Descifrar el reporte de otl

Cerrado
TELLYSAN
Message postés
2
Date d'inscription
domingo, 14 de octubre de 2012
Estatus
Miembro
Última intervención
martes, 16 de octubre de 2012
- 16 oct 2012 a las 01:03
Hola,
Me gustaría que me descifraran el reporte de otl asi como el siguiente paso.

OTL logfile created on: 15/10/2012 05:42:17 p.m. - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\VICTOR\Escritorio
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 0000080A | Country: México | Language: ESM | Date Format: dd/MM/yyyy

1.22 Gb Total Physical Memory | 0.80 Gb Available Physical Memory | 65.60% Memory free
2.91 Gb Paging File | 2.64 Gb Available in Paging File | 90.69% Paging File free
Paging file location(s): C:\pagefile.sys 1872 3744 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Archivos de programa
Drive C: | 76.68 Gb Total Space | 31.85 Gb Free Space | 41.53% Space Free | Partition Type: NTFS
Drive D: | 74.52 Gb Total Space | 67.42 Gb Free Space | 90.47% Space Free | Partition Type: NTFS

Computer Name: PAPELERI-5FEF00 | User Name: VICTOR | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

[color=#E56717]========== Processes (SafeList) ==========/color

PRC - C:\Documents and Settings\VICTOR\Escritorio\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\Installer\MSI3AB.tmp (Solid Documents, LLC)
PRC - C:\Archivos de programa\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Google\Update\1.3.21.123\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Archivos de programa\Tutoriales100\tutoriales100_mx_3.exe ()
PRC - C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\tutoriales100_mx_3\UpdTuto100SlmbaHP.exe ()
PRC - C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
PRC - C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
PRC - C:\Archivos de programa\USB Disk Security\USBGuard.exe (Zbshareware Lab)
PRC - C:\Archivos de programa\Archivos comunes\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\msfeedssync.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


[color=#E56717]========== Modules (No Company Name) ==========/color

MOD - C:\Archivos de programa\Tutoriales100\tutoriales100_mx_3.exe ()
MOD - C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\tutoriales100_mx_3\UpdTuto100SlmbaHP.exe ()
MOD - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\PDFShell.ESP ()
MOD - C:\Archivos de programa\WinRAR\RarExt.dll ()
MOD - C:\Archivos de programa\USB Disk Security\locales\spanish.dll ()
MOD - C:\WINDOWS\system32\solidlocalmon.dll ()
MOD - C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF ()


[color=#E56717]========== Services (SafeList) ==========/color

SRV - (TuneUp.UtilitiesSvc) -- C:\Archivos de programa\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe File not found
SRV - (HidServ) -- %SystemRoot%\System32\hidserv.dll File not found
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SCPDFReadSpool) -- C:\WINDOWS\Installer\MSI3AB.tmp (Solid Documents, LLC)
SRV - (ekrn) -- C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe (ESET)
SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Archivos de programa\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (osppsvc) -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation)
SRV - (ose) -- C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (NMIndexingService) -- C:\Archivos de programa\Archivos comunes\Ahead\Lib\NMIndexingService.exe (Nero AG)


[color=#E56717]========== Driver Services (SafeList) ==========/color

DRV - (WDICA) -- File not found
DRV - (TuneUpUtilitiesDrv) -- C:\Archivos de programa\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (epfwtdir) -- C:\WINDOWS\system32\drivers\epfwtdir.sys (ESET)
DRV - (eamon) -- C:\WINDOWS\system32\drivers\eamon.sys (ESET)
DRV - (ehdrv) -- C:\WINDOWS\system32\drivers\ehdrv.sys (ESET)
DRV - (videX32) -- C:\WINDOWS\system32\drivers\videX32.sys (VIA Technologies, Inc.)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (S3SavageNB) -- C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (S3Psddr) -- C:\WINDOWS\system32\drivers\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (viaagp1) -- C:\WINDOWS\system32\drivers\VIAAGP1.SYS (VIA Technologies, Inc.)
DRV - (ms_mpu401) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (SetupNT) -- C:\WINDOWS\system32\SetupNT.sys ()


[color=#E56717]========== Standard Registry (SafeList) ==========/color


[color=#E56717]========== Internet Explorer ==========/color

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.onmylike.com/?utm_source=b&utm_medium=smk&from=smk&uid=HDS728080PLAT20_PFD2V3SERRM15HRRM15HX&ts=1349826710&k2020=v2020
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.onmylike.com/?utm_source=b&utm_medium=smk&from=smk&uid=HDS728080PLAT20_PFD2V3SERRM15HRRM15HX&ts=1349826710&k2020=v2020
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.v9.com/web/?q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.v9.com/web/?q={searchTerms}
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = https://www.google.com/?gws_rd=ssl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,default_page_url = http://www.onmylike.com/?utm_source=b&utm_medium=smk&from=smk&uid=HDS728080PLAT20_PFD2V3SERRM15HRRM15HX&ts=1349826710&k2020=v2020
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com.mx/
IE - HKCU\..\URLSearchHook: {ef0682e9-597e-414f-a6ea-e5af4a32b0b3} - C:\Archivos de programa\ytbyclick1.4\prxtbytby.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.v9.com/web/?q={searchTerms}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=112842&tt=120912_pcp_3712_6&babsrc=SP_ss&mntrId=6838202900000000000000115bfa1378
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2481025
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[color=#E56717]========== FireFox ==========/color

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Archivos de programa\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\ARCHIV~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\ARCHIV~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: C:\Archivos de programa\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: C:\Archivos de programa\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: C:\Archivos de programa\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Archivos de programa\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Archivos de programa\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Archivos de programa\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Archivos de programa\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{0153E448-190B-4987-BDE1-F256CADA672F}: C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/09/19 17:21:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/09/19 17:21:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Archivos de programa\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2012/08/26 22:02:05 | 000,000,000 | ---D | M]

[2012/09/16 22:13:02 | 000,000,000 | ---D | M] (No name found) -- C:\Archivos de programa\Mozilla Firefox\extensions

[color=#E56717]========== Chrome ==========/color

CHR - homepage: http://www.onmylike.com/?utm_source=b&utm_medium=smk&from=smk&uid=HDS728080PLAT20_PFD2V3SERRM15HRRM15HX&ts=1349826710&k2020=v2020
CHR - default_search_provider: Google Desktop (Enabled)
CHR - default_search_provider: search_url = http://127.0.0.1:4664/search&s=hBboO6ptW5KREa9XK9I4YgslTkc?q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.onmylike.com/?utm_source=b&utm_medium=smk&from=smk&uid=HDS728080PLAT20_PFD2V3SERRM15HRRM15HX&ts=1349826710&k2020=v2020
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\VICTOR\Configuraci\u00F3n local\Datos de programa\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\VICTOR\Configuraci\u00F3n local\Datos de programa\Google\Chrome\Application\22.0.1229.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\VICTOR\Configuraci\u00F3n local\Datos de programa\Google\Chrome\Application\22.0.1229.94\pdf.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Documents and Settings\VICTOR\Configuraci\u00F3n local\Datos de programa\Google\Chrome\User Data\Default\Extensions\ghicgddlkiabiolcalboepcnccfpinmp\10.11.21.5_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Documents and Settings\VICTOR\Configuraci\u00F3n local\Datos de programa\Google\Chrome\User Data\Default\Extensions\ghicgddlkiabiolcalboepcnccfpinmp\10.11.21.5_0\plugins/np-cwmp.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Archivos de programa\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Archivos de programa\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Archivos de programa\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Archivos de programa\Windows Media Player\npdsplay.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\ARCHIV~1\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\ARCHIV~1\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Archivos de programa\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Archivos de programa\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Archivos de programa\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Archivos de programa\Real\RealPlayer\Netscape6\nprpplugin.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Archivos de programa\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Archivos de programa\VideoLAN\VLC\npvlc.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw_1166636.dll
CHR - Extension: Adblock Plus (Beta) = C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Ashampoo ES = C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\ghicgddlkiabiolcalboepcnccfpinmp\10.11.21.5_0\
CHR - Extension: ytbyclick1.4 = C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\hfpghkmipjbamgnlilimjdmgkalpmcjn\10.11.21.5_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Angry Aliens = C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\lpbcdidbmghcmooekkbejlagekafeeaf\0.1.0.6_0\
CHR - Extension: 365Scores - Resultados en Vivo, Noticias y Notificaciones = C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\nmpppefjehmjbiplimkfjeamnohldmko\1.7.1_0\
CHR - Extension: Picasa = C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb\6.2.2_0\

O1 HOSTS File: ([2006/03/02 07:00:00 | 000,000,792 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {2EECD738-5844-4a99-B4B6-146BF802613B} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Archivos de programa\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Archivos de programa\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (ytbyclick1.4 Toolbar) - {ef0682e9-597e-414f-a6ea-e5af4a32b0b3} - C:\Archivos de programa\ytbyclick1.4\prxtbytby.dll (Conduit Ltd.)
O2 - BHO: (blekko search bar) - {f4f99c6d-f390-4fbc-858b-1541f9113fd8} - C:\Archivos de programa\blekkotb_001\blekkotb_019X.dll File not found
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (ytbyclick1.4 Toolbar) - {ef0682e9-597e-414f-a6ea-e5af4a32b0b3} - C:\Archivos de programa\ytbyclick1.4\prxtbytby.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (blekko search bar) - {f4f99c6d-f390-4fbc-858b-1541f9113fd8} - C:\Archivos de programa\blekkotb_001\blekkotb_019X.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (ytbyclick1.4 Toolbar) - {EF0682E9-597E-414F-A6EA-E5AF4A32B0B3} - C:\Archivos de programa\ytbyclick1.4\prxtbytby.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Anti-phishing Domain Advisor] C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Anti-phishing Domain Advisor\visicom_antiphishing.exe (Visicom Media Inc. (Powered by Panda Security))
O4 - HKLM..\Run: [egui] C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [LanguageShortcut] C:\Archivos de programa\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Archivos de programa\Archivos comunes\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [TkBellExe] C:\Archivos de programa\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TNOD UP] C:\Archivos de programa\ESET\TNod User & Password Finder\TNODUP.exe (Tukero[X]Team)
O4 - HKLM..\Run: [Tutorials] C:\Archivos de programa\Tutoriales100\tutoriales100_mx_3.exe ()
O4 - HKLM..\Run: [UpdTuto100SlmbaHP.exe] C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\tutoriales100_mx_3\UpdTuto100SlmbaHP.exe ()
O4 - HKLM..\Run: [USB Security] C:\Archivos de programa\USB Disk Security\USBGuard.exe (Zbshareware Lab)
O4 - HKLM..\Run: [VTPreset] C:\WINDOWS\System32\VTPreset.exe (S3 Graphics, Inc.)
O4 - HKCU..\Run: [GoogleDriveSync] "C:\Archivos de programa\Google\Drive\googledrivesync.exe" /autostart File not found
O4 - Startup: C:\Documents and Settings\VICTOR\Menú Inicio\Programas\Inicio\winlockless.lnk = C:\Documents and Settings\VICTOR\Mis documentos\Downloads\winlockless (1).exe (Hispasec)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 159
O8 - Extra context menu item: &Enviar a OneNote - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O8 - Extra context menu item: Descargar con Mipony - C:\Archivos de programa\MiPony\Browser\IEContext.htm ()
O8 - Extra context menu item: E&xportar a Microsoft Excel - C:\Archivos de programa\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Notas &vinculadas de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Notas &vinculadas de OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Archivos de programa\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe File not found
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1346114244921 (WUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A4F54B69-4487-4263-80F7-651701E2CDBE}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807573E5-5146-11D5-A672-00B0D022E945} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE14\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\docume~1\alluse~1.win\datosd~1\browse~1\23787~1.43\{16cdf~1\browse~1.dll) - File not found
O20 - AppInit_DLLs: (c:\docume~1\alluse~1.win\datosd~1\browse~1\22643~1.41\{16cdf~1\browse~1.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Mi página de inicio actual) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Felicidad.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Felicidad.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Archivos de programa\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Archivos de programa\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/06/09 23:04:45 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

[color=#E56717]========== Files/Folders - Created Within 30 Days ==========/color

[2012/10/15 17:24:03 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/10/15 17:23:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Menú Inicio\Programas\CyberLink PowerDVD
[2012/10/15 17:23:17 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012/10/14 21:19:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\VICTOR\Escritorio\OTL.exe
[2012/10/14 20:04:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menú Inicio\Programas\PIPO
[2012/10/14 20:04:42 | 000,000,000 | ---D | C] -- C:\PIPOING
[2012/10/14 17:56:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Datos de programa\ImgBurn
[2012/10/14 17:54:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menú Inicio\Programas\ImgBurn
[2012/10/14 17:54:03 | 000,000,000 | ---D | C] -- C:\Archivos de programa\ImgBurn
[2012/10/13 12:49:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Mis documentos\Mipony
[2012/10/13 08:35:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\galileoComer
[2012/10/13 08:34:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menú Inicio\Programas\Serie Galileo
[2012/10/13 08:34:42 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Serie Galileo
[2012/10/13 08:34:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\Downloaded Installations
[2012/10/11 17:57:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Datos de programa\PriceGong
[2012/10/11 16:10:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Mis documentos\CyberLink
[2012/10/11 13:22:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Datos de programa\blekkotb_019
[2012/10/09 21:55:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\A MI PADRE
[2012/10/09 21:55:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\EL PORVENIR
[2012/10/09 21:54:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\manuales office2010
[2012/10/09 21:40:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\SolidConverterPOrt6.0
[2012/10/09 19:09:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Datos de programa\Mipony
[2012/10/09 19:09:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Menú Inicio\Programas\MiPony
[2012/10/09 19:09:01 | 000,000,000 | ---D | C] -- C:\Archivos de programa\MiPony
[2012/10/08 20:44:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Datos de programa\AVS4YOU
[2012/10/08 20:41:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\AVS4YOU
[2012/10/08 20:38:49 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Archivos comunes\AVSMedia
[2012/10/08 18:49:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\tutoriales100_mx_3
[2012/10/08 18:49:21 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Tutoriales100
[2012/10/08 17:13:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\loca
[2012/10/06 20:30:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\MARVIN MP3
[2012/10/06 16:28:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Ahead
[2012/10/06 14:02:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\JOSE A. JIMENEZ
[2012/10/06 13:56:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\JAVIER SOLIS
[2012/10/06 13:55:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\ANTONIO AGUILAR
[2012/10/06 13:55:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\VICENTE FERNANDEZ
[2012/10/05 17:54:11 | 000,000,000 | ---D | C] -- C:\Archivos de programa\CyberLink
[2012/10/04 21:50:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\CyberLink
[2012/10/04 19:42:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Datos de programa\CyberLink
[2012/10/04 19:32:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Documentos\CyberLink
[2012/10/04 19:32:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\MediaServer
[2012/10/04 19:32:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\PDVD
[2012/10/04 19:32:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\CyberLink
[2012/10/04 19:32:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\CyberLink
[2012/10/04 19:28:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp
[2012/10/04 19:28:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\install_clap
[2012/10/04 19:24:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menú Inicio\Programas\Nero 7 Essentials
[2012/10/04 19:22:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Datos de programa\Ahead
[2012/10/04 19:13:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Nero
[2012/10/04 19:13:09 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Nero
[2012/10/04 19:13:09 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Archivos comunes\Ahead
[2012/10/02 16:44:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menú Inicio\Programas\PDF Password Remover v3.0
[2012/10/02 16:44:35 | 000,000,000 | ---D | C] -- C:\Archivos de programa\PDF Password Remover v3.0
[2012/10/02 16:33:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\comprimidos
[2012/09/26 22:31:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2012/09/26 22:31:20 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Reference Assemblies
[2012/09/26 16:49:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\Accesos directos de escritorio no usados
[2012/09/24 14:56:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Datos de programa\dvdcss
[2012/09/23 21:51:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Datos de programa\SolidDocuments
[2012/09/23 21:49:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menú Inicio\Programas\SolidDocuments
[2012/09/23 21:48:45 | 000,000,000 | ---D | C] -- C:\Archivos de programa\SolidDocuments
[2012/09/23 21:47:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\SolidDocuments
[2012/09/23 19:31:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\Crash Bandicoot Coleccion
[2012/09/23 19:30:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Escritorio\ALEXANDRA FORTUNE Y EL MISTERIO DEL ARCHIPIELAGO LUNAR
[2012/09/23 17:57:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menú Inicio\Programas\TNod User & Password Finder
[2012/09/23 14:01:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Datos de programa\blekkotb_001
[2012/09/23 14:01:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\blekkotb_001
[2012/09/23 14:01:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Anti-phishing Domain Advisor
[2012/09/23 11:41:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Datos de programa\Windows Search
[2012/09/23 07:48:18 | 001,082,081 | ---- | C] (www.minidvdsoft.com ) -- C:\Documents and Settings\VICTOR\Escritorio\freeisocreator.exe
[2012/09/22 17:07:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Datos de programa\Windows Desktop Search
[2012/09/22 17:07:17 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Windows Desktop Search
[2012/09/22 17:07:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2012/09/21 21:20:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2012/09/20 21:21:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Skymonk2
[2012/09/20 19:01:52 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Conduit
[2012/09/20 19:01:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\ytbyclick1.4
[2012/09/20 19:01:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\Conduit
[2012/09/20 19:01:39 | 000,000,000 | ---D | C] -- C:\Archivos de programa\ytbyclick1.4
[2012/09/20 19:00:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\CRE
[2012/09/19 17:20:12 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\WINDOWS\System32\pncrt.dll
[2012/09/19 17:20:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menú Inicio\Programas\RealNetworks
[2012/09/16 22:13:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Extensions
[2012/09/16 22:13:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\searchplugins
[2012/09/16 22:13:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\VICTOR\Start Menu
[2012/09/16 22:13:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Browser Manager
[2012/09/16 22:13:02 | 000,000,000 | ---D | C] -- C:\Archivos de programa\Mozilla Firefox
[2012/09/16 19:45:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Menú Inicio\Programas\VideoLAN
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color=#E56717]========== Files - Modified Within 30 Days ==========/color

[2012/10/15 17:42:59 | 000,000,490 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{B1678808-736E-40FC-8AEB-59C6E1FC2B60}.job
[2012/10/15 17:24:30 | 000,000,266 | ---- | M] () -- C:\WINDOWS\tasks\AutoKMS.job
[2012/10/15 17:23:44 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-1292428093-1214440339-682003330-1003.job
[2012/10/15 17:23:41 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/10/15 17:23:21 | 000,001,098 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/15 17:23:18 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/10/15 17:23:16 | 1308,151,808 | -HS- | M] () -- C:\hiberfil.sys
[2012/10/14 22:37:14 | 000,000,302 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-1292428093-1214440339-682003330-1003.job
[2012/10/14 22:10:00 | 000,000,838 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/10/14 22:09:05 | 000,001,132 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1292428093-1214440339-682003330-1003UA.job
[2012/10/14 22:01:00 | 000,001,102 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/14 20:17:24 | 000,000,094 | ---- | M] () -- C:\WINDOWS\MTB40.INI
[2012/10/14 20:04:55 | 000,000,060 | ---- | M] () -- C:\WINDOWS\ASYM.INI
[2012/10/14 09:46:59 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\VICTOR\Escritorio\OTL.exe
[2012/10/14 09:09:04 | 000,001,080 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1292428093-1214440339-682003330-1003Core.job
[2012/10/14 08:10:07 | 000,272,576 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/10/13 17:09:28 | 000,001,540 | ---- | M] () -- C:\Documents and Settings\VICTOR\Menú Inicio\Programas\Inicio\winlockless.lnk
[2012/10/13 13:52:06 | 000,140,976 | ---- | M] () -- C:\Documents and Settings\VICTOR\Escritorio\mcomision.jpg
[2012/10/11 09:20:49 | 000,002,347 | ---- | M] () -- C:\Documents and Settings\VICTOR\Escritorio\Google Chrome.lnk
[2012/10/09 22:16:31 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/10/09 20:44:04 | 001,971,704 | ---- | M] () -- C:\Documents and Settings\VICTOR\Escritorio\Medicina Tradicional Mexicana.pdf
[2012/10/09 19:09:02 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\VICTOR\Escritorio\MiPony.lnk
[2012/10/09 18:30:49 | 000,734,425 | ---- | M] () -- C:\Documents and Settings\VICTOR\Escritorio\obtenerEcPdfStream (1).pdf
[2012/10/09 18:26:51 | 000,645,783 | ---- | M] () -- C:\Documents and Settings\VICTOR\Escritorio\obtenerEcPdfStream.pdf
[2012/10/07 22:26:21 | 000,027,136 | ---- | M] () -- C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/05 21:30:29 | 000,000,049 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/10/05 18:05:59 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\VICTOR\Mis documentos\PDVD_MediaDisc.PlayList
[2012/10/02 16:46:32 | 000,010,752 | ---- | M] () -- C:\WINDOWS\System32\BASSMOD.dll
[2012/10/02 16:44:36 | 000,000,762 | ---- | M] () -- C:\Documents and Settings\VICTOR\Escritorio\PDF Password Remover v3.0.lnk
[2012/09/28 05:59:26 | 000,608,024 | ---- | M] () -- C:\WINDOWS\System32\perfh00A.dat
[2012/09/28 05:59:26 | 000,513,658 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/09/28 05:59:26 | 000,126,514 | ---- | M] () -- C:\WINDOWS\System32\perfc00A.dat
[2012/09/28 05:59:26 | 000,091,424 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/09/27 19:14:12 | 009,024,987 | ---- | M] () -- C:\Documents and Settings\VICTOR\Escritorio\TableDance.wmv
[2012/09/23 13:42:43 | 000,000,009 | ---- | M] () -- C:\END
[2012/09/23 07:48:30 | 001,082,081 | ---- | M] (www.minidvdsoft.com ) -- C:\Documents and Settings\VICTOR\Escritorio\freeisocreator.exe
[2012/09/19 17:20:12 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\WINDOWS\System32\pncrt.dll
[2012/09/16 22:13:05 | 000,000,315 | ---- | M] () -- C:\user.js
[2012/09/16 19:34:03 | 000,688,679 | ---- | M] () -- C:\Documents and Settings\VICTOR\Mis documentos\comprobante.pdf
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

[color=#E56717]========== Files Created - No Company Name ==========/color

[2012/10/15 17:23:16 | 1308,151,808 | -HS- | C] () -- C:\hiberfil.sys
[2012/10/14 20:04:55 | 000,000,507 | ---- | C] () -- C:\WINDOWS\WIN._IN
[2012/10/14 20:04:55 | 000,000,094 | ---- | C] () -- C:\WINDOWS\MTB40.INI
[2012/10/14 20:04:55 | 000,000,060 | ---- | C] () -- C:\WINDOWS\ASYM.INI
[2012/10/13 17:09:27 | 000,001,540 | ---- | C] () -- C:\Documents and Settings\VICTOR\Menú Inicio\Programas\Inicio\winlockless.lnk
[2012/10/13 15:53:37 | 000,140,976 | ---- | C] () -- C:\Documents and Settings\VICTOR\Escritorio\mcomision.jpg
[2012/10/09 20:43:07 | 001,971,704 | ---- | C] () -- C:\Documents and Settings\VICTOR\Escritorio\Medicina Tradicional Mexicana.pdf
[2012/10/09 19:09:02 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\VICTOR\Escritorio\MiPony.lnk
[2012/10/09 18:30:48 | 000,734,425 | ---- | C] () -- C:\Documents and Settings\VICTOR\Escritorio\obtenerEcPdfStream (1).pdf
[2012/10/09 18:26:49 | 000,645,783 | ---- | C] () -- C:\Documents and Settings\VICTOR\Escritorio\obtenerEcPdfStream.pdf
[2012/10/06 16:25:36 | 001,512,960 | ---- | C] () -- C:\Documents and Settings\VICTOR\Escritorio\Retoque_digital.pps
[2012/10/05 21:11:05 | 000,000,049 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2012/10/05 18:05:59 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\VICTOR\Mis documentos\PDVD_MediaDisc.PlayList
[2012/10/02 16:44:48 | 000,010,752 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2012/10/02 16:44:36 | 000,000,762 | ---- | C] () -- C:\Documents and Settings\VICTOR\Escritorio\PDF Password Remover v3.0.lnk
[2012/09/27 19:12:42 | 009,024,987 | ---- | C] () -- C:\Documents and Settings\VICTOR\Escritorio\TableDance.wmv
[2012/09/23 21:49:09 | 000,027,976 | ---- | C] () -- C:\WINDOWS\System32\solidlocalmon.dll
[2012/09/23 21:49:09 | 000,019,272 | ---- | C] () -- C:\WINDOWS\System32\solidlocalui.dll
[2012/09/22 17:07:28 | 000,001,874 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Menú Inicio\Programas\Windows Search.lnk
[2012/09/20 19:07:29 | 000,000,009 | ---- | C] () -- C:\END
[2012/09/16 22:13:04 | 000,000,315 | ---- | C] () -- C:\user.js
[2012/09/16 19:34:07 | 000,688,679 | ---- | C] () -- C:\Documents and Settings\VICTOR\Mis documentos\comprobante.pdf
[2012/09/04 19:16:36 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/09/04 18:21:14 | 000,065,536 | ---- | C] () -- C:\WINDOWS\IFinst27.exe
[2012/08/29 17:46:37 | 000,233,472 | R--- | C] () -- C:\WINDOWS\System32\cmirmdrv.exe
[2012/08/29 17:46:37 | 000,028,672 | R--- | C] () -- C:\WINDOWS\System32\cmirmdrv.dll
[2012/08/29 17:46:22 | 000,000,092 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2012/08/29 17:46:21 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2012/08/29 17:46:19 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Wininit.ini
[2012/08/29 17:46:15 | 000,121,329 | R--- | C] () -- C:\WINDOWS\Cmuda.ini
[2012/08/29 17:46:09 | 000,266,240 | ---- | C] () -- C:\WINDOWS\CMIUninstall.exe
[2012/08/29 17:46:09 | 000,225,280 | ---- | C] () -- C:\WINDOWS\CmiRmRedundDir.exe
[2012/08/29 17:46:09 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CMIRmDriver.dll
[2012/08/29 17:45:25 | 000,003,000 | R--- | C] () -- C:\WINDOWS\System32\SetupNT.sys
[2012/08/27 19:45:17 | 000,000,000 | ---- | C] () -- C:\WINDOWS\HPMProp.INI
[2012/08/27 19:02:09 | 000,068,710 | ---- | C] () -- C:\WINDOWS\hpoins05.dat
[2012/08/27 19:02:09 | 000,019,696 | ---- | C] () -- C:\WINDOWS\hpomdl05.dat
[2012/08/26 21:54:59 | 000,027,136 | ---- | C] () -- C:\Documents and Settings\VICTOR\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/26 21:16:23 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012/08/26 21:09:36 | 000,021,900 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012/08/26 14:32:31 | 000,004,205 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012/08/26 14:31:13 | 000,272,576 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

[color=#E56717]========== ZeroAccess Check ==========/color

[2012/09/22 09:40:41 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 07:48:38 | 001,499,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 05:52:53 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 07:48:48 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[color=#E56717]========== LOP Check ==========/color

[2012/09/28 20:31:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Anti-phishing Domain Advisor
[2012/08/29 21:47:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\avg9
[2012/10/11 15:07:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Browser Manager
[2012/08/27 19:57:07 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Common Files
[2012/09/14 09:02:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\DFX
[2012/08/27 19:52:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\DriverGenius
[2012/08/26 22:02:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\ESET
[2012/10/13 08:35:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\galileoComer
[2012/10/04 21:15:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\install_clap
[2012/10/04 19:32:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\PDVD
[2012/09/10 20:23:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Playrix Entertainment
[2012/09/23 21:47:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\SolidDocuments
[2012/09/06 18:43:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\SugarGames
[2012/09/04 19:29:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Tarma Installer
[2012/10/04 21:15:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Temp
[2012/08/29 17:39:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Zbshareware Lab
[2012/08/26 22:14:11 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users.WINDOWS\Datos de programa\{32364CEA-7855-4A3C-B674-53D8E9B97936}
[2012/10/11 13:22:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\VICTOR\Datos de programa\blekkotb_001
[2012/10/11 13:22:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\VICTOR\Datos de programa\blekkotb_019
[2012/09/04 19:26:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\VICTOR\Datos de programa\CrystalIdea Software
[2012/09/10 12:48:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\VICTOR\Datos de programa\Deep Shadows
[2012/10/14 18:15:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\VICTOR\Datos de programa\ImgBurn
[2012/10/14 17:45:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\VICTOR\Datos de programa\Mipony
[2012/09/14 09:13:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\VICTOR\Datos de programa\OpenCandy
[2012/10/14 10:31:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\VICTOR\Datos de programa\PriceGong
[2012/09/23 21:51:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\VICTOR\Datos de programa\SolidDocuments
[2012/09/22 17:07:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\VICTOR\Datos de programa\Windows Desktop Search
[2012/09/23 11:41:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\VICTOR\Datos de programa\Windows Search
[2012/08/29 17:37:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\VICTOR\Datos de programa\Zbshareware Lab

[color=#E56717]========== Purity Check ==========/color



< End of report >