts: 42.209.221.66 ad-aware-se.uptodown.com

O1 - Hosts: 206.229.41.92 ad.fastclick.net

O1 - Hosts: 195.6.199.132 ads.fastclick.net

O1 - Hosts: 10.120.113.252 agfirewall.ru

O1 - Hosts: 161.246.177.197 agnitum.com

...

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARCHIV~1\MICROS~1\Office14\GROOVEEX.DLL

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ARCHIV~1\MICROS~1\Office14\URLREDIR.DLL

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Archivos de programa\CCleaner\CCleaner.exe" /MONITOR

O4 - HKCU\..\Run: [CCleaner] "C:\Archivos de programa\CCleaner\CCleaner.exe" /AUTO

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [3DF2DDB8E09303B13C06EF177C5870417C1F1B1BC8599812] C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe

O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [SoundMAXPnP] C:\Archivos de programa\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [ISUSScheduler] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [CA8172C6666DD356443770CC60B6E6C6E1744C15B2F855B5] C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio Local')

O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Servicio Local')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')

O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Servicio de red')

O4 - Startup: Windows Anytime Upgrade.exe

O4 - Global Startup: Windows Update.exe

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Archivos de programa\WinZip\WZQKPICK.EXE

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1

O7 - HKCU\Software\Policies\Microsoft\Windows\System, DisableCMD=1

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, DisableRun=1

O8 - Extra context menu item: &Enviar a OneNote - res://C:\ARCHIV~1\MICROS~1\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~1\Office14\EXCEL.EXE/3000

O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIE.dll (HKLM)

O9 - Extra button: Notas &vinculadas de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (HKLM)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (HKLM)

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll

O20 - Winlogon Notify: DIMSNTFY - %SYSTEMROOT%\SYSTEM32\DIMSNTFY.DLL

O20 - Winlogon Notify: IGFXCUI - IGFXSRVC.DLL

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - %SystemRoot%\system32\webcheck.dll

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll

O22 - SharedTaskScheduler: Precargador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - %SystemRoot%\system32\browseui.dll

O22 - SharedTaskScheduler: Demonio de caché de las categorías de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll

O22 - ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\ARCHIV~1\MICROS~1\Office14\GROOVEEX.DLL



Información Adicional:

----------------------

Acceso Rapido ('Administrador'): BurnAware Professional.lnk = C:\Archivos de programa\BurnAware Pro Retail by minimaL\burnaware.exe

Acceso Rapido ('Administrador'): Google Chrome.lnk = C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Google\Chrome\Application\chrome.exe

Acceso Rapido ('Administrador'): Iniciar el explorador Internet Explorer.lnk = C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE

Acceso Rapido ('Administrador'): Mozilla Firefox.lnk = C:\Archivos de programa\Mozilla Firefox\firefox.exe

Clave "HKLM\...\Image File Execution Options\.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\a2servic.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ackwin32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\acs.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\advxdwin.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\agentsvr.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\agentw.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ahnsd.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\alerter.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\alertsvc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\alogserv.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\amon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\amon9x.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\anti-trojan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\antigen.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\antivirus.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ants.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\apimonitor.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\aplica32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\apvxdwin.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ashWebSv.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\atcon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\atguard.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\atro55en.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\atupdater.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\atwatch.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\aupdate.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\autodown.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\autotrace.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\autoupdate.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avcenter.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avconfig.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avconsol.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ave32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avgcc32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avgctrl.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avgemc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avgnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avgserv.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avgserv9.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avguard.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avgw.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avkpop.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avkserv.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avkservice.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avkwcl9.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avkwctl9.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avnotify.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avp32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avpcc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avpdos32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avpexec.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avpinst.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avpm.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avpmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avpnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avptc32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avpupd.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avrescue.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avsched32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avshadow.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avsynmgr.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avupgsvc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avwebloader.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avwin95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avwinnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avwsc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avwupd32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avxmonitor9x.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avxmonitornt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avxquar.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\avxw.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\azonealarm.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\bd_professional.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\bidef.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\bidserver.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\bipcp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\bipcpevalsetup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\bisp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\blackd.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\blackice.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\boot.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\bootwarn.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\borg2.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\bs120.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\BullGuard.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\callmsi.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ccapp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ccevtmgr.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cclaw.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ccpxysvc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ccsetmgr.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ccshtdwn.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cdp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cfgwiz.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cfiadmin.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cfiaudit.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cfind.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cfinet.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cfinet32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ChromeSetup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\clamauto.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\claw95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\claw95cf.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\claw95ct.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\clean.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cleaner.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cleaner3.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cleanpc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cmd.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cmgrdian.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cmon016.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ComboFix.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\connectionmonitor.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cpd.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cpdclnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cpf.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cpf9x206.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cpfnt206.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\csinject.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\csinsm32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\css1631.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ctfmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ctrl.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cv.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cwnb181.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\cwntdwmo.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\defalert.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\defscangui.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\defwatch.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\deputy.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\Diskmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\doors.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\dpf.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\drvins32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\drwatson.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\drweb32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\dumphive.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\dv95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\dv95_o.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\dvp95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\dvp95_0.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\earthagent.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ecengine.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ecls.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ecmd.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\edi.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\efinet32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\efpeadm.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\egui.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\EHttpSrv.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ekrn.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ent.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\esafe.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\escanh95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\escanhnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\escanv95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\espwatch.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\etrustcipe.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\evpn.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ewido.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\exantivirus-cnet.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\exit.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\expert.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\explored.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\f-agnt95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\f-prot.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\f-prot95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\f-stopw.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fa-setup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fact.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fameh32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fast.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fch32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fih32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\Filemon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\findviru.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\firewall.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\FirewallControlPanel.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\FirewallSettings.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fix-it.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\flowprotector.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fnrb32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fp-win.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fp-win_trial.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\FPAVServer.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fprot.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fprot95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\frw.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fsaa.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fsav.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fsav32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fsav530stbyb.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fsav530wtbyb.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fsav95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fsave32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fsgk32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fslaunch.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fsm32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fsma32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fsmb32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fssm32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fwenc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\fwinstall.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\gbmenu.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\gbpoll.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\GenericRenosFix.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\generics.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\gibe.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\GoogleToolbarInstaller_download_signed.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\gpedit.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\guard.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\guarddog.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\guardgui.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\guardhlp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\hacktracersetup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\HelpPane.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\hidec.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\HiJackThis.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\HJTInstall.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\HostsChk.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\htlog.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\hwpe.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\iamapp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\iamserv.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\iamstats.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ibmasn.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ibmavsp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\icload95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\icloadnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\icmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\icmoon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\icssuppnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\icsupp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\icsupp95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\icsuppnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\IEDFix.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\iface.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ifw2000.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\iomon98.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\iparmor.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\iris.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\isrv95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\jammer.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\jed.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\jedi.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\kav8.0.0.357es.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\kavlite40eng.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\kavpers40eng.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\kavsvc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\kerio-pf-213-en-win.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\kerio-wrl-421-en-win.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\kerio-wrp-421-en-win.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\killprocesssetup161.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\kis8.0.0.506latam.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\kpf.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\kpfw32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ldnetmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ldpro.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ldpromenu.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ldscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\licmgr.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\localnet.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\lockdown.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\lockdown2000.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\lookout.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\lsetup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\luall.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\luau.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\lucomserver.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\luinit.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\luspt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mbam.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mbamgui.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mbamservice.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mcadmin.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mcagent.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mcconsol.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mcmnhdlr.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mcshield.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mctool.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mcuimgr.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mcupdate.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mcvsrte.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mcvsshld.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mdll.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mfeann.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mfw2en.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mfweng3.02d30.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mgavrtcl.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mgavrte.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mghtml.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mgui.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\minilog.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\monitor.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\monsys32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\monsysnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\monwow.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\moolive.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mpfagent.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mpfservice.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mpftray.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mrflux.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\MSASCui.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\msblast.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\msconfig.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\msinfo32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\msn.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mspatch.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mssmmc32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mu0311ad.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mwatch.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\mxtask.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\n32scan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\n32scanw.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nai_vs_stat.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nav32_loader.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nav80try.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navap.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navapsvc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navapw32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navauto-protect.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navdx.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\naveng.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navengnavex15.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navex15.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navlu32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navrunr.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navsched.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navstub.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navw.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navw32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\navwnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nc2000.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ncinst4.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nd98spst.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ndd32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ndntspst.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\neomonitor.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\neowatchlog.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\netarmor.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\netcfg.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\netinfo.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\netmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\netscanpro.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\Netscape.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\netspyhunter-1.2.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\netstat.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\netutils.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nisserv.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nisum.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nmain.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nod32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\normist.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\norton_internet_secu_3.0_407.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\notstart.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\npf40_tw_98_nt_me_2k.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\npfmessenger.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nprotect.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\npscheck.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\npssvc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nsched32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ntdetect.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ntrtscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ntxconfig.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nui.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nupdate.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nupgrade.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nvapsvc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nvarch16.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nvc95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nvlaunch.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nvsvc32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nwinst4.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nwservice.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\nwtool16.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\offguard.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ogrc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\opera.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\Opera_964_int_Setup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ostronet.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\outpost.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\outpostinstall.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\outpostproinstall.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\padmin.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\panixk.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pathping.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pavcl.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pavproxy.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pavsched.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pavw.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pcc2002s902.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pcc2k_76_1436.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pccclient.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pccguide.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pcciomon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pccmain.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pccntmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pccpfw.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pccwin97.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pccwin98.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pcdsetup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pcfwallicon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pcip10117_0.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pcscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pcscanpdsetup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\penis32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\periscope.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\persfw.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\perswf.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pev.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pf2.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pfwadmin.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ping.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pingscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\platin.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pop3trap.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\poproxy.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\popscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\portdetective.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\portmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\portmonitor.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ppinupdt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pptbc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ppvstop.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\prckiller.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\Process.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\processmonitor.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\procexp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\procexplorerv1.0.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\Procmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\programauditor.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\proport.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\protectx.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pspf.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\purge.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pview.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\pview95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\qconsole.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\qserver.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\rapapp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\rav.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\rav7.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\rav7win.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\rav8win32eng.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\realmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\regedit.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\regedt32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\Regmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\rescue.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\rescue32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\Restart.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\route.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\routemon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\rrguard.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\rshell.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\rstrui.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\rtvscn95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\rulaunch.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\Safari.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\safeweb.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\SandboxieBITS.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\SandboxieCrypto.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\SandboxieDcomLaunch.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\SandboxieRpcSs.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\SandboxieWUAU.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\SbieCtrl.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\SbieSvc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sbserv.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\scan32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\scan95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\scanpm.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sched.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\schedapp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\scrscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\scvhosl.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sd.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sdclt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\serv95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\setupvameeval.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\setup_flowprotector_us.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sgssfw32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sh.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sharedaccess.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\shellspyinstall.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\shn.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\shstat.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\smc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\SmitfraudFix.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sofi.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\spf.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sphinx.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\spider.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\spysweeper.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\spyxx.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\SrchSTS.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\srwatch.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\ss3edit.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\st2.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\supftrl.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\supporter5.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sweep.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sweep95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sweepnet.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sweepsrv.sys.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\swnetsup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\swreg.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\swsc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\swxcacls.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\symproxysvc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\symtray.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\sysdoc32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\syshelp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\taskkill.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tasklist.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\taskmgr.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\taskmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\taumon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tauscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tbscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tca.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tcm.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tcpsvs32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tds-3.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tds2-98.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tds2-nt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tds2.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tfak.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tfak5.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tftpd.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tgbob.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\titanin.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\titaninxp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tmlisten.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tmntsrv.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tracerpt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\tracert.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\trjscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\trjsetup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\trojantrap3.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\UCCLSID.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\UI0Detect.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\undoboot.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\unzip.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\update.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\UserAccountControlSettings.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\VACFix.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vbcmserv.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vbcons.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vbust.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vbwin9x.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vbwinntw.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vccmserv.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vcleaner.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vcontrol.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vcsetup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vet32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vet95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vet98.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vettray.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vfsetup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vir-help.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\virusmdpersonalfirewall.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vmsrvc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vnlan300.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vnpc3000.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vpc32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vpc42.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vpcmap.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vpfw30s.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vptray.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vscan40.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vscenu6.02d30.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vsched.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vsecomr.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vshwin32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vsisetup.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vsmain.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vsmon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vsscan40.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vsstat.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vswin9xe.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vswinntse.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vswinperse.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\vvstat.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\w32dsm89.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\w9x.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\watchdog.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\webscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\webscanx.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\webtrap.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\WerFault.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wfindv32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wgfe95.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\whoswatchingme.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wimmun32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wingate.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\winhlpp32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wink.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\winmgm32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\winppr32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\winrecon.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\winroute.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\winservices.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\winsfcm.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wmias.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wmiav.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wnt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wradmin.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wrctrl.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\WS2Fix.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wsbgate.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wuauclt.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\wyvernworksfirewall.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\xpf202en.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\xscan.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\zapro.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\zapsetup3001.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\zatutor.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\zatutorzauinst.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\zauinst.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\zlh.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\zonalarm.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\zonalm2601.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\zonealarm.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\_avp.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\_avp32.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\_avpcc.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\_avpm.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Clave "HKLM\...\Image File Execution Options\_findviru.exe"

"Debugger"=""C:\Documents and Settings\Administrador\27F6461627473796E696D64614\winlogon.exe""

Ext.Google Chrome. ('Administrador') Id: aohghmighlieiainnegkcijnfilokake

Ext.Google Chrome. ('Administrador') Id: gmlllbghnfkpflemihljekbapjopfjik

Ext.Google Chrome. ('Administrador') Id: lccekmodgklaepjeofjdjpbminllajkg

Ext.Google Chrome. ('Administrador') Id: nmmhkkegccagdldgiimedpiccmgmieda

DataBases Google Chrome. ('Administrador'): Databases.db



Listado de Servicios (Carga Automatica):

----------------------------------------

O23 - Service: NMSAccessU - Unknown owner - C:\Archivos de programa\BurnAware Pro Retail by minimaL\nmsaccessu.exe



Listado de Servicios (Carga Manual):

------------------------------------

**O23 - Service: Servicio del administrador de discos lógicos (dmadmin) - Microsoft Corp., VERITAS Software - C:\WINDOWS\System32\dmadmin.exe

O23 - Service: Intel(R) PRO/1000 Network Connection Driver (E1000) - Intel Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\e1000325.sys

O23 - Service: ialm - Intel Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\ialmnt5.sys

O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Archivos de programa\Mozilla Maintenance Service\maintenanceservice.exe

O23 - Service: Controlador de vínculo paralelo directo (Ptilink) - Parallel Technologies, Inc. - C:\WINDOWS\SYSTEM32\DRIVERS\ptilink.sys

O23 - Service: Secdrv - Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. - C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys

O23 - Service: senfilt - Creative Technology Ltd. - C:\WINDOWS\SYSTEM32\drivers\senfilt.sys

O23 - Service: smwdm - Analog Devices, Inc. - C:\WINDOWS\SYSTEM32\drivers\smwdm.sys



Listado de Servicios (Deshabilitados):

--------------------------------------

**O23 - Service: dmboot - Microsoft Corp., Veritas Software - C:\WINDOWS\SYSTEM32\drivers\dmboot.sys



10 Servicios.

1 de Carga Automatica.

8 de Carga Manual.

1 Deshabilitados.



Listado de Programas Instalados:

--------------------------------

Adobe Flash Player ActiveX -> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe

Adobe Flash Player 10 Plugin -> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe

BurnAware Pro 2.3.2 Retail by minimaL -> "C:\Archivos de programa\BurnAware Pro Retail by minimaL\unins000.exe"

CCleaner -> "C:\Archivos de programa\CCleaner\uninst.exe"

Flash CS3 9.0 -> C:\Archivos de programa\Adobe\Flash CS3\Uninstall.exe

Mozilla Firefox 38.0.5 (x86 es-ES) -> "C:\Archivos de programa\Mozilla Firefox\uninstall\helper.exe"

Mozilla Maintenance Service -> "C:\Archivos de programa\Mozilla Maintenance Service\uninstall.exe"

Intel(R) Network Connections Drivers -> Prounstl.exe

Compresor WinRAR -> C:\Archivos de programa\Winrar\uninstall.exe

Safari -> MsiExec.exe /I{0A9C92A5-D27F-4BD9-9DB9-0EFD8C681E29}

Adobe Shockwave Player -> MsiExec.exe /X{211E8730-5681-49ED-BC6A-78C9F88E95F5}

FontNav -> MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}

CorelDRAW Graphics Suite X3 -> MsiExec.exe /I{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}

Intel(R) Extreme Graphics Driver -> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562

Adobe Reader 9 - Español -> MsiExec.exe /I{AC76BA86-7AD7-1034-7B44-A90000000001}

VBA -> MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}

ES -> MsiExec.exe /I{CBFAD664-763E-4A7D-BF92-BB0E493F3C66}

WinZip 15.0 -> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}

Update Manager -> MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}

Google Chrome -> "C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Google\Chrome\Application\43.0.2357.81\Installer\setup.exe" --uninstall --multi-install --chrome











(8-6-2015 17:00:47 (GMT))

EliStartPage v32.45 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 8 de Junio del 2015)

--------------------------------------------------

Sistema Operativo: EvoLite® (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-1715567821-823518204-1606980848-500

Cadenas Víricas: 24092



Lista de Acciones (por Acción Directa):

Por favor, envienos el INFOSAT.TXT y una muestra del fichero

C:\Muestras\WINDOWS ANYTIME UPGRADE.EXE.Muestra EliStartPage v32.45

a "virus@satinfo.es". Gracias.

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\MENú INICIO\PROGRAMAS\INICIO\WINDOWS ANYTIME UPGRADE.EXE --> Eliminado

Por favor, envienos el INFOSAT.TXT y una muestra del fichero

C:\Muestras\WINDOWS UPDATE.EXE.Muestra EliStartPage v32.45

a "virus@satinfo.es". Gracias.

C:\DOCUMENTS AND SETTINGS\ALL USERS\MENú INICIO\PROGRAMAS\INICIO\WINDOWS UPDATE.EXE --> Eliminado

Por favor, envienos el INFOSAT.TXT y una muestra del fichero

C:\Muestras\FAX Y ESCáNER DE WINDOWS.EXE.Muestra EliStartPage v32.45

a "virus@satinfo.es". Gracias.

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\MENú INICIO\FAX Y ESCáNER DE WINDOWS.EXE --> Eliminado

Por favor, envienos el INFOSAT.TXT y una muestra del fichero

C:\Muestras\WINDOWS DVD MAKER.EXE.Muestra EliStartPage v32.45

a "virus@satinfo.es". Gracias.

C:\DOCUMENTS AND SETTINGS\ALL USERS\MENú INICIO\WINDOWS DVD MAKER.EXE --> Eliminado

Por favor, envienos el INFOSAT.TXT y una muestra del fichero

C:\Muestras\INTERNET EXPLORER.EXE.Muestra EliStartPage v32.45

a "virus@satinfo.es". Gracias.

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\MENú INICIO\PROGRAMAS\INTERNET EXPLORER.EXE --> Eliminado

Por favor, envienos el INFOSAT.TXT y una muestra del fichero

C:\Muestras\WINDOWS MEDIA CENTER.EXE.Muestra EliStartPage v32.45

a "virus@satinfo.es". Gracias.

C:\DOCUMENTS AND SETTINGS\ALL USERS\MENú INICIO\PROGRAMAS\WINDOWS MEDIA CENTER.EXE --> Eliminado

Por favor, envienos el INFOSAT.TXT y una muestra del fichero

C:\Muestras\WINLOGON.EXE.Muestra EliStartPage v32.45

a "virus@satinfo.es". Gracias.

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE --> Eliminado

Eliminada Clave "HKLM\...\Image File Execution Options\.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\A2SERVIC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ACKWIN32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ACS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ADVXDWIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AGENTSVR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AGENTW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AHNSD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ALERTER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ALERTSVC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ALOGSERV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AMON9X.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ANTI-TROJAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ANTIGEN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ANTIVIRUS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ANTS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\APIMONITOR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\APLICA32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\APVXDWIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ASHWEBSV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ATCON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ATGUARD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ATRO55EN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ATUPDATER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ATWATCH.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AUPDATE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AUTODOWN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AUTOTRACE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AUTOUPDATE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVCENTER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVCONFIG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVCONSOL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVE32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVGCC32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVGCTRL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVGEMC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVGNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVGSERV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVGSERV9.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVGUARD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVGW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVKPOP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVKSERV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVKSERVICE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVKWCL9.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVKWCTL9.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVNOTIFY.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVP32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVPCC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVPDOS32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVPEXEC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVPINST.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVPM.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVPMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVPNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVPTC32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVPUPD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVRESCUE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVSCHED32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVSHADOW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVSYNMGR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVUPGSVC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVWEBLOADER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVWIN95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVWINNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVWSC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVWUPD32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVXMONITOR9X.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVXMONITORNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVXQUAR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AVXW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\AZONEALARM.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BD_PROFESSIONAL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BIDEF.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BIDSERVER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BIPCP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BIPCPEVALSETUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BISP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BLACKD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BLACKICE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BOOT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BOOTWARN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BORG2.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BS120.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\BULLGUARD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CALLMSI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CCAPP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CCEVTMGR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CCLAW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CCPXYSVC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CCSETMGR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CCSHTDWN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CDP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CFGWIZ.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CFIADMIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CFIAUDIT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CFIND.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CFINET.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CFINET32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CHROMESETUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CLAMAUTO.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CLAW95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CLAW95CF.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CLAW95CT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CLEAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CLEANER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CLEANER3.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CLEANPC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CMD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CMGRDIAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CMON016.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\COMBOFIX.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CONNECTIONMONITOR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CPD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CPDCLNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CPF.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CPF9X206.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CPFNT206.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CSINJECT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CSINSM32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CSS1631.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CTFMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CTRL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CWNB181.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\CWNTDWMO.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DEFALERT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DEFSCANGUI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DEFWATCH.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DEPUTY.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DISKMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DOORS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DPF.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DRVINS32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DRWATSON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DRWEB32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DUMPHIVE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DV95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DV95_O.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DVP95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\DVP95_0.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EARTHAGENT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ECENGINE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ECLS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ECMD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EDI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EFINET32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EFPEADM.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EGUI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EHTTPSRV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EKRN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ENT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ESAFE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ESCANH95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ESCANHNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ESCANV95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ESPWATCH.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ETRUSTCIPE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EVPN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EWIDO.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EXANTIVIRUS-CNET.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EXIT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EXPERT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\EXPLORED.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\F-AGNT95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\F-PROT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\F-PROT95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\F-STOPW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FA-SETUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FACT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FAMEH32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FAST.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FCH32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FIH32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FILEMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FINDVIRU.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FIREWALL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FIREWALLCONTROLPANEL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FIREWALLSETTINGS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FIX-IT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FLOWPROTECTOR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FNRB32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FP-WIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FP-WIN_TRIAL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FPAVSERVER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FPROT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FPROT95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FRW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSAA.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSAV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSAV32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSAV530STBYB.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSAV530WTBYB.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSAV95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSAVE32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSGK32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSLAUNCH.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSM32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSMA32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSMB32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FSSM32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FWENC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\FWINSTALL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\GBMENU.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\GBPOLL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\GENERICRENOSFIX.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\GENERICS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\GIBE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\GOOGLETOOLBARINSTALLER_DOWNLOAD_SIGNED.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\GPEDIT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\GUARD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\GUARDDOG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\GUARDGUI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\GUARDHLP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\HACKTRACERSETUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\HELPPANE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\HIDEC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\HIJACKTHIS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\HJTINSTALL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\HOSTSCHK.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\HTLOG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\HWPE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\IAMAPP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\IAMSERV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\IAMSTATS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\IBMASN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\IBMAVSP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ICLOAD95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ICLOADNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ICMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ICMOON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ICSSUPPNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ICSUPP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ICSUPP95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ICSUPPNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\IEDFIX.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\IFACE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\IFW2000.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\IOMON98.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\IPARMOR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\IRIS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ISRV95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\JAMMER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\JED.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\JEDI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\KAV8.0.0.357ES.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\KAVLITE40ENG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\KAVPERS40ENG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\KAVSVC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\KERIO-PF-213-EN-WIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\KERIO-WRL-421-EN-WIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\KERIO-WRP-421-EN-WIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\KILLPROCESSSETUP161.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\KIS8.0.0.506LATAM.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\KPF.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\KPFW32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LDNETMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LDPRO.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LDPROMENU.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LDSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LICMGR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LOCALNET.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LOCKDOWN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LOCKDOWN2000.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LOOKOUT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LSETUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LUALL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LUAU.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LUCOMSERVER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LUINIT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\LUSPT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MBAM.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MBAMGUI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MBAMSERVICE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MCADMIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MCAGENT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MCCONSOL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MCMNHDLR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MCSHIELD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MCTOOL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MCUIMGR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MCUPDATE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MCVSRTE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MCVSSHLD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MDLL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MFEANN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MFW2EN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MFWENG3.02D30.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MGAVRTCL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MGAVRTE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MGHTML.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MGUI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MINILOG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MONITOR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MONSYS32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MONSYSNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MONWOW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MOOLIVE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MPFAGENT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MPFSERVICE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MPFTRAY.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MRFLUX.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MSASCUI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MSBLAST.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MSCONFIG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MSINFO32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MSN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MSPATCH.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MSSMMC32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MU0311AD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MWATCH.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\MXTASK.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\N32SCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\N32SCANW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAI_VS_STAT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAV32_LOADER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAV80TRY.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVAP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVAPSVC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVAPW32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVAUTO-PROTECT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVDX.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVENG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVENGNAVEX15.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVEX15.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVLU32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVRUNR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVSCHED.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVSTUB.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVW32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NAVWNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NC2000.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NCINST4.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ND98SPST.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NDD32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NDNTSPST.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NEOMONITOR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NEOWATCHLOG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NETARMOR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NETCFG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NETINFO.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NETMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NETSCANPRO.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NETSCAPE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NETSPYHUNTER-1.2.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NETSTAT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NETUTILS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NISSERV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NISUM.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NMAIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NOD32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NORMIST.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NORTON_INTERNET_SECU_3.0_407.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NOTSTART.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NPF40_TW_98_NT_ME_2K.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NPFMESSENGER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NPROTECT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NPSCHECK.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NPSSVC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NSCHED32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NTDETECT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NTRTSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NTXCONFIG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NUI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NUPDATE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NUPGRADE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NVAPSVC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NVARCH16.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NVC95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NVLAUNCH.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NVSVC32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NWINST4.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NWSERVICE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\NWTOOL16.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\OFFGUARD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\OGRC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\OPERA.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\OPERA_964_INT_SETUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\OSTRONET.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\OUTPOST.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\OUTPOSTINSTALL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\OUTPOSTPROINSTALL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PADMIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PANIXK.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PATHPING.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PAVCL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PAVPROXY.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PAVSCHED.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PAVW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCC2002S902.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCC2K_76_1436.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCCCLIENT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCCGUIDE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCCIOMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCCMAIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCCNTMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCCPFW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCCWIN97.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCCWIN98.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCDSETUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCFWALLICON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCIP10117_0.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PCSCANPDSETUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PENIS32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PERISCOPE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PERSFW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PERSWF.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PEV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PF2.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PFWADMIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PING.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PINGSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PLATIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\POP3TRAP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\POPROXY.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\POPSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PORTDETECTIVE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PORTMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PORTMONITOR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PPINUPDT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PPTBC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PPVSTOP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PRCKILLER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PROCESS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PROCESSMONITOR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PROCEXP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PROCEXPLORERV1.0.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PROCMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PROGRAMAUDITOR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PROPORT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PROTECTX.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PSPF.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PURGE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PVIEW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\PVIEW95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\QCONSOLE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\QSERVER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RAPAPP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RAV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RAV7.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RAV7WIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RAV8WIN32ENG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\REALMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\REGEDIT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\REGEDT32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\REGMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RESCUE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RESCUE32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RESTART.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ROUTE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ROUTEMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RRGUARD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RSHELL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RSTRUI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RTVSCN95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\RULAUNCH.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SAFARI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SAFEWEB.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SANDBOXIEBITS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SANDBOXIECRYPTO.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SANDBOXIEDCOMLAUNCH.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SANDBOXIERPCSS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SANDBOXIEWUAU.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SBIECTRL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SBIESVC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SBSERV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SCAN32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SCAN95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SCANPM.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SCHED.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SCHEDAPP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SCRSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SCVHOSL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SDCLT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SERV95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SETUPVAMEEVAL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SETUP_FLOWPROTECTOR_US.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SGSSFW32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SH.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SHAREDACCESS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SHELLSPYINSTALL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SHN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SHSTAT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SMC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SMITFRAUDFIX.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SOFI.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SPF.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SPHINX.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SPIDER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SPYSWEEPER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SPYXX.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SRCHSTS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SRWATCH.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SS3EDIT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ST2.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SUPFTRL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SUPPORTER5.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SWEEP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SWEEP95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SWEEPNET.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SWEEPSRV.SYS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SWNETSUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SWREG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SWSC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SWXCACLS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SYMPROXYSVC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SYMTRAY.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SYSDOC32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\SYSHELP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TASKKILL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TASKLIST.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TASKMGR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TASKMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TAUMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TAUSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TBSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TCA.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TCM.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TCPSVS32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TDS-3.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TDS2-98.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TDS2-NT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TDS2.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TFAK.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TFAK5.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TFTPD.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TGBOB.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TITANIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TITANINXP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TMLISTEN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TMNTSRV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TRACERPT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TRACERT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TRJSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TRJSETUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\TROJANTRAP3.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\UCCLSID.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\UI0DETECT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\UNDOBOOT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\UNZIP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\UPDATE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\USERACCOUNTCONTROLSETTINGS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VACFIX.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VBCMSERV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VBCONS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VBUST.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VBWIN9X.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VBWINNTW.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VCCMSERV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VCLEANER.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VCONTROL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VCSETUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VET32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VET95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VET98.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VETTRAY.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VFSETUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VIR-HELP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VIRUSMDPERSONALFIREWALL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VMSRVC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VNLAN300.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VNPC3000.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VPC32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VPC42.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VPCMAP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VPFW30S.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VPTRAY.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSCAN40.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSCENU6.02D30.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSCHED.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSECOMR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSHWIN32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSISETUP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSMAIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSMON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSSCAN40.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSSTAT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSWIN9XE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSWINNTSE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VSWINPERSE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\VVSTAT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\W32DSM89.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\W9X.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WATCHDOG.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WEBSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WEBSCANX.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WEBTRAP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WERFAULT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WFINDV32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WGFE95.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WHOSWATCHINGME.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WIMMUN32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WINGATE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WINHLPP32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WINK.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WINMGM32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WINPPR32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WINRECON.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WINROUTE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WINSERVICES.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WINSFCM.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WMIAS.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WMIAV.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WNT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WRADMIN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WRCTRL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WS2FIX.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WSBGATE.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WUAUCLT.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\WYVERNWORKSFIREWALL.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\XPF202EN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\XSCAN.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ZAPRO.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ZAPSETUP3001.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ZATUTOR.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ZATUTORZAUINST.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ZAUINST.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ZLH.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ZONALARM.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ZONALM2601.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\ZONEALARM.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\_AVP.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\_AVP32.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\_AVPCC.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\_AVPM.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Eliminada Clave "HKLM\...\Image File Execution Options\_FINDVIRU.EXE"

"Debugger"=""C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE""

Entrada Eliminada "LowRiskFileTypes"=".exe"

Detectado HOSTS no Standar.

Restaurado HOSTS por el Original.

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE



(8-6-2015 17:02:51 (GMT))

EliStartPage v32.45 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 8 de Junio del 2015)

--------------------------------------------------

Sistema Operativo: EvoLite® (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-1715567821-823518204-1606980848-500

Cadenas Víricas: 24092



Lista de Acciones (por Exploración):

Explorando "C:\"



Nº Total de Directorios: 2244

Nº Total de Ficheros: 20001

Nº de Ficheros Analizados: 6354

Nº de Ficheros Infectados: 0

Nº de Ficheros Limpiados: 0





[url=http://www.imagebam.com/image/d6286f414452945][img]http://thumbnails107.imagebam.com/41446/d6286f414452945.jpg[/img][/url]



----------------------------------------------------------------------------------------------------------------------------------------------------

MAQUINA 2



(8-6-2015 17:57:42 GMT)

SProces v8.5 (c)2015 S.G.H. / Satinfo S.L.

-------------------------------------------

Sistema Operativo: Microsoft Windows XP (v5.1.2600) Service Pack 3

Parche MS08-067 (Servicio Servidor) NO Instalado.

Parche MS10-046 (Exploit.CPLlink) NO Instalado.

Parche MS14-021 (Seguridad IE8) NO Instalado.

Internet Explorer: (v8.0.6001.18702) 0

Equipo: WINSTALKER

Usuario: Administrador

Sesión de Usuario: Administrador



33 Procesos Activos:

C:\WINDOWS\SYSTEM32\SMSS.EXE

C:\WINDOWS\SYSTEM32\CSRSS.EXE

C:\WINDOWS\SYSTEM32\WINLOGON.EXE

C:\WINDOWS\SYSTEM32\SERVICES.EXE

C:\WINDOWS\SYSTEM32\LSASS.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\ARCHIVOS DE PROGRAMA\ALWIL SOFTWARE\AVAST5\AVASTSVC.EXE

C:\WINDOWS\SYSTEM32\SPOOLSV.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\ALG.EXE

C:\WINDOWS\EXPLORER.EXE

C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE

C:\ARCHIVOS DE PROGRAMA\ALWIL SOFTWARE\AVAST5\AVASTUI.EXE

C:\WINDOWS\SYSTEM32\CTFMON.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE

C:\WINDOWS\SYSTEM32\MSPAINT.EXE

C:\WINDOWS\EXPLORER.EXE

C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\MICROSOFT SHARED\OFFICESOFTWAREPROTECTIONPLATFORM\OSPPSVC.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\ESCRITORIO\SPROCES (1)\SPROCES.EXE



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.yahoo.com/?fr=hp-avast&type=avastbcl

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://ve.search.yahoo.com/yhs/search?type=avastbcl&hspart=avast&hsimp=yhs-001&p={searchTerms}

O1 - Hosts: 127.0.0.1 apps.corel.com

O1 - Hosts: 127.0.0.1 activate.adobe.com

O1 - Hosts: 127.0.0.1 practivate.adobe.com

O1 - Hosts: 127.0.0.1 ereg.adobe.com

O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com

O1 - Hosts: 127.0.0.1 wip3.adobe.com

O1 - Hosts: 127.0.0.1 3dns-3.adobe.com

O1 - Hosts: 127.0.0.1 3dns-2.adobe.com

O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com

O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com

O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com

O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com

O1 - Hosts: 127.0.0.1 activate-sea.adobe.com

O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com

O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com

O1 - Hosts: 127.0.0.1 adobeereg.com

O1 - Hosts: 127.0.0.1 http://www.adobeereg.com

O1 - Hosts: 127.0.0.1 activate.adobe.com

O1 - Hosts: 127.0.0.1 activate-sea.adobe.com

O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com

...

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARCHIV~1\MICROS~1\Office14\GROOVEEX.DLL

O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre7\bin\ssv.dll

O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Archivos de programa\Alwil Software\Avast5\aswWebRepIE.dll

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ARCHIV~1\MICROS~1\Office14\URLREDIR.DLL

O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Archivos de programa\Java\jre7\bin\jp2ssv.dll

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\isuspm.exe" -startup

O4 - HKLM\..\Run: [ISUSScheduler] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [AvastUI.exe] "C:\Archivos de programa\Alwil Software\Avast5\AvastUI.exe" /nogui

O4 - HKLM\..\Run: [BCSSync] "C:\Archivos de programa\Microsoft Office\Office14\BCSSync.exe" /DelayServices

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')

O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Servicio de red')

O8 - Extra context menu item: &Enviar a OneNote - res://C:\ARCHIV~1\MICROS~1\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~1\Office14\EXCEL.EXE/3000

O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIE.dll (HKLM)

O9 - Extra button: Notas &vinculadas de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (HKLM)

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (HKLM)

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll

O20 - Winlogon Notify: DIMSNTFY - %SYSTEMROOT%\SYSTEM32\DIMSNTFY.DLL

O20 - Winlogon Notify: IGFXCUI - IGFXDEV.DLL

O20 - Winlogon Notify: RAILNOTIFICATION - WINLOGONNOTIFICATION.DLL

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll

O22 - SharedTaskScheduler: Precargador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - %SystemRoot%\system32\browseui.dll

O22 - SharedTaskScheduler: Demonio de caché de las categorías de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll

O22 - ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\ARCHIV~1\MICROS~1\Office14\GROOVEEX.DLL



Información Adicional:

----------------------

Acceso Rapido ('Administrador'): Google Chrome.lnk = C:\Archivos de programa\Google\Chrome\Application\chrome.exe

Acceso Rapido ('Administrador'): Iniciar el explorador Internet Explorer.lnk = C:\Archivos de programa\Internet Explorer\iexplore.exe

Clave "HKLM\...\Image File Execution Options\notepad.exe"

"Debugger"=""C:\Archivos de programa\Notepad2\Notepad2.exe" /z"

Ext.Google Chrome. ('Administrador') Id: aohghmighlieiainnegkcijnfilokake

Ext.Google Chrome. ('Administrador') Id: apdfllckaahabafndbhieahigkjlhalf

Ext.Google Chrome. ('Administrador') Id: blpcfgokakmgnkcojhhkbfbldkacnbeo

Ext.Google Chrome. ('Administrador') Id: coobgpohoikkiipiblmjeljniedjpjpf

Ext.Google Chrome. ('Administrador') Id: gmlllbghnfkpflemihljekbapjopfjik

Ext.Google Chrome. ('Administrador') Id: lccekmodgklaepjeofjdjpbminllajkg

Ext.Google Chrome. ('Administrador') Id: nmmhkkegccagdldgiimedpiccmgmieda

Ext.Google Chrome. ('Administrador') Id: pjkljhegncpnkpknbcohdijeoejaedia

DataBases Google Chrome. ('Administrador'): Databases.db

DataBases Google Chrome. ('Administrador'): Databases.db-journal

Tarea Programada: C:\WINDOWS\Tasks\avast! Emergency Update.job



Listado de Servicios (Carga Automatica):

----------------------------------------

O23 - Service: avast! HardwareID (aswHwid) - AVAST Software - C:\WINDOWS\system32\drivers\aswHwid.sys

O23 - Service: aswMonFlt - AVAST Software - C:\WINDOWS\system32\drivers\aswMonFlt.sys

O23 - Service: avast! Antivirus - AVAST Software - C:\Archivos de programa\Alwil Software\Avast5\AvastSvc.exe

O23 - Service: Google Update Servicio (gupdate) (gupdate) - Google Inc. - C:\Archivos de programa\Google\Update\GoogleUpdate.exe



Listado de Servicios (Carga Manual):

------------------------------------

O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe

O23 - Service: Ambfilt - Creative - C:\WINDOWS\SYSTEM32\drivers\Ambfilt.sys

**O23 - Service: Servicio del administrador de discos lógicos (dmadmin) - Microsoft Corp., VERITAS Software - C:\WINDOWS\System32\dmadmin.exe

O23 - Service: Google Update Servicio (gupdatem) (gupdatem) - Google Inc. - C:\Archivos de programa\Google\Update\GoogleUpdate.exe

O23 - Service: Controlador de bus de Microsoft UAA para High Definition Audio (HDAudBus) - Windows (R) Server 2003 DDK provider - C:\WINDOWS\SYSTEM32\DRIVERS\HDAudBus.sys

O23 - Service: ialm - Intel Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\igxpmp32.sys

O23 - Service: Service for Realtek HD Audio (WDM) (IntcAzAudAddService) - Realtek Semiconductor Corp. - C:\WINDOWS\SYSTEM32\drivers\RtkHDAud.sys

O23 - Service: Monfilt - Creative Technology Ltd. - C:\WINDOWS\SYSTEM32\drivers\Monfilt.sys

O23 - Service: Controlador de vínculo paralelo directo (Ptilink) - Parallel Technologies, Inc. - C:\WINDOWS\SYSTEM32\DRIVERS\ptilink.sys

O23 - Service: Realtek 10/100/1000 PCI NIC Family NDIS XP Driver (RTL8023xp) - Realtek Semiconductor Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\Rtnicxp.sys

O23 - Service: Secdrv - Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. - C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys



Listado de Servicios (Deshabilitados):

--------------------------------------

**O23 - Service: dmboot - Microsoft Corp., Veritas Software - C:\WINDOWS\SYSTEM32\drivers\dmboot.sys

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Archivos de programa\Java\jre7\bin\jqs.exe" -service -config "C:\Archivos de programa\Java\jre7\lib\deploy\jqs\jqs.con (file missing)



17 Servicios.

4 de Carga Automatica.

11 de Carga Manual.

2 Deshabilitados.



Listado de Programas Instalados:

--------------------------------

avast! Free Antivirus -> C:\Archivos de programa\Alwil Software\Avast5\Setup\Instup.exe /control_panel /instop:uninstall

Flash CS3 9.0 -> C:\Archivos de programa\Adobe\Flash CS3\Uninstall.exe

Google Chrome -> "C:\Archivos de programa\Google\Chrome\Application\43.0.2357.81\Installer\setup.exe" --uninstall --multi-install --chrome --system-level

Intel(R) Graphics Media Accelerator Driver -> C:\WINDOWS\system32\igxpun.exe -uninstall

Notepad2 (Reemplazo del Bloc de Notas) -> "C:\Archivos de programa\Notepad2\uninstall.exe"

WinRAR 5.01 (32-bit) -> C:\Archivos de programa\WinRAR\uninstall.exe

Java 7 Update 51 -> MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217051FF}

FontNav -> MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}

Adobe Flash Player 12 ActiveX -> MsiExec.exe /X{52793F88-BF4D-4AA6-8696-80E72CE758B1}

Google Update Helper -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}

CorelDRAW Graphics Suite X3 -> MsiExec.exe /I{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}

VC_CRT_x86 -> MsiExec.exe /I{8054D734-39C7-463D-B764-9C883982B8F9}

Adobe Flash Player 12 Plugin -> MsiExec.exe /X{934168C8-55AC-4593-A138-E64BA8367E6E}

Google Update Helper -> MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

Adobe Reader 9.5.0 - Español -> MsiExec.exe /I{AC76BA86-7AD7-1034-7B44-A95000000001}

VBA -> MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}

REALTEK GbE & FE Ethernet PCI-E NIC Driver -> C:\Archivos de programa\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x000a -removeonly

ES -> MsiExec.exe /I{CBFAD664-763E-4A7D-BF92-BB0E493F3C66}

Realtek High Definition Audio Driver -> RtlUpd.exe -r -m -nrg2709

Update Manager -> MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}

Adobe Shockwave Player 12.0 -> MsiExec.exe /X{FF2A5498-4EFE-430F-A138-7EB365DBEBAD}





(8-6-2015 17:59:13 (GMT))

EliStartPage v32.45 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 8 de Junio del 2015)

--------------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-329068152-1708537768-1417001333-500

Cadenas Víricas: 24092



Lista de Acciones (por Acción Directa):

C:\WINDOWS\ALCMTR.EXE --> Eliminado SpyRealtek

Eliminada Clave "HKLM\...\Image File Execution Options\NOTEPAD.EXE"

"Debugger"=""C:\ARCHIVOS DE PROGRAMA\NOTEPAD2\NOTEPAD2.EXE" /Z"

Entrada Eliminada "LowRiskFileTypes"=".js;.zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.hta;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;.ade;.adp;.bas;.chm;.cmd;.cpl;.crt;.dll;.hlp;.inf;.ins;.isp;.jse;.lnk;.mdb;.mde;.msc;.msp;.mst;.pcd;.pif;.scr;.sct;.shs;.url;.vb;.vbe;.vbs;.wsc;.wsf;.wsh"

Detectado HOSTS no Standar.

Restaurado HOSTS por el Original.

No detectado Parche MS08-067 de Microsoft instalado. (SServidor)

No detectado Parche MS10-046 de Microsoft instalado. (Exploit.CPLlink)

No detectado Parche MS14-021 de Microsoft instalado. (Seguridad IE8)

Eliminada Carpeta "C:\WINDOWS\SYSTEM32\Adobe"

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE



(8-6-2015 18:17:03 (GMT))

EliStartPage v32.45 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 8 de Junio del 2015)

--------------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-329068152-1708537768-1417001333-500

Cadenas Víricas: 24092



Lista de Acciones (por Exploración):

Explorando "C:\"



Nº Total de Directorios: 4965

Nº Total de Ficheros: 27516

Nº de Ficheros Analizados: 9845

Nº de Ficheros Infectados: 0

Nº de Ficheros Limpiados: 0





[url=http://www.imagebam.com/image/bbfc77414457476][img]http://thumbnails107.imagebam.com/41446/bbfc77414457476.jpg[/img][/url]



------------------------------------------------------------------------------------------------------------------------------------



Maquina 3



(8-6-2015 17:52:49 GMT)

SProces v8.5 (c)2015 S.G.H. / Satinfo S.L.

-------------------------------------------

Sistema Operativo: Microsoft Windows XP (v5.1.2600) Service Pack 3

Parche MS08-067 (Servicio Servidor) NO Instalado.

Parche MS10-046 (Exploit.CPLlink) NO Instalado.

Parche MS14-021 (Seguridad IE8) NO Instalado.

Internet Explorer: (v6.0.2900.2180) ;SP2;

Equipo: AA-11

Usuario: Administrador

Sesión de Usuario: Administrador



25 Procesos Activos:

C:\WINDOWS\SYSTEM32\SMSS.EXE

C:\WINDOWS\SYSTEM32\CSRSS.EXE

C:\WINDOWS\SYSTEM32\WINLOGON.EXE

C:\WINDOWS\SYSTEM32\SERVICES.EXE

C:\WINDOWS\SYSTEM32\LSASS.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\ARCHIVOS DE PROGRAMA\PSAFE\TOTAL\SAFEMON\QHACTIVEDEFENSE.EXE

C:\WINDOWS\EXPLORER.EXE

C:\WINDOWS\SYSTEM32\SPOOLSV.EXE

C:\WINDOWS\SYSTEM32\IGFXTRAY.EXE

C:\WINDOWS\SYSTEM32\HKCMD.EXE

C:\ARCHIVOS DE PROGRAMA\ANALOG DEVICES\CORE\SMAX4PNP.EXE

C:\ARCHIVOS DE PROGRAMA\PSAFE\TOTAL\SAFEMON\QHSAFETRAY.EXE

C:\WINDOWS\SYSTEM32\CTFMON.EXE

C:\ARCHIVOS DE PROGRAMA\MESSENGER\MSMSGS.EXE

C:\ARCHIVOS DE PROGRAMA\WINZIP\WZQKPICK.EXE

C:\WINDOWS\SYSTEM32\IPROSETMONITOR.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\MICROSOFT SHARED\OFFICESOFTWAREPROTECTIONPLATFORM\OSPPSVC.EXE

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\ESCRITORIO\SPROCES (1)\SPROCES.EXE



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.psafe.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARCHIV~1\MICROS~4\Office14\GROOVEEX.DLL

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ARCHIV~1\MICROS~4\Office14\URLREDIR.DLL

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [dcrunwvfev] wscript.exe //B "C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\dcrunwvfev..vbs"

O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [SoundMAXPnP] C:\Archivos de programa\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [QHSafeTray] "C:\Archivos de programa\PSafe\Total\safemon\QHSafeTray.exe" /start

O4 - HKLM\..\Run: [dcrunwvfev] wscript.exe //B "C:\DOCUME~1\ADMINI~1\CONFIG~1\Temp\dcrunwvfev..vbs"

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio Local')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')

O4 - Global Startup: Acelerador de inicio de AutoCAD.lnk = C:\Archivos de programa\Archivos comunes\Autodesk Shared\acstart17.exe

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Archivos de programa\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: &Enviar a OneNote - res://C:\ARCHIV~1\MICROS~4\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~4\Office14\EXCEL.EXE/3000

O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIE.dll (HKLM)

O9 - Extra button: Notas &vinculadas de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (HKLM)

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll

O20 - Winlogon Notify: IGFXCUI - IGFXSRVC.DLL

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - %SystemRoot%\system32\webcheck.dll

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll

O21 - SSODL: UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll

O22 - SharedTaskScheduler: Precargador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - %SystemRoot%\system32\browseui.dll

O22 - SharedTaskScheduler: Demonio de caché de las categorías de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll

O22 - ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\ARCHIV~1\MICROS~4\Office14\GROOVEEX.DLL



Información Adicional:

----------------------

Acceso Rapido ('Administrador'): Google Chrome.lnk = C:\Archivos de programa\Google\Chrome\Application\chrome.exe

Acceso Rapido ('Administrador'): Iniciar el explorador Internet Explorer.lnk = C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE

Acceso Rapido ('Administrador'): Reproductor de Windows Media.lnk = C:\Archivos de programa\Windows Media Player\wmplayer.exe /prefetch:1

.scr (HKCR): AutoCADScriptFile -> "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"

Ext.Google Chrome. ('Administrador') Id: eooncjejnppfjjklapaamhcdmjbilmde C:\Documents and Settings\Administrador\Datos de programa\BabSolution\CR\Delta.crx

Ext.Google Chrome. ('Administrador') Id: gmlllbghnfkpflemihljekbapjopfjik

Ext.Google Chrome. ('Administrador') Id: lccekmodgklaepjeofjdjpbminllajkg

Ext.Google Chrome. ('Administrador') Id: nmmhkkegccagdldgiimedpiccmgmieda

DataBases Google Chrome. ('Administrador'): Databases.db



Listado de Servicios (Carga Automatica):

----------------------------------------

O23 - Service: Intel(R) PROSet Monitoring Service - Intel Corporation - C:\WINDOWS\system32\IProsetMonitor.exe

O23 - Service: KMService - Unknown owner - C:\WINDOWS\system32\srvany.exe (file missing)

O23 - Service: PSafe Total (QHActiveDefense) - Unknown owner - C:\Archivos de programa\PSafe\Total\safemon\QHActiveDefense.exe

O23 - Service: S - Unknown owner - C:\WINDOWS\SYSTEM32\C (file missing)



Listado de Servicios (Carga Manual):

------------------------------------

O23 - Service: 360Safe Anti Hacker Service (360AntiHacker) - 360.cn - C:\WINDOWS\SYSTEM32\Drivers\360AntiHacker.sys

O23 - Service: 360AvFlt mini-filter driver (360AvFlt) - 360.cn - C:\WINDOWS\SYSTEM32\DRIVERS\360AvFlt.sys

O23 - Service: 360Safe Camera Filter Service (360Camera) - 360.cn - C:\WINDOWS\SYSTEM32\Drivers\360Camera.sys

O23 - Service: Autodesk Licensing Service - Autodesk - C:\Archivos de programa\Archivos comunes\Autodesk Shared\Service\AdskScSrv.exe

O23 - Service: Controlador WDM de SoundFusion(TM) (cwrwdm) - Crystal Semiconductor Corp. - C:\WINDOWS\SYSTEM32\DRIVERS\cwrwdm.sys

**O23 - Service: Servicio del administrador de discos lógicos (dmadmin) - Microsoft Corp., VERITAS Software - C:\WINDOWS\System32\dmadmin.exe

O23 - Service: Intel(R) PRO/1000 Network Connection Driver (E1000) - Intel Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\e1000325.sys

O23 - Service: Google Update Servicio (gupdate) (gupdate) - Google Inc. - C:\Archivos de programa\Google\Update\GoogleUpdate.exe

O23 - Service: Google Update Servicio (gupdatem) (gupdatem) - Google Inc. - C:\Archivos de programa\Google\Update\GoogleUpdate.exe

O23 - Service: ialm - Intel Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\ialmnt5.sys

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Archivos de programa\Archivos comunes\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: Controlador de vínculo paralelo directo (Ptilink) - Parallel Technologies, Inc. - C:\WINDOWS\SYSTEM32\DRIVERS\ptilink.sys

O23 - Service: Controlador de Windows NT del adaptador Fast Ethernet PCI basado en Realtek RTL8139(A/B/C) (rtl8139) - Realtek Semiconductor Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.SYS

O23 - Service: Secdrv - Unknown owner - C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys

O23 - Service: senfilt - Creative Technology Ltd. - C:\WINDOWS\SYSTEM32\drivers\senfilt.sys

O23 - Service: smwdm - Analog Devices, Inc. - C:\WINDOWS\SYSTEM32\drivers\smwdm.sys

O23 - Service: Intel(R) Graphics Chipset (KCH) Driver ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91}) - Intel Corporation - C:\WINDOWS\SYSTEM32\drivers\ialmkchw.sys



Listado de Servicios (Deshabilitados):

--------------------------------------

**O23 - Service: dmboot - Microsoft Corp., Veritas Software - C:\WINDOWS\SYSTEM32\drivers\dmboot.sys

O23 - Service: Acceso a dispositivo de interfaz humana (HidServ) - Unknown owner - %SystemRoot%\System32\svchost.exe -k netsvcs - C:\WINDOWS\System32\hidserv.dll (file missing)



23 Servicios.

4 de Carga Automatica.

17 de Carga Manual.

2 Deshabilitados.



Listado de Programas Instalados:

--------------------------------

Autodesk DWF Viewer -> C:\ARCHIV~1\Autodesk\AUTODE~1\Setup.exe /remove /q0

Delta Chrome Toolbar -> "C:\Documents and Settings\Administrador\Datos de programa\BabSolution\Shared\GUninstaller.exe" -key "Delta Chrome Toolbar" -rmkey -rmbus "Delta Chrome Toolbar" -ask -plgdll enhancedNT -nontfy

Flash CS3 9.0 -> C:\Archivos de programa\Adobe\Flash CS3\Uninstall.exe

Google Chrome -> "C:\Archivos de programa\Google\Chrome\Application\43.0.2357.81\Installer\setup.exe" --uninstall --multi-install --chrome --system-level

Windows Installer 3.1 (KB893803) -> "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"

PSafe Total -> C:\Archivos de programa\PSafe\Total\Uninstall.exe

SoftwareUpdater -> C:\Archivos de programa\SoftwareUpdater\uninstall.exe

FontNav -> MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}

Analizador de MSXML 6.0 -> MsiExec.exe /I{5661DB2D-A5AF-4D0F-B34E-3CD45EC6B607}

AutoCAD 2007 - Español -> MsiExec.exe /I{5783F2D7-5001-040A-0002-0060B0CE6BBA}

Google Update Helper -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}

CorelDRAW Graphics Suite X3 -> MsiExec.exe /I{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}

VC_CRT_x86 -> MsiExec.exe /I{8054D734-39C7-463D-B764-9C883982B8F9}

Macromedia Flash Player 8 -> MsiExec.exe /X{885A63EA-382B-4DD4-A755-14809B8557D6}

Intel(R) Extreme Graphics Driver -> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562

Macromedia Flash 8 Video Encoder -> MsiExec.exe /X{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}

Macromedia Flash Player 8 Plugin -> MsiExec.exe /X{91057632-CA70-413C-B628-2D3CDBBB906B}

Macromedia FreeHand MXa -> RunDll32 C:\ARCHIV~1\ARCHIV~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Archivos de programa\InstallShield Installation Information\{939740B5-0064-4779-854A-8C1086181C05}\Setup.exe" -l0xa UNINSTALL

VBA -> MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}

ES -> MsiExec.exe /I{CBFAD664-763E-4A7D-BF92-BB0E493F3C66}

WinZip 15.0 -> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}

Update Manager -> MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}

Macromedia Extension Manager -> MsiExec.exe /I{F443F171-B49B-4645-915C-580E7ED79992}

Intel(R) Network Connections 18.3.62.0 -> MsiExec.exe /i{FCF3ECF7-7AE0-4E26-B387-09A3A80B79CC} ARPREMOVE=1











(8-6-2015 17:53:27 (GMT))

EliStartPage v32.45 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 8 de Junio del 2015)

--------------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-329068152-1958367476-725345543-500

Cadenas Víricas: 24092



Lista de Acciones (por Acción Directa):

No detectado Parche MS08-067 de Microsoft instalado. (SServidor)

No detectado Parche MS10-046 de Microsoft instalado. (Exploit.CPLlink)

No detectado Parche MS14-021 de Microsoft instalado. (Seguridad IE8)

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE



(8-6-2015 17:56:48 (GMT))

EliStartPage v32.45 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 8 de Junio del 2015)

--------------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-329068152-1958367476-725345543-500

Cadenas Víricas: 24092



Lista de Acciones (por Exploración):

Explorando "C:\"



Nº Total de Directorios: 3281

Nº Total de Ficheros: 31287

Nº de Ficheros Analizados: 11846

Nº de Ficheros Infectados: 0

Nº de Ficheros Limpiados: 0



(8-6-2015 18:01:58 (GMT))

EliStartPage v32.45 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 8 de Junio del 2015)

--------------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1.2600) SERVICE PACK 3

Usuario: Administrador

ID de Usuario: S-1-5-21-329068152-1958367476-725345543-500

Cadenas Víricas: 24092



Lista de Acciones (por Cierre):

Detectados Programas Potecialmente No Deseados (PUPs).

Ejecute el EliPUPs para proceder con su Desinstalación.

"SoftwareUpdater"





[url=http://www.imagebam.com/image/b7d677414457764][img]http://thumbnails107.imagebam.com/41446/b7d677414457764.jpg[/img][/url]



-----------------------------------------------------------------------------------------------------------------------------



Maquina 4





(8-6-2015 17:57:26 GMT)

SProces v8.5 (c)2015 S.G.H. / Satinfo S.L.

-------------------------------------------

Sistema Operativo: Microsoft Windows XP (v5.1.2600) Service Pack 3

Parche MS08-067 (Servicio Servidor) NO Instalado.

Parche MS10-046 (Exploit.CPLlink) NO Instalado.

Parche MS14-021 (Seguridad IE8) NO Instalado.

Internet Explorer: (v6.0.2900.2180) ;SP2;

Equipo: AA-19

Usuario: Alumno

Sesión de Usuario: Alumno



29 Procesos Activos:

C:\WINDOWS\SYSTEM32\SMSS.EXE

C:\WINDOWS\SYSTEM32\CSRSS.EXE

C:\WINDOWS\SYSTEM32\WINLOGON.EXE

C:\WINDOWS\SYSTEM32\SERVICES.EXE

C:\WINDOWS\SYSTEM32\LSASS.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\ARCHIVOS DE PROGRAMA\AVAST SOFTWARE\AVAST\AVASTSVC.EXE

C:\WINDOWS\EXPLORER.EXE

C:\WINDOWS\SYSTEM32\SPOOLSV.EXE

C:\ARCHIVOS DE PROGRAMA\ASKPARTNERNETWORK\TOOLBAR\APNMCP.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\RTHDCPL.EXE

C:\ARCHIVOS DE PROGRAMA\AVAST SOFTWARE\AVAST\AVASTUI.EXE

C:\ARCHIVOS DE PROGRAMA\ASKPARTNERNETWORK\TOOLBAR\UPDATER\TBNOTIFIER.EXE

C:\WINDOWS\SYSTEM32\CTFMON.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\ARCHIVOS DE PROGRAMA\GOOGLE\CHROME\APPLICATION\CHROME.EXE

C:\DOCUMENTS AND SETTINGS\ALUMNO\ESCRITORIO\SPROCES (1)\SPROCES.EXE



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.ve/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

R3 - URLSearchHook: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)

O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARCHIV~1\MICROS~2\Office14\GROOVEEX.DLL

O2 - BHO: (no name) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - (no file)

O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\ARCHIV~1\MICROS~2\Office14\URLREDIR.DLL

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Avdodo] C:\Documents and Settings\Alumno\Datos de programa\Avdodo.exe

O4 - HKCU\..\Run: [Evdods] C:\Documents and Settings\Alumno\Datos de programa\Evdods.exe

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [AvastUI.exe] "C:\Archivos de programa\AVAST Software\Avast\AvastUI.exe" /nogui

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [ApnTBMon] "C:\Archivos de programa\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"

O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\ISUSPM.exe" -startup

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio Local')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')

O4 - Global Startup: Acelerador de inicio de AutoCAD.lnk = C:\Archivos de programa\Archivos comunes\Autodesk Shared\acstart17.exe

O8 - Extra context menu item: &Enviar a OneNote - res://C:\ARCHIV~1\MICROS~2\Office14\ONBttnIE.dll/105

O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office14\EXCEL.EXE/3000

O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIE.dll (HKLM)

O9 - Extra button: iRobinHood Partners Addon - {54E67346-EE5A-45B6-82AA-4F0BB28C79C2} - (no file) (HKLM)

O9 - Extra button: Notas &vinculadas de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (HKLM)

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll

O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - %SystemRoot%\system32\webcheck.dll

O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll

O22 - SharedTaskScheduler: Precargador Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - %SystemRoot%\system32\browseui.dll

O22 - SharedTaskScheduler: Demonio de caché de las categorías de componente - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll

O22 - ShellExecuteHooks: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\ARCHIV~1\MICROS~2\Office14\GROOVEEX.DLL



Información Adicional:

----------------------

Acceso Rapido ('Alumno'): Google Chrome.lnk = C:\Archivos de programa\Google\Chrome\Application\chrome.exe

Acceso Rapido ('Alumno'): Iniciar el explorador Internet Explorer.lnk = C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE

Acceso Rapido ('Alumno'): Reproductor de Windows Media.lnk = C:\Archivos de programa\Windows Media Player\wmplayer.exe /prefetch:1

.scr (HKCR): AutoCADScriptFile -> "C:\WINDOWS\system32\NOTEPAD.EXE" "%1"

Clave "HKLM\...\Image File Execution Options\DatamngrCoordinator.exe"

"Debugger"="tasklist.exe"

Ext.Google Chrome. ('Alumno') Id: aaaaadgepjkdffhjbkfjgnnffnfcffbg C:\Documents and Settings\All Users\Datos de programa\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaadgepjkdffhjbkfjgnnffnfcffbg.crx

Ext.Google Chrome. ('Alumno') Id: aohghmighlieiainnegkcijnfilokake

Ext.Google Chrome. ('Alumno') Id: apdfllckaahabafndbhieahigkjlhalf

Ext.Google Chrome. ('Alumno') Id: blpcfgokakmgnkcojhhkbfbldkacnbeo

Ext.Google Chrome. ('Alumno') Id: coobgpohoikkiipiblmjeljniedjpjpf

Ext.Google Chrome. ('Alumno') Id: ejihekcemjghahmoofljdfbgkocndmem

Ext.Google Chrome. ('Alumno') Id: gmlllbghnfkpflemihljekbapjopfjik

Ext.Google Chrome. ('Alumno') Id: gomekmidlodglbbmalcneegieacbdmki C:\Archivos de programa\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx

Ext.Google Chrome. ('Alumno') Id: iidmoehhpbghchkaogkhmcckhlhebekn C:\Archivos de programa\iRobinHood\iRobinHood Addon\iRobinHoodPartnersExtension12_86.crx

Ext.Google Chrome. ('Alumno') Id: lccekmodgklaepjeofjdjpbminllajkg

Ext.Google Chrome. ('Alumno') Id: nmmhkkegccagdldgiimedpiccmgmieda

Ext.Google Chrome. ('Alumno') Id: pjkljhegncpnkpknbcohdijeoejaedia

DataBases Google Chrome. ('Alumno'): Databases.db

DataBases Google Chrome. ('Alumno'): Databases.db-journal

Tarea Programada: C:\WINDOWS\Tasks\avast! Emergency Update.job



Listado de Servicios (Carga Automatica):

----------------------------------------

O23 - Service: Servicio de actualización Ask (APNMCP) - APN LLC. - C:\Archivos de programa\AskPartnerNetwork\Toolbar\apnmcp.exe

O23 - Service: avast! HardwareID (aswHwid) - AVAST Software - C:\WINDOWS\system32\drivers\aswHwid.sys

O23 - Service: aswMonFlt - AVAST Software - C:\WINDOWS\system32\drivers\aswMonFlt.sys

O23 - Service: avast! Antivirus - AVAST Software - C:\Archivos de programa\AVAST Software\Avast\AvastSvc.exe

O23 - Service: Google Update Servicio (gupdate) (gupdate) - Google Inc. - C:\Archivos de programa\Google\Update\GoogleUpdate.exe

O23 - Service: KMService - Unknown owner - C:\WINDOWS\system32\srvany.exe



Listado de Servicios (Carga Manual):

------------------------------------

O23 - Service: Autodesk Licensing Service - Autodesk - C:\Archivos de programa\Archivos comunes\Autodesk Shared\Service\AdskScSrv.exe

O23 - Service: Servicio del administrador de discos lógicos (dmadmin) - Microsoft Corp., VERITAS Software - C:\WINDOWS\System32\dmadmin.exe

O23 - Service: eopkeqp - Unknown owner - C:\WINDOWS\system32\02.tmp (file missing)

O23 - Service: Google Update Servicio (gupdatem) (gupdatem) - Google Inc. - C:\Archivos de programa\Google\Update\GoogleUpdate.exe

O23 - Service: Microsoft UAA Bus Driver for High Definition Audio (HDAudBus) - Windows (R) Server 2003 DDK provider - C:\WINDOWS\SYSTEM32\DRIVERS\HDAudBus.sys

O23 - Service: hxnnyweh - Unknown owner - C:\WINDOWS\system32\03.tmp (file missing)

O23 - Service: Service for Realtek HD Audio (WDM) (IntcAzAudAddService) - Realtek Semiconductor Corp. - C:\WINDOWS\SYSTEM32\drivers\RtkHDAud.sys

O23 - Service: Controlador de vínculo paralelo directo (Ptilink) - Parallel Technologies, Inc. - C:\WINDOWS\SYSTEM32\DRIVERS\ptilink.sys

O23 - Service: Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver (RTLE8023xp) - Realtek Semiconductor Corporation - C:\WINDOWS\SYSTEM32\DRIVERS\Rtenicxp.sys

O23 - Service: Secdrv - Unknown owner - C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys



Listado de Servicios (Deshabilitados):

--------------------------------------

O23 - Service: dmboot - Microsoft Corp., Veritas Software - C:\WINDOWS\SYSTEM32\drivers\dmboot.sys



17 Servicios.

6 de Carga Automatica.

10 de Carga Manual.

1 Deshabilitados.



Listado de Programas Instalados:

--------------------------------

aTube Catcher -> C:\Archivos de programa\DsNET Corp\aTube Catcher 2.0\uninstall.exe

Autodesk DWF Viewer -> C:\ARCHIV~1\Autodesk\AUTODE~1\Setup.exe /remove /q0

avast! Free Antivirus -> C:\Archivos de programa\AVAST Software\Avast\Setup\Instup.exe /control_panel /instop:uninstall

Flash CS3 9.0 -> C:\Archivos de programa\Adobe\Flash CS3\Uninstall.exe

Google Chrome -> "C:\Archivos de programa\Google\Chrome\Application\43.0.2357.81\Installer\setup.exe" --uninstall --multi-install --chrome --system-level

iRobinHood Partners Addon -> "C:\Archivos de programa\iRobinHood\iRobinHood Addon\uninstall.exe" /S

High Definition Audio Driver Package - KB888111 -> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"

Windows Installer 3.1 (KB893803) -> "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"

Malwarebytes Anti-Malware versión 2.0.1.1004 -> "C:\Archivos de programa\Malwarebytes Anti-Malware\unins000.exe"

NAPALM 1.0 -> "C:\Archivos de programa\NAPALM\unins000.exe"

Macromedia Flash Player 8 -> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\swflash.inf,DefaultUninstall,5

Stellarium 0.11.3 -> "C:\Archivos de programa\Stellarium\unins000.exe"

VLC media player -> C:\Archivos de programa\VideoLAN\VLC\uninstall.exe

WinRAR archiver -> C:\Archivos de programa\WinRAR\uninstall.exe

Search App by Ask -> MsiExec.exe /X{41545534-2D53-5000-76A7-A758B70C1D00}

FontNav -> MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}

Analizador de MSXML 6.0 -> MsiExec.exe /I{5661DB2D-A5AF-4D0F-B34E-3CD45EC6B607}

AutoCAD 2007 - Español -> MsiExec.exe /I{5783F2D7-5001-040A-0002-0060B0CE6BBA}

Google Update Helper -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}

CorelDRAW Graphics Suite X3 -> MsiExec.exe /I{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}

VC_CRT_x86 -> MsiExec.exe /I{8054D734-39C7-463D-B764-9C883982B8F9}

Google Update Helper -> MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}

Adobe Reader 9 - Español -> MsiExec.exe /I{AC76BA86-7AD7-1034-7B44-A90000000001}

VBA -> MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}

REALTEK GbE & FE Ethernet PCI-E NIC Driver -> C:\Archivos de programa\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x000a -removeonly

ES -> MsiExec.exe /I{CBFAD664-763E-4A7D-BF92-BB0E493F3C66}

Realtek High Definition Audio Driver -> RunDll32 C:\ARCHIV~1\ARCHIV~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Archivos de programa\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0xa -removeonly

Update Manager -> MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}











(8-6-2015 17:58:22 (GMT))

EliStartPage v32.45 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 8 de Junio del 2015)

--------------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1.2600) SERVICE PACK 3

Usuario: Alumno

ID de Usuario: S-1-5-21-57989841-1292428093-725345543-1003

Cadenas Víricas: 24092



Lista de Acciones (por Acción Directa):

C:\WINDOWS\ALCMTR.EXE --> Eliminado SpyRealtek

Entrada Eliminada [HKUS\S-1-5-21-57989841-1292428093-725345543-1003\...\Run] "AVDODO"="C:\Documents and Settings\Alumno\Datos de programa\Avdodo.exe"

Entrada Eliminada [HKUS\S-1-5-21-57989841-1292428093-725345543-1003\...\Run] "EVDODS"="C:\Documents and Settings\Alumno\Datos de programa\Evdods.exe"

Entrada Eliminada [HKLM\...\Run] "Alcmtr"="ALCMTR.EXE"

Eliminada Class, "{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}" -> E:\stellarium.exe

Eliminada Clave "HKLM\...\Image File Execution Options\DATAMNGRCOORDINATOR.EXE"

"Debugger"="TASKLIST.EXE"

No detectado Parche MS08-067 de Microsoft instalado. (SServidor)

No detectado Parche MS10-046 de Microsoft instalado. (Exploit.CPLlink)

No detectado Parche MS14-021 de Microsoft instalado. (Seguridad IE8)

Eliminadas las Paginas de Inicio y de Busqueda del IE

Eliminados Ficheros Temporales del IE

Restaurada Clave: "SafeBoot\Minimal y Network"



(8-6-2015 18:01:06 (GMT))

EliStartPage v32.45 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 8 de Junio del 2015)

--------------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1.2600) SERVICE PACK 3

Usuario: Alumno

ID de Usuario: S-1-5-21-57989841-1292428093-725345543-1003

Cadenas Víricas: 24092



Lista de Acciones (por Exploración):

Explorando "C:\"



Nº Total de Directorios: 1201

Nº Total de Ficheros: 13157

Nº de Ficheros Analizados: 3381

Nº de Ficheros Infectados: 0

Nº de Ficheros Limpiados: 0

Exploración Detenida por el Usuario.



(8-6-2015 18:01:21 (GMT))

EliStartPage v32.45 (c)2015 S.G.H. / Satinfo S.L. (Actualizado el 8 de Junio del 2015)

--------------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1.2600) SERVICE PACK 3

Usuario: Alumno

ID de Usuario: S-1-5-21-57989841-1292428093-725345543-1003

Cadenas Víricas: 24092



Lista de Acciones (por Cierre):

Detectados Programas Potecialmente No Deseados (PUPs).

Ejecute el EliPUPs para proceder con su Desinstalación.

"iRobinHood Partners Addon"

"Search App by Ask"





[url=http://www.imagebam.com/image/f265c6414458019][img]http://thumbnails107.imagebam.com/41446/f265c6414458019.jpg[/img][/url]





me gustaría saber que es exactamente lo que esta causando esta falla

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Re: NO puedo abrir google ni facebook

Mensaje por msc hotline sat » 09 Jun 2015, 10:13

El primer informe es de un ordenador con sistema no soportado:



Sistema Operativo: EvoLite® (v5.1.2600) Service Pack 3



Por lo que se prescinde de dicho informe.





______





Y por otra parte estamos pendientes de recibir las muestras solicitadas en nuestra anterior respuesta:





C:\DOCUMENTS AND SETTINGS\ALL USERS\DATOS DE PROGRAMA\{6529EE8E-7ED3-8EDE-6529-9EE8E7EDBA39}\LUPA.EXE



"c:\Archivos de programa\BorderlineInit\BorderlineInit.dll





Dejamos el Tema en standBye hasta recibirlas.





_______



Aparte, deciamos que pasara el ELIPUPS y desinstalara los PUPS que encontrara, y parece que no lo ha hecho...:



"iRobinHood Partners Addon"

"Search App by Ask"





Y si quiere, pruebe de restaurar el HOSTS cuando se lo ofrezca el ELISTARA, ya que es posible que tenga redireccionadas las URL de dichas paginas a las que no accede...



saludos



ms, 9-6-2015

RUY-Montev.

Pcsur2014
Mensajes: 19
Registrado: 14 Ene 2015, 15:26

Re: NO puedo abrir google ni facebook

Mensaje por Pcsur2014 » 10 Jun 2015, 20:15

Resultado de Elipups de la maquina 1



(10-6-2015 16:46:11 (GMT))

EliPUPs v2.32 (c)2015 S.G.H. / Satinfo S.L. (Modificado el 8 de Junio del 2015)

-------------------------------------------

Sistema Operativo: EvoLite® (5.1)



Lista de Todos los Programas Instalados.

Descripción -> Cadena de Desinstalación.

----------------------------------------

Adobe Flash Player ActiveX -> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe

Adobe Flash Player 10 Plugin -> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe

BurnAware Pro 2.3.2 Retail by minimaL -> "C:\Archivos de programa\BurnAware Pro Retail by minimaL\unins000.exe"

CCleaner -> "C:\Archivos de programa\CCleaner\uninst.exe"

Flash CS3 9.0 -> C:\Archivos de programa\Adobe\Flash CS3\Uninstall.exe

Actualización para Windows XP (KB898461) ->

Actualización de seguridad para Windows XP (KB923789) -> C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf

Actualización de seguridad para Windows XP (KB950760) ->

Mozilla Firefox 38.0.5 (x86 es-ES) -> "C:\Archivos de programa\Mozilla Firefox\uninstall\helper.exe"

Mozilla Maintenance Service -> "C:\Archivos de programa\Mozilla Maintenance Service\uninstall.exe"

Intel(R) Network Connections Drivers -> Prounstl.exe

Compresor WinRAR -> C:\Archivos de programa\Winrar\uninstall.exe

Safari -> MsiExec.exe /I{0A9C92A5-D27F-4BD9-9DB9-0EFD8C681E29}

Adobe Shockwave Player -> MsiExec.exe /X{211E8730-5681-49ED-BC6A-78C9F88E95F5}

FontNav -> MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}

CorelDRAW Graphics Suite X3 -> MsiExec.exe /I{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}

Intel(R) Extreme Graphics Driver -> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562

Microsoft Office Professional Plus 2010 -> MsiExec.exe /X{90140000-0011-0000-0000-0000000FF1CE}

Microsoft Office Access MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0015-0C0A-0000-0000000FF1CE}

Microsoft Office Excel MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0016-0C0A-0000-0000000FF1CE}

Microsoft Office PowerPoint MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0018-0C0A-0000-0000000FF1CE}

Microsoft Office Publisher MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0019-0C0A-0000-0000000FF1CE}

Microsoft Office Outlook MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-001A-0C0A-0000-0000000FF1CE}

Microsoft Office Word MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-001B-0C0A-0000-0000000FF1CE}

Microsoft Office Proof (Catalan) 2010 -> MsiExec.exe /X{90140000-001F-0403-0000-0000000FF1CE}

Microsoft Office Proof (English) 2010 -> MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}

Microsoft Office Proof (French) 2010 -> MsiExec.exe /X{90140000-001F-040C-0000-0000000FF1CE}

Microsoft Office Proof (Portuguese (Brazil)) 2010 -> MsiExec.exe /X{90140000-001F-0416-0000-0000000FF1CE}

Microsoft Office Proof (Basque) 2010 -> MsiExec.exe /X{90140000-001F-042D-0000-0000000FF1CE}

Microsoft Office Proof (Galician) 2010 -> MsiExec.exe /X{90140000-001F-0456-0000-0000000FF1CE}

Microsoft Office Proof (Spanish) 2010 -> MsiExec.exe /X{90140000-001F-0C0A-0000-0000000FF1CE}

Microsoft Office Proofing (Spanish) 2010 -> MsiExec.exe /X{90140000-002C-0C0A-0000-0000000FF1CE}

Microsoft Office InfoPath MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0044-0C0A-0000-0000000FF1CE}

Microsoft Office Shared MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-006E-0C0A-0000-0000000FF1CE}

Microsoft Office OneNote MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-00A1-0C0A-0000-0000000FF1CE}

Microsoft Office Groove MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-00BA-0C0A-0000-0000000FF1CE}

Adobe Reader 9 - Español -> MsiExec.exe /I{AC76BA86-7AD7-1034-7B44-A90000000001}

VBA -> MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}

ES -> MsiExec.exe /I{CBFAD664-763E-4A7D-BF92-BB0E493F3C66}

WinZip 15.0 -> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}

Update Manager -> MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}

Google Chrome -> "C:\Documents and Settings\Administrador\Configuración local\Datos de programa\Google\Chrome\Application\43.0.2357.124\Installer\setup.exe" --uninstall --multi-install --chrome



Lista de PUPs conocidos.

Descripción -> Cadena de Desinstalación.

----------------------------------------











Resultado de Elipups de la maquina 2



(10-6-2015 10:28:07 (GMT))

EliPUPs v2.32 (c)2015 S.G.H. / Satinfo S.L. (Modificado el 8 de Junio del 2015)

-------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1)



Lista de Todos los Programas Instalados.

Descripción -> Cadena de Desinstalación.

----------------------------------------

avast! Free Antivirus -> C:\Archivos de programa\Alwil Software\Avast5\Setup\Instup.exe /control_panel /instop:uninstall

Flash CS3 9.0 -> C:\Archivos de programa\Adobe\Flash CS3\Uninstall.exe

Google Chrome -> "C:\Archivos de programa\Google\Chrome\Application\43.0.2357.124\Installer\setup.exe" --uninstall --multi-install --chrome --system-level

Intel(R) Graphics Media Accelerator Driver -> C:\WINDOWS\system32\igxpun.exe -uninstall

Microsoft .NET Framework 1.1 -> msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}

Notepad2 (Reemplazo del Bloc de Notas) -> "C:\Archivos de programa\Notepad2\uninstall.exe"

WinRAR 5.01 (32-bit) -> C:\Archivos de programa\WinRAR\uninstall.exe

Microsoft .NET Framework 4 Extended -> MsiExec.exe /X{0A0CADCF-78DA-33C4-A350-CD51849B9702}

Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 -> MsiExec.exe /X{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 -> MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}

Java 7 Update 51 -> MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217051FF}

Microsoft .NET Framework 4 Client Profile -> MsiExec.exe /X{3C3901C5-3455-3E0A-A214-0B093A5070A6}

FontNav -> MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}

Adobe Flash Player 12 ActiveX -> MsiExec.exe /X{52793F88-BF4D-4AA6-8696-80E72CE758B1}

Google Update Helper -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}

Microsoft Visual C++ 2005 Redistributable -> MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}

Microsoft Visual C++ 2005 Redistributable -> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}

CorelDRAW Graphics Suite X3 -> MsiExec.exe /I{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}

VC_CRT_x86 -> MsiExec.exe /I{8054D734-39C7-463D-B764-9C883982B8F9}

Paquete de idioma de Microsoft .NET Framework 1.1 Service Pack 1 - ESN -> MsiExec.exe /X{83169D43-4660-4347-BC95-E9D6E6BE65CE}

Paquete de idioma de Microsoft .NET Framework 2.0 Service Pack 2 - ESN -> MsiExec.exe /X{85AC0FFA-643D-3103-9310-7086ECB0C36C}

Complemento Guardar como PDF o XPS de Microsoft para programas de Microsoft Office 2007 -> MsiExec.exe /X{90120000-00B2-0C0A-0000-0000000FF1CE}

Microsoft Office Professional Plus 2010 -> MsiExec.exe /X{90140000-0011-0000-0000-0000000FF1CE}

Microsoft Office Access MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0015-0C0A-0000-0000000FF1CE}

Microsoft Office Excel MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0016-0C0A-0000-0000000FF1CE}

Microsoft Office PowerPoint MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0018-0C0A-0000-0000000FF1CE}

Microsoft Office Publisher MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0019-0C0A-0000-0000000FF1CE}

Microsoft Office Outlook MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-001A-0C0A-0000-0000000FF1CE}

Microsoft Office Word MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-001B-0C0A-0000-0000000FF1CE}

Microsoft Office Proof (Catalan) 2010 -> MsiExec.exe /X{90140000-001F-0403-0000-0000000FF1CE}

Microsoft Office Proof (English) 2010 -> MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}

Microsoft Office Proof (French) 2010 -> MsiExec.exe /X{90140000-001F-040C-0000-0000000FF1CE}

Microsoft Office Proof (Portuguese (Brazil)) 2010 -> MsiExec.exe /X{90140000-001F-0416-0000-0000000FF1CE}

Microsoft Office Proof (Basque) 2010 -> MsiExec.exe /X{90140000-001F-042D-0000-0000000FF1CE}

Microsoft Office Proof (Galician) 2010 -> MsiExec.exe /X{90140000-001F-0456-0000-0000000FF1CE}

Microsoft Office Proof (Spanish) 2010 -> MsiExec.exe /X{90140000-001F-0C0A-0000-0000000FF1CE}

Microsoft Office Proofing (Spanish) 2010 -> MsiExec.exe /X{90140000-002C-0C0A-0000-0000000FF1CE}

Microsoft Office InfoPath MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0044-0C0A-0000-0000000FF1CE}

Microsoft Office Shared MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-006E-0C0A-0000-0000000FF1CE}

Microsoft Office OneNote MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-00A1-0C0A-0000-0000000FF1CE}

Microsoft Office Groove MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-00BA-0C0A-0000-0000000FF1CE}

Paquete de idioma de Microsoft .NET Framework 3.5 SP1 - esn -> MsiExec.exe /X{92E4A65F-7007-3357-A69A-167F71A337BD}

Adobe Flash Player 12 Plugin -> MsiExec.exe /X{934168C8-55AC-4593-A138-E64BA8367E6E}

Paquete de idioma de Microsoft .NET Framework 4 Client Profile ESN -> MsiExec.exe /X{95B012AD-3A4A-31D7-9167-5D07D2A71F47}

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.7523 -> MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}

Microsoft .NET Framework 3.0 Service Pack 2 -> MsiExec.exe /X{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}

Adobe Reader 9.5.0 - Español -> MsiExec.exe /I{AC76BA86-7AD7-1034-7B44-A95000000001}

Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 -> MsiExec.exe /X{B175520C-86A2-35A7-8619-86DC379688B9}

Paquete de idioma de Microsoft .NET Framework 4 Extended ESN -> MsiExec.exe /X{B4B6D789-EF42-39D5-B36B-A1282951E0D5}

Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 -> MsiExec.exe /X{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}

Paquete de idioma de Microsoft .NET Framework 3.0 Service Pack 2 - ESN -> MsiExec.exe /X{BDEDB104-4067-3D5E-81F0-DBEBFE856B45}

Microsoft .NET Framework 2.0 Service Pack 2 -> MsiExec.exe /X{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}

VBA -> MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}

REALTEK GbE & FE Ethernet PCI-E NIC Driver -> C:\Archivos de programa\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x000a -removeonly

Microsoft .NET Framework 1.1 Service Pack 1 -> MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}

ES -> MsiExec.exe /I{CBFAD664-763E-4A7D-BF92-BB0E493F3C66}

Microsoft .NET Framework 3.5 SP1 -> MsiExec.exe /X{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 -> MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}

Realtek High Definition Audio Driver -> RtlUpd.exe -r -m -nrg2709

Update Manager -> MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}

Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 -> MsiExec.exe /X{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}

Adobe Shockwave Player 12.0 -> MsiExec.exe /X{FF2A5498-4EFE-430F-A138-7EB365DBEBAD}



Lista de PUPs conocidos.

Descripción -> Cadena de Desinstalación.

----------------------------------------







Resultado de Elipups de la maquina 3



(10-6-2015 17:15:28 (GMT))

EliPUPs v2.32 (c)2015 S.G.H. / Satinfo S.L. (Modificado el 8 de Junio del 2015)

-------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1)



Lista de Todos los Programas Instalados.

Descripción -> Cadena de Desinstalación.

----------------------------------------

Autodesk DWF Viewer -> C:\ARCHIV~1\Autodesk\AUTODE~1\Setup.exe /remove /q0

Delta Chrome Toolbar -> "C:\Documents and Settings\Administrador\Datos de programa\BabSolution\Shared\GUninstaller.exe" -key "Delta Chrome Toolbar" -rmkey -rmbus "Delta Chrome Toolbar" -ask -plgdll enhancedNT -nontfy

Flash CS3 9.0 -> C:\Archivos de programa\Adobe\Flash CS3\Uninstall.exe

Google Chrome -> "C:\Archivos de programa\Google\Chrome\Application\43.0.2357.124\Installer\setup.exe" --uninstall --multi-install --chrome --system-level

Windows Installer 3.1 (KB893803) -> "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"

Microsoft .NET Framework 2.0 -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe

Paquete de idioma de Microsoft .NET Framework 2.0 - ESN -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - ESN\install.exe

PSafe Total -> C:\Archivos de programa\PSafe\Total\Uninstall.exe

SoftwareUpdater -> C:\Archivos de programa\SoftwareUpdater\uninstall.exe

FontNav -> MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}

Analizador de MSXML 6.0 -> MsiExec.exe /I{5661DB2D-A5AF-4D0F-B34E-3CD45EC6B607}

AutoCAD 2007 - Español -> MsiExec.exe /I{5783F2D7-5001-040A-0002-0060B0CE6BBA}

Google Update Helper -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}

CorelDRAW Graphics Suite X3 -> MsiExec.exe /I{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}

VC_CRT_x86 -> MsiExec.exe /I{8054D734-39C7-463D-B764-9C883982B8F9}

Macromedia Flash Player 8 -> MsiExec.exe /X{885A63EA-382B-4DD4-A755-14809B8557D6}

Intel(R) Extreme Graphics Driver -> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562

Macromedia Flash 8 Video Encoder -> MsiExec.exe /X{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}

Microsoft Office Professional Plus 2010 -> MsiExec.exe /X{90140000-0011-0000-0000-0000000FF1CE}

Microsoft Office Access MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0015-0C0A-0000-0000000FF1CE}

Microsoft Office Excel MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0016-0C0A-0000-0000000FF1CE}

Microsoft Office PowerPoint MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0018-0C0A-0000-0000000FF1CE}

Microsoft Office Publisher MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0019-0C0A-0000-0000000FF1CE}

Microsoft Office Outlook MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-001A-0C0A-0000-0000000FF1CE}

Microsoft Office Word MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-001B-0C0A-0000-0000000FF1CE}

Microsoft Office Proof (Catalan) 2010 -> MsiExec.exe /X{90140000-001F-0403-0000-0000000FF1CE}

Microsoft Office Proof (English) 2010 -> MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}

Microsoft Office Proof (French) 2010 -> MsiExec.exe /X{90140000-001F-040C-0000-0000000FF1CE}

Microsoft Office Proof (Portuguese (Brazil)) 2010 -> MsiExec.exe /X{90140000-001F-0416-0000-0000000FF1CE}

Microsoft Office Proof (Basque) 2010 -> MsiExec.exe /X{90140000-001F-042D-0000-0000000FF1CE}

Microsoft Office Proof (Galician) 2010 -> MsiExec.exe /X{90140000-001F-0456-0000-0000000FF1CE}

Microsoft Office Proof (Spanish) 2010 -> MsiExec.exe /X{90140000-001F-0C0A-0000-0000000FF1CE}

Microsoft Office Proofing (Spanish) 2010 -> MsiExec.exe /X{90140000-002C-0C0A-0000-0000000FF1CE}

Microsoft Office InfoPath MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0044-0C0A-0000-0000000FF1CE}

Microsoft Office Shared MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-006E-0C0A-0000-0000000FF1CE}

Microsoft Office OneNote MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-00A1-0C0A-0000-0000000FF1CE}

Microsoft Office Groove MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-00BA-0C0A-0000-0000000FF1CE}

Macromedia Flash Player 8 Plugin -> MsiExec.exe /X{91057632-CA70-413C-B628-2D3CDBBB906B}

Macromedia FreeHand MXa -> RunDll32 C:\ARCHIV~1\ARCHIV~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Archivos de programa\InstallShield Installation Information\{939740B5-0064-4779-854A-8C1086181C05}\Setup.exe" -l0xa UNINSTALL

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 -> MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}

VBA -> MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}

ES -> MsiExec.exe /I{CBFAD664-763E-4A7D-BF92-BB0E493F3C66}

WinZip 15.0 -> MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}

Update Manager -> MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}

Macromedia Extension Manager -> MsiExec.exe /I{F443F171-B49B-4645-915C-580E7ED79992}

Intel(R) Network Connections 18.3.62.0 -> MsiExec.exe /i{FCF3ECF7-7AE0-4E26-B387-09A3A80B79CC} ARPREMOVE=1



Lista de PUPs conocidos.

Descripción -> Cadena de Desinstalación.

----------------------------------------

SoftwareUpdater -> C:\Archivos de programa\SoftwareUpdater\uninstall.exe









Resultado de Elipups de la maquina 4



(10-6-2015 17:04:48 (GMT))

EliPUPs v2.32 (c)2015 S.G.H. / Satinfo S.L. (Modificado el 8 de Junio del 2015)

-------------------------------------------

Sistema Operativo: Microsoft Windows XP (5.1)



Lista de Todos los Programas Instalados.

Descripción -> Cadena de Desinstalación.

----------------------------------------

aTube Catcher -> C:\Archivos de programa\DsNET Corp\aTube Catcher 2.0\uninstall.exe

Autodesk DWF Viewer -> C:\ARCHIV~1\Autodesk\AUTODE~1\Setup.exe /remove /q0

avast! Free Antivirus -> C:\Archivos de programa\AVAST Software\Avast\Setup\Instup.exe /control_panel /instop:uninstall

Flash CS3 9.0 -> C:\Archivos de programa\Adobe\Flash CS3\Uninstall.exe

Google Chrome -> "C:\Archivos de programa\Google\Chrome\Application\43.0.2357.124\Installer\setup.exe" --uninstall --multi-install --chrome --system-level

High Definition Audio Driver Package - KB888111 -> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"

Windows Installer 3.1 (KB893803) -> "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"

Malwarebytes Anti-Malware versión 2.0.1.1004 -> "C:\Archivos de programa\Malwarebytes Anti-Malware\unins000.exe"

Microsoft .NET Framework 2.0 -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe

Paquete de idioma de Microsoft .NET Framework 2.0 - ESN -> C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - ESN\install.exe

NAPALM 1.0 -> "C:\Archivos de programa\NAPALM\unins000.exe"

Macromedia Flash Player 8 -> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\swflash.inf,DefaultUninstall,5

Stellarium 0.11.3 -> "C:\Archivos de programa\Stellarium\unins000.exe"

VLC media player -> C:\Archivos de programa\VideoLAN\VLC\uninstall.exe

WinRAR archiver -> C:\Archivos de programa\WinRAR\uninstall.exe

FontNav -> MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}

Analizador de MSXML 6.0 -> MsiExec.exe /I{5661DB2D-A5AF-4D0F-B34E-3CD45EC6B607}

AutoCAD 2007 - Español -> MsiExec.exe /I{5783F2D7-5001-040A-0002-0060B0CE6BBA}

Google Update Helper -> MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}

CorelDRAW Graphics Suite X3 -> MsiExec.exe /I{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}

VC_CRT_x86 -> MsiExec.exe /I{8054D734-39C7-463D-B764-9C883982B8F9}

Microsoft Office Professional Plus 2010 -> MsiExec.exe /X{90140000-0011-0000-0000-0000000FF1CE}

Microsoft Office Access MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0015-0C0A-0000-0000000FF1CE}

Microsoft Office Excel MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0016-0C0A-0000-0000000FF1CE}

Microsoft Office PowerPoint MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0018-0C0A-0000-0000000FF1CE}

Microsoft Office Publisher MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0019-0C0A-0000-0000000FF1CE}

Microsoft Office Outlook MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-001A-0C0A-0000-0000000FF1CE}

Microsoft Office Word MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-001B-0C0A-0000-0000000FF1CE}

Microsoft Office Proof (Catalan) 2010 -> MsiExec.exe /X{90140000-001F-0403-0000-0000000FF1CE}

Microsoft Office Proof (English) 2010 -> MsiExec.exe /X{90140000-001F-0409-0000-0000000FF1CE}

Microsoft Office Proof (French) 2010 -> MsiExec.exe /X{90140000-001F-040C-0000-0000000FF1CE}

Microsoft Office Proof (Portuguese (Brazil)) 2010 -> MsiExec.exe /X{90140000-001F-0416-0000-0000000FF1CE}

Microsoft Office Proof (Basque) 2010 -> MsiExec.exe /X{90140000-001F-042D-0000-0000000FF1CE}

Microsoft Office Proof (Galician) 2010 -> MsiExec.exe /X{90140000-001F-0456-0000-0000000FF1CE}

Microsoft Office Proof (Spanish) 2010 -> MsiExec.exe /X{90140000-001F-0C0A-0000-0000000FF1CE}

Microsoft Office Proofing (Spanish) 2010 -> MsiExec.exe /X{90140000-002C-0C0A-0000-0000000FF1CE}

Microsoft Office InfoPath MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-0044-0C0A-0000-0000000FF1CE}

Microsoft Office Shared MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-006E-0C0A-0000-0000000FF1CE}

Microsoft Office OneNote MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-00A1-0C0A-0000-0000000FF1CE}

Microsoft Office Groove MUI (Spanish) 2010 -> MsiExec.exe /X{90140000-00BA-0C0A-0000-0000000FF1CE}

Adobe Reader 9 - Español -> MsiExec.exe /I{AC76BA86-7AD7-1034-7B44-A90000000001}

VBA -> MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}

REALTEK GbE & FE Ethernet PCI-E NIC Driver -> C:\Archivos de programa\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x000a -removeonly

ES -> MsiExec.exe /I{CBFAD664-763E-4A7D-BF92-BB0E493F3C66}

Realtek High Definition Audio Driver -> RunDll32 C:\ARCHIV~1\ARCHIV~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Archivos de programa\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0xa -removeonly

Update Manager -> MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}



Lista de PUPs conocidos.

Descripción -> Cadena de Desinstalación.

----------------------------------------

Pcsur2014
Mensajes: 19
Registrado: 14 Ene 2015, 15:26

Re: NO puedo abrir google ni facebook

Mensaje por Pcsur2014 » 10 Jun 2015, 20:18

ya se elimino..



"iRobinHood Partners Addon"

"Search App by Ask"





no halle los archivos..





C:\DOCUMENTS AND SETTINGS\ALL USERS\DATOS DE PROGRAMA\{6529EE8E-7ED3-8EDE-6529-9EE8E7EDBA39}\LUPA.EXE.VIR



C:\WINDOWS\system32\rundll32.exe" "c:\Archivos de programa\BorderlineInit\BorderlineInit.dll.VIR

Pcsur2014
Mensajes: 19
Registrado: 14 Ene 2015, 15:26

Re: NO puedo abrir google ni facebook

Mensaje por Pcsur2014 » 10 Jun 2015, 20:20

el problema continua!!

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Re: NO puedo abrir google ni facebook

Mensaje por msc hotline sat » 11 Jun 2015, 09:10

Pues mire si encuentra los ficheros que no encuentra, con el ELIMOVER, y si existen, serán copiados a C:\muestras, desde donde podrá enviarnoslos comodamente.



De todas formas, si ya les ha añadido .VIR a su extension, ya no incordiarán a partir del siguiente reinicio.



saludos



ms, 11-6-2015

Pcsur2014
Mensajes: 19
Registrado: 14 Ene 2015, 15:26

Re: NO puedo abrir google ni facebook

Mensaje por Pcsur2014 » 11 Jun 2015, 22:22

me disculpa mi insistencia.. pero si usted se toma la molestia de leer los infosat.. que les mande de las 4 maquinas.. se dara cuenta que BorderlineInit.dll..no existe.. ni tampoco lo de la lupa.. me hago referencia a los ultimos infosat que les envie... los primeros infosat obvielo..por eso que en mi introducion.. dije voy a retomar el caso..



fijese.. mi objetivo es solventar el problema ... buscar la causa del porque google chrome no me esta mostrando el facebook.. o en algunas ocasiones el youtube.. e incluso tambien google chrome.. por favor revise los infosat que les mande y se dara cuenta el BorderlineInit.dll no existe.. .. (pues no son la mismas maquinas de la ves anterior..).. NO QUIERO FORMATEAR...solo quiero encontrar la causa y solventar el problema..

Pcsur2014
Mensajes: 19
Registrado: 14 Ene 2015, 15:26

Re: NO puedo abrir google ni facebook

Mensaje por Pcsur2014 » 11 Jun 2015, 22:36

puede observar las imagenes y se dara cuenta de que es cierto...



[url=http://www.imagebam.com/image/471ed9415044311][img]http://thumbnails107.imagebam.com/41505/471ed9415044311.jpg[/img][/url]





[url=http://www.imagebam.com/image/d93735415044317][img]http://thumbnails107.imagebam.com/41505/d93735415044317.jpg[/img][/url]







[url=http://www.imagebam.com/image/04afce415044335][img]http://thumbnails108.imagebam.com/41505/04afce415044335.jpg[/img][/url]







[url=http://www.imagebam.com/image/1dbbe3415044365][img]http://thumbnails108.imagebam.com/41505/1dbbe3415044365.jpg[/img][/url]







[url=http://www.imagebam.com/image/5c3db6415044376][img]http://thumbnails108.imagebam.com/41505/5c3db6415044376.jpg[/img][/url]







[url=http://www.imagebam.com/image/973a03415044297][img]http://thumbnails108.imagebam.com/41505/973a03415044297.jpg[/img][/url]





si puede trate de ayudarme, en verdad que estoy interesado en resolver el caso...revise todo lo que le manade desde esta semana.. lo otro paselo por alto.. pleasee

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Re: NO puedo abrir google ni facebook

Mensaje por msc hotline sat » 12 Jun 2015, 12:18

No he visto que restaurara el HOSTS, lo ha hecho ?



Y de los ficheros indicados, los ha buscado con el ELIMOVER ?



Piense que si están con atributo de oculto o de sistema , Vd no los verá, aunque estén, pero el ELIMOVER si, y los copiará a C:\muestras sin atributos, para que pueda enviarnoslos



recuerde, con un COPIAR Y PEGAR incluirlos en el ELIMOVER:





C:\DOCUMENTS AND SETTINGS\ALL USERS\DATOS DE PROGRAMA\{6529EE8E-7ED3-8EDE-6529-9EE8E7EDBA39}\LUPA.EXE



C:\WINDOWS\system32\rundll32.exe" "c:\Archivos de programa\BorderlineInit\BorderlineInit.dll





Y mas que esto no le puedo decir...



saludos



ms, 13-6-2015



PD: Y por cierto, en el caso del fichero LUPA.EXE lo tiene seguro ya que está entre los que tiene en uso:



22 Procesos Activos:

C:\WINDOWS\SYSTEM32\SMSS.EXE

C:\WINDOWS\SYSTEM32\CSRSS.EXE

C:\WINDOWS\SYSTEM32\WINLOGON.EXE

C:\WINDOWS\SYSTEM32\SERVICES.EXE

C:\WINDOWS\SYSTEM32\LSASS.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\WINDOWS\EXPLORER.EXE

C:\WINDOWS\SYSTEM32\SPOOLSV.EXE

C:\ARCHIVOS DE PROGRAMA\ARCHIVOS COMUNES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE

C:\WINDOWS\SYSTEM32\CTFMON.EXE

C:\ARCHIVOS DE PROGRAMA\WINZIP\WZQKPICK.EXE

[color=#FF0000]C:\DOCUMENTS AND SETTINGS\ALL USERS\DATOS DE PROGRAMA\{6529EE8E-7ED3-8EDE-6529-9EE8E7EDBA39}\LUPA.EXE[/color]

C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\CONFIGURACIóN LOCAL\DATOS DE PROGRAMA\GOOGLE\UPDATE\1.3.26.9\GOOGLECRASHHANDLER.EXE

C:\WINDOWS\SYSTEM32\RUNDLL32.EXE

C:\WINDOWS\SYSTEM32\ALG.EXE

C:\WINDOWS\SYSTEM32\SVCHOST.EXE

C:\ARCHIVOS DE PROGRAMA\WINRAR\WINRAR.EXE

C:\DOCUME~1\ADMINI~1\CONFIG~1\TEMP\RAR$EX00.156\SPROCES.EXE





ms.

Pcsur2014
Mensajes: 19
Registrado: 14 Ene 2015, 15:26

Re: NO puedo abrir google ni facebook

Mensaje por Pcsur2014 » 15 Jun 2015, 19:47

con todo el respeto que usted se merece..mire, solo hay una maquina que tiene la lupa.. las demas no la tiene.. la pregunta mia es.. porque google chrome.. no me esta mostrando las paginas como facebook, youtube.. y otras.. los cuatros informes que le pase..no tiene la lupa.. el cual.l ogicamente.. no tiene nada que ver con lo de la lupa.. lo otro..pues si asi fuera.. los cuatro informe que le mande deberia tener lo de la lupa y lo de borderline.. por favor no se estanque en un solo punto.. pues no me esta ayudando..lo unico que hace es complicarme la gestion...



por favor. analize los informe que les mande.... los ultimos 4 informe de elistara son 4 maquinas distinta.. ninguna tiene lo de la lupa..



por favor, tome el caso en serio.... lo otro.. eso lo del host.. cuando yo le paso el elistara a todo le doy SI.... y no veo nada que restablezca el host..



por favor.. analize los ultimos informes.. los primeros que les envie.. obvielo, pues no interesa en este momento.. le digo eso.. porque estamos hablando de 4 maquinas distintas... a la de las primera

Avatar de Usuario
msc hotline sat
Mensajes: 93500
Registrado: 09 Mar 2004, 20:39
Ubicación: BARCELONA (ESPAÑA)
Contactar:

Re: NO puedo abrir google ni facebook

Mensaje por msc hotline sat » 16 Jun 2015, 07:23

Aparte de los dos ficheros indicados, envianos este otro:



C:\DOCUMENTS AND SETTINGS\ADMINISTRADOR\27F6461627473796E696D64614\WINLOGON.EXE



Hasta que no recibamos los tres, este Tema quedara cerrado.



Cuando los hayamos recibido, lo abriremos de nuevo informando del resultado del analisis.



saludos



ms, 16-6-2015







[b]Nota[/b]:



Y ya que el problema lo tiene con el chrome, desinstale todas sus extensiones, y, tras ver el resultado, ya instalara las que le sean imprescindibles.



ms.

RUYMONTEV

Cerrado

Volver a “Foro Virus - Cuentanos tu problema”