You are on page 1of 4

ComboFix 11-03-14.07 - Administrador 15/03/2011 16:04:18.1.

1 - x86 MINIMAL
Microsoft Windows 2000 Professional 5.0.2195.4.1252.34.3082.18.1022.777 [GMT -5
:00]
Running from: c:\documents and settings\Administrador\Escritorio\ComboFix.exe
.
/wow section - STAGE 10
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))
)))))))))))))))))))))))))))))
.
.
c:\winnt\system32\i
c:\winnt\System32\jrxoq.dll
c:\winnt\Web\default.htt
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))
))))))))))))))))))))))))))))))
.
.
-------\Legacy_ccdnxeu
-------\Service_ccdnxeu
.
.
((((((((((((((((((((((((( Files Created from 2011-02-15 to 2011-03-15 )))))))
))))))))))))))))))))))))
.
.
2011-03-08 18:43 . 2011-03-08 18:48
-------d---a-wC:\matla
bR12
2011-03-07 18:42 . 2011-03-07 18:42
-------d-----wC:\LVSIM
2011-03-07 18:42 . 2011-03-07 18:42
-------d-----wC:\LVDAM
2011-03-02 20:06 . 2011-03-02 20:06
-------d---a-wC:\WUTem
p
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))
)))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))
)))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [1999-12-16 20752]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [2003-06-19 111888]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"nod32kui"="c:\archivos de programa\Eset\nod32kui.exe" [2011-03-07 921600]
"UpdateReminder"="c:\archivos de programa\Eset\UpdateReminder.exe" [2011-03-07 4
34176]
"IgfxTray"="c:\winnt\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\winnt\system32\hkcmd.exe" [2005-10-19 126976]

exe " [2009-12-11 948672] .EXE/3000 IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} .IPNAT *NewlyCreated* .... scanning hidden autostart entries . uStart Page = hxxp://www.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "internat. . catchme 0.exe -k netsvcs [16/12/1999 1:00 7952] R3 usbhub20.exe" [1999-12-16 20752] . scan completed successfully hidden files: 0 .com.c:\winnt\system32\driv ers\usbhub20..RASAUTO *NewlyCreated* .exe" [2003-06-19 189712] . *NewlyCreated* ..google.3.dll LSP: %SystemRoot%\system32\msafd. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost .0.c:\archiv~1\MICROS~2\Office10\EXCEL.0\AdobeARM.lnk .net Rootkit scan 2011-03-15 16:12 Windows 5.exe"="internat.c:\winnt\system32\svchost.co/ IE: E&xportar a Microsoft Excel . .file://c:\winnt\Java\classes\dajava. R?2 ccdnxeu. c:\documents and settings\All Users\Men£ Inicio\Programas\Inicio\ Microsoft Office.Other Services/Drivers In Memory --. ************************************************************************** .2195 Service Pack 4 NTFS .dll DPF: DirectAnimation Java Classes . . [HKEY_USERS\. scanning hidden files .DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "^SetupICWDesktop"="c:\archivos de programa\Internet Explorer\Connection Wizard\ icwconn1.sys [02/03/2011 15:37 49776] . --..Manager Driver.Supplementary Scan ------. http:/ /www. [HKEY_USERS\.EXE [2001-2-13 83360] .Compatibilidad con concentrador de raíz USB 2."Adobe Reader Speed Launcher"="c:\archivos de programa\Adobe\Reader 9.rootkit/stealth malware detector by Gmer.cab .c:\archivos de programa\Microsoft Office\Office10\OSA.SHAREDACCESS . scanning hidden processes . ************************************************************************** . .cab DPF: Microsoft XML Parser for Java . .1398 W2K/XP/Vista .file://c:\winnt\Java\classes\xmldso.0.NetSv cs ccdnxeu .gmer.htm LSP: c:\winnt\system32\imon.exe" [2009-12-22 35760] "Adobe ARM"="c:\archivos de programa\Archivos comunes\Adobe\ARM\1.%SystemRoot%\web\related. ------.0\Reader\R eader_sl.

Other Running Processes -----------------------. [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6A F30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1..dll" .exe . . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6A F30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E }\Elevation] "Enabled"=dword:00000001 .exe c:\winnt\system32\MSTask.-101" ... ..exe c:\winnt\BCMSMMSG.0" . .DLL . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6A F30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" .DLLs Loaded Under Running Processes --------------------....dll c:\winnt\system32\WZCSAPI.... [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E }\LocalServer32] @="c:\\WINNT\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.LOCKED REGISTRY KEYS --------------------. [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E }\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . c:\archivos de programa\Eset\nod32krn...exe'(656) c:\winnt\system32\SHDOCVW. -----------------------.exe c:\winnt\system32\regsvc.> 'explorer..dll c:\archivos de programa\Eset\pr_imon.exe'(236) c:\winnt\system32\imon.. --------------------. [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccdnxeu] "ServiceDll"="c:\winnt\System32\jrxoq..e xe..> 'lsass..exe'(196) c:\winnt\system32\wzcdlg..exe c:\winnt\System32\WBEM\WinMgmt.> 'winlogon..dll . --------------------.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E }] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINNT\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe c:\winnt\system32\internat.DLL .

.693..488 bytes libres Post-Run: 16.248 bytes libres .machine was rebooted ComboFix-quarantined-files.647.txt 2011-03-15 21:14 .483.. Pre-Run: 16.. Completion time: 2011-03-15 16:14:56 .End Of File . ************************************************************************** .301.0D4D47C80573AC0D72BCEF8A94A6287C .