Beruflich Dokumente
Kultur Dokumente
2 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.591.3082.18.1015.764 [GMT -4:
00]
Running from: d:\pc\ComboFix.exe
AV: Trend Micro OfficeScan Antivirus *Enabled/Updated* {4CA5B9AB-4295-4D4C-96640EBE85AE0525}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))
)))))))))))))))))))))))))))))
.
.
c:\documents and settings\lortizf\beiapo.exe
c:\documents and settings\lortizf\cieav.exe
c:\documents and settings\lortizf\daaru.exe
c:\documents and settings\lortizf\gouqiug.exe
c:\documents and settings\lortizf\hbcar.exe
c:\documents and settings\lortizf\hiuzoa.exe
c:\documents and settings\lortizf\koifia.exe
c:\documents and settings\lortizf\kouoxeq.exe
c:\documents and settings\lortizf\lieay.exe
c:\documents and settings\lortizf\liuxuq.exe
c:\documents and settings\lortizf\loowee.exe
c:\documents and settings\lortizf\moiyu.exe
c:\documents and settings\lortizf\muaip.exe
c:\documents and settings\lortizf\muipis.exe
c:\documents and settings\lortizf\noeep.exe
c:\documents and settings\lortizf\pairue.exe
c:\documents and settings\lortizf\qieoz.exe
c:\documents and settings\lortizf\quoxua.exe
c:\documents and settings\lortizf\raoniu.exe
c:\documents and settings\lortizf\saiif.exe
c:\documents and settings\lortizf\sieuz.exe
c:\documents and settings\lortizf\soubui.exe
c:\documents and settings\lortizf\symoem.exe
c:\documents and settings\lortizf\teetiav.exe
c:\documents and settings\lortizf\veoehu.exe
c:\documents and settings\lortizf\vowon.exe
c:\documents and settings\lortizf\wfug.com
c:\documents and settings\lortizf\xtvit.exe
c:\documents and settings\lortizf\xuuuv.exe
c:\documents and settings\lortizf\zepos.exe
c:\documents and settings\lortizf\ziuip.exe
c:\documents and settings\lortizf\zohek.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-09-08 to 2013-10-08 )))))))
))))))))))))))))))))))))
.
.
2013-10-08 13:16 . 2010-06-15 15:26
67664 ----a-wc:\windows\syste
m32\drivers\tmactmon.sys
2013-10-08 13:16 . 2010-06-15 15:26
57424 ----a-wc:\windows\syste
m32\drivers\tmevtmgr.sys
2013-10-08 13:16 . 2010-06-15 15:25
177232 ----a-wc:\windows\syste
m32\drivers\tmcomm.sys
2013-10-08 13:15 . 2013-10-08 13:15
-------d-----wc:\windo
ws\system32\log
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Authoriz
edApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Archivos de programa\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Archivos de programa\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Archivos de programa\\Microsoft Office\\Office12\\ONENOTE.EXE"=
.
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [23/07/2008 11:31 44800]
S2 ArcGIS License Manager;ArcGIS License Manager;c:\archivos de programa\ESRI\Li
cense\arcgis9x\lmgrd.exe [05/03/2012 15:30 1431440]
S2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [26/07/2011 17:52 9
9896]
S2 ManageEngine AssetExplorer Agent;ManageEngine AssetExplorer Agent;c:\archivos
de programa\ManageEngine\AssetExplorer\bin\agentmonitor.exe [17/06/2011 18:18 3
03104]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [08/10/2013 9:16 5
7424]
S2 TmFilter;Trend Micro Filter;c:\archivos de programa\Trend Micro\OfficeScan Cl
ient\tmxpflt.sys [25/03/2011 16:12 264504]
S2 TmPreFilter;Trend Micro PreFilter;c:\archivos de programa\Trend Micro\OfficeS
can Client\tmpreflt.sys [25/03/2011 16:12 36664]
S3 Com4QLBEx;Com4QLBEx;c:\archivos de programa\Hewlett-Packard\HP Quick Launch B
uttons\Com4QLBEx.exe [26/07/2011 15:43 193840]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\docume~1\usuario\CONFIG~1\
Temp\EverestDriver.sys --> c:\docume~1\usuario\CONFIG~1\Temp\EverestDriver.sys [
?]
S3 HP24X;HP PC Card Smart Card Reader;c:\windows\system32\drivers\HP24X.sys [26/
07/2011 14:48 33024]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.
sys [28/07/2011 8:40 100736]
S3 ManageEngine AssetExplorer RemoteControl;ManageEngine AssetExplorer RemoteCon
trol;c:\archivos de programa\ManageEngine\AssetExplorer\RemoteControl\Service.ex
e [17/06/2011 18:18 278528]
S3 mvusbews;USB EWS Device;c:\windows\system32\drivers\mvusbews.sys [26/07/2011
17:51 17408]
S3 TmProxy;OfficeScan NT Proxy Service;c:\archivos de programa\Trend Micro\Offic
eScan Client\TmProxy.exe [25/03/2011 16:12 689416]
.
Contents of the 'Scheduled Tasks' folder
.
2013-10-08 c:\windows\Tasks\User_Feed_Synchronization-{013BFEFB-4368-415C-8EF0-B
FBB7208F1D2}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
2013-10-08 c:\windows\Tasks\User_Feed_Synchronization-{57FDFB2D-7CC0-430D-A80B-5
0F74E024FF9}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
------- Supplementary Scan ------.
IE: E&xportar a Microsoft Excel - c:\archiv~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: Interfaces\{620A6084-ADCB-4E64-85AE-F8083C0FB393}: NameServer = 100.192.1.4
,100.192.1.30
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http:/
/www.gmer.net
Rootkit scan 2013-10-08 09:40
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS --------------------.
[HKEY_USERS\S-1-5-21-796845957-838170752-1417001333-500\Software\Microsoft\Inter
net Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a8,d0,20,f7,1d,05,cc,40,a5,58,64,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a8,d0,20,f7,1d,05,cc,40,a5,58,64,\
.
Completion time: 2013-10-08 09:41:19
ComboFix-quarantined-files.txt 2013-10-08 13:41
.
Pre-Run: 65.272.029.184 bytes libres
Post-Run: 66.076.467.200 bytes libres
.
- - End Of File - - 7730667071E4E43F5272851FF69270E2
792F61657FECE3D17A9122B4EE282847