florenciam
2015-04-30, 23:30
Hi, a week ago my USB drive got infected with a virus that turned my files into shortcuts, and my brother accidentally clicked on one of them. I ran the Spybot scan on my computer and it found some threats but after "deleting" such threats they appear again in the following scans. I run Windows XP and I had already scanned my computer with ESET NOD 32 antivirus, which didn't find anything.
Here are the logs:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-04-2015 01
Ran by cacha (administrator) on FLORNOTE on 30-04-2015 17:15:47
Running from C:\Documents and Settings\cacha\Escritorio
Loaded Profiles: cacha (Available profiles: cacha & Administrador & Invitado)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Español (alfabetización internacional)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Broadcom Corporation.) C:\Archivos de programa\WIDCOMM\Bluetooth Software\bin\btwdins.exe
() C:\WINDOWS\system32\WLTRYSVC.EXE
(Dell Inc.) C:\WINDOWS\system32\BCMWLTRY.EXE
(IDT, Inc.) C:\Archivos de programa\IDT\XPV10_6147v005\WDM\stacsv.exe
(IDT, Inc.) C:\Archivos de programa\IDT\WDM\sttray.exe
(Andrea Electronics Corporation) C:\WINDOWS\system32\AESTFltr.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\Apoint.exe
(Creative Technology Ltd.) C:\WINDOWS\OEM13Mon.exe
(Dell Inc.) C:\WINDOWS\system32\WLTRAY.EXE
(ESET) C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe
(Hewlett-Packard) C:\Archivos de programa\HP\HP Software Update\hpwuSchd2.exe
(Oracle Corporation) C:\Archivos de programa\Archivos comunes\Java\Java Update\jusched.exe
(ESET) C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe
(Safer-Networking Ltd.) C:\Archivos de programa\Spybot - Search & Destroy 2\SDTray.exe
(Oracle Corporation) C:\Archivos de programa\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Archivos de programa\Windows Media Player\wmpnscfg.exe
(Spotify Ltd) C:\Documents and Settings\cacha\Datos de programa\Spotify\SpotifyWebHelper.exe
(Nalpeiron Ltd.) C:\WINDOWS\system32\NLSSRV32.EXE
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Broadcom Corporation.) C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTTray.exe
(Absolute Software Corp.) C:\WINDOWS\system32\rpcnet.exe
(Safer-Networking Ltd.) C:\Archivos de programa\Spybot - Search & Destroy 2\SDFSSvc.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\ApMsgFwd.exe
(Broadcom Corporation.) C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\hidfind.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\ApntEx.exe
(Safer-Networking Ltd.) C:\Archivos de programa\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Archivos de programa\Windows Media Player\wmpnetwk.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Archivos de programa\Microsoft Office\Office12\WINWORD.EXE
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Archivos de programa\IDT\WDM\sttray.exe [483420 2009-02-20] (IDT, Inc.)
HKLM\...\Run: [AESTFltr] => C:\WINDOWS\system32\AESTFltr.exe [729088 2009-02-20] (Andrea Electronics Corporation)
HKLM\...\Run: [Apoint] => C:\Archivos de programa\DellTPad\Apoint.exe [217088 2009-03-13] (Alps Electric Co., Ltd.)
HKLM\...\Run: [OEM13Mon.exe] => C:\WINDOWS\OEM13Mon.exe [36864 2008-01-08] (Creative Technology Ltd.)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\WINDOWS\system32\WLTRAY.exe [2220032 2008-10-24] (Dell Inc.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /installquiet
HKLM\...\Run: [NVHotkey] => rundll32.exe nvHotkey.dll,Start
HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit
HKLM\...\Run: [DELL Webcam Manager] => C:\Archivos de programa\Dell\Dell Webcam Manager\DellWMgr.exe [118784 2007-07-27] (Creative Technology Ltd.)
HKLM\...\Run: [GrooveMonitor] => C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [HP Software Update] => C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [SunJavaUpdateSched] => C:\Archivos de programa\Archivos comunes\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Run: [egui] => C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe [5046472 2014-09-30] (ESET)
HKLM\...\Run: [SDTray] => C:\Archivos de programa\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [WMPNSCFG] => C:\Archivos de programa\Windows Media Player\WMPNSCFG.exe [204800 2009-02-04] (Microsoft Corporation)
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [Spotify Web Helper] => C:\Documents and Settings\cacha\Datos de programa\Spotify\SpotifyWebHelper.exe [1959992 2015-03-11] (Spotify Ltd)
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [Hide.me] => [X]
HKU\S-1-5-18\...\Run: [GoogleChromeAutoLaunch_A2E3159C0817FADA26422CFDCE0E82F1] => C:\Archivos de programa\Google\Chrome\Application\chrome.exe [812872 2015-04-13] (Google Inc.)
Startup: C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio\BTTray.lnk [2012-03-07]
ShortcutTarget: BTTray.lnk -> C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2 (GFS Stub)] -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 3 (GFS Folder)] -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyServer: [S-1-5-21-1844237615-1767777339-1417001333-1003] => localhost:8080
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.ar/
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://es.msn.com/?ocid=iehp
URLSearchHook: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 - BittorrentBar_ES Toolbar - {ad06fb5f-fef7-4a84-8c58-dca34f8e3d36} - No File
URLSearchHook: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No File
SearchScopes: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> {3E3A04E4-65A7-4BF0-BE56-A25D6C594ACF} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=es_ES&apn_ptnrs=^U3&apn_dtid=^OSJ000^YY^AR&apn_uid=29B3F03A-E8F4-4364-BB2F-056CD38F361A&apn_sauid=74974A9E-826B-490A-A51C-B8A407B7C46D
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Archivos de programa\Java\jre7\bin\ssv.dll [2014-11-04] (Oracle Corporation)
BHO: BitTorrentBar Toolbar -> {88c7f2aa-f93f-432c-8f0e-b7d85967a527} -> No File
BHO: Windows Live Aplicación auxiliar de inicio de sesión -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO: BittorrentBar_ES Toolbar -> {ad06fb5f-fef7-4a84-8c58-dca34f8e3d36} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Archivos de programa\Java\jre7\bin\jp2ssv.dll [2014-11-04] (Oracle Corporation)
Toolbar: HKLM - BittorrentBar_ES Toolbar - {ad06fb5f-fef7-4a84-8c58-dca34f8e3d36} - No File
Toolbar: HKLM - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No File
Toolbar: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> BitTorrentBar Toolbar - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
Toolbar: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> BittorrentBar_ES Toolbar - {AD06FB5F-FEF7-4A84-8C58-DCA34F8E3D36} - No File
Toolbar: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-1_4_2_08-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Archivos de programa\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll [2013-09-25] (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 108.168.162.137 8.8.4.4
FireFox:
========
FF ProfilePath: C:\Documents and Settings\cacha\Datos de programa\Mozilla\Firefox\Profiles\8webyrm2.default
FF Homepage: hxxp://www.google.com.ar/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Archivos de programa\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Archivos de programa\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-11-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Archivos de programa\Java\jre7\bin\plugin2\npjp2.dll [2014-11-04] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Archivos de programa\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Archivos de programa\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Archivos de programa\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Archivos de programa\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Archivos de programa\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Archivos de programa\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Archivos de programa\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin HKU\S-1-5-21-1844237615-1767777339-1417001333-1003: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Archivos de programa\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-1844237615-1767777339-1417001333-1003: samsung.com/SamsungLinkPCPlugin -> C:\Archivos de programa\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll No File
FF Plugin ProgramFiles/Appdata: C:\Archivos de programa\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Archivos de programa\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF SearchPlugin: C:\Archivos de programa\mozilla firefox\browser\searchplugins\creativecommons.xml [2014-07-22]
FF SearchPlugin: C:\Archivos de programa\mozilla firefox\browser\searchplugins\mercadolibre-ar.xml [2014-07-22]
FF Extension: FlashGot - C:\Documents and Settings\cacha\Datos de programa\Mozilla\Firefox\Profiles\8webyrm2.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2015-01-21]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-03-17]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Archivos de programa\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Archivos de programa\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2015-01-25]
Chrome:
=======
CHR HomePage: Default ->
CHR Profile: C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-22]
CHR Extension: (Easy Clock) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\dplbpgapoedppajbikieafefmcceaagn [2014-08-26]
CHR Extension: (BetaFish Adblocker) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-17]
CHR Extension: (Hola Better Internet) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2014-07-07]
CHR Extension: (Pin It Button) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2014-08-26]
CHR Extension: (Eye Dropper) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\hmdcmlfkchdmnmnmheododdhjedfccka [2014-11-11]
CHR Extension: (Kindle Cloud Reader) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2014-05-17]
CHR Extension: (StayFocusd) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2014-10-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-15]
CHR Extension: (Google Dictionary (by Google)) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2014-08-26]
CHR Extension: (Pocket) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2015-02-25]
CHR Extension: (feedly) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\ndhinffkekpekljifjkkkkkhopnjodja [2014-11-11]
CHR Extension: (Do It (Tomorrow)) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\nfagjoblnoeagfhfhohcdklnddjaiglo [2014-10-29]
CHR Extension: (Google Wallet) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-17]
CHR Extension: (Sidekick by HubSpot) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\oiiaigjnkhngdbnoookogelabohpglmd [2014-07-05]
CHR Extension: (Evernote Web Clipper) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2014-09-09]
CHR Extension: (Writer) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\pnengefjfhgcceajaepbjhanoojifmog [2014-11-11]
CHR HKLM\...\Chrome\Extension: [lhpgolofjlpnkdafbgejgnclbjnpgfee] - C:\DOCUME~1\cacha\CONFIG~1\Temp\ccex.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [mhfdcmehmjcclgopdodkjdicohagipid] - C:\Documents and Settings\cacha\Configuración local\Datos de programa\CRE\mhfdcmehmjcclgopdodkjdicohagipid.crx [2012-04-17]
CHR HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\DOCUME~1\cacha\CONFIG~1\DATOSD~1\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2015-02-21]
CHR HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mhfdcmehmjcclgopdodkjdicohagipid] - C:\Documents and Settings\cacha\Configuración local\Datos de programa\CRE\mhfdcmehmjcclgopdodkjdicohagipid.crx [2012-04-17]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 btwdins; C:\Archivos de programa\WIDCOMM\Bluetooth Software\bin\btwdins.exe [264800 2008-09-17] (Broadcom Corporation.)
R2 ekrn; C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe [1343920 2014-09-30] (ESET)
S2 gupdate; C:\Archivos de programa\Google\Update\GoogleUpdate.exe [116648 2013-12-17] (Google Inc.)
S3 gupdatem; C:\Archivos de programa\Google\Update\GoogleUpdate.exe [116648 2013-12-17] (Google Inc.)
R3 hpqcxs08; C:\Archivos de programa\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Archivos de programa\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Archivos de programa\Archivos comunes\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Archivos de programa\Java\jre7\bin\jqs.exe [182696 2014-11-04] (Oracle Corporation)
S3 Microsoft Office Groove Audit Service; C:\Archivos de programa\Microsoft Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation)
S3 MozillaMaintenance; C:\Archivos de programa\Mozilla Maintenance Service\maintenanceservice.exe [148080 2015-04-24] (Mozilla Foundation)
R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
S3 odserv; C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE12\ODSERV.EXE [440696 2011-07-20] (Microsoft Corporation)
S3 ose; C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE [145184 2006-10-26] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 rpcnet; C:\WINDOWS\system32\rpcnet.exe [78032 2015-04-26] (Absolute Software Corp.)
R2 SDScannerService; C:\Archivos de programa\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Archivos de programa\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Archivos de programa\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 STacSV; c:\archivos de programa\idt\xpv10_6147v005\wdm\stacsv.exe [249938 2009-02-20] (IDT, Inc.)
R2 wltrysvc; C:\WINDOWS\System32\bcmwltry.exe [1961984 2008-10-24] (Dell Inc.) [File not signed]
R2 WMPNetworkSvc; C:\Archivos de programa\Windows Media Player\WMPNetwk.exe [916480 2009-02-04] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 AESTAud; C:\WINDOWS\System32\drivers\AESTAud.sys [112512 2009-02-20] (Andrea Electronics Corporation)
R3 BCM43XX; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [1287552 2008-10-24] (Broadcom Corporation)
R3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [539640 2008-07-26] (Broadcom Corporation.)
R3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [37424 2008-07-26] (Broadcom Corporation.)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [879832 2008-07-29] (Broadcom Corporation.)
R3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [156816 2008-07-29] (Broadcom Corporation.)
R3 btwhid; C:\WINDOWS\System32\DRIVERS\btwhid.sys [55352 2008-07-26] (Broadcom Corporation.)
R3 btwmodem; C:\WINDOWS\System32\DRIVERS\btwmodem.sys [37280 2008-07-26] (Broadcom Corporation.)
R3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [74688 2008-07-26] (Broadcom Corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R1 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [185688 2014-09-30] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [135296 2014-09-30] (ESET)
R1 epfwtdir; C:\WINDOWS\System32\DRIVERS\epfwtdir.sys [118768 2014-09-30] (ESET)
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 O2MDGRDR; C:\WINDOWS\System32\DRIVERS\o2mdg.sys [58144 2009-03-19] (O2Micro )
R3 O2SDGRDR; C:\WINDOWS\System32\DRIVERS\o2sdg.sys [41376 2009-02-24] (O2Micro )
R3 OEM13Afx; C:\WINDOWS\system32\Drivers\OEM13Afx.sys [141376 2007-06-08] (Creative Technology Ltd.)
R3 OEM13Vfx; C:\WINDOWS\System32\DRIVERS\OEM13Vfx.sys [7424 2007-03-05] (EyePower Games Pte. Ltd.)
R3 OEM13Vid; C:\WINDOWS\System32\DRIVERS\OEM13Vid.sys [235840 2008-05-29] (Creative Technology Ltd.)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1548339 2009-02-20] (IDT, Inc.)
S3 vulfnths; C:\WINDOWS\System32\Drivers\vulfnth.sys [6912 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S3 vulfntrs; C:\WINDOWS\System32\Drivers\vulfntr.sys [11392 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S0 cerc6; No ImagePath
S3 CrystalSysInfo; \??\C:\Archivos de programa\MediaCoder\SysInfo.sys [X]
S3 GenericMount; system32\DRIVERS\GenericMount.sys [X]
S4 IntelIde; No ImagePath
U2 V2iMount; No ImagePath
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-30 17:15 - 2015-04-30 17:16 - 00030070 _____ () C:\Documents and Settings\cacha\Escritorio\FRST.txt
2015-04-30 17:11 - 2015-04-30 17:15 - 00000000 ____D () C:\FRST
2015-04-30 17:09 - 2015-04-30 17:09 - 01140736 _____ (Farbar) C:\Documents and Settings\cacha\Escritorio\FRST.exe
2015-04-30 13:22 - 2015-04-30 13:22 - 00012285 _____ () C:\Documents and Settings\cacha\Escritorio\Scan Results.150430-1322.txt
2015-04-28 08:21 - 2015-04-28 08:21 - 00065536 _____ () C:\WINDOWS\Minidump\Mini042815-01.dmp
2015-04-24 19:11 - 2015-04-24 19:13 - 00000000 ____D () C:\Archivos de programa\Mozilla Firefox
2015-04-24 08:20 - 2015-04-24 08:20 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\ProcAlyzer Dumps
2015-04-23 19:59 - 2015-04-23 19:59 - 00000000 ___RD () C:\Documents and Settings\NetworkService\Mis documentos\Mi música
2015-04-23 19:59 - 2015-04-23 19:59 - 00000000 ____D () C:\Documents and Settings\NetworkService\Mis documentos
2015-04-20 15:41 - 2015-04-30 00:06 - 00013312 ____H () C:\Documents and Settings\cacha\Escritorio\photothumb.db
2015-04-18 16:17 - 2015-04-18 16:18 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio\Para leer
2015-04-18 16:15 - 2015-04-18 16:16 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio\Art in Translation texts
2015-04-17 22:09 - 2015-04-17 22:09 - 00000000 ____D () C:\Documents and Settings\LocalService\Menú Inicio\Programas
2015-04-17 22:09 - 2015-04-17 22:09 - 00000000 ____D () C:\Documents and Settings\LocalService\Menú Inicio
2015-04-17 22:08 - 2015-04-17 22:08 - 00000000 ____D () C:\Archivos de programa\Asoftech
2015-04-17 21:44 - 2015-04-30 17:00 - 00000658 _____ () C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
2015-04-17 21:44 - 2015-04-17 21:44 - 00001905 _____ () C:\Documents and Settings\All Users\Menú Inicio\Programas\Spybot-S&D Start Center.lnk
2015-04-17 21:44 - 2015-04-17 21:44 - 00001899 _____ () C:\Documents and Settings\All Users\Escritorio\Spybot-S&D Start Center.lnk
2015-04-17 21:44 - 2015-04-17 21:44 - 00000630 _____ () C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2015-04-17 21:44 - 2015-04-17 21:44 - 00000460 _____ () C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
2015-04-17 21:44 - 2015-04-17 21:44 - 00000000 ____D () C:\Documents and Settings\All Users\Menú Inicio\Programas\Spybot - Search & Destroy 2
2015-04-17 21:43 - 2015-04-17 22:10 - 00000000 ____D () C:\Archivos de programa\Spybot - Search & Destroy 2
2015-04-17 21:43 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean.exe
2015-04-17 21:28 - 2012-07-27 06:45 - 00000102 _____ () C:\medicina.cmd
2015-04-16 19:23 - 2015-04-18 17:31 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\pinguino
2015-04-15 21:40 - 2015-04-15 21:40 - 00000132 _____ () C:\Documents and Settings\cacha\Datos de programa\Prefs. de formato PNG de Adobe CS6
2015-04-09 21:54 - 2015-04-10 16:08 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Stock Photography
2015-04-07 17:54 - 2015-04-07 17:54 - 00065536 _____ () C:\WINDOWS\Minidump\Mini040715-01.dmp
2015-04-07 17:51 - 2015-04-28 08:21 - 205238272 _____ () C:\WINDOWS\MEMORY.DMP
2015-03-31 11:24 - 2015-03-31 11:24 - 00000737 _____ () C:\Documents and Settings\cacha\Escritorio\Acceso directo a Red - Logan, J..lnk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-30 17:15 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio
2015-04-30 17:14 - 2014-05-27 15:26 - 00000488 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{C604CD4C-5685-42BB-8F60-C2D813575826}.job
2015-04-30 17:00 - 2012-03-07 23:57 - 00077291 _____ () C:\WINDOWS\system32\nvModes.001
2015-04-30 17:00 - 2008-04-13 20:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2015-04-30 16:58 - 2014-03-08 10:15 - 00000222 _____ () C:\WINDOWS\Tasks\Notificación de inicio de sesión de fin de servicio de Microsoft Windows XP.job
2015-04-30 16:58 - 2013-12-17 14:43 - 00001098 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-30 16:58 - 2012-03-08 00:03 - 00078032 _____ (Absolute Software Corp.) C:\WINDOWS\system32\rpcnet.dll
2015-04-30 16:58 - 2012-03-07 23:55 - 00200942 _____ () C:\WINDOWS\system32\nvapps.xml
2015-04-30 16:58 - 2012-03-07 21:10 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-04-30 16:58 - 2012-03-07 16:54 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-04-30 16:58 - 2012-03-07 16:54 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2015-04-30 16:58 - 2012-03-07 16:52 - 00017408 _____ () C:\WINDOWS\system32\rpcnetp.exe
2015-04-30 16:29 - 2012-03-10 14:50 - 00000192 ___SH () C:\Documents and Settings\cacha\ntuser.ini
2015-04-30 16:29 - 2012-03-07 21:10 - 00032404 _____ () C:\WINDOWS\SchedLgU.Txt
2015-04-30 16:29 - 2012-03-07 21:06 - 01513853 _____ () C:\WINDOWS\WindowsUpdate.log
2015-04-30 15:37 - 2013-12-17 14:43 - 00001102 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-30 15:32 - 2012-04-03 18:27 - 00000838 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-04-30 13:09 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha
2015-04-29 23:27 - 2013-09-24 14:22 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\Spotify
2015-04-29 16:21 - 2013-05-15 17:54 - 00000000 ___RD () C:\Documents and Settings\cacha\Mis documentos\Dropbox
2015-04-29 14:06 - 2012-03-10 14:50 - 00000000 ___HD () C:\Documents and Settings\cacha\Configuración local\Datos de programa
2015-04-29 14:06 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa
2015-04-29 14:06 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa
2015-04-29 14:06 - 2012-03-07 16:53 - 00000000 ____D () C:\Archivos de programa\Archivos comunes
2015-04-29 09:07 - 2013-05-15 17:54 - 00000995 _____ () C:\Documents and Settings\cacha\Escritorio\Dropbox.lnk
2015-04-29 09:07 - 2013-05-15 17:39 - 00000000 ____D () C:\Documents and Settings\cacha\Menú Inicio\Programas\Dropbox
2015-04-29 09:07 - 2013-05-15 17:38 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\Dropbox
2015-04-28 17:27 - 2012-03-10 18:19 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\BitTorrent
2015-04-28 09:26 - 2013-09-24 16:07 - 00000000 ____D () C:\Documents and Settings\cacha\Configuración local\Datos de programa\Spotify
2015-04-28 08:21 - 2013-12-22 09:15 - 00000000 ____D () C:\WINDOWS\Minidump
2015-04-27 18:10 - 2015-02-06 11:17 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio\The Translator's Tools
2015-04-27 13:39 - 2012-03-14 10:36 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\vlc
2015-04-26 12:35 - 2012-03-08 00:03 - 00078032 ____N (Absolute Software Corp.) C:\WINDOWS\system32\rpcnet.exe
2015-04-25 20:56 - 2012-04-04 23:33 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\My Shared Folder
2015-04-25 08:16 - 2014-02-28 23:20 - 00000000 ____D () C:\Archivos de programa\Mozilla Maintenance Service
2015-04-24 21:40 - 2012-03-07 16:53 - 00000000 ___RD () C:\Archivos de programa
2015-04-24 13:53 - 2012-03-12 22:52 - 00094720 _____ () C:\Documents and Settings\cacha\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-24 08:20 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos
2015-04-24 08:20 - 2012-03-07 17:51 - 00000245 ___SH () C:\boot.ini
2015-04-23 19:59 - 2012-03-07 21:09 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2015-04-23 19:58 - 2012-11-23 19:19 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Mi Música
2015-04-23 08:00 - 2015-02-21 20:47 - 00000000 ___RD () C:\Documents and Settings\cacha\Mis documentos\Google Drive
2015-04-20 16:03 - 2014-04-16 23:59 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Descargas
2015-04-18 16:20 - 2012-03-14 10:26 - 00000000 ____D () C:\Archivos de programa\Adobe
2015-04-18 16:19 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Menú Inicio\Programas
2015-04-18 16:16 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Escritorio
2015-04-18 10:39 - 2012-03-10 14:50 - 00000000 __SHD () C:\Documents and Settings\cacha\Configuración local\Archivos temporales de Internet
2015-04-18 08:23 - 2012-03-07 21:09 - 00000000 __SHD () C:\Documents and Settings\NetworkService\Configuración local\Archivos temporales de Internet
2015-04-17 23:16 - 2012-08-24 23:29 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa\Skype
2015-04-17 23:15 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Menú Inicio
2015-04-17 22:59 - 2014-05-12 13:24 - 00000000 ____D () C:\Documents and Settings\cacha\Menú Inicio\Programas\Amazon
2015-04-17 22:59 - 2014-05-12 13:23 - 00000000 ____D () C:\Archivos de programa\Amazon
2015-04-17 22:58 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Menú Inicio\Programas
2015-04-17 22:29 - 2014-08-28 16:56 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Dibujos low-res
2015-04-17 22:09 - 2012-03-07 21:10 - 00000000 __SHD () C:\Documents and Settings\LocalService
2015-04-17 22:08 - 2012-03-07 21:56 - 00000000 ____D () C:\Archivos de programa\InstallShield Installation Information
2015-04-17 21:44 - 2012-03-07 21:10 - 00000000 __SHD () C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet
2015-04-17 21:43 - 2013-08-17 12:32 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa\Spybot - Search & Destroy
2015-04-17 21:27 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\Default User\Configuración local\Archivos temporales de Internet
2015-04-16 10:14 - 2015-01-20 15:02 - 00000000 ____D () C:\Documents and Settings\cacha\Configuración local\Datos de programa\Adobe
2015-04-15 18:12 - 2013-05-15 17:25 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Mis imágenes
2015-04-15 16:11 - 2013-07-13 23:16 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-04-15 16:02 - 2012-03-10 00:53 - 125832184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-04-15 16:01 - 2012-03-09 21:25 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa\Microsoft Help
2015-04-15 13:39 - 2013-12-17 14:46 - 00001874 _____ () C:\Documents and Settings\All Users\Escritorio\Google Chrome.lnk
2015-04-15 11:33 - 2012-04-03 18:27 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-04-15 11:33 - 2012-03-12 22:29 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-04-13 11:50 - 2012-03-10 18:03 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Mis escaneos
2015-04-10 14:48 - 2012-03-10 14:51 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Directorio de intercambio Bluetooth
2015-04-08 15:00 - 2014-03-08 10:15 - 00000216 _____ () C:\WINDOWS\Tasks\Notificación mensual de fin de servicio de Microsoft Windows XP.job
==================== Files in the root of some directories =======
2015-04-15 21:40 - 2015-04-15 21:40 - 0000132 _____ () C:\Documents and Settings\cacha\Datos de programa\Prefs. de formato PNG de Adobe CS6
2012-03-12 22:52 - 2015-04-24 13:53 - 0094720 _____ () C:\Documents and Settings\cacha\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-13 19:02 - 2012-04-13 19:02 - 0000134 _____ () C:\Documents and Settings\cacha\Configuración local\Datos de programa\fusioncache.dat
Some content of TEMP:
====================
C:\Documents and Settings\cacha\Configuración local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp1nbvlu.dll
C:\Documents and Settings\cacha\Configuración local\Temp\swt-gdip-win32-3346.dll
C:\Documents and Settings\cacha\Configuración local\Temp\swt-win32-3346.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-04-2015 01
Ran by cacha (administrator) on FLORNOTE on 30-04-2015 17:15:47
Running from C:\Documents and Settings\cacha\Escritorio
Loaded Profiles: cacha (Available profiles: cacha & Administrador & Invitado)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Español (alfabetización internacional)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Broadcom Corporation.) C:\Archivos de programa\WIDCOMM\Bluetooth Software\bin\btwdins.exe
() C:\WINDOWS\system32\WLTRYSVC.EXE
(Dell Inc.) C:\WINDOWS\system32\BCMWLTRY.EXE
(IDT, Inc.) C:\Archivos de programa\IDT\XPV10_6147v005\WDM\stacsv.exe
(IDT, Inc.) C:\Archivos de programa\IDT\WDM\sttray.exe
(Andrea Electronics Corporation) C:\WINDOWS\system32\AESTFltr.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\Apoint.exe
(Creative Technology Ltd.) C:\WINDOWS\OEM13Mon.exe
(Dell Inc.) C:\WINDOWS\system32\WLTRAY.EXE
(ESET) C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe
(Hewlett-Packard) C:\Archivos de programa\HP\HP Software Update\hpwuSchd2.exe
(Oracle Corporation) C:\Archivos de programa\Archivos comunes\Java\Java Update\jusched.exe
(ESET) C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe
(Safer-Networking Ltd.) C:\Archivos de programa\Spybot - Search & Destroy 2\SDTray.exe
(Oracle Corporation) C:\Archivos de programa\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Archivos de programa\Windows Media Player\wmpnscfg.exe
(Spotify Ltd) C:\Documents and Settings\cacha\Datos de programa\Spotify\SpotifyWebHelper.exe
(Nalpeiron Ltd.) C:\WINDOWS\system32\NLSSRV32.EXE
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Broadcom Corporation.) C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTTray.exe
(Absolute Software Corp.) C:\WINDOWS\system32\rpcnet.exe
(Safer-Networking Ltd.) C:\Archivos de programa\Spybot - Search & Destroy 2\SDFSSvc.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\ApMsgFwd.exe
(Broadcom Corporation.) C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\hidfind.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\ApntEx.exe
(Safer-Networking Ltd.) C:\Archivos de programa\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Archivos de programa\Windows Media Player\wmpnetwk.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Archivos de programa\Microsoft Office\Office12\WINWORD.EXE
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Archivos de programa\IDT\WDM\sttray.exe [483420 2009-02-20] (IDT, Inc.)
HKLM\...\Run: [AESTFltr] => C:\WINDOWS\system32\AESTFltr.exe [729088 2009-02-20] (Andrea Electronics Corporation)
HKLM\...\Run: [Apoint] => C:\Archivos de programa\DellTPad\Apoint.exe [217088 2009-03-13] (Alps Electric Co., Ltd.)
HKLM\...\Run: [OEM13Mon.exe] => C:\WINDOWS\OEM13Mon.exe [36864 2008-01-08] (Creative Technology Ltd.)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\WINDOWS\system32\WLTRAY.exe [2220032 2008-10-24] (Dell Inc.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /installquiet
HKLM\...\Run: [NVHotkey] => rundll32.exe nvHotkey.dll,Start
HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit
HKLM\...\Run: [DELL Webcam Manager] => C:\Archivos de programa\Dell\Dell Webcam Manager\DellWMgr.exe [118784 2007-07-27] (Creative Technology Ltd.)
HKLM\...\Run: [GrooveMonitor] => C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [HP Software Update] => C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [SunJavaUpdateSched] => C:\Archivos de programa\Archivos comunes\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Run: [egui] => C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe [5046472 2014-09-30] (ESET)
HKLM\...\Run: [SDTray] => C:\Archivos de programa\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [WMPNSCFG] => C:\Archivos de programa\Windows Media Player\WMPNSCFG.exe [204800 2009-02-04] (Microsoft Corporation)
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [Spotify Web Helper] => C:\Documents and Settings\cacha\Datos de programa\Spotify\SpotifyWebHelper.exe [1959992 2015-03-11] (Spotify Ltd)
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [Hide.me] => [X]
HKU\S-1-5-18\...\Run: [GoogleChromeAutoLaunch_A2E3159C0817FADA26422CFDCE0E82F1] => C:\Archivos de programa\Google\Chrome\Application\chrome.exe [812872 2015-04-13] (Google Inc.)
Startup: C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio\BTTray.lnk [2012-03-07]
ShortcutTarget: BTTray.lnk -> C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2 (GFS Stub)] -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 3 (GFS Folder)] -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyServer: [S-1-5-21-1844237615-1767777339-1417001333-1003] => localhost:8080
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.ar/
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://es.msn.com/?ocid=iehp
URLSearchHook: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 - BittorrentBar_ES Toolbar - {ad06fb5f-fef7-4a84-8c58-dca34f8e3d36} - No File
URLSearchHook: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No File
SearchScopes: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> {3E3A04E4-65A7-4BF0-BE56-A25D6C594ACF} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=es_ES&apn_ptnrs=^U3&apn_dtid=^OSJ000^YY^AR&apn_uid=29B3F03A-E8F4-4364-BB2F-056CD38F361A&apn_sauid=74974A9E-826B-490A-A51C-B8A407B7C46D
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Archivos de programa\Java\jre7\bin\ssv.dll [2014-11-04] (Oracle Corporation)
BHO: BitTorrentBar Toolbar -> {88c7f2aa-f93f-432c-8f0e-b7d85967a527} -> No File
BHO: Windows Live Aplicación auxiliar de inicio de sesión -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO: BittorrentBar_ES Toolbar -> {ad06fb5f-fef7-4a84-8c58-dca34f8e3d36} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Archivos de programa\Java\jre7\bin\jp2ssv.dll [2014-11-04] (Oracle Corporation)
Toolbar: HKLM - BittorrentBar_ES Toolbar - {ad06fb5f-fef7-4a84-8c58-dca34f8e3d36} - No File
Toolbar: HKLM - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No File
Toolbar: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> BitTorrentBar Toolbar - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
Toolbar: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> BittorrentBar_ES Toolbar - {AD06FB5F-FEF7-4A84-8C58-DCA34F8E3D36} - No File
Toolbar: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-1_4_2_08-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Archivos de programa\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll [2013-09-25] (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 108.168.162.137 8.8.4.4
FireFox:
========
FF ProfilePath: C:\Documents and Settings\cacha\Datos de programa\Mozilla\Firefox\Profiles\8webyrm2.default
FF Homepage: hxxp://www.google.com.ar/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Archivos de programa\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Archivos de programa\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-11-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Archivos de programa\Java\jre7\bin\plugin2\npjp2.dll [2014-11-04] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Archivos de programa\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Archivos de programa\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Archivos de programa\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Archivos de programa\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Archivos de programa\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Archivos de programa\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Archivos de programa\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin HKU\S-1-5-21-1844237615-1767777339-1417001333-1003: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Archivos de programa\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-1844237615-1767777339-1417001333-1003: samsung.com/SamsungLinkPCPlugin -> C:\Archivos de programa\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll No File
FF Plugin ProgramFiles/Appdata: C:\Archivos de programa\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Archivos de programa\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF SearchPlugin: C:\Archivos de programa\mozilla firefox\browser\searchplugins\creativecommons.xml [2014-07-22]
FF SearchPlugin: C:\Archivos de programa\mozilla firefox\browser\searchplugins\mercadolibre-ar.xml [2014-07-22]
FF Extension: FlashGot - C:\Documents and Settings\cacha\Datos de programa\Mozilla\Firefox\Profiles\8webyrm2.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2015-01-21]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-03-17]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Archivos de programa\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Archivos de programa\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2015-01-25]
Chrome:
=======
CHR HomePage: Default ->
CHR Profile: C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-22]
CHR Extension: (Easy Clock) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\dplbpgapoedppajbikieafefmcceaagn [2014-08-26]
CHR Extension: (BetaFish Adblocker) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-17]
CHR Extension: (Hola Better Internet) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2014-07-07]
CHR Extension: (Pin It Button) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2014-08-26]
CHR Extension: (Eye Dropper) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\hmdcmlfkchdmnmnmheododdhjedfccka [2014-11-11]
CHR Extension: (Kindle Cloud Reader) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2014-05-17]
CHR Extension: (StayFocusd) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2014-10-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-15]
CHR Extension: (Google Dictionary (by Google)) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2014-08-26]
CHR Extension: (Pocket) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2015-02-25]
CHR Extension: (feedly) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\ndhinffkekpekljifjkkkkkhopnjodja [2014-11-11]
CHR Extension: (Do It (Tomorrow)) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\nfagjoblnoeagfhfhohcdklnddjaiglo [2014-10-29]
CHR Extension: (Google Wallet) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-17]
CHR Extension: (Sidekick by HubSpot) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\oiiaigjnkhngdbnoookogelabohpglmd [2014-07-05]
CHR Extension: (Evernote Web Clipper) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2014-09-09]
CHR Extension: (Writer) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\pnengefjfhgcceajaepbjhanoojifmog [2014-11-11]
CHR HKLM\...\Chrome\Extension: [lhpgolofjlpnkdafbgejgnclbjnpgfee] - C:\DOCUME~1\cacha\CONFIG~1\Temp\ccex.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [mhfdcmehmjcclgopdodkjdicohagipid] - C:\Documents and Settings\cacha\Configuración local\Datos de programa\CRE\mhfdcmehmjcclgopdodkjdicohagipid.crx [2012-04-17]
CHR HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\DOCUME~1\cacha\CONFIG~1\DATOSD~1\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2015-02-21]
CHR HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mhfdcmehmjcclgopdodkjdicohagipid] - C:\Documents and Settings\cacha\Configuración local\Datos de programa\CRE\mhfdcmehmjcclgopdodkjdicohagipid.crx [2012-04-17]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 btwdins; C:\Archivos de programa\WIDCOMM\Bluetooth Software\bin\btwdins.exe [264800 2008-09-17] (Broadcom Corporation.)
R2 ekrn; C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe [1343920 2014-09-30] (ESET)
S2 gupdate; C:\Archivos de programa\Google\Update\GoogleUpdate.exe [116648 2013-12-17] (Google Inc.)
S3 gupdatem; C:\Archivos de programa\Google\Update\GoogleUpdate.exe [116648 2013-12-17] (Google Inc.)
R3 hpqcxs08; C:\Archivos de programa\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Archivos de programa\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Archivos de programa\Archivos comunes\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Archivos de programa\Java\jre7\bin\jqs.exe [182696 2014-11-04] (Oracle Corporation)
S3 Microsoft Office Groove Audit Service; C:\Archivos de programa\Microsoft Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation)
S3 MozillaMaintenance; C:\Archivos de programa\Mozilla Maintenance Service\maintenanceservice.exe [148080 2015-04-24] (Mozilla Foundation)
R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
S3 odserv; C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE12\ODSERV.EXE [440696 2011-07-20] (Microsoft Corporation)
S3 ose; C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE [145184 2006-10-26] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 rpcnet; C:\WINDOWS\system32\rpcnet.exe [78032 2015-04-26] (Absolute Software Corp.)
R2 SDScannerService; C:\Archivos de programa\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Archivos de programa\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Archivos de programa\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 STacSV; c:\archivos de programa\idt\xpv10_6147v005\wdm\stacsv.exe [249938 2009-02-20] (IDT, Inc.)
R2 wltrysvc; C:\WINDOWS\System32\bcmwltry.exe [1961984 2008-10-24] (Dell Inc.) [File not signed]
R2 WMPNetworkSvc; C:\Archivos de programa\Windows Media Player\WMPNetwk.exe [916480 2009-02-04] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 AESTAud; C:\WINDOWS\System32\drivers\AESTAud.sys [112512 2009-02-20] (Andrea Electronics Corporation)
R3 BCM43XX; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [1287552 2008-10-24] (Broadcom Corporation)
R3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [539640 2008-07-26] (Broadcom Corporation.)
R3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [37424 2008-07-26] (Broadcom Corporation.)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [879832 2008-07-29] (Broadcom Corporation.)
R3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [156816 2008-07-29] (Broadcom Corporation.)
R3 btwhid; C:\WINDOWS\System32\DRIVERS\btwhid.sys [55352 2008-07-26] (Broadcom Corporation.)
R3 btwmodem; C:\WINDOWS\System32\DRIVERS\btwmodem.sys [37280 2008-07-26] (Broadcom Corporation.)
R3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [74688 2008-07-26] (Broadcom Corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R1 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [185688 2014-09-30] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [135296 2014-09-30] (ESET)
R1 epfwtdir; C:\WINDOWS\System32\DRIVERS\epfwtdir.sys [118768 2014-09-30] (ESET)
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 O2MDGRDR; C:\WINDOWS\System32\DRIVERS\o2mdg.sys [58144 2009-03-19] (O2Micro )
R3 O2SDGRDR; C:\WINDOWS\System32\DRIVERS\o2sdg.sys [41376 2009-02-24] (O2Micro )
R3 OEM13Afx; C:\WINDOWS\system32\Drivers\OEM13Afx.sys [141376 2007-06-08] (Creative Technology Ltd.)
R3 OEM13Vfx; C:\WINDOWS\System32\DRIVERS\OEM13Vfx.sys [7424 2007-03-05] (EyePower Games Pte. Ltd.)
R3 OEM13Vid; C:\WINDOWS\System32\DRIVERS\OEM13Vid.sys [235840 2008-05-29] (Creative Technology Ltd.)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1548339 2009-02-20] (IDT, Inc.)
S3 vulfnths; C:\WINDOWS\System32\Drivers\vulfnth.sys [6912 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S3 vulfntrs; C:\WINDOWS\System32\Drivers\vulfntr.sys [11392 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S0 cerc6; No ImagePath
S3 CrystalSysInfo; \??\C:\Archivos de programa\MediaCoder\SysInfo.sys [X]
S3 GenericMount; system32\DRIVERS\GenericMount.sys [X]
S4 IntelIde; No ImagePath
U2 V2iMount; No ImagePath
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-30 17:15 - 2015-04-30 17:16 - 00030070 _____ () C:\Documents and Settings\cacha\Escritorio\FRST.txt
2015-04-30 17:11 - 2015-04-30 17:15 - 00000000 ____D () C:\FRST
2015-04-30 17:09 - 2015-04-30 17:09 - 01140736 _____ (Farbar) C:\Documents and Settings\cacha\Escritorio\FRST.exe
2015-04-30 13:22 - 2015-04-30 13:22 - 00012285 _____ () C:\Documents and Settings\cacha\Escritorio\Scan Results.150430-1322.txt
2015-04-28 08:21 - 2015-04-28 08:21 - 00065536 _____ () C:\WINDOWS\Minidump\Mini042815-01.dmp
2015-04-24 19:11 - 2015-04-24 19:13 - 00000000 ____D () C:\Archivos de programa\Mozilla Firefox
2015-04-24 08:20 - 2015-04-24 08:20 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\ProcAlyzer Dumps
2015-04-23 19:59 - 2015-04-23 19:59 - 00000000 ___RD () C:\Documents and Settings\NetworkService\Mis documentos\Mi música
2015-04-23 19:59 - 2015-04-23 19:59 - 00000000 ____D () C:\Documents and Settings\NetworkService\Mis documentos
2015-04-20 15:41 - 2015-04-30 00:06 - 00013312 ____H () C:\Documents and Settings\cacha\Escritorio\photothumb.db
2015-04-18 16:17 - 2015-04-18 16:18 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio\Para leer
2015-04-18 16:15 - 2015-04-18 16:16 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio\Art in Translation texts
2015-04-17 22:09 - 2015-04-17 22:09 - 00000000 ____D () C:\Documents and Settings\LocalService\Menú Inicio\Programas
2015-04-17 22:09 - 2015-04-17 22:09 - 00000000 ____D () C:\Documents and Settings\LocalService\Menú Inicio
2015-04-17 22:08 - 2015-04-17 22:08 - 00000000 ____D () C:\Archivos de programa\Asoftech
2015-04-17 21:44 - 2015-04-30 17:00 - 00000658 _____ () C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
2015-04-17 21:44 - 2015-04-17 21:44 - 00001905 _____ () C:\Documents and Settings\All Users\Menú Inicio\Programas\Spybot-S&D Start Center.lnk
2015-04-17 21:44 - 2015-04-17 21:44 - 00001899 _____ () C:\Documents and Settings\All Users\Escritorio\Spybot-S&D Start Center.lnk
2015-04-17 21:44 - 2015-04-17 21:44 - 00000630 _____ () C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2015-04-17 21:44 - 2015-04-17 21:44 - 00000460 _____ () C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
2015-04-17 21:44 - 2015-04-17 21:44 - 00000000 ____D () C:\Documents and Settings\All Users\Menú Inicio\Programas\Spybot - Search & Destroy 2
2015-04-17 21:43 - 2015-04-17 22:10 - 00000000 ____D () C:\Archivos de programa\Spybot - Search & Destroy 2
2015-04-17 21:43 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean.exe
2015-04-17 21:28 - 2012-07-27 06:45 - 00000102 _____ () C:\medicina.cmd
2015-04-16 19:23 - 2015-04-18 17:31 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\pinguino
2015-04-15 21:40 - 2015-04-15 21:40 - 00000132 _____ () C:\Documents and Settings\cacha\Datos de programa\Prefs. de formato PNG de Adobe CS6
2015-04-09 21:54 - 2015-04-10 16:08 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Stock Photography
2015-04-07 17:54 - 2015-04-07 17:54 - 00065536 _____ () C:\WINDOWS\Minidump\Mini040715-01.dmp
2015-04-07 17:51 - 2015-04-28 08:21 - 205238272 _____ () C:\WINDOWS\MEMORY.DMP
2015-03-31 11:24 - 2015-03-31 11:24 - 00000737 _____ () C:\Documents and Settings\cacha\Escritorio\Acceso directo a Red - Logan, J..lnk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-30 17:15 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio
2015-04-30 17:14 - 2014-05-27 15:26 - 00000488 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{C604CD4C-5685-42BB-8F60-C2D813575826}.job
2015-04-30 17:00 - 2012-03-07 23:57 - 00077291 _____ () C:\WINDOWS\system32\nvModes.001
2015-04-30 17:00 - 2008-04-13 20:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2015-04-30 16:58 - 2014-03-08 10:15 - 00000222 _____ () C:\WINDOWS\Tasks\Notificación de inicio de sesión de fin de servicio de Microsoft Windows XP.job
2015-04-30 16:58 - 2013-12-17 14:43 - 00001098 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-30 16:58 - 2012-03-08 00:03 - 00078032 _____ (Absolute Software Corp.) C:\WINDOWS\system32\rpcnet.dll
2015-04-30 16:58 - 2012-03-07 23:55 - 00200942 _____ () C:\WINDOWS\system32\nvapps.xml
2015-04-30 16:58 - 2012-03-07 21:10 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-04-30 16:58 - 2012-03-07 16:54 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-04-30 16:58 - 2012-03-07 16:54 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2015-04-30 16:58 - 2012-03-07 16:52 - 00017408 _____ () C:\WINDOWS\system32\rpcnetp.exe
2015-04-30 16:29 - 2012-03-10 14:50 - 00000192 ___SH () C:\Documents and Settings\cacha\ntuser.ini
2015-04-30 16:29 - 2012-03-07 21:10 - 00032404 _____ () C:\WINDOWS\SchedLgU.Txt
2015-04-30 16:29 - 2012-03-07 21:06 - 01513853 _____ () C:\WINDOWS\WindowsUpdate.log
2015-04-30 15:37 - 2013-12-17 14:43 - 00001102 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-30 15:32 - 2012-04-03 18:27 - 00000838 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-04-30 13:09 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha
2015-04-29 23:27 - 2013-09-24 14:22 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\Spotify
2015-04-29 16:21 - 2013-05-15 17:54 - 00000000 ___RD () C:\Documents and Settings\cacha\Mis documentos\Dropbox
2015-04-29 14:06 - 2012-03-10 14:50 - 00000000 ___HD () C:\Documents and Settings\cacha\Configuración local\Datos de programa
2015-04-29 14:06 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa
2015-04-29 14:06 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa
2015-04-29 14:06 - 2012-03-07 16:53 - 00000000 ____D () C:\Archivos de programa\Archivos comunes
2015-04-29 09:07 - 2013-05-15 17:54 - 00000995 _____ () C:\Documents and Settings\cacha\Escritorio\Dropbox.lnk
2015-04-29 09:07 - 2013-05-15 17:39 - 00000000 ____D () C:\Documents and Settings\cacha\Menú Inicio\Programas\Dropbox
2015-04-29 09:07 - 2013-05-15 17:38 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\Dropbox
2015-04-28 17:27 - 2012-03-10 18:19 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\BitTorrent
2015-04-28 09:26 - 2013-09-24 16:07 - 00000000 ____D () C:\Documents and Settings\cacha\Configuración local\Datos de programa\Spotify
2015-04-28 08:21 - 2013-12-22 09:15 - 00000000 ____D () C:\WINDOWS\Minidump
2015-04-27 18:10 - 2015-02-06 11:17 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio\The Translator's Tools
2015-04-27 13:39 - 2012-03-14 10:36 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\vlc
2015-04-26 12:35 - 2012-03-08 00:03 - 00078032 ____N (Absolute Software Corp.) C:\WINDOWS\system32\rpcnet.exe
2015-04-25 20:56 - 2012-04-04 23:33 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\My Shared Folder
2015-04-25 08:16 - 2014-02-28 23:20 - 00000000 ____D () C:\Archivos de programa\Mozilla Maintenance Service
2015-04-24 21:40 - 2012-03-07 16:53 - 00000000 ___RD () C:\Archivos de programa
2015-04-24 13:53 - 2012-03-12 22:52 - 00094720 _____ () C:\Documents and Settings\cacha\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-24 08:20 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos
2015-04-24 08:20 - 2012-03-07 17:51 - 00000245 ___SH () C:\boot.ini
2015-04-23 19:59 - 2012-03-07 21:09 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2015-04-23 19:58 - 2012-11-23 19:19 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Mi Música
2015-04-23 08:00 - 2015-02-21 20:47 - 00000000 ___RD () C:\Documents and Settings\cacha\Mis documentos\Google Drive
2015-04-20 16:03 - 2014-04-16 23:59 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Descargas
2015-04-18 16:20 - 2012-03-14 10:26 - 00000000 ____D () C:\Archivos de programa\Adobe
2015-04-18 16:19 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Menú Inicio\Programas
2015-04-18 16:16 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Escritorio
2015-04-18 10:39 - 2012-03-10 14:50 - 00000000 __SHD () C:\Documents and Settings\cacha\Configuración local\Archivos temporales de Internet
2015-04-18 08:23 - 2012-03-07 21:09 - 00000000 __SHD () C:\Documents and Settings\NetworkService\Configuración local\Archivos temporales de Internet
2015-04-17 23:16 - 2012-08-24 23:29 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa\Skype
2015-04-17 23:15 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Menú Inicio
2015-04-17 22:59 - 2014-05-12 13:24 - 00000000 ____D () C:\Documents and Settings\cacha\Menú Inicio\Programas\Amazon
2015-04-17 22:59 - 2014-05-12 13:23 - 00000000 ____D () C:\Archivos de programa\Amazon
2015-04-17 22:58 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Menú Inicio\Programas
2015-04-17 22:29 - 2014-08-28 16:56 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Dibujos low-res
2015-04-17 22:09 - 2012-03-07 21:10 - 00000000 __SHD () C:\Documents and Settings\LocalService
2015-04-17 22:08 - 2012-03-07 21:56 - 00000000 ____D () C:\Archivos de programa\InstallShield Installation Information
2015-04-17 21:44 - 2012-03-07 21:10 - 00000000 __SHD () C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet
2015-04-17 21:43 - 2013-08-17 12:32 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa\Spybot - Search & Destroy
2015-04-17 21:27 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\Default User\Configuración local\Archivos temporales de Internet
2015-04-16 10:14 - 2015-01-20 15:02 - 00000000 ____D () C:\Documents and Settings\cacha\Configuración local\Datos de programa\Adobe
2015-04-15 18:12 - 2013-05-15 17:25 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Mis imágenes
2015-04-15 16:11 - 2013-07-13 23:16 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-04-15 16:02 - 2012-03-10 00:53 - 125832184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-04-15 16:01 - 2012-03-09 21:25 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa\Microsoft Help
2015-04-15 13:39 - 2013-12-17 14:46 - 00001874 _____ () C:\Documents and Settings\All Users\Escritorio\Google Chrome.lnk
2015-04-15 11:33 - 2012-04-03 18:27 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-04-15 11:33 - 2012-03-12 22:29 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-04-13 11:50 - 2012-03-10 18:03 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Mis escaneos
2015-04-10 14:48 - 2012-03-10 14:51 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Directorio de intercambio Bluetooth
2015-04-08 15:00 - 2014-03-08 10:15 - 00000216 _____ () C:\WINDOWS\Tasks\Notificación mensual de fin de servicio de Microsoft Windows XP.job
==================== Files in the root of some directories =======
2015-04-15 21:40 - 2015-04-15 21:40 - 0000132 _____ () C:\Documents and Settings\cacha\Datos de programa\Prefs. de formato PNG de Adobe CS6
2012-03-12 22:52 - 2015-04-24 13:53 - 0094720 _____ () C:\Documents and Settings\cacha\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-13 19:02 - 2012-04-13 19:02 - 0000134 _____ () C:\Documents and Settings\cacha\Configuración local\Datos de programa\fusioncache.dat
Some content of TEMP:
====================
C:\Documents and Settings\cacha\Configuración local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp1nbvlu.dll
C:\Documents and Settings\cacha\Configuración local\Temp\swt-gdip-win32-3346.dll
C:\Documents and Settings\cacha\Configuración local\Temp\swt-win32-3346.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
aswMBR version 1.0.1.2252 Copyright(c) 2014 AVAST Software
Run date: 2015-04-30 17:21:12
-----------------------------
17:21:12.890 OS Version: Windows 5.1.2600 Service Pack 3
17:21:12.890 Number of processors: 2 586 0x170A
17:21:12.906 ComputerName: FLORNOTE UserName: cacha
17:21:13.750 Initialize success
17:21:13.843 VM: initialized successfully
17:21:13.843 VM: Intel CPU BiosDisabled
17:22:12.687 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
17:22:12.687 Disk 0 Vendor: WDC_WD25 11.0 Size: 238475MB BusType: 3
17:22:12.859 Disk 0 MBR read successfully
17:22:12.875 Disk 0 MBR scan
17:22:12.875 Disk 0 Windows XP default MBR code
17:22:12.875 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
17:22:12.875 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 238434 MB offset 81920
17:22:12.875 Disk 0 Boot: NTFS code=1
17:22:12.875 Disk 0 scanning sectors +488395120
17:22:12.953 Disk 0 scanning C:\WINDOWS\system32\drivers
17:22:17.718 Service scanning
17:22:22.687 Service ehdrv C:\WINDOWS\system32\DRIVERS\ehdrv.sys **LOCKED** 5
17:22:22.796 Service epfwtdir C:\WINDOWS\system32\DRIVERS\epfwtdir.sys **LOCKED** 5
17:22:30.312 Modules scanning
17:22:30.328 Disk 0 trace - called modules:
17:22:30.328
17:22:30.328 Disk 0 statistics 44898/0/0 @ 4,59 MB/s
17:22:30.328 Scan finished successfully
17:22:41.156 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\cacha\Escritorio\MBR.dat"
17:22:41.171 The log file has been saved successfully to "C:\Documents and Settings\cacha\Escritorio\aswMBR.txt"
Here are the logs:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-04-2015 01
Ran by cacha (administrator) on FLORNOTE on 30-04-2015 17:15:47
Running from C:\Documents and Settings\cacha\Escritorio
Loaded Profiles: cacha (Available profiles: cacha & Administrador & Invitado)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Español (alfabetización internacional)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Broadcom Corporation.) C:\Archivos de programa\WIDCOMM\Bluetooth Software\bin\btwdins.exe
() C:\WINDOWS\system32\WLTRYSVC.EXE
(Dell Inc.) C:\WINDOWS\system32\BCMWLTRY.EXE
(IDT, Inc.) C:\Archivos de programa\IDT\XPV10_6147v005\WDM\stacsv.exe
(IDT, Inc.) C:\Archivos de programa\IDT\WDM\sttray.exe
(Andrea Electronics Corporation) C:\WINDOWS\system32\AESTFltr.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\Apoint.exe
(Creative Technology Ltd.) C:\WINDOWS\OEM13Mon.exe
(Dell Inc.) C:\WINDOWS\system32\WLTRAY.EXE
(ESET) C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe
(Hewlett-Packard) C:\Archivos de programa\HP\HP Software Update\hpwuSchd2.exe
(Oracle Corporation) C:\Archivos de programa\Archivos comunes\Java\Java Update\jusched.exe
(ESET) C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe
(Safer-Networking Ltd.) C:\Archivos de programa\Spybot - Search & Destroy 2\SDTray.exe
(Oracle Corporation) C:\Archivos de programa\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Archivos de programa\Windows Media Player\wmpnscfg.exe
(Spotify Ltd) C:\Documents and Settings\cacha\Datos de programa\Spotify\SpotifyWebHelper.exe
(Nalpeiron Ltd.) C:\WINDOWS\system32\NLSSRV32.EXE
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Broadcom Corporation.) C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTTray.exe
(Absolute Software Corp.) C:\WINDOWS\system32\rpcnet.exe
(Safer-Networking Ltd.) C:\Archivos de programa\Spybot - Search & Destroy 2\SDFSSvc.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\ApMsgFwd.exe
(Broadcom Corporation.) C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\hidfind.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\ApntEx.exe
(Safer-Networking Ltd.) C:\Archivos de programa\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Archivos de programa\Windows Media Player\wmpnetwk.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Archivos de programa\Microsoft Office\Office12\WINWORD.EXE
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Archivos de programa\IDT\WDM\sttray.exe [483420 2009-02-20] (IDT, Inc.)
HKLM\...\Run: [AESTFltr] => C:\WINDOWS\system32\AESTFltr.exe [729088 2009-02-20] (Andrea Electronics Corporation)
HKLM\...\Run: [Apoint] => C:\Archivos de programa\DellTPad\Apoint.exe [217088 2009-03-13] (Alps Electric Co., Ltd.)
HKLM\...\Run: [OEM13Mon.exe] => C:\WINDOWS\OEM13Mon.exe [36864 2008-01-08] (Creative Technology Ltd.)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\WINDOWS\system32\WLTRAY.exe [2220032 2008-10-24] (Dell Inc.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /installquiet
HKLM\...\Run: [NVHotkey] => rundll32.exe nvHotkey.dll,Start
HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit
HKLM\...\Run: [DELL Webcam Manager] => C:\Archivos de programa\Dell\Dell Webcam Manager\DellWMgr.exe [118784 2007-07-27] (Creative Technology Ltd.)
HKLM\...\Run: [GrooveMonitor] => C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [HP Software Update] => C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [SunJavaUpdateSched] => C:\Archivos de programa\Archivos comunes\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Run: [egui] => C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe [5046472 2014-09-30] (ESET)
HKLM\...\Run: [SDTray] => C:\Archivos de programa\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [WMPNSCFG] => C:\Archivos de programa\Windows Media Player\WMPNSCFG.exe [204800 2009-02-04] (Microsoft Corporation)
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [Spotify Web Helper] => C:\Documents and Settings\cacha\Datos de programa\Spotify\SpotifyWebHelper.exe [1959992 2015-03-11] (Spotify Ltd)
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [Hide.me] => [X]
HKU\S-1-5-18\...\Run: [GoogleChromeAutoLaunch_A2E3159C0817FADA26422CFDCE0E82F1] => C:\Archivos de programa\Google\Chrome\Application\chrome.exe [812872 2015-04-13] (Google Inc.)
Startup: C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio\BTTray.lnk [2012-03-07]
ShortcutTarget: BTTray.lnk -> C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2 (GFS Stub)] -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 3 (GFS Folder)] -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyServer: [S-1-5-21-1844237615-1767777339-1417001333-1003] => localhost:8080
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.ar/
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://es.msn.com/?ocid=iehp
URLSearchHook: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 - BittorrentBar_ES Toolbar - {ad06fb5f-fef7-4a84-8c58-dca34f8e3d36} - No File
URLSearchHook: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No File
SearchScopes: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> {3E3A04E4-65A7-4BF0-BE56-A25D6C594ACF} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=es_ES&apn_ptnrs=^U3&apn_dtid=^OSJ000^YY^AR&apn_uid=29B3F03A-E8F4-4364-BB2F-056CD38F361A&apn_sauid=74974A9E-826B-490A-A51C-B8A407B7C46D
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Archivos de programa\Java\jre7\bin\ssv.dll [2014-11-04] (Oracle Corporation)
BHO: BitTorrentBar Toolbar -> {88c7f2aa-f93f-432c-8f0e-b7d85967a527} -> No File
BHO: Windows Live Aplicación auxiliar de inicio de sesión -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO: BittorrentBar_ES Toolbar -> {ad06fb5f-fef7-4a84-8c58-dca34f8e3d36} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Archivos de programa\Java\jre7\bin\jp2ssv.dll [2014-11-04] (Oracle Corporation)
Toolbar: HKLM - BittorrentBar_ES Toolbar - {ad06fb5f-fef7-4a84-8c58-dca34f8e3d36} - No File
Toolbar: HKLM - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No File
Toolbar: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> BitTorrentBar Toolbar - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
Toolbar: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> BittorrentBar_ES Toolbar - {AD06FB5F-FEF7-4A84-8C58-DCA34F8E3D36} - No File
Toolbar: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-1_4_2_08-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Archivos de programa\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll [2013-09-25] (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 108.168.162.137 8.8.4.4
FireFox:
========
FF ProfilePath: C:\Documents and Settings\cacha\Datos de programa\Mozilla\Firefox\Profiles\8webyrm2.default
FF Homepage: hxxp://www.google.com.ar/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Archivos de programa\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Archivos de programa\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-11-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Archivos de programa\Java\jre7\bin\plugin2\npjp2.dll [2014-11-04] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Archivos de programa\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Archivos de programa\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Archivos de programa\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Archivos de programa\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Archivos de programa\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Archivos de programa\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Archivos de programa\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin HKU\S-1-5-21-1844237615-1767777339-1417001333-1003: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Archivos de programa\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-1844237615-1767777339-1417001333-1003: samsung.com/SamsungLinkPCPlugin -> C:\Archivos de programa\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll No File
FF Plugin ProgramFiles/Appdata: C:\Archivos de programa\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Archivos de programa\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF SearchPlugin: C:\Archivos de programa\mozilla firefox\browser\searchplugins\creativecommons.xml [2014-07-22]
FF SearchPlugin: C:\Archivos de programa\mozilla firefox\browser\searchplugins\mercadolibre-ar.xml [2014-07-22]
FF Extension: FlashGot - C:\Documents and Settings\cacha\Datos de programa\Mozilla\Firefox\Profiles\8webyrm2.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2015-01-21]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-03-17]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Archivos de programa\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Archivos de programa\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2015-01-25]
Chrome:
=======
CHR HomePage: Default ->
CHR Profile: C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-22]
CHR Extension: (Easy Clock) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\dplbpgapoedppajbikieafefmcceaagn [2014-08-26]
CHR Extension: (BetaFish Adblocker) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-17]
CHR Extension: (Hola Better Internet) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2014-07-07]
CHR Extension: (Pin It Button) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2014-08-26]
CHR Extension: (Eye Dropper) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\hmdcmlfkchdmnmnmheododdhjedfccka [2014-11-11]
CHR Extension: (Kindle Cloud Reader) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2014-05-17]
CHR Extension: (StayFocusd) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2014-10-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-15]
CHR Extension: (Google Dictionary (by Google)) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2014-08-26]
CHR Extension: (Pocket) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2015-02-25]
CHR Extension: (feedly) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\ndhinffkekpekljifjkkkkkhopnjodja [2014-11-11]
CHR Extension: (Do It (Tomorrow)) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\nfagjoblnoeagfhfhohcdklnddjaiglo [2014-10-29]
CHR Extension: (Google Wallet) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-17]
CHR Extension: (Sidekick by HubSpot) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\oiiaigjnkhngdbnoookogelabohpglmd [2014-07-05]
CHR Extension: (Evernote Web Clipper) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2014-09-09]
CHR Extension: (Writer) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\pnengefjfhgcceajaepbjhanoojifmog [2014-11-11]
CHR HKLM\...\Chrome\Extension: [lhpgolofjlpnkdafbgejgnclbjnpgfee] - C:\DOCUME~1\cacha\CONFIG~1\Temp\ccex.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [mhfdcmehmjcclgopdodkjdicohagipid] - C:\Documents and Settings\cacha\Configuración local\Datos de programa\CRE\mhfdcmehmjcclgopdodkjdicohagipid.crx [2012-04-17]
CHR HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\DOCUME~1\cacha\CONFIG~1\DATOSD~1\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2015-02-21]
CHR HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mhfdcmehmjcclgopdodkjdicohagipid] - C:\Documents and Settings\cacha\Configuración local\Datos de programa\CRE\mhfdcmehmjcclgopdodkjdicohagipid.crx [2012-04-17]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 btwdins; C:\Archivos de programa\WIDCOMM\Bluetooth Software\bin\btwdins.exe [264800 2008-09-17] (Broadcom Corporation.)
R2 ekrn; C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe [1343920 2014-09-30] (ESET)
S2 gupdate; C:\Archivos de programa\Google\Update\GoogleUpdate.exe [116648 2013-12-17] (Google Inc.)
S3 gupdatem; C:\Archivos de programa\Google\Update\GoogleUpdate.exe [116648 2013-12-17] (Google Inc.)
R3 hpqcxs08; C:\Archivos de programa\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Archivos de programa\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Archivos de programa\Archivos comunes\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Archivos de programa\Java\jre7\bin\jqs.exe [182696 2014-11-04] (Oracle Corporation)
S3 Microsoft Office Groove Audit Service; C:\Archivos de programa\Microsoft Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation)
S3 MozillaMaintenance; C:\Archivos de programa\Mozilla Maintenance Service\maintenanceservice.exe [148080 2015-04-24] (Mozilla Foundation)
R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
S3 odserv; C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE12\ODSERV.EXE [440696 2011-07-20] (Microsoft Corporation)
S3 ose; C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE [145184 2006-10-26] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 rpcnet; C:\WINDOWS\system32\rpcnet.exe [78032 2015-04-26] (Absolute Software Corp.)
R2 SDScannerService; C:\Archivos de programa\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Archivos de programa\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Archivos de programa\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 STacSV; c:\archivos de programa\idt\xpv10_6147v005\wdm\stacsv.exe [249938 2009-02-20] (IDT, Inc.)
R2 wltrysvc; C:\WINDOWS\System32\bcmwltry.exe [1961984 2008-10-24] (Dell Inc.) [File not signed]
R2 WMPNetworkSvc; C:\Archivos de programa\Windows Media Player\WMPNetwk.exe [916480 2009-02-04] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 AESTAud; C:\WINDOWS\System32\drivers\AESTAud.sys [112512 2009-02-20] (Andrea Electronics Corporation)
R3 BCM43XX; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [1287552 2008-10-24] (Broadcom Corporation)
R3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [539640 2008-07-26] (Broadcom Corporation.)
R3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [37424 2008-07-26] (Broadcom Corporation.)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [879832 2008-07-29] (Broadcom Corporation.)
R3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [156816 2008-07-29] (Broadcom Corporation.)
R3 btwhid; C:\WINDOWS\System32\DRIVERS\btwhid.sys [55352 2008-07-26] (Broadcom Corporation.)
R3 btwmodem; C:\WINDOWS\System32\DRIVERS\btwmodem.sys [37280 2008-07-26] (Broadcom Corporation.)
R3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [74688 2008-07-26] (Broadcom Corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R1 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [185688 2014-09-30] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [135296 2014-09-30] (ESET)
R1 epfwtdir; C:\WINDOWS\System32\DRIVERS\epfwtdir.sys [118768 2014-09-30] (ESET)
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 O2MDGRDR; C:\WINDOWS\System32\DRIVERS\o2mdg.sys [58144 2009-03-19] (O2Micro )
R3 O2SDGRDR; C:\WINDOWS\System32\DRIVERS\o2sdg.sys [41376 2009-02-24] (O2Micro )
R3 OEM13Afx; C:\WINDOWS\system32\Drivers\OEM13Afx.sys [141376 2007-06-08] (Creative Technology Ltd.)
R3 OEM13Vfx; C:\WINDOWS\System32\DRIVERS\OEM13Vfx.sys [7424 2007-03-05] (EyePower Games Pte. Ltd.)
R3 OEM13Vid; C:\WINDOWS\System32\DRIVERS\OEM13Vid.sys [235840 2008-05-29] (Creative Technology Ltd.)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1548339 2009-02-20] (IDT, Inc.)
S3 vulfnths; C:\WINDOWS\System32\Drivers\vulfnth.sys [6912 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S3 vulfntrs; C:\WINDOWS\System32\Drivers\vulfntr.sys [11392 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S0 cerc6; No ImagePath
S3 CrystalSysInfo; \??\C:\Archivos de programa\MediaCoder\SysInfo.sys [X]
S3 GenericMount; system32\DRIVERS\GenericMount.sys [X]
S4 IntelIde; No ImagePath
U2 V2iMount; No ImagePath
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-30 17:15 - 2015-04-30 17:16 - 00030070 _____ () C:\Documents and Settings\cacha\Escritorio\FRST.txt
2015-04-30 17:11 - 2015-04-30 17:15 - 00000000 ____D () C:\FRST
2015-04-30 17:09 - 2015-04-30 17:09 - 01140736 _____ (Farbar) C:\Documents and Settings\cacha\Escritorio\FRST.exe
2015-04-30 13:22 - 2015-04-30 13:22 - 00012285 _____ () C:\Documents and Settings\cacha\Escritorio\Scan Results.150430-1322.txt
2015-04-28 08:21 - 2015-04-28 08:21 - 00065536 _____ () C:\WINDOWS\Minidump\Mini042815-01.dmp
2015-04-24 19:11 - 2015-04-24 19:13 - 00000000 ____D () C:\Archivos de programa\Mozilla Firefox
2015-04-24 08:20 - 2015-04-24 08:20 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\ProcAlyzer Dumps
2015-04-23 19:59 - 2015-04-23 19:59 - 00000000 ___RD () C:\Documents and Settings\NetworkService\Mis documentos\Mi música
2015-04-23 19:59 - 2015-04-23 19:59 - 00000000 ____D () C:\Documents and Settings\NetworkService\Mis documentos
2015-04-20 15:41 - 2015-04-30 00:06 - 00013312 ____H () C:\Documents and Settings\cacha\Escritorio\photothumb.db
2015-04-18 16:17 - 2015-04-18 16:18 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio\Para leer
2015-04-18 16:15 - 2015-04-18 16:16 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio\Art in Translation texts
2015-04-17 22:09 - 2015-04-17 22:09 - 00000000 ____D () C:\Documents and Settings\LocalService\Menú Inicio\Programas
2015-04-17 22:09 - 2015-04-17 22:09 - 00000000 ____D () C:\Documents and Settings\LocalService\Menú Inicio
2015-04-17 22:08 - 2015-04-17 22:08 - 00000000 ____D () C:\Archivos de programa\Asoftech
2015-04-17 21:44 - 2015-04-30 17:00 - 00000658 _____ () C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
2015-04-17 21:44 - 2015-04-17 21:44 - 00001905 _____ () C:\Documents and Settings\All Users\Menú Inicio\Programas\Spybot-S&D Start Center.lnk
2015-04-17 21:44 - 2015-04-17 21:44 - 00001899 _____ () C:\Documents and Settings\All Users\Escritorio\Spybot-S&D Start Center.lnk
2015-04-17 21:44 - 2015-04-17 21:44 - 00000630 _____ () C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2015-04-17 21:44 - 2015-04-17 21:44 - 00000460 _____ () C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
2015-04-17 21:44 - 2015-04-17 21:44 - 00000000 ____D () C:\Documents and Settings\All Users\Menú Inicio\Programas\Spybot - Search & Destroy 2
2015-04-17 21:43 - 2015-04-17 22:10 - 00000000 ____D () C:\Archivos de programa\Spybot - Search & Destroy 2
2015-04-17 21:43 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean.exe
2015-04-17 21:28 - 2012-07-27 06:45 - 00000102 _____ () C:\medicina.cmd
2015-04-16 19:23 - 2015-04-18 17:31 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\pinguino
2015-04-15 21:40 - 2015-04-15 21:40 - 00000132 _____ () C:\Documents and Settings\cacha\Datos de programa\Prefs. de formato PNG de Adobe CS6
2015-04-09 21:54 - 2015-04-10 16:08 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Stock Photography
2015-04-07 17:54 - 2015-04-07 17:54 - 00065536 _____ () C:\WINDOWS\Minidump\Mini040715-01.dmp
2015-04-07 17:51 - 2015-04-28 08:21 - 205238272 _____ () C:\WINDOWS\MEMORY.DMP
2015-03-31 11:24 - 2015-03-31 11:24 - 00000737 _____ () C:\Documents and Settings\cacha\Escritorio\Acceso directo a Red - Logan, J..lnk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-30 17:15 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio
2015-04-30 17:14 - 2014-05-27 15:26 - 00000488 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{C604CD4C-5685-42BB-8F60-C2D813575826}.job
2015-04-30 17:00 - 2012-03-07 23:57 - 00077291 _____ () C:\WINDOWS\system32\nvModes.001
2015-04-30 17:00 - 2008-04-13 20:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2015-04-30 16:58 - 2014-03-08 10:15 - 00000222 _____ () C:\WINDOWS\Tasks\Notificación de inicio de sesión de fin de servicio de Microsoft Windows XP.job
2015-04-30 16:58 - 2013-12-17 14:43 - 00001098 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-30 16:58 - 2012-03-08 00:03 - 00078032 _____ (Absolute Software Corp.) C:\WINDOWS\system32\rpcnet.dll
2015-04-30 16:58 - 2012-03-07 23:55 - 00200942 _____ () C:\WINDOWS\system32\nvapps.xml
2015-04-30 16:58 - 2012-03-07 21:10 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-04-30 16:58 - 2012-03-07 16:54 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-04-30 16:58 - 2012-03-07 16:54 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2015-04-30 16:58 - 2012-03-07 16:52 - 00017408 _____ () C:\WINDOWS\system32\rpcnetp.exe
2015-04-30 16:29 - 2012-03-10 14:50 - 00000192 ___SH () C:\Documents and Settings\cacha\ntuser.ini
2015-04-30 16:29 - 2012-03-07 21:10 - 00032404 _____ () C:\WINDOWS\SchedLgU.Txt
2015-04-30 16:29 - 2012-03-07 21:06 - 01513853 _____ () C:\WINDOWS\WindowsUpdate.log
2015-04-30 15:37 - 2013-12-17 14:43 - 00001102 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-30 15:32 - 2012-04-03 18:27 - 00000838 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-04-30 13:09 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha
2015-04-29 23:27 - 2013-09-24 14:22 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\Spotify
2015-04-29 16:21 - 2013-05-15 17:54 - 00000000 ___RD () C:\Documents and Settings\cacha\Mis documentos\Dropbox
2015-04-29 14:06 - 2012-03-10 14:50 - 00000000 ___HD () C:\Documents and Settings\cacha\Configuración local\Datos de programa
2015-04-29 14:06 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa
2015-04-29 14:06 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa
2015-04-29 14:06 - 2012-03-07 16:53 - 00000000 ____D () C:\Archivos de programa\Archivos comunes
2015-04-29 09:07 - 2013-05-15 17:54 - 00000995 _____ () C:\Documents and Settings\cacha\Escritorio\Dropbox.lnk
2015-04-29 09:07 - 2013-05-15 17:39 - 00000000 ____D () C:\Documents and Settings\cacha\Menú Inicio\Programas\Dropbox
2015-04-29 09:07 - 2013-05-15 17:38 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\Dropbox
2015-04-28 17:27 - 2012-03-10 18:19 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\BitTorrent
2015-04-28 09:26 - 2013-09-24 16:07 - 00000000 ____D () C:\Documents and Settings\cacha\Configuración local\Datos de programa\Spotify
2015-04-28 08:21 - 2013-12-22 09:15 - 00000000 ____D () C:\WINDOWS\Minidump
2015-04-27 18:10 - 2015-02-06 11:17 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio\The Translator's Tools
2015-04-27 13:39 - 2012-03-14 10:36 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\vlc
2015-04-26 12:35 - 2012-03-08 00:03 - 00078032 ____N (Absolute Software Corp.) C:\WINDOWS\system32\rpcnet.exe
2015-04-25 20:56 - 2012-04-04 23:33 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\My Shared Folder
2015-04-25 08:16 - 2014-02-28 23:20 - 00000000 ____D () C:\Archivos de programa\Mozilla Maintenance Service
2015-04-24 21:40 - 2012-03-07 16:53 - 00000000 ___RD () C:\Archivos de programa
2015-04-24 13:53 - 2012-03-12 22:52 - 00094720 _____ () C:\Documents and Settings\cacha\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-24 08:20 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos
2015-04-24 08:20 - 2012-03-07 17:51 - 00000245 ___SH () C:\boot.ini
2015-04-23 19:59 - 2012-03-07 21:09 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2015-04-23 19:58 - 2012-11-23 19:19 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Mi Música
2015-04-23 08:00 - 2015-02-21 20:47 - 00000000 ___RD () C:\Documents and Settings\cacha\Mis documentos\Google Drive
2015-04-20 16:03 - 2014-04-16 23:59 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Descargas
2015-04-18 16:20 - 2012-03-14 10:26 - 00000000 ____D () C:\Archivos de programa\Adobe
2015-04-18 16:19 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Menú Inicio\Programas
2015-04-18 16:16 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Escritorio
2015-04-18 10:39 - 2012-03-10 14:50 - 00000000 __SHD () C:\Documents and Settings\cacha\Configuración local\Archivos temporales de Internet
2015-04-18 08:23 - 2012-03-07 21:09 - 00000000 __SHD () C:\Documents and Settings\NetworkService\Configuración local\Archivos temporales de Internet
2015-04-17 23:16 - 2012-08-24 23:29 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa\Skype
2015-04-17 23:15 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Menú Inicio
2015-04-17 22:59 - 2014-05-12 13:24 - 00000000 ____D () C:\Documents and Settings\cacha\Menú Inicio\Programas\Amazon
2015-04-17 22:59 - 2014-05-12 13:23 - 00000000 ____D () C:\Archivos de programa\Amazon
2015-04-17 22:58 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Menú Inicio\Programas
2015-04-17 22:29 - 2014-08-28 16:56 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Dibujos low-res
2015-04-17 22:09 - 2012-03-07 21:10 - 00000000 __SHD () C:\Documents and Settings\LocalService
2015-04-17 22:08 - 2012-03-07 21:56 - 00000000 ____D () C:\Archivos de programa\InstallShield Installation Information
2015-04-17 21:44 - 2012-03-07 21:10 - 00000000 __SHD () C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet
2015-04-17 21:43 - 2013-08-17 12:32 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa\Spybot - Search & Destroy
2015-04-17 21:27 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\Default User\Configuración local\Archivos temporales de Internet
2015-04-16 10:14 - 2015-01-20 15:02 - 00000000 ____D () C:\Documents and Settings\cacha\Configuración local\Datos de programa\Adobe
2015-04-15 18:12 - 2013-05-15 17:25 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Mis imágenes
2015-04-15 16:11 - 2013-07-13 23:16 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-04-15 16:02 - 2012-03-10 00:53 - 125832184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-04-15 16:01 - 2012-03-09 21:25 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa\Microsoft Help
2015-04-15 13:39 - 2013-12-17 14:46 - 00001874 _____ () C:\Documents and Settings\All Users\Escritorio\Google Chrome.lnk
2015-04-15 11:33 - 2012-04-03 18:27 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-04-15 11:33 - 2012-03-12 22:29 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-04-13 11:50 - 2012-03-10 18:03 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Mis escaneos
2015-04-10 14:48 - 2012-03-10 14:51 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Directorio de intercambio Bluetooth
2015-04-08 15:00 - 2014-03-08 10:15 - 00000216 _____ () C:\WINDOWS\Tasks\Notificación mensual de fin de servicio de Microsoft Windows XP.job
==================== Files in the root of some directories =======
2015-04-15 21:40 - 2015-04-15 21:40 - 0000132 _____ () C:\Documents and Settings\cacha\Datos de programa\Prefs. de formato PNG de Adobe CS6
2012-03-12 22:52 - 2015-04-24 13:53 - 0094720 _____ () C:\Documents and Settings\cacha\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-13 19:02 - 2012-04-13 19:02 - 0000134 _____ () C:\Documents and Settings\cacha\Configuración local\Datos de programa\fusioncache.dat
Some content of TEMP:
====================
C:\Documents and Settings\cacha\Configuración local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp1nbvlu.dll
C:\Documents and Settings\cacha\Configuración local\Temp\swt-gdip-win32-3346.dll
C:\Documents and Settings\cacha\Configuración local\Temp\swt-win32-3346.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-04-2015 01
Ran by cacha (administrator) on FLORNOTE on 30-04-2015 17:15:47
Running from C:\Documents and Settings\cacha\Escritorio
Loaded Profiles: cacha (Available profiles: cacha & Administrador & Invitado)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) OS Language: Español (alfabetización internacional)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Broadcom Corporation.) C:\Archivos de programa\WIDCOMM\Bluetooth Software\bin\btwdins.exe
() C:\WINDOWS\system32\WLTRYSVC.EXE
(Dell Inc.) C:\WINDOWS\system32\BCMWLTRY.EXE
(IDT, Inc.) C:\Archivos de programa\IDT\XPV10_6147v005\WDM\stacsv.exe
(IDT, Inc.) C:\Archivos de programa\IDT\WDM\sttray.exe
(Andrea Electronics Corporation) C:\WINDOWS\system32\AESTFltr.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\Apoint.exe
(Creative Technology Ltd.) C:\WINDOWS\OEM13Mon.exe
(Dell Inc.) C:\WINDOWS\system32\WLTRAY.EXE
(ESET) C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Microsoft Corporation) C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe
(Hewlett-Packard) C:\Archivos de programa\HP\HP Software Update\hpwuSchd2.exe
(Oracle Corporation) C:\Archivos de programa\Archivos comunes\Java\Java Update\jusched.exe
(ESET) C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe
(Safer-Networking Ltd.) C:\Archivos de programa\Spybot - Search & Destroy 2\SDTray.exe
(Oracle Corporation) C:\Archivos de programa\Java\jre7\bin\jqs.exe
(Microsoft Corporation) C:\Archivos de programa\Windows Media Player\wmpnscfg.exe
(Spotify Ltd) C:\Documents and Settings\cacha\Datos de programa\Spotify\SpotifyWebHelper.exe
(Nalpeiron Ltd.) C:\WINDOWS\system32\NLSSRV32.EXE
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Broadcom Corporation.) C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTTray.exe
(Absolute Software Corp.) C:\WINDOWS\system32\rpcnet.exe
(Safer-Networking Ltd.) C:\Archivos de programa\Spybot - Search & Destroy 2\SDFSSvc.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\ApMsgFwd.exe
(Broadcom Corporation.) C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\hidfind.exe
(Alps Electric Co., Ltd.) C:\Archivos de programa\DellTPad\ApntEx.exe
(Safer-Networking Ltd.) C:\Archivos de programa\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Archivos de programa\Windows Media Player\wmpnetwk.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Archivos de programa\Microsoft Office\Office12\WINWORD.EXE
(Google Inc.) C:\Archivos de programa\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Archivos de programa\IDT\WDM\sttray.exe [483420 2009-02-20] (IDT, Inc.)
HKLM\...\Run: [AESTFltr] => C:\WINDOWS\system32\AESTFltr.exe [729088 2009-02-20] (Andrea Electronics Corporation)
HKLM\...\Run: [Apoint] => C:\Archivos de programa\DellTPad\Apoint.exe [217088 2009-03-13] (Alps Electric Co., Ltd.)
HKLM\...\Run: [OEM13Mon.exe] => C:\WINDOWS\OEM13Mon.exe [36864 2008-01-08] (Creative Technology Ltd.)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\WINDOWS\system32\WLTRAY.exe [2220032 2008-10-24] (Dell Inc.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [nwiz] => nwiz.exe /installquiet
HKLM\...\Run: [NVHotkey] => rundll32.exe nvHotkey.dll,Start
HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit
HKLM\...\Run: [DELL Webcam Manager] => C:\Archivos de programa\Dell\Dell Webcam Manager\DellWMgr.exe [118784 2007-07-27] (Creative Technology Ltd.)
HKLM\...\Run: [GrooveMonitor] => C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [HP Software Update] => C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe [49152 2007-10-14] (Hewlett-Packard)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [SunJavaUpdateSched] => C:\Archivos de programa\Archivos comunes\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Run: [egui] => C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe [5046472 2014-09-30] (ESET)
HKLM\...\Run: [SDTray] => C:\Archivos de programa\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [WMPNSCFG] => C:\Archivos de programa\Windows Media Player\WMPNSCFG.exe [204800 2009-02-04] (Microsoft Corporation)
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [Spotify Web Helper] => C:\Documents and Settings\cacha\Datos de programa\Spotify\SpotifyWebHelper.exe [1959992 2015-03-11] (Spotify Ltd)
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\...\Run: [Hide.me] => [X]
HKU\S-1-5-18\...\Run: [GoogleChromeAutoLaunch_A2E3159C0817FADA26422CFDCE0E82F1] => C:\Archivos de programa\Google\Chrome\Application\chrome.exe [812872 2015-04-13] (Google Inc.)
Startup: C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio\BTTray.lnk [2012-03-07]
ShortcutTarget: BTTray.lnk -> C:\Archivos de programa\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Documents and Settings\cacha\Datos de programa\Dropbox\bin\DropboxExt.25.dll [2015-02-10] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [GDriveBlacklistedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedEditOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedViewOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [GDriveSyncingOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Archivos de programa\Google\Drive\googledrivesync32.dll [2015-02-19] (Google)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2 (GFS Stub)] -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 3 (GFS Folder)] -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
ProxyServer: [S-1-5-21-1844237615-1767777339-1417001333-1003] => localhost:8080
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.ar/
HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://es.msn.com/?ocid=iehp
URLSearchHook: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 - BittorrentBar_ES Toolbar - {ad06fb5f-fef7-4a84-8c58-dca34f8e3d36} - No File
URLSearchHook: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No File
SearchScopes: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> {3E3A04E4-65A7-4BF0-BE56-A25D6C594ACF} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=es_ES&apn_ptnrs=^U3&apn_dtid=^OSJ000^YY^AR&apn_uid=29B3F03A-E8F4-4364-BB2F-056CD38F361A&apn_sauid=74974A9E-826B-490A-A51C-B8A407B7C46D
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Archivos de programa\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Archivos de programa\Java\jre7\bin\ssv.dll [2014-11-04] (Oracle Corporation)
BHO: BitTorrentBar Toolbar -> {88c7f2aa-f93f-432c-8f0e-b7d85967a527} -> No File
BHO: Windows Live Aplicación auxiliar de inicio de sesión -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO: BittorrentBar_ES Toolbar -> {ad06fb5f-fef7-4a84-8c58-dca34f8e3d36} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Archivos de programa\Java\jre7\bin\jp2ssv.dll [2014-11-04] (Oracle Corporation)
Toolbar: HKLM - BittorrentBar_ES Toolbar - {ad06fb5f-fef7-4a84-8c58-dca34f8e3d36} - No File
Toolbar: HKLM - BitTorrentBar Toolbar - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - No File
Toolbar: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> BitTorrentBar Toolbar - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - No File
Toolbar: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> BittorrentBar_ES Toolbar - {AD06FB5F-FEF7-4A84-8C58-DCA34F8E3D36} - No File
Toolbar: HKU\S-1-5-21-1844237615-1767777339-1417001333-1003 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-1_4_2_08-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Archivos de programa\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Help\hxds.dll [2013-09-25] (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Archivos de programa\Archivos comunes\System\Ole DB\MSDAIPP.DLL [2009-02-26] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Archivos de programa\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll [2014-03-06] (Microsoft Corporation)
Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 108.168.162.137 8.8.4.4
FireFox:
========
FF ProfilePath: C:\Documents and Settings\cacha\Datos de programa\Mozilla\Firefox\Profiles\8webyrm2.default
FF Homepage: hxxp://www.google.com.ar/
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-15] ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Archivos de programa\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Archivos de programa\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-11-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Archivos de programa\Java\jre7\bin\plugin2\npjp2.dll [2014-11-04] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Archivos de programa\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Archivos de programa\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Archivos de programa\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Archivos de programa\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Archivos de programa\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Archivos de programa\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Archivos de programa\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin HKU\S-1-5-21-1844237615-1767777339-1417001333-1003: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Archivos de programa\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-1844237615-1767777339-1417001333-1003: samsung.com/SamsungLinkPCPlugin -> C:\Archivos de programa\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll No File
FF Plugin ProgramFiles/Appdata: C:\Archivos de programa\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Archivos de programa\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll [2013-06-18] (Tracker Software Products (Canada) Ltd.)
FF SearchPlugin: C:\Archivos de programa\mozilla firefox\browser\searchplugins\creativecommons.xml [2014-07-22]
FF SearchPlugin: C:\Archivos de programa\mozilla firefox\browser\searchplugins\mercadolibre-ar.xml [2014-07-22]
FF Extension: FlashGot - C:\Documents and Settings\cacha\Datos de programa\Mozilla\Firefox\Profiles\8webyrm2.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2015-01-21]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-03-17]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Archivos de programa\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Archivos de programa\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2015-01-25]
Chrome:
=======
CHR HomePage: Default ->
CHR Profile: C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-22]
CHR Extension: (Easy Clock) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\dplbpgapoedppajbikieafefmcceaagn [2014-08-26]
CHR Extension: (BetaFish Adblocker) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-17]
CHR Extension: (Hola Better Internet) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2014-07-07]
CHR Extension: (Pin It Button) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2014-08-26]
CHR Extension: (Eye Dropper) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\hmdcmlfkchdmnmnmheododdhjedfccka [2014-11-11]
CHR Extension: (Kindle Cloud Reader) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2014-05-17]
CHR Extension: (StayFocusd) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2014-10-11]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-15]
CHR Extension: (Google Dictionary (by Google)) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2014-08-26]
CHR Extension: (Pocket) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2015-02-25]
CHR Extension: (feedly) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\ndhinffkekpekljifjkkkkkhopnjodja [2014-11-11]
CHR Extension: (Do It (Tomorrow)) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\nfagjoblnoeagfhfhohcdklnddjaiglo [2014-10-29]
CHR Extension: (Google Wallet) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-17]
CHR Extension: (Sidekick by HubSpot) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\oiiaigjnkhngdbnoookogelabohpglmd [2014-07-05]
CHR Extension: (Evernote Web Clipper) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2014-09-09]
CHR Extension: (Writer) - C:\Documents and Settings\cacha\Configuración local\Datos de programa\Google\Chrome\User Data\Default\Extensions\pnengefjfhgcceajaepbjhanoojifmog [2014-11-11]
CHR HKLM\...\Chrome\Extension: [lhpgolofjlpnkdafbgejgnclbjnpgfee] - C:\DOCUME~1\cacha\CONFIG~1\Temp\ccex.crx [Not Found]
CHR HKLM\...\Chrome\Extension: [mhfdcmehmjcclgopdodkjdicohagipid] - C:\Documents and Settings\cacha\Configuración local\Datos de programa\CRE\mhfdcmehmjcclgopdodkjdicohagipid.crx [2012-04-17]
CHR HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\DOCUME~1\cacha\CONFIG~1\DATOSD~1\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2015-02-21]
CHR HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1844237615-1767777339-1417001333-1003\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [mhfdcmehmjcclgopdodkjdicohagipid] - C:\Documents and Settings\cacha\Configuración local\Datos de programa\CRE\mhfdcmehmjcclgopdodkjdicohagipid.crx [2012-04-17]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 btwdins; C:\Archivos de programa\WIDCOMM\Bluetooth Software\bin\btwdins.exe [264800 2008-09-17] (Broadcom Corporation.)
R2 ekrn; C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe [1343920 2014-09-30] (ESET)
S2 gupdate; C:\Archivos de programa\Google\Update\GoogleUpdate.exe [116648 2013-12-17] (Google Inc.)
S3 gupdatem; C:\Archivos de programa\Google\Update\GoogleUpdate.exe [116648 2013-12-17] (Google Inc.)
R3 hpqcxs08; C:\Archivos de programa\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-11-06] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Archivos de programa\HP\Digital Imaging\bin\hpqddsvc.dll [139264 2007-11-06] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Archivos de programa\Archivos comunes\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Archivos de programa\Java\jre7\bin\jqs.exe [182696 2014-11-04] (Oracle Corporation)
S3 Microsoft Office Groove Audit Service; C:\Archivos de programa\Microsoft Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation)
S3 MozillaMaintenance; C:\Archivos de programa\Mozilla Maintenance Service\maintenanceservice.exe [148080 2015-04-24] (Mozilla Foundation)
R2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [43520 2006-11-08] (Hewlett-Packard) [File not signed]
S3 odserv; C:\Archivos de programa\Archivos comunes\Microsoft Shared\OFFICE12\ODSERV.EXE [440696 2011-07-20] (Microsoft Corporation)
S3 ose; C:\Archivos de programa\Archivos comunes\Microsoft Shared\Source Engine\OSE.EXE [145184 2006-10-26] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53248 2006-11-08] (Hewlett-Packard) [File not signed]
R2 rpcnet; C:\WINDOWS\system32\rpcnet.exe [78032 2015-04-26] (Absolute Software Corp.)
R2 SDScannerService; C:\Archivos de programa\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Archivos de programa\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Archivos de programa\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 STacSV; c:\archivos de programa\idt\xpv10_6147v005\wdm\stacsv.exe [249938 2009-02-20] (IDT, Inc.)
R2 wltrysvc; C:\WINDOWS\System32\bcmwltry.exe [1961984 2008-10-24] (Dell Inc.) [File not signed]
R2 WMPNetworkSvc; C:\Archivos de programa\Windows Media Player\WMPNetwk.exe [916480 2009-02-04] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 AESTAud; C:\WINDOWS\System32\drivers\AESTAud.sys [112512 2009-02-20] (Andrea Electronics Corporation)
R3 BCM43XX; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [1287552 2008-10-24] (Broadcom Corporation)
R3 btaudio; C:\WINDOWS\System32\drivers\btaudio.sys [539640 2008-07-26] (Broadcom Corporation.)
R3 BTDriver; C:\WINDOWS\System32\DRIVERS\btport.sys [37424 2008-07-26] (Broadcom Corporation.)
R3 BTKRNL; C:\WINDOWS\System32\DRIVERS\btkrnl.sys [879832 2008-07-29] (Broadcom Corporation.)
R3 BTWDNDIS; C:\WINDOWS\System32\DRIVERS\btwdndis.sys [156816 2008-07-29] (Broadcom Corporation.)
R3 btwhid; C:\WINDOWS\System32\DRIVERS\btwhid.sys [55352 2008-07-26] (Broadcom Corporation.)
R3 btwmodem; C:\WINDOWS\System32\DRIVERS\btwmodem.sys [37280 2008-07-26] (Broadcom Corporation.)
R3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [74688 2008-07-26] (Broadcom Corporation.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R1 eamon; C:\WINDOWS\System32\DRIVERS\eamon.sys [185688 2014-09-30] (ESET)
R1 ehdrv; C:\WINDOWS\System32\DRIVERS\ehdrv.sys [135296 2014-09-30] (ESET)
R1 epfwtdir; C:\WINDOWS\System32\DRIVERS\epfwtdir.sys [118768 2014-09-30] (ESET)
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-10-30] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-10-30] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-10-30] (HP)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 O2MDGRDR; C:\WINDOWS\System32\DRIVERS\o2mdg.sys [58144 2009-03-19] (O2Micro )
R3 O2SDGRDR; C:\WINDOWS\System32\DRIVERS\o2sdg.sys [41376 2009-02-24] (O2Micro )
R3 OEM13Afx; C:\WINDOWS\system32\Drivers\OEM13Afx.sys [141376 2007-06-08] (Creative Technology Ltd.)
R3 OEM13Vfx; C:\WINDOWS\System32\DRIVERS\OEM13Vfx.sys [7424 2007-03-05] (EyePower Games Pte. Ltd.)
R3 OEM13Vid; C:\WINDOWS\System32\DRIVERS\OEM13Vid.sys [235840 2008-05-29] (Creative Technology Ltd.)
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1548339 2009-02-20] (IDT, Inc.)
S3 vulfnths; C:\WINDOWS\System32\Drivers\vulfnth.sys [6912 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S3 vulfntrs; C:\WINDOWS\System32\Drivers\vulfntr.sys [11392 2003-08-04] (VIA Technologies, Inc.) [File not signed]
S0 cerc6; No ImagePath
S3 CrystalSysInfo; \??\C:\Archivos de programa\MediaCoder\SysInfo.sys [X]
S3 GenericMount; system32\DRIVERS\GenericMount.sys [X]
S4 IntelIde; No ImagePath
U2 V2iMount; No ImagePath
U1 WS2IFSL; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-30 17:15 - 2015-04-30 17:16 - 00030070 _____ () C:\Documents and Settings\cacha\Escritorio\FRST.txt
2015-04-30 17:11 - 2015-04-30 17:15 - 00000000 ____D () C:\FRST
2015-04-30 17:09 - 2015-04-30 17:09 - 01140736 _____ (Farbar) C:\Documents and Settings\cacha\Escritorio\FRST.exe
2015-04-30 13:22 - 2015-04-30 13:22 - 00012285 _____ () C:\Documents and Settings\cacha\Escritorio\Scan Results.150430-1322.txt
2015-04-28 08:21 - 2015-04-28 08:21 - 00065536 _____ () C:\WINDOWS\Minidump\Mini042815-01.dmp
2015-04-24 19:11 - 2015-04-24 19:13 - 00000000 ____D () C:\Archivos de programa\Mozilla Firefox
2015-04-24 08:20 - 2015-04-24 08:20 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\ProcAlyzer Dumps
2015-04-23 19:59 - 2015-04-23 19:59 - 00000000 ___RD () C:\Documents and Settings\NetworkService\Mis documentos\Mi música
2015-04-23 19:59 - 2015-04-23 19:59 - 00000000 ____D () C:\Documents and Settings\NetworkService\Mis documentos
2015-04-20 15:41 - 2015-04-30 00:06 - 00013312 ____H () C:\Documents and Settings\cacha\Escritorio\photothumb.db
2015-04-18 16:17 - 2015-04-18 16:18 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio\Para leer
2015-04-18 16:15 - 2015-04-18 16:16 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio\Art in Translation texts
2015-04-17 22:09 - 2015-04-17 22:09 - 00000000 ____D () C:\Documents and Settings\LocalService\Menú Inicio\Programas
2015-04-17 22:09 - 2015-04-17 22:09 - 00000000 ____D () C:\Documents and Settings\LocalService\Menú Inicio
2015-04-17 22:08 - 2015-04-17 22:08 - 00000000 ____D () C:\Archivos de programa\Asoftech
2015-04-17 21:44 - 2015-04-30 17:00 - 00000658 _____ () C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job
2015-04-17 21:44 - 2015-04-17 21:44 - 00001905 _____ () C:\Documents and Settings\All Users\Menú Inicio\Programas\Spybot-S&D Start Center.lnk
2015-04-17 21:44 - 2015-04-17 21:44 - 00001899 _____ () C:\Documents and Settings\All Users\Escritorio\Spybot-S&D Start Center.lnk
2015-04-17 21:44 - 2015-04-17 21:44 - 00000630 _____ () C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2015-04-17 21:44 - 2015-04-17 21:44 - 00000460 _____ () C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job
2015-04-17 21:44 - 2015-04-17 21:44 - 00000000 ____D () C:\Documents and Settings\All Users\Menú Inicio\Programas\Spybot - Search & Destroy 2
2015-04-17 21:43 - 2015-04-17 22:10 - 00000000 ____D () C:\Archivos de programa\Spybot - Search & Destroy 2
2015-04-17 21:43 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean.exe
2015-04-17 21:28 - 2012-07-27 06:45 - 00000102 _____ () C:\medicina.cmd
2015-04-16 19:23 - 2015-04-18 17:31 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\pinguino
2015-04-15 21:40 - 2015-04-15 21:40 - 00000132 _____ () C:\Documents and Settings\cacha\Datos de programa\Prefs. de formato PNG de Adobe CS6
2015-04-09 21:54 - 2015-04-10 16:08 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Stock Photography
2015-04-07 17:54 - 2015-04-07 17:54 - 00065536 _____ () C:\WINDOWS\Minidump\Mini040715-01.dmp
2015-04-07 17:51 - 2015-04-28 08:21 - 205238272 _____ () C:\WINDOWS\MEMORY.DMP
2015-03-31 11:24 - 2015-03-31 11:24 - 00000737 _____ () C:\Documents and Settings\cacha\Escritorio\Acceso directo a Red - Logan, J..lnk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-30 17:15 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio
2015-04-30 17:14 - 2014-05-27 15:26 - 00000488 ____H () C:\WINDOWS\Tasks\User_Feed_Synchronization-{C604CD4C-5685-42BB-8F60-C2D813575826}.job
2015-04-30 17:00 - 2012-03-07 23:57 - 00077291 _____ () C:\WINDOWS\system32\nvModes.001
2015-04-30 17:00 - 2008-04-13 20:00 - 00002206 _____ () C:\WINDOWS\system32\wpa.dbl
2015-04-30 16:58 - 2014-03-08 10:15 - 00000222 _____ () C:\WINDOWS\Tasks\Notificación de inicio de sesión de fin de servicio de Microsoft Windows XP.job
2015-04-30 16:58 - 2013-12-17 14:43 - 00001098 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-30 16:58 - 2012-03-08 00:03 - 00078032 _____ (Absolute Software Corp.) C:\WINDOWS\system32\rpcnet.dll
2015-04-30 16:58 - 2012-03-07 23:55 - 00200942 _____ () C:\WINDOWS\system32\nvapps.xml
2015-04-30 16:58 - 2012-03-07 21:10 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-04-30 16:58 - 2012-03-07 16:54 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-04-30 16:58 - 2012-03-07 16:54 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2015-04-30 16:58 - 2012-03-07 16:52 - 00017408 _____ () C:\WINDOWS\system32\rpcnetp.exe
2015-04-30 16:29 - 2012-03-10 14:50 - 00000192 ___SH () C:\Documents and Settings\cacha\ntuser.ini
2015-04-30 16:29 - 2012-03-07 21:10 - 00032404 _____ () C:\WINDOWS\SchedLgU.Txt
2015-04-30 16:29 - 2012-03-07 21:06 - 01513853 _____ () C:\WINDOWS\WindowsUpdate.log
2015-04-30 15:37 - 2013-12-17 14:43 - 00001102 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-30 15:32 - 2012-04-03 18:27 - 00000838 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-04-30 13:09 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha
2015-04-29 23:27 - 2013-09-24 14:22 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\Spotify
2015-04-29 16:21 - 2013-05-15 17:54 - 00000000 ___RD () C:\Documents and Settings\cacha\Mis documentos\Dropbox
2015-04-29 14:06 - 2012-03-10 14:50 - 00000000 ___HD () C:\Documents and Settings\cacha\Configuración local\Datos de programa
2015-04-29 14:06 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa
2015-04-29 14:06 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa
2015-04-29 14:06 - 2012-03-07 16:53 - 00000000 ____D () C:\Archivos de programa\Archivos comunes
2015-04-29 09:07 - 2013-05-15 17:54 - 00000995 _____ () C:\Documents and Settings\cacha\Escritorio\Dropbox.lnk
2015-04-29 09:07 - 2013-05-15 17:39 - 00000000 ____D () C:\Documents and Settings\cacha\Menú Inicio\Programas\Dropbox
2015-04-29 09:07 - 2013-05-15 17:38 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\Dropbox
2015-04-28 17:27 - 2012-03-10 18:19 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\BitTorrent
2015-04-28 09:26 - 2013-09-24 16:07 - 00000000 ____D () C:\Documents and Settings\cacha\Configuración local\Datos de programa\Spotify
2015-04-28 08:21 - 2013-12-22 09:15 - 00000000 ____D () C:\WINDOWS\Minidump
2015-04-27 18:10 - 2015-02-06 11:17 - 00000000 ____D () C:\Documents and Settings\cacha\Escritorio\The Translator's Tools
2015-04-27 13:39 - 2012-03-14 10:36 - 00000000 ____D () C:\Documents and Settings\cacha\Datos de programa\vlc
2015-04-26 12:35 - 2012-03-08 00:03 - 00078032 ____N (Absolute Software Corp.) C:\WINDOWS\system32\rpcnet.exe
2015-04-25 20:56 - 2012-04-04 23:33 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\My Shared Folder
2015-04-25 08:16 - 2014-02-28 23:20 - 00000000 ____D () C:\Archivos de programa\Mozilla Maintenance Service
2015-04-24 21:40 - 2012-03-07 16:53 - 00000000 ___RD () C:\Archivos de programa
2015-04-24 13:53 - 2012-03-12 22:52 - 00094720 _____ () C:\Documents and Settings\cacha\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-04-24 08:20 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos
2015-04-24 08:20 - 2012-03-07 17:51 - 00000245 ___SH () C:\boot.ini
2015-04-23 19:59 - 2012-03-07 21:09 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2015-04-23 19:58 - 2012-11-23 19:19 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Mi Música
2015-04-23 08:00 - 2015-02-21 20:47 - 00000000 ___RD () C:\Documents and Settings\cacha\Mis documentos\Google Drive
2015-04-20 16:03 - 2014-04-16 23:59 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Descargas
2015-04-18 16:20 - 2012-03-14 10:26 - 00000000 ____D () C:\Archivos de programa\Adobe
2015-04-18 16:19 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Menú Inicio\Programas
2015-04-18 16:16 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Escritorio
2015-04-18 10:39 - 2012-03-10 14:50 - 00000000 __SHD () C:\Documents and Settings\cacha\Configuración local\Archivos temporales de Internet
2015-04-18 08:23 - 2012-03-07 21:09 - 00000000 __SHD () C:\Documents and Settings\NetworkService\Configuración local\Archivos temporales de Internet
2015-04-17 23:16 - 2012-08-24 23:29 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa\Skype
2015-04-17 23:15 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\All Users\Menú Inicio
2015-04-17 22:59 - 2014-05-12 13:24 - 00000000 ____D () C:\Documents and Settings\cacha\Menú Inicio\Programas\Amazon
2015-04-17 22:59 - 2014-05-12 13:23 - 00000000 ____D () C:\Archivos de programa\Amazon
2015-04-17 22:58 - 2012-03-10 14:50 - 00000000 ____D () C:\Documents and Settings\cacha\Menú Inicio\Programas
2015-04-17 22:29 - 2014-08-28 16:56 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Dibujos low-res
2015-04-17 22:09 - 2012-03-07 21:10 - 00000000 __SHD () C:\Documents and Settings\LocalService
2015-04-17 22:08 - 2012-03-07 21:56 - 00000000 ____D () C:\Archivos de programa\InstallShield Installation Information
2015-04-17 21:44 - 2012-03-07 21:10 - 00000000 __SHD () C:\Documents and Settings\LocalService\Configuración local\Archivos temporales de Internet
2015-04-17 21:43 - 2013-08-17 12:32 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa\Spybot - Search & Destroy
2015-04-17 21:27 - 2012-03-07 16:53 - 00000000 ____D () C:\Documents and Settings\Default User\Configuración local\Archivos temporales de Internet
2015-04-16 10:14 - 2015-01-20 15:02 - 00000000 ____D () C:\Documents and Settings\cacha\Configuración local\Datos de programa\Adobe
2015-04-15 18:12 - 2013-05-15 17:25 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Mis imágenes
2015-04-15 16:11 - 2013-07-13 23:16 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-04-15 16:02 - 2012-03-10 00:53 - 125832184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-04-15 16:01 - 2012-03-09 21:25 - 00000000 ____D () C:\Documents and Settings\All Users\Datos de programa\Microsoft Help
2015-04-15 13:39 - 2013-12-17 14:46 - 00001874 _____ () C:\Documents and Settings\All Users\Escritorio\Google Chrome.lnk
2015-04-15 11:33 - 2012-04-03 18:27 - 00778416 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-04-15 11:33 - 2012-03-12 22:29 - 00142512 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-04-13 11:50 - 2012-03-10 18:03 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Mis escaneos
2015-04-10 14:48 - 2012-03-10 14:51 - 00000000 ____D () C:\Documents and Settings\cacha\Mis documentos\Directorio de intercambio Bluetooth
2015-04-08 15:00 - 2014-03-08 10:15 - 00000216 _____ () C:\WINDOWS\Tasks\Notificación mensual de fin de servicio de Microsoft Windows XP.job
==================== Files in the root of some directories =======
2015-04-15 21:40 - 2015-04-15 21:40 - 0000132 _____ () C:\Documents and Settings\cacha\Datos de programa\Prefs. de formato PNG de Adobe CS6
2012-03-12 22:52 - 2015-04-24 13:53 - 0094720 _____ () C:\Documents and Settings\cacha\Configuración local\Datos de programa\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-04-13 19:02 - 2012-04-13 19:02 - 0000134 _____ () C:\Documents and Settings\cacha\Configuración local\Datos de programa\fusioncache.dat
Some content of TEMP:
====================
C:\Documents and Settings\cacha\Configuración local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp1nbvlu.dll
C:\Documents and Settings\cacha\Configuración local\Temp\swt-gdip-win32-3346.dll
C:\Documents and Settings\cacha\Configuración local\Temp\swt-win32-3346.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================
aswMBR version 1.0.1.2252 Copyright(c) 2014 AVAST Software
Run date: 2015-04-30 17:21:12
-----------------------------
17:21:12.890 OS Version: Windows 5.1.2600 Service Pack 3
17:21:12.890 Number of processors: 2 586 0x170A
17:21:12.906 ComputerName: FLORNOTE UserName: cacha
17:21:13.750 Initialize success
17:21:13.843 VM: initialized successfully
17:21:13.843 VM: Intel CPU BiosDisabled
17:22:12.687 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
17:22:12.687 Disk 0 Vendor: WDC_WD25 11.0 Size: 238475MB BusType: 3
17:22:12.859 Disk 0 MBR read successfully
17:22:12.875 Disk 0 MBR scan
17:22:12.875 Disk 0 Windows XP default MBR code
17:22:12.875 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
17:22:12.875 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 238434 MB offset 81920
17:22:12.875 Disk 0 Boot: NTFS code=1
17:22:12.875 Disk 0 scanning sectors +488395120
17:22:12.953 Disk 0 scanning C:\WINDOWS\system32\drivers
17:22:17.718 Service scanning
17:22:22.687 Service ehdrv C:\WINDOWS\system32\DRIVERS\ehdrv.sys **LOCKED** 5
17:22:22.796 Service epfwtdir C:\WINDOWS\system32\DRIVERS\epfwtdir.sys **LOCKED** 5
17:22:30.312 Modules scanning
17:22:30.328 Disk 0 trace - called modules:
17:22:30.328
17:22:30.328 Disk 0 statistics 44898/0/0 @ 4,59 MB/s
17:22:30.328 Scan finished successfully
17:22:41.156 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\cacha\Escritorio\MBR.dat"
17:22:41.171 The log file has been saved successfully to "C:\Documents and Settings\cacha\Escritorio\aswMBR.txt"