Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:14:20, on 10/12/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Toshiba\SmoothView\SmoothView.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
C:\Program Files\AVG\AVG2012\avgtray.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\xavigomez\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\xavigomez\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\xavigomez\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\xavigomez\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Aplicación auxiliar de vínculos de Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [cfFncEnabler.exe] cfFncEnabler.exe
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Servicio de red')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Servicio auxiliar de host para aplicaciones (AppHostSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (Audiosrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Cortafuegos de AVG (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: WatchDog de AVG (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: BackupService - ArcSoft, Inc. - C:\Users\xavigomez\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe
O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Servicio Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dhcpcsvc.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\ehome\ehrecvr.exe,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe
O23 - Service: @%SystemRoot%\ehome\ehsched.exe,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\emdmgmt.dll,-1000 (EMDMgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (Eventlog) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe
O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Aplicación auxiliar de NetBIOS sobre TCP/IP (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe
O23 - Service: Servicio del iniciador iSCSI de Microsoft (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe
O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\netprof.dll,-246 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: NIHardwareService - Native Instruments GmbH - C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe
O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe
O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: ServiceLayer - Unknown owner - C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe
O23 - Service: @%SystemRoot%\system32\SLUINotify.dll,-103 (SLUINotify) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe
O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - Unknown owner - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (file missing)
O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
O23 - Service: Cliente de seguimiento de vínculos distribuidos (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\uxtuneup.dll,-4096 (UxTuneUp) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe
O23 - Service: vToolbarUpdater - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30001 (WAS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Servicio de detección automática de proxy web WinHTTP (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\wmpnetwk.exe
O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100 (WPFFontCache_v0400) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe
--
End of file - 20563 bytes
Y este el logo de AVG"Análisis de ""Analizar todo el equipo"" completado."
"Infecciones";"4";"2";"2"
"Advertencias";"79";"79";"0"
"Carpetas seleccionadas para analizar:";"Analizar todo el equipo"
"Análisis iniciado:";"sábado, 10 de diciembre de 2011, 2:32:56"
"Análisis finalizado:";"sábado, 10 de diciembre de 2011, 4:17:19 (1 hora(s) 44 minuto(s) 22 segundo(s))"
"Total de objetos analizados:";"2257490"
"Usuario que inició el análisis:";"xavigomez"
"Infecciones"
"";"Archivo";"Infección";"Resultado"
"";"C:\Users\xavigomez\Desktop\Escritorio\tuneup2011-keygen.exe";"Troyano Generic24.AVDD";"Movido al Almacén de virus"
"";"C:\Windows\system32\DRIVERS\tdx.sys";"Troyano BackDoor.Generic14.CBHE";"El objeto se encuentra en la lista blanca (archivo del sistema o crítico que no debe eliminarse)"
"";"C:\Windows\System32\drivers\tdx.sys";"Troyano BackDoor.Generic14.CBHE";"El objeto se encuentra en la lista blanca (archivo del sistema o crítico que no debe eliminarse)"
"";"C:\Windows\winsxs\x86_microsoft-windows-tdi-over-tcpip_31bf3856ad364e35_6.0.6002.18005_none_ec294157d9377403\tdx.sys";"Troyano BackDoor.Generic14.CBHE";"Movido al Almacén de virus"
"Advertencias"
"";"Archivo";"Infección";"Resultado"
"";"C:\Toshiba\Preinst\CancelTopi.exe";"Archivo ejecutable dañado";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ZQR49BQ7.txt:\serving-sys.com.db46cecc";"Se encontró Tracking cookie.Serving-sys";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\037DFBSX.txt:\ad.yieldmanager.com.539b0606";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\037DFBSX.txt:\ad.yieldmanager.com.8a47878";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\037DFBSX.txt:\ad.yieldmanager.com.b68f2b7b";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\037DFBSX.txt:\ad.yieldmanager.com.e626e6be";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\037DFBSX.txt:\ad.yieldmanager.com.ff92306";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ZQR49BQ7.txt:\serving-sys.com.bb39fa8c";"Se encontró Tracking cookie.Serving-sys";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\CPFO3J2E.txt:\atdmt.com.7247c262";"Se encontró Tracking cookie.Atdmt";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\CPFO3J2E.txt:\atdmt.com.b3e33b5f";"Se encontró Tracking cookie.Atdmt";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ZQR49BQ7.txt:\serving-sys.com.3c465e6e";"Se encontró Tracking cookie.Serving-sys";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\IREHTX88.txt:\overture.com.52ca467a";"Se encontró Tracking cookie.Overture";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\IREHTX88.txt:\overture.com.e626e6be";"Se encontró Tracking cookie.Overture";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ZQR49BQ7.txt:\serving-sys.com.176b0dad";"Se encontró Tracking cookie.Serving-sys";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KC4NN7UF.txt:\atdmt.com.7247c262";"Se encontró Tracking cookie.Atdmt";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KC4NN7UF.txt:\atdmt.com.b3e33b5f";"Se encontró Tracking cookie.Atdmt";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\XV2BCKXF.txt:\bs.serving-sys.com.5bf1f00f";"Se encontró Tracking cookie.Serving-sys";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KFU2FX5S.txt:\ad.yieldmanager.com.539b0606";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KFU2FX5S.txt:\ad.yieldmanager.com.8a47878";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KFU2FX5S.txt:\ad.yieldmanager.com.b68f2b7b";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KFU2FX5S.txt:\ad.yieldmanager.com.e626e6be";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KFU2FX5S.txt:\ad.yieldmanager.com.ff92306";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\L7D321KV.txt:\atdmt.com.b3e33b5f";"Se encontró Tracking cookie.Atdmt";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KLBEJW05.txt:\serving-sys.com.176b0dad";"Se encontró Tracking cookie.Serving-sys";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KLBEJW05.txt:\serving-sys.com.3c465e6e";"Se encontró Tracking cookie.Serving-sys";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KLBEJW05.txt:\serving-sys.com.bb39fa8c";"Se encontró Tracking cookie.Serving-sys";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KLBEJW05.txt:\serving-sys.com.db46cecc";"Se encontró Tracking cookie.Serving-sys";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\L7D321KV.txt:\atdmt.com.7247c262";"Se encontró Tracking cookie.Atdmt";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\QWT1IIM9.txt:\bs.serving-sys.com.5bf1f00f";"Se encontró Tracking cookie.Serving-sys";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\J1AI6UTS.txt:\adbrite.com.d5e309c2";"Se encontró Tracking cookie.Adbrite";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\UPO8QV08.txt:\weborama.fr.30104bcb";"Se encontró Tracking cookie.Weborama";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\UPO8QV08.txt:\weborama.fr.9fbfedb3";"Se encontró Tracking cookie.Weborama";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\J1AI6UTS.txt:\adbrite.com.37283d89";"Se encontró Tracking cookie.Adbrite";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\W0I7KTAG.txt:\weborama.fr.30104bcb";"Se encontró Tracking cookie.Weborama";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\IFFGXWKA.txt:\casalemedia.com.987e6b46";"Se encontró Tracking cookie.Casalemedia";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\XPA18LWE.txt:\overture.com.52ca467a";"Se encontró Tracking cookie.Overture";"Movido al Almacén de virus"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\XPA18LWE.txt:\overture.com.e626e6be";"Se encontró Tracking cookie.Overture";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\IFFGXWKA.txt:\casalemedia.com.80ad4799";"Se encontró Tracking cookie.Casalemedia";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\3Z2ADY4L.txt:\revsci.net.1ecc4d24";"Se encontró Tracking cookie.Revsci";"Movido al Almacén de virus"
"";"HKLM\SYSTEM\CurrentControlSet\services\tdx";"Se encontró una clave del Registro con referencia al archivo infectado C:\Windows\system32\DRIVERS\tdx.sys";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\77BGZCA2.txt:\ru4.com.5a5e0633";"Se encontró Tracking cookie.Ru4";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\77BGZCA2.txt:\ru4.com.82a499d7";"Se encontró Tracking cookie.Ru4";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\IFFGXWKA.txt:\casalemedia.com.350339d4";"Se encontró Tracking cookie.Casalemedia";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\9VERTF93.txt:\weborama.fr.30104bcb";"Se encontró Tracking cookie.Weborama";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\IFFGXWKA.txt:\casalemedia.com.2d37ad26";"Se encontró Tracking cookie.Casalemedia";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\AOF9RCXA.txt:\ad.yieldmanager.com.539b0606";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\AOF9RCXA.txt:\ad.yieldmanager.com.557bf2b0";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\AOF9RCXA.txt:\ad.yieldmanager.com.712ec9fe";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\AOF9RCXA.txt:\ad.yieldmanager.com.830b6f08";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\AOF9RCXA.txt:\ad.yieldmanager.com.87a9ab5d";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\AOF9RCXA.txt:\ad.yieldmanager.com.8a47878";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\AOF9RCXA.txt:\ad.yieldmanager.com.b68f2b7b";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\AOF9RCXA.txt:\ad.yieldmanager.com.e626e6be";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\AOF9RCXA.txt:\ad.yieldmanager.com.ff92306";"Se encontró Tracking cookie.Yieldmanager";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\IFFGXWKA.txt:\casalemedia.com.1e1e0e23";"Se encontró Tracking cookie.Casalemedia";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\E1W1MSAU.txt:\tradedoubler.com.ba12c0e9";"Se encontró Tracking cookie.Tradedoubler";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\E1W1MSAU.txt:\tradedoubler.com.eab0972e";"Se encontró Tracking cookie.Tradedoubler";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\E1W1MSAU.txt:\tradedoubler.com.ef90aa95";"Se encontró Tracking cookie.Tradedoubler";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\IFFGXWKA.txt:\casalemedia.com.1773afc";"Se encontró Tracking cookie.Casalemedia";"Movido al Almacén de virus"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\IFFGXWKA.txt";"Se encontró Tracking cookie.Casalemedia";"Reparado"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\E1W1MSAU.txt";"Se encontró Tracking cookie.Tradedoubler";"Reparado"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\AOF9RCXA.txt";"Se encontró Tracking cookie.Yieldmanager";"Reparado"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\9VERTF93.txt";"Se encontró Tracking cookie.Weborama";"Reparado"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\3Z2ADY4L.txt";"Se encontró Tracking cookie.Revsci";"Reparado"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\XPA18LWE.txt";"Se encontró Tracking cookie.Overture";"Reparado"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\J1AI6UTS.txt";"Se encontró Tracking cookie.Adbrite";"Reparado"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\W0I7KTAG.txt";"Se encontró Tracking cookie.Weborama";"Reparado"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\UPO8QV08.txt";"Se encontró Tracking cookie.Weborama";"Reparado"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\L7D321KV.txt";"Se encontró Tracking cookie.Atdmt";"Reparado"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\QWT1IIM9.txt";"Se encontró Tracking cookie.Serving-sys";"Reparado"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KLBEJW05.txt";"Se encontró Tracking cookie.Serving-sys";"Reparado"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\XV2BCKXF.txt";"Se encontró Tracking cookie.Serving-sys";"Reparado"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KFU2FX5S.txt";"Se encontró Tracking cookie.Yieldmanager";"Reparado"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\ZQR49BQ7.txt";"Se encontró Tracking cookie.Serving-sys";"Reparado"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\KC4NN7UF.txt";"Se encontró Tracking cookie.Atdmt";"Reparado"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\IREHTX88.txt";"Se encontró Tracking cookie.Overture";"Reparado"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\CPFO3J2E.txt";"Se encontró Tracking cookie.Atdmt";"Reparado"
"";"C:\Users\xavigomez\AppData\Roaming\Microsoft\Windows\Cookies\037DFBSX.txt";"Se encontró Tracking cookie.Yieldmanager";"Reparado"
"";"C:\Windows\$NtUninstallKB45236$\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\77BGZCA2.txt";"Se encontró Tracking cookie.Ru4";"Reparado"
y este el logo panda online
;***********************************************************************************************************************************************************************************
ANALYSIS: 2011-12-10 21:20:09
PROTECTIONS: 1
MALWARE: 1
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
Windows Defender Yes No
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\windows\cookies\oc6eiqub.txt
;===================================================================================================================================================================================
SUSPECTS
Sent Location
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description
;===================================================================================================================================================================================
;===================================================================================================================================================================================
espero que puedo hacer. gracias