elkpp
2006-02-20, 04:59
hi thanks for your help.
my machione is really bad...
any way here is my log and one popup page is opening all the time ad_w-a-r-e
pc cillin is bloking it but steel popup al the time
http://www.ad-w-a-r-e.com/cgi-bin/PopupV3?ID={94BF011D-9003-3025-1534-8BD6748167E5}&type=normal&mSkip=1&rnd=16492
--- Search result list ---
Look2Me.Topconverting: Configuración (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\H323TSP
SpywareNo: Clase raíz (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\Software\Classes\winapi32.Intelinks
SpywareNo: ID de clase (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C619394D-AE6F-4497-B49D-78FD76F9C986}
SpywareNo: Clase raíz (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\Software\Classes\winapi32.MyBaner
SpywareNo: ID de clase (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{E9320EFC-C75C-432C-8C51-86618C6F3952}
--- Process list ---
PID: 1564 ( 208) C:\WINDOWS\system32\rundll32.exe
size: 10000
MD5: CA6468AE463FCE9C434BF9B29352B7E0
PID: 1640 (1376) C:\Archivos de programa\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
size: 94208
MD5: CBF9C089B3BE2C4054A2EBBE7A5C1AC4
PID: 1652 (1376) C:\Archivos de programa\D-Tools\daemon.exe
size: 73728
MD5: 05F19EE0628A18BF79C377BF7EE9403D
PID: 412 (1376) C:\Archivos de programa\QuickTime\qttask.exe
size: 77824
MD5: 5D22B4258489575412F6D18AFFC847A2
PID: 1656 (1376) C:\Archivos de programa\Trend Micro\Internet Security 2006\pccguide.exe
size: 897089
MD5: 5FB38700D1317134DBB9D0CD626A8EF6
PID: 1228 (1376) C:\Archivos de programa\MSN Messenger\msnmsgr.exe
size: 6856704
MD5: 79AC63592F9B6750F2026A2520C11BEE
PID: 1916 (1376) C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe
size: 1415824
MD5: 70496EEE0DDBE485F658693826F44D38
PID: 700 (1644) C:\Archivos de programa\Yahoo!\Messenger\ymsgr_tray.exe
size: 90112
MD5: BED117A8BAB5D2C85D50E44F8E90705C
PID: 356 (1376) C:\Archivos de programa\LPerri\CiberControl 4.0 PRO\Control.exe
size: 4294656
MD5: 865093544290F16BED9AEE88B013AB5D
PID: 2800 ( 208) C:\WINDOWS\explorer.exe
size: 244496
MD5: 14586805C83DDB7DB7C25A57DD40CD67
PID: 3048 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 3160 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 1588 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 3024 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 2900 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 3272 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 2756 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 1904 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 1836 (2800) C:\Archivos de programa\Spybot - Search & Destroy\SpybotSD.exe
size: 4393096
MD5: 09CA174A605B480318731E691DC98539
PID: 0 ( 0) [System Process]
PID: 8 ( 0) System
PID: 164 ( 8) smss.exe
PID: 188 ( 164) csrss.exe
PID: 208 ( 164) winlogon.exe
PID: 236 ( 208) services.exe
PID: 248 ( 208) lsass.exe
PID: 428 ( 236) svchost.exe
PID: 460 ( 236) spoolsv.exe
PID: 488 ( 236) ccEvtMgr.exe
PID: 608 ( 236) svchost.exe
PID: 620 ( 236) GHOSTS~2.EXE
PID: 660 ( 236) navapsvc.exe
PID: 696 ( 236) NPROTECT.EXE
PID: 776 ( 236) PcCtlCom.exe
PID: 892 ( 236) MSTask.exe
PID: 920 ( 236) nopdb.exe
PID: 992 ( 236) stisvc.exe
PID: 1020 ( 236) Tmntsrv.exe
PID: 1036 ( 236) tmproxy.exe
PID: 1100 ( 236) WinMgmt.exe
PID: 1112 ( 236) svchost.exe
PID: 1132 ( 236) TmPfw.exe
PID: 272 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 2788 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 2348 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 2712 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
SpywareNo: Clase raíz (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\Software\Classes\winapi32.MyBHO
SpywareNo: ID de clase (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B439D5EB-0A61-4ED9-8C8F-EC4148BB23F7}
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2006-02-16 unins000.exe (51.41.0.0)
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-05-31 Update.exe (1.4.0.0)
2005-05-31 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-02-17 Includes\Cookies.sbi (*)
2006-02-17 Includes\PUPS.sbi (*)
2006-02-17 Includes\Dialer.sbi (*)
2006-02-17 Includes\Hijackers.sbi (*)
2006-02-17 Includes\Keyloggers.sbi (*)
2006-02-17 Includes\Malware.sbi (*)
2006-02-17 Includes\Revision.sbi (*)
2006-02-17 Includes\Security.sbi (*)
2006-02-17 Includes\Spybots.sbi (*)
2006-02-17 Includes\Trojans.sbi (*)
2005-02-17 Includes\Tracks.uti
--- System information ---
Windows 2000 (Build: 2195) Service Pack 4
--- Startup entries list ---
Located: HK_LM:Run, ccRegVfy
command: "C:\Archivos de programa\Archivos comunes\Symantec Shared\ccRegVfy.exe"
file: C:\Archivos de programa\Archivos comunes\Symantec Shared\ccRegVfy.exe
size: 62080
MD5: 08067f001876dbbc66c3472d0338922e
Located: HK_LM:Run, DAEMON Tools-1033
command: "C:\Archivos de programa\D-Tools\daemon.exe" -lang 1033
file: C:\Archivos de programa\D-Tools\daemon.exe
size: 73728
MD5: 05f19ee0628a18bf79c377bf7ee9403d
Located: HK_LM:Run, GhostStartTrayApp
command: C:\Archivos de programa\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
file: C:\Archivos de programa\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
size: 94208
MD5: cbf9c089b3be2c4054a2ebbe7a5c1ac4
Located: HK_LM:Run, pccguide.exe
command: "C:\Archivos de programa\Trend Micro\Internet Security 2006\pccguide.exe"
file: C:\Archivos de programa\Trend Micro\Internet Security 2006\pccguide.exe
size: 897089
MD5: 5fb38700d1317134dbb9d0cd626a8ef6
Located: HK_LM:Run, QuickTime Task
command: "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
file: C:\Archivos de programa\QuickTime\qttask.exe
size: 77824
MD5: 5d22b4258489575412f6d18affc847a2
Located: HK_LM:Run, SpybotSnD
command: "C:\Archivos de programa\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
file: C:\Archivos de programa\Spybot - Search & Destroy\SpybotSD.exe
size: 4393096
MD5: 09ca174a605b480318731e691dc98539
Located: HK_LM:Run, Synchronization Manager
command: mobsync.exe /logon
file: C:\WINDOWS\system32\mobsync.exe
size: 111888
MD5: 869697fd0b75de3cb54c17ccfc4e4f1c
Located: HK_LM:Run, EPSON Stylus C45 Series (DISABLED)
command: C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE /P23 "EPSON Stylus C45 Series" /O6 "USB001" /M "Stylus C45"
file: C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE
size: 99840
MD5: 3a498cf69876d3e87bf82e06e7de8541
Located: HK_LM:Run, GhostStartTrayApp (DISABLED)
command: C:\Archivos de programa\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
file: C:\Archivos de programa\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
size: 94208
MD5: cbf9c089b3be2c4054a2ebbe7a5c1ac4
Located: HK_LM:Run, NvCplDaemon (DISABLED)
command: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 10000
MD5: ca6468ae463fce9c434bf9b29352b7e0
Located: HK_LM:Run, QuickTime Task (DISABLED)
command: "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
file: C:\Archivos de programa\QuickTime\qttask.exe
size: 77824
MD5: 5d22b4258489575412f6d18affc847a2
Located: HK_LM:Run, Symantec NetDriver Monitor (DISABLED)
command: C:\ARCHIV~1\SYMNET~1\SNDMon.exe
file: C:\ARCHIV~1\SYMNET~1\SNDMon.exe
size: 95960
MD5: abba14e4513a3eb53194c472d94943d7
Located: HK_LM:Run, nwiz (DISABLED)
command: nwiz.exe /install
file: C:\WINDOWS\system32\nwiz.exe
size: 741376
MD5: a4ae9ba1e10cb9f6c0949c4db91a1f72
Located: HK_CU:Run, msnmsgr
command: "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
file: C:\Archivos de programa\MSN Messenger\msnmsgr.exe
size: 6856704
MD5: 79ac63592f9b6750f2026a2520c11bee
Located: HK_CU:Run, SpybotSD TeaTimer
command: C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe
size: 1415824
MD5: 70496eee0ddbe485f658693826f44d38
Located: HK_CU:Run, Yahoo! Pager
command: "C:\Archivos de programa\Yahoo!\Messenger\ypager.exe" -quiet
file: C:\Archivos de programa\Yahoo!\Messenger\ypager.exe
size: 3084288
MD5: 1374e98301bd093b60f93623c313dea2
Located: HK_CU:Run, EPSON Stylus C45 Series (DISABLED)
command: C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE /P23 "EPSON Stylus C45 Series" /M "Stylus C45" /EF "HKCU"
file: C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE
size: 99840
MD5: 3a498cf69876d3e87bf82e06e7de8541
Located: Inicio (común), Adobe Gamma Loader.lnk (DISABLED)
command: C:\Archivos de programa\Archivos comunes\Adobe\Calibration\Adobe Gamma Loader.exe
file: C:\Archivos de programa\Archivos comunes\Adobe\Calibration\Adobe Gamma Loader.exe
size: 110592
MD5: 5cd0cd0ec4dc5df459b3ac016764f5aa
Located: Inicio (común), CleanSweep Smart Sweep-Internet Sweep.LNK (DISABLED)
command: C:\Archivos de programa\Norton SystemWorks\Norton CleanSweep\csinsmnt.exe
file: C:\Archivos de programa\Norton SystemWorks\Norton CleanSweep\csinsmnt.exe
size: 225280
MD5: 6fb0878257593031786dda0cdede3a37
Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
Located: WinLogon, H323TSP
command: C:\WINDOWS\system32\dnrm0191e.dll
file: C:\WINDOWS\system32\dnrm0191e.dll
size: 0
MD5: d41d8cd98f00b204e9800998ecf8427e ???
Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
Located: WinLogon, wzcnotif
command: wzcdlg.dll
file: wzcdlg.dll
Located: WinLogon, FS Templates (DISABLED)
command: C:\WINDOWS\system32\j2p0lc7m1f.dll
file: C:\WINDOWS\system32\j2p0lc7m1f.dll
Located: WinLogon, Group Policy (DISABLED)
command: C:\WINDOWS\system32\kwdhe220.dll
file: C:\WINDOWS\system32\kwdhe220.dll
Located: WinLogon, H323TSP (DISABLED)
command: C:\WINDOWS\system32\dnrm0191e.dll
file: C:\WINDOWS\system32\dnrm0191e.dll
size: 0
MD5: d41d8cd98f00b204e9800998ecf8427e ???
Located: WinLogon, IPConfTSP (DISABLED)
command: C:\WINDOWS\system32\kwdhe220.dll
file: C:\WINDOWS\system32\kwdhe220.dll
Located: WinLogon, SensLogn (DISABLED)
command: WlNotify.dll
file: WlNotify.dll
Located: WinLogon, Telephony (DISABLED)
command: C:\WINDOWS\system32\i2420choef4c0.dll
file: C:\WINDOWS\system32\i2420choef4c0.dll
Located: WinLogon, WindowsUpdate (DISABLED)
command: C:\WINDOWS\system32\jtp0077me.dll
file: C:\WINDOWS\system32\jtp0077me.dll
--- Browser helper object list ---
--- ActiveX list ---
DirectAnimation Java Classes (DirectAnimation Java Classes)
DPF name: DirectAnimation Java Classes
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\Java\classes\dajava.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\dajava.cab
info link:
info source: Patrick M. Kolla
Internet Explorer Classes for Java (Internet Explorer Classes for Java)
DPF name: Internet Explorer Classes for Java
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\SYSTEM\iejava.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\iejava.cab
info link:
info source: Patrick M. Kolla
Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\Java\classes\xmldso.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla
Yahoo! Chat (Yahoo! Chat)
DPF name: Yahoo! Chat
CLSID name:
Installer:
Codebase: http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Yahoo! Checkers (Yahoo! Checkers)
DPF name: Yahoo! Checkers
CLSID name:
Installer:
Codebase: http://download.games.yahoo.com/games/clients/y/kt4_x.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Yahoo! Chess (Yahoo! Chess)
DPF name: Yahoo! Chess
CLSID name:
Installer:
Codebase: http://download.games.yahoo.com/games/clients/y/ct2_x.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Yahoo! Freecell Solitaire (Yahoo! Freecell Solitaire)
DPF name: Yahoo! Freecell Solitaire
CLSID name:
Installer:
Codebase: http://presence.games.yahoo.com/yog/y/fs10_x.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Yahoo! Literati (Yahoo! Literati)
DPF name: Yahoo! Literati
CLSID name:
Installer:
Codebase: http://download.games.yahoo.com/games/clients/y/tt4_x.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Yahoo! Pool 2 (Yahoo! Pool 2)
DPF name: Yahoo! Pool 2
CLSID name:
Installer:
Codebase: http://download.games.yahoo.com/games/clients/y/pote_x.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
{04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control)
DPF name:
CLSID name: HouseCall Control
Installer: C:\WINDOWS\Downloaded Program Files\xscan60.inf
Codebase: http://housecall60.trendmicro.com/housecall/xscan60.cab
description:
classification: Legitimate
known filename: xscan60.ocx
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\DOWNLO~1\
Long name: xscan60.ocx
Short name:
Date (created): 03/05/2005 11:45:54 a.m.
Date (last access): 19/02/2006
Date (last write): 03/05/2005 11:45:54 a.m.
Filesize: 475190
Attributes: archive
MD5: 145C288D55A91D6469223136EA93A406
CRC32: A36DBA2A
Version: 6.0.0.1261
{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
Codebase: http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
description: Macromedia ShockWave Flash Player 7
classification: Legitimate
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM32\Macromed\Director\
Long name: SwDir.dll
Short name: SWDIR.DLL
Date (created): 19/04/2004 04:58:48 a.m.
Date (last access): 19/02/2006
Date (last write): 09/09/2004 02:49:12 p.m.
Filesize: 54488
Attributes: archive
MD5: 943193399C341AC34E842CB07B5F29A0
CRC32: 12DEB8F4
Version: 10.1.0.11
{6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5)
DPF name:
CLSID name: Housecall ActiveX 6.5
Installer: C:\WINDOWS\Downloaded Program Files\hcImpl.inf
Codebase: http://us-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: Housecall_ActiveX.dll
Short name: HOUSEC~1.DLL
Date (created): 02/02/2006 04:22:42 p.m.
Date (last access): 19/02/2006
Date (last write): 02/02/2006 04:22:42 p.m.
Filesize: 357376
Attributes: archive
MD5: D91BD5AA0DA1728C1B11ECB5A7D4B3D7
CRC32: B40F7F41
Version: 6.5.2.7
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class)
DPF name:
CLSID name: MsnMessengerSetupDownloadControl Class
Installer: C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.inf
Codebase: http://messenger.msn.com/download/msnmessengersetupdownloader.cab
description:
classification: Legitimate
known filename: MsnMessengerSetupDownloader.ocx
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: MsnMessengerSetupDownloader.ocx
Short name: MSNMES~1.OCX
Date (created): 17/03/2005 02:48:34 p.m.
Date (last access): 19/02/2006
Date (last write): 17/03/2005 02:48:34 p.m.
Filesize: 113152
Attributes: archive
MD5: 92D24B6643919005213F60D5B537196A
CRC32: 31684779
Version: 1.0.0.2
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
Codebase: http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\system32\Macromed\Flash\
Long name: Flash8.ocx
Short name: FLASH8.OCX
Date (created): 27/08/2005 05:38:56 p.m.
Date (last access): 19/02/2006
Date (last write): 27/08/2005 05:38:56 p.m.
Filesize: 1435272
Attributes: archive
MD5: 900373C059C2B51CA91BF110DBDECB33
CRC32: F19599BC
Version: 8.0.22.0
my machione is really bad...
any way here is my log and one popup page is opening all the time ad_w-a-r-e
pc cillin is bloking it but steel popup al the time
http://www.ad-w-a-r-e.com/cgi-bin/PopupV3?ID={94BF011D-9003-3025-1534-8BD6748167E5}&type=normal&mSkip=1&rnd=16492
--- Search result list ---
Look2Me.Topconverting: Configuración (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\H323TSP
SpywareNo: Clase raíz (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\Software\Classes\winapi32.Intelinks
SpywareNo: ID de clase (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C619394D-AE6F-4497-B49D-78FD76F9C986}
SpywareNo: Clase raíz (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\Software\Classes\winapi32.MyBaner
SpywareNo: ID de clase (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{E9320EFC-C75C-432C-8C51-86618C6F3952}
--- Process list ---
PID: 1564 ( 208) C:\WINDOWS\system32\rundll32.exe
size: 10000
MD5: CA6468AE463FCE9C434BF9B29352B7E0
PID: 1640 (1376) C:\Archivos de programa\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
size: 94208
MD5: CBF9C089B3BE2C4054A2EBBE7A5C1AC4
PID: 1652 (1376) C:\Archivos de programa\D-Tools\daemon.exe
size: 73728
MD5: 05F19EE0628A18BF79C377BF7EE9403D
PID: 412 (1376) C:\Archivos de programa\QuickTime\qttask.exe
size: 77824
MD5: 5D22B4258489575412F6D18AFFC847A2
PID: 1656 (1376) C:\Archivos de programa\Trend Micro\Internet Security 2006\pccguide.exe
size: 897089
MD5: 5FB38700D1317134DBB9D0CD626A8EF6
PID: 1228 (1376) C:\Archivos de programa\MSN Messenger\msnmsgr.exe
size: 6856704
MD5: 79AC63592F9B6750F2026A2520C11BEE
PID: 1916 (1376) C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe
size: 1415824
MD5: 70496EEE0DDBE485F658693826F44D38
PID: 700 (1644) C:\Archivos de programa\Yahoo!\Messenger\ymsgr_tray.exe
size: 90112
MD5: BED117A8BAB5D2C85D50E44F8E90705C
PID: 356 (1376) C:\Archivos de programa\LPerri\CiberControl 4.0 PRO\Control.exe
size: 4294656
MD5: 865093544290F16BED9AEE88B013AB5D
PID: 2800 ( 208) C:\WINDOWS\explorer.exe
size: 244496
MD5: 14586805C83DDB7DB7C25A57DD40CD67
PID: 3048 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 3160 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 1588 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 3024 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 2900 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 3272 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 2756 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 1904 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 1836 (2800) C:\Archivos de programa\Spybot - Search & Destroy\SpybotSD.exe
size: 4393096
MD5: 09CA174A605B480318731E691DC98539
PID: 0 ( 0) [System Process]
PID: 8 ( 0) System
PID: 164 ( 8) smss.exe
PID: 188 ( 164) csrss.exe
PID: 208 ( 164) winlogon.exe
PID: 236 ( 208) services.exe
PID: 248 ( 208) lsass.exe
PID: 428 ( 236) svchost.exe
PID: 460 ( 236) spoolsv.exe
PID: 488 ( 236) ccEvtMgr.exe
PID: 608 ( 236) svchost.exe
PID: 620 ( 236) GHOSTS~2.EXE
PID: 660 ( 236) navapsvc.exe
PID: 696 ( 236) NPROTECT.EXE
PID: 776 ( 236) PcCtlCom.exe
PID: 892 ( 236) MSTask.exe
PID: 920 ( 236) nopdb.exe
PID: 992 ( 236) stisvc.exe
PID: 1020 ( 236) Tmntsrv.exe
PID: 1036 ( 236) tmproxy.exe
PID: 1100 ( 236) WinMgmt.exe
PID: 1112 ( 236) svchost.exe
PID: 1132 ( 236) TmPfw.exe
PID: 272 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 2788 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 2348 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 2712 ( 208) C:\ARCHIVOS DE PROGRAMA\INTERNET EXPLORER\IEXPLORE.EXE
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
SpywareNo: Clase raíz (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\Software\Classes\winapi32.MyBHO
SpywareNo: ID de clase (Clave del registro, fixing failed)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B439D5EB-0A61-4ED9-8C8F-EC4148BB23F7}
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2006-02-16 unins000.exe (51.41.0.0)
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-05-31 Update.exe (1.4.0.0)
2005-05-31 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-02-17 Includes\Cookies.sbi (*)
2006-02-17 Includes\PUPS.sbi (*)
2006-02-17 Includes\Dialer.sbi (*)
2006-02-17 Includes\Hijackers.sbi (*)
2006-02-17 Includes\Keyloggers.sbi (*)
2006-02-17 Includes\Malware.sbi (*)
2006-02-17 Includes\Revision.sbi (*)
2006-02-17 Includes\Security.sbi (*)
2006-02-17 Includes\Spybots.sbi (*)
2006-02-17 Includes\Trojans.sbi (*)
2005-02-17 Includes\Tracks.uti
--- System information ---
Windows 2000 (Build: 2195) Service Pack 4
--- Startup entries list ---
Located: HK_LM:Run, ccRegVfy
command: "C:\Archivos de programa\Archivos comunes\Symantec Shared\ccRegVfy.exe"
file: C:\Archivos de programa\Archivos comunes\Symantec Shared\ccRegVfy.exe
size: 62080
MD5: 08067f001876dbbc66c3472d0338922e
Located: HK_LM:Run, DAEMON Tools-1033
command: "C:\Archivos de programa\D-Tools\daemon.exe" -lang 1033
file: C:\Archivos de programa\D-Tools\daemon.exe
size: 73728
MD5: 05f19ee0628a18bf79c377bf7ee9403d
Located: HK_LM:Run, GhostStartTrayApp
command: C:\Archivos de programa\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
file: C:\Archivos de programa\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
size: 94208
MD5: cbf9c089b3be2c4054a2ebbe7a5c1ac4
Located: HK_LM:Run, pccguide.exe
command: "C:\Archivos de programa\Trend Micro\Internet Security 2006\pccguide.exe"
file: C:\Archivos de programa\Trend Micro\Internet Security 2006\pccguide.exe
size: 897089
MD5: 5fb38700d1317134dbb9d0cd626a8ef6
Located: HK_LM:Run, QuickTime Task
command: "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
file: C:\Archivos de programa\QuickTime\qttask.exe
size: 77824
MD5: 5d22b4258489575412f6d18affc847a2
Located: HK_LM:Run, SpybotSnD
command: "C:\Archivos de programa\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
file: C:\Archivos de programa\Spybot - Search & Destroy\SpybotSD.exe
size: 4393096
MD5: 09ca174a605b480318731e691dc98539
Located: HK_LM:Run, Synchronization Manager
command: mobsync.exe /logon
file: C:\WINDOWS\system32\mobsync.exe
size: 111888
MD5: 869697fd0b75de3cb54c17ccfc4e4f1c
Located: HK_LM:Run, EPSON Stylus C45 Series (DISABLED)
command: C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE /P23 "EPSON Stylus C45 Series" /O6 "USB001" /M "Stylus C45"
file: C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE
size: 99840
MD5: 3a498cf69876d3e87bf82e06e7de8541
Located: HK_LM:Run, GhostStartTrayApp (DISABLED)
command: C:\Archivos de programa\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
file: C:\Archivos de programa\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
size: 94208
MD5: cbf9c089b3be2c4054a2ebbe7a5c1ac4
Located: HK_LM:Run, NvCplDaemon (DISABLED)
command: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 10000
MD5: ca6468ae463fce9c434bf9b29352b7e0
Located: HK_LM:Run, QuickTime Task (DISABLED)
command: "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
file: C:\Archivos de programa\QuickTime\qttask.exe
size: 77824
MD5: 5d22b4258489575412f6d18affc847a2
Located: HK_LM:Run, Symantec NetDriver Monitor (DISABLED)
command: C:\ARCHIV~1\SYMNET~1\SNDMon.exe
file: C:\ARCHIV~1\SYMNET~1\SNDMon.exe
size: 95960
MD5: abba14e4513a3eb53194c472d94943d7
Located: HK_LM:Run, nwiz (DISABLED)
command: nwiz.exe /install
file: C:\WINDOWS\system32\nwiz.exe
size: 741376
MD5: a4ae9ba1e10cb9f6c0949c4db91a1f72
Located: HK_CU:Run, msnmsgr
command: "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
file: C:\Archivos de programa\MSN Messenger\msnmsgr.exe
size: 6856704
MD5: 79ac63592f9b6750f2026a2520c11bee
Located: HK_CU:Run, SpybotSD TeaTimer
command: C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe
size: 1415824
MD5: 70496eee0ddbe485f658693826f44d38
Located: HK_CU:Run, Yahoo! Pager
command: "C:\Archivos de programa\Yahoo!\Messenger\ypager.exe" -quiet
file: C:\Archivos de programa\Yahoo!\Messenger\ypager.exe
size: 3084288
MD5: 1374e98301bd093b60f93623c313dea2
Located: HK_CU:Run, EPSON Stylus C45 Series (DISABLED)
command: C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE /P23 "EPSON Stylus C45 Series" /M "Stylus C45" /EF "HKCU"
file: C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\E_S4I4T1.EXE
size: 99840
MD5: 3a498cf69876d3e87bf82e06e7de8541
Located: Inicio (común), Adobe Gamma Loader.lnk (DISABLED)
command: C:\Archivos de programa\Archivos comunes\Adobe\Calibration\Adobe Gamma Loader.exe
file: C:\Archivos de programa\Archivos comunes\Adobe\Calibration\Adobe Gamma Loader.exe
size: 110592
MD5: 5cd0cd0ec4dc5df459b3ac016764f5aa
Located: Inicio (común), CleanSweep Smart Sweep-Internet Sweep.LNK (DISABLED)
command: C:\Archivos de programa\Norton SystemWorks\Norton CleanSweep\csinsmnt.exe
file: C:\Archivos de programa\Norton SystemWorks\Norton CleanSweep\csinsmnt.exe
size: 225280
MD5: 6fb0878257593031786dda0cdede3a37
Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
Located: WinLogon, H323TSP
command: C:\WINDOWS\system32\dnrm0191e.dll
file: C:\WINDOWS\system32\dnrm0191e.dll
size: 0
MD5: d41d8cd98f00b204e9800998ecf8427e ???
Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
Located: WinLogon, wzcnotif
command: wzcdlg.dll
file: wzcdlg.dll
Located: WinLogon, FS Templates (DISABLED)
command: C:\WINDOWS\system32\j2p0lc7m1f.dll
file: C:\WINDOWS\system32\j2p0lc7m1f.dll
Located: WinLogon, Group Policy (DISABLED)
command: C:\WINDOWS\system32\kwdhe220.dll
file: C:\WINDOWS\system32\kwdhe220.dll
Located: WinLogon, H323TSP (DISABLED)
command: C:\WINDOWS\system32\dnrm0191e.dll
file: C:\WINDOWS\system32\dnrm0191e.dll
size: 0
MD5: d41d8cd98f00b204e9800998ecf8427e ???
Located: WinLogon, IPConfTSP (DISABLED)
command: C:\WINDOWS\system32\kwdhe220.dll
file: C:\WINDOWS\system32\kwdhe220.dll
Located: WinLogon, SensLogn (DISABLED)
command: WlNotify.dll
file: WlNotify.dll
Located: WinLogon, Telephony (DISABLED)
command: C:\WINDOWS\system32\i2420choef4c0.dll
file: C:\WINDOWS\system32\i2420choef4c0.dll
Located: WinLogon, WindowsUpdate (DISABLED)
command: C:\WINDOWS\system32\jtp0077me.dll
file: C:\WINDOWS\system32\jtp0077me.dll
--- Browser helper object list ---
--- ActiveX list ---
DirectAnimation Java Classes (DirectAnimation Java Classes)
DPF name: DirectAnimation Java Classes
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\Java\classes\dajava.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\dajava.cab
info link:
info source: Patrick M. Kolla
Internet Explorer Classes for Java (Internet Explorer Classes for Java)
DPF name: Internet Explorer Classes for Java
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\SYSTEM\iejava.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\iejava.cab
info link:
info source: Patrick M. Kolla
Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\Java\classes\xmldso.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla
Yahoo! Chat (Yahoo! Chat)
DPF name: Yahoo! Chat
CLSID name:
Installer:
Codebase: http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Yahoo! Checkers (Yahoo! Checkers)
DPF name: Yahoo! Checkers
CLSID name:
Installer:
Codebase: http://download.games.yahoo.com/games/clients/y/kt4_x.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Yahoo! Chess (Yahoo! Chess)
DPF name: Yahoo! Chess
CLSID name:
Installer:
Codebase: http://download.games.yahoo.com/games/clients/y/ct2_x.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Yahoo! Freecell Solitaire (Yahoo! Freecell Solitaire)
DPF name: Yahoo! Freecell Solitaire
CLSID name:
Installer:
Codebase: http://presence.games.yahoo.com/yog/y/fs10_x.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Yahoo! Literati (Yahoo! Literati)
DPF name: Yahoo! Literati
CLSID name:
Installer:
Codebase: http://download.games.yahoo.com/games/clients/y/tt4_x.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Yahoo! Pool 2 (Yahoo! Pool 2)
DPF name: Yahoo! Pool 2
CLSID name:
Installer:
Codebase: http://download.games.yahoo.com/games/clients/y/pote_x.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
{04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control)
DPF name:
CLSID name: HouseCall Control
Installer: C:\WINDOWS\Downloaded Program Files\xscan60.inf
Codebase: http://housecall60.trendmicro.com/housecall/xscan60.cab
description:
classification: Legitimate
known filename: xscan60.ocx
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\DOWNLO~1\
Long name: xscan60.ocx
Short name:
Date (created): 03/05/2005 11:45:54 a.m.
Date (last access): 19/02/2006
Date (last write): 03/05/2005 11:45:54 a.m.
Filesize: 475190
Attributes: archive
MD5: 145C288D55A91D6469223136EA93A406
CRC32: A36DBA2A
Version: 6.0.0.1261
{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
Codebase: http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
description: Macromedia ShockWave Flash Player 7
classification: Legitimate
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM32\Macromed\Director\
Long name: SwDir.dll
Short name: SWDIR.DLL
Date (created): 19/04/2004 04:58:48 a.m.
Date (last access): 19/02/2006
Date (last write): 09/09/2004 02:49:12 p.m.
Filesize: 54488
Attributes: archive
MD5: 943193399C341AC34E842CB07B5F29A0
CRC32: 12DEB8F4
Version: 10.1.0.11
{6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5)
DPF name:
CLSID name: Housecall ActiveX 6.5
Installer: C:\WINDOWS\Downloaded Program Files\hcImpl.inf
Codebase: http://us-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
Path: C:\WINDOWS\Downloaded Program Files\
Long name: Housecall_ActiveX.dll
Short name: HOUSEC~1.DLL
Date (created): 02/02/2006 04:22:42 p.m.
Date (last access): 19/02/2006
Date (last write): 02/02/2006 04:22:42 p.m.
Filesize: 357376
Attributes: archive
MD5: D91BD5AA0DA1728C1B11ECB5A7D4B3D7
CRC32: B40F7F41
Version: 6.5.2.7
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class)
DPF name:
CLSID name: MsnMessengerSetupDownloadControl Class
Installer: C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.inf
Codebase: http://messenger.msn.com/download/msnmessengersetupdownloader.cab
description:
classification: Legitimate
known filename: MsnMessengerSetupDownloader.ocx
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: MsnMessengerSetupDownloader.ocx
Short name: MSNMES~1.OCX
Date (created): 17/03/2005 02:48:34 p.m.
Date (last access): 19/02/2006
Date (last write): 17/03/2005 02:48:34 p.m.
Filesize: 113152
Attributes: archive
MD5: 92D24B6643919005213F60D5B537196A
CRC32: 31684779
Version: 1.0.0.2
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
Codebase: http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\system32\Macromed\Flash\
Long name: Flash8.ocx
Short name: FLASH8.OCX
Date (created): 27/08/2005 05:38:56 p.m.
Date (last access): 19/02/2006
Date (last write): 27/08/2005 05:38:56 p.m.
Filesize: 1435272
Attributes: archive
MD5: 900373C059C2B51CA91BF110DBDECB33
CRC32: F19599BC
Version: 8.0.22.0