Vous êtes sur la page 1sur 23

ComboFix 14-03-24.01 - Candiani Movil 30/03/2014 1:41.1.

4 - x64 NETWORK
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.52.3082.18.4012.2893 [GMT -6:00]
Running from: c:\users\Candiani Movil\Downloads\ComboFix.exe
AV: Norton AntiVirus *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Norton AntiVirus *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other
Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\SupTab\SuPTab.dll
c:\programdata\Roaming
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\background.html
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\chromeCoreFilesI
ndex.txt
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\crossriderManife
st.json
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\ma
nifest.xml
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins.json
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\1.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\102.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\103.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\104.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\13.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\14.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\17.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\177.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\182.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\183.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\184.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\19.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\191.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\207.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\21.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\22.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\223.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\242.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\246.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\28.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\4.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\47.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\64.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\72.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\78.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\80.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\91.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\93.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\pl
ugins\97.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\us
erCode\background.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\extensionData\us
erCode\extension.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\icons\actions\1.
png
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\icons\icon128.pn
g
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\icons\icon16.png
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\icons\icon48.png
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\api\chrome.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\api\cookie.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\api\message.j
s
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\api\monitor.j
s
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\api\pageActio
n.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\api\pageActio
nBG.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\background.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\app_api.j
s
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\bg_app_ap
i.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\consts.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\cookie_st
ore.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\crossride
rAPI.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\delegate.
js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\events.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\extension
DataStore.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\installer
.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\logFile.j
s
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\logging.j
s
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\onBGDocum
entLoad.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\popupReso
urce\newPopup.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\popupReso
urce\popup.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\reports.j
s
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\storageWr
apper.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\updateMan
ager.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\util.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\lib\xhr.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\main.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\js\platformVersi
on.js
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\manifest.json
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User
Data\Default\Extensions\imonhoeiopfgoncjdldhhfjgocghkbbl\1.26.14_0\popup.html
c:\users\Candiani Movil\AppData\Local\Google\Chrome\User Data\Default\Preferences
c:\users\Candiani Movil\AppData\Local\lollipop
c:\users\Candiani Movil\AppData\Local\lollipop\logo.ico
c:\users\Candiani Movil\AppData\Local\lollipop\lollipop.bat
c:\users\Candiani Movil\AppData\Local\lollipop\lollipop.dat
c:\users\Candiani Movil\AppData\Local\lollipop\Lollipop.exe
c:\users\Candiani Movil\AppData\Local\lollipop\lollipop.lpd
c:\users\Candiani Movil\AppData\Local\lollipop\lollipop_cfg.lpd
c:\users\Candiani Movil\AppData\Local\lollipop\lollipop_ps.lpd
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-e188e6f4fb8a.com
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome.manifest
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\asyncDB.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\background.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\browserAction.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\contextMenu.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\dbManager.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\dom_bg.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\fileManager.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\firefox.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\firefoxNotifications.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\firefoxOmnibox.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\message.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\pageAction.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\request.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\tabs.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\webRequest.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\api\windowsMessagingHandler.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\background.html
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\baseObject.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\browser.xul
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\addressBarChangeObserver.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\console.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\consts.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\delegate.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\extensionDataStore.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\folderIOWrapper.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\httpObserver.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\IDBWrapper.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\installer.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\logFile.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\prefs.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\progressListenerObserver.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\registry.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\reloadObserver.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\reports.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\requestObject.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\searchSettings.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\uninstallObserver.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\updateManager.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\utils.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\core\xhr.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\dialog.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\ffCoreFilesIndex.txt
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\main.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\options.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\options.xul
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\platformVersion.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\chrome\content\search_dialog.xul
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\defaults\preferences\prefs.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\manifest.xml
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins.json
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\1.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\102.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\103.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\104.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\13.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\14.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\16.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\17.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\177.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\182.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\183.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\184.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\191.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\207.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\21.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\22.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\223.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\242.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\246.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\28.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\4.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\47.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\64.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\72.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\78.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\91.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\93.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\plugins\98.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\userCode\background.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\extensionData\userCode\extension.js
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-e188e6f4fb8a.com\install.rdf
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-e188e6f4fb8a.com\locale\en-
US\translations.dtd
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\button1.png
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\button2.png
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\button3.png
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\button4.png
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\button5.png
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\crossrider_statusbar.png
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\icon128.png
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\icon16.png
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\icon24.png
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\icon48.png
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\panelarrow-up.png
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\popup.html
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-e188e6f4fb8a.com\skin\skin.css
c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\extensions\a0046b9b
-fdb9-497f-a4b1-2a108ad6007a@5cdf80b7-0420-4bb7-b3c0-
e188e6f4fb8a.com\skin\update.css
.
.
((((((((((((((((((((((((( Files Created from 2014-02-28 to 2014-03-
30 )))))))))))))))))))))))))))))))
.
.
2014-03-30 07:47 . 2014-03-30 07:47 -------- d-----w-
c:\users\Default\AppData\Local\temp
2014-03-30 07:28 . 2014-03-30 07:28 -------- d-----w- c:\program files
(x86)\ESET
2014-03-30 07:11 . 2014-03-30 07:11 -------- d-----w- c:\programdata\FLEXnet
2014-03-29 17:32 . 2014-03-29 17:32 -------- d-----w-
c:\windows\SysWow64\wbem\en-US
2014-03-29 17:32 . 2014-03-29 17:32 -------- d-----w-
c:\windows\system32\wbem\en-US
2014-03-29 17:32 . 2014-03-29 17:32 -------- d-----w- c:\windows\SysWow64\Wat
2014-03-29 17:32 . 2014-03-29 17:32 -------- d-----w- c:\windows\system32\Wat
2014-03-29 17:08 . 2014-03-29 17:08 -------- d-----w-
C:\0cd6c2cf368afe24a310ccd867
2014-03-29 16:00 . 2014-03-29 16:00 86528 ----a-w-
c:\windows\SysWow64\iesysprep.dll
2014-03-29 15:25 . 2014-03-29 15:34 -------- d-----w- c:\windows\system32\MRT
2014-03-29 15:17 . 2012-07-26 03:08 229888 ----a-w-
c:\windows\system32\WUDFHost.exe
2014-03-29 15:17 . 2012-07-26 03:08 84992 ----a-w-
c:\windows\system32\WUDFSvc.dll
2014-03-29 15:17 . 2012-07-26 03:08 744448 ----a-w-
c:\windows\system32\WUDFx.dll
2014-03-29 15:17 . 2012-07-26 03:08 45056 ----a-w-
c:\windows\system32\WUDFCoinstaller.dll
2014-03-29 15:17 . 2012-07-26 03:08 194048 ----a-w-
c:\windows\system32\WUDFPlatform.dll
2014-03-29 15:17 . 2012-07-26 02:26 87040 ----a-w-
c:\windows\system32\drivers\WUDFPf.sys
2014-03-29 15:17 . 2012-07-26 02:26 198656 ----a-w-
c:\windows\system32\drivers\WUDFRd.sys
2014-03-29 14:54 . 2012-03-01 06:46 23408 ----a-w-
c:\windows\system32\drivers\fs_rec.sys
2014-03-29 14:54 . 2012-03-01 06:38 220672 ----a-w-
c:\windows\system32\wintrust.dll
2014-03-29 14:54 . 2012-03-01 06:28 5120 ----a-w- c:\windows\system32\wmi.dll
2014-03-29 14:54 . 2012-03-01 05:37 172544 ----a-w-
c:\windows\SysWow64\wintrust.dll
2014-03-29 14:54 . 2012-03-01 05:29 5120 ----a-w- c:\windows\SysWow64\wmi.dll
2014-03-29 14:53 . 2014-03-29 14:53 -------- d-----w- c:\program
files\Microsoft Silverlight
2014-03-29 14:53 . 2014-03-29 14:53 -------- d-----w- c:\program files
(x86)\Microsoft Silverlight
2014-03-29 14:37 . 2014-03-29 14:37 -------- d-----w-
c:\programdata\IePluginService
2014-03-29 14:37 . 2014-03-30 07:46 -------- d-----w- c:\program files
(x86)\SupTab
2014-03-29 14:37 . 2014-03-29 14:37 -------- d-----w- c:\programdata\WPM
2014-03-29 14:36 . 2014-03-29 14:36 -------- d-----w- c:\program files
(x86)\Coupon Server
2014-03-29 14:35 . 2014-03-29 15:35 -------- d-----w- c:\program files
(x86)\Freeven pro
2014-03-29 14:35 . 2014-03-29 14:35 -------- d-----w- c:\program files
(x86)\Bench
2014-03-29 14:24 . 2014-03-29 14:24 -------- d-----w- c:\programdata\Xilisoft
2014-03-29 14:24 . 2014-03-29 14:24 -------- d-----w- c:\program files
(x86)\Xilisoft
2014-03-29 14:08 . 2014-03-29 14:08 -------- d-----w- c:\program files\WinRAR
2014-03-29 14:06 . 2014-03-29 14:06 -------- d-----w- c:\program files
(x86)\Mozilla Maintenance Service
2014-03-29 13:54 . 2013-04-12 14:45 1656680 ----a-w-
c:\windows\system32\drivers\ntfs.sys
2014-03-29 13:53 . 2013-10-05 20:25 1474048 ----a-w-
c:\windows\system32\crypt32.dll
2014-03-29 13:53 . 2013-10-05 19:57 1168384 ----a-w-
c:\windows\SysWow64\crypt32.dll
2014-03-29 13:53 . 2013-07-09 05:46 184320 ----a-w-
c:\windows\system32\cryptsvc.dll
2014-03-29 13:53 . 2013-07-09 05:46 139776 ----a-w-
c:\windows\system32\cryptnet.dll
2014-03-29 13:53 . 2013-07-09 04:46 140288 ----a-w-
c:\windows\SysWow64\cryptsvc.dll
2014-03-29 13:53 . 2013-07-09 04:46 103936 ----a-w-
c:\windows\SysWow64\cryptnet.dll
2014-03-29 13:50 . 2013-08-05 02:25 155584 ----a-w-
c:\windows\system32\drivers\ataport.sys
2014-03-29 13:49 . 2013-11-27 01:41 99840 ----a-w-
c:\windows\system32\drivers\usbccgp.sys
2014-03-29 13:48 . 2013-07-04 12:57 259584 ----a-w-
c:\windows\system32\WebClnt.dll
2014-03-29 13:48 . 2013-07-04 12:50 102400 ----a-w-
c:\windows\system32\davclnt.dll
2014-03-29 13:48 . 2013-07-04 11:57 205824 ----a-w-
c:\windows\SysWow64\WebClnt.dll
2014-03-29 13:48 . 2013-07-04 11:51 81920 ----a-w-
c:\windows\SysWow64\davclnt.dll
2014-03-29 13:48 . 2013-07-04 10:11 140800 ----a-w-
c:\windows\system32\drivers\mrxdav.sys
2014-03-29 13:48 . 2012-11-02 05:59 478208 ----a-w-
c:\windows\system32\dpnet.dll
2014-03-29 13:48 . 2012-11-02 05:11 376832 ----a-w-
c:\windows\SysWow64\dpnet.dll
2014-03-29 13:48 . 2012-08-21 21:01 245760 ----a-w-
c:\windows\system32\OxpsConverter.exe
2014-03-29 13:45 . 2011-08-17 05:26 613888 ----a-w-
c:\windows\system32\psisdecd.dll
2014-03-29 13:45 . 2011-08-17 05:25 108032 ----a-w-
c:\windows\system32\psisrndr.ax
2014-03-29 13:45 . 2011-08-17 04:24 465408 ----a-w-
c:\windows\SysWow64\psisdecd.dll
2014-03-29 13:45 . 2011-08-17 04:19 75776 ----a-w-
c:\windows\SysWow64\psisrndr.ax
2014-03-29 13:45 . 2012-04-28 03:55 210944 ----a-w-
c:\windows\system32\drivers\rdpwd.sys
2014-03-29 13:42 . 2012-08-11 00:56 715776 ----a-w-
c:\windows\system32\kerberos.dll
2014-03-29 13:42 . 2012-08-10 23:56 542208 ----a-w-
c:\windows\SysWow64\kerberos.dll
2014-03-29 13:42 . 2012-04-07 12:31 3216384 ----a-w-
c:\windows\system32\msi.dll
2014-03-29 13:42 . 2012-04-07 11:26 2342400 ----a-w-
c:\windows\SysWow64\msi.dll
2014-03-29 13:42 . 2012-11-30 05:45 362496 ----a-w-
c:\windows\system32\wow64win.dll
2014-03-29 13:42 . 2012-11-30 05:43 16384 ----a-w-
c:\windows\system32\ntvdm64.dll
2014-03-29 13:42 . 2012-11-30 05:45 13312 ----a-w-
c:\windows\system32\wow64cpu.dll
2014-03-29 13:39 . 2013-04-26 05:51 751104 ----a-w-
c:\windows\system32\win32spl.dll
2014-03-29 13:39 . 2013-04-26 04:55 492544 ----a-w-
c:\windows\SysWow64\win32spl.dll
2014-03-29 13:39 . 2013-10-03 02:23 404480 ----a-w-
c:\windows\system32\gdi32.dll
2014-03-29 13:39 . 2013-10-03 02:00 311808 ----a-w-
c:\windows\SysWow64\gdi32.dll
2014-03-29 13:39 . 2012-11-23 03:13 68608 ----a-w-
c:\windows\system32\taskhost.exe
2014-03-29 13:39 . 2014-02-04 02:32 624128 ----a-w-
c:\windows\system32\qedit.dll
2014-03-29 13:39 . 2014-02-04 02:04 509440 ----a-w-
c:\windows\SysWow64\qedit.dll
2014-03-29 13:39 . 2013-05-10 05:49 30720 ----a-w-
c:\windows\system32\cryptdlg.dll
2014-03-29 13:39 . 2013-05-10 03:20 24576 ----a-w-
c:\windows\SysWow64\cryptdlg.dll
2014-03-29 13:37 . 2011-02-18 10:51 31232 ----a-w-
c:\windows\system32\prevhost.exe
2014-03-29 13:37 . 2011-02-18 05:39 31232 ----a-w-
c:\windows\SysWow64\prevhost.exe
2014-03-29 13:37 . 2014-03-29 13:37 -------- d-----w- c:\program files\Google
2014-03-29 13:37 . 2013-01-24 06:01 223752 ----a-w-
c:\windows\system32\drivers\fvevol.sys
2014-03-29 13:37 . 2012-05-05 08:36 503808 ----a-w-
c:\windows\system32\srcore.dll
2014-03-29 13:37 . 2012-05-05 07:46 43008 ----a-w-
c:\windows\SysWow64\srclient.dll
2014-03-29 13:37 . 2011-02-12 11:34 267776 ----a-w-
c:\windows\system32\FXSCOVER.exe
2014-03-29 13:37 . 2011-05-03 05:29 976896 ----a-w-
c:\windows\system32\inetcomm.dll
2014-03-29 13:37 . 2011-05-03 04:30 741376 ----a-w-
c:\windows\SysWow64\inetcomm.dll
2014-03-29 13:37 . 2011-12-16 08:46 634880 ----a-w-
c:\windows\system32\msvcrt.dll
2014-03-29 13:37 . 2011-12-16 07:52 690688 ----a-w-
c:\windows\SysWow64\msvcrt.dll
2014-03-29 13:36 . 2013-05-13 03:43 1192448 ----a-w-
c:\windows\system32\certutil.exe
2014-03-29 13:36 . 2013-05-13 03:08 903168 ----a-w-
c:\windows\SysWow64\certutil.exe
2014-03-29 13:36 . 2013-05-13 05:50 52224 ----a-w-
c:\windows\system32\certenc.dll
2014-03-29 13:36 . 2013-05-13 03:08 43008 ----a-w-
c:\windows\SysWow64\certenc.dll
2014-03-29 13:36 . 2014-03-29 13:36 -------- d-----w- c:\program files
(x86)\Common Files\Symantec Shared
2014-03-29 13:34 . 2011-10-15 06:31 723456 ----a-w-
c:\windows\system32\EncDec.dll
2014-03-29 13:33 . 2011-11-19 14:58 77312 ----a-w-
c:\windows\system32\packager.dll
2014-03-29 13:33 . 2011-11-19 14:01 67072 ----a-w-
c:\windows\SysWow64\packager.dll
2014-03-29 13:06 . 2014-03-30 07:19 -------- d-----w-
c:\windows\system32\drivers\NSTx64
2014-03-29 13:06 . 2014-03-29 13:06 -------- d-----w- c:\program files
(x86)\Norton Identity Safe
2014-03-29 13:06 . 2014-03-30 07:25 177312 ----a-w-
c:\windows\system32\drivers\SYMEVENT64x86.SYS
2014-03-29 13:06 . 2014-03-29 13:06 -------- d-----w- c:\program
files\Symantec
2014-03-29 13:06 . 2014-03-29 13:06 -------- d-----w- c:\program files\Common
Files\Symantec Shared
2014-03-29 13:05 . 2014-03-30 07:20 -------- d-----w-
c:\windows\system32\drivers\NAVx64
2014-03-29 13:05 . 2014-03-29 13:05 -------- d-----w- c:\program files
(x86)\Norton AntiVirus
2014-03-29 11:21 . 2014-03-17 16:16 10521840 ----a-w-
c:\programdata\Microsoft\Windows Defender\Definition Updates\{C17CB40F-3B59-
45FB-AE72-BB107A09E0C0}\mpengine.dll
2014-03-29 07:36 . 2014-03-30 07:31 -------- d-----w- c:\programdata\Microsoft
Help
2014-03-29 07:33 . 2014-03-29 07:33 -------- d-----w-
c:\programdata\PCSettings
2014-03-29 07:32 . 2014-03-29 07:32 -------- d-----w- c:\program files\Common
Files\Apple
2014-03-29 07:31 . 2014-03-29 07:31 -------- d-----w- c:\program files
(x86)\Bonjour
2014-03-29 07:31 . 2014-03-29 07:31 -------- d-----w- c:\program files\Bonjour
2014-03-29 07:31 . 2014-03-29 13:03 -------- d-----w- c:\programdata\Apple
2014-03-29 07:31 . 2014-03-29 07:32 -------- d-----w- c:\program files
(x86)\Common Files\Apple
2014-03-29 07:23 . 2006-03-17 20:49 368640 ----a-w-
c:\windows\SysWow64\TwnLib4.dll
2014-03-29 07:23 . 2006-03-17 17:45 802816 ----a-w-
c:\windows\SysWow64\imagXRA7.dll
2014-03-29 07:23 . 2006-03-17 17:45 497296 ----a-w-
c:\windows\SysWow64\imagXpr7.dll
2014-03-29 07:23 . 2006-03-17 17:45 258048 ----a-w-
c:\windows\SysWow64\imagXR7.dll
2014-03-29 07:23 . 2006-03-17 17:45 1757184 ----a-w-
c:\windows\SysWow64\imagX7.dll
2014-03-29 07:23 . 2014-03-29 07:24 -------- d-----w- c:\program files
(x86)\Nero
2014-03-29 07:23 . 2014-03-29 07:23 -------- d-----w- c:\program files
(x86)\Common Files\Nero
2014-03-29 07:23 . 2014-03-29 07:23 -------- d-----w- c:\programdata\Nero
2014-03-29 07:21 . 2014-03-29 07:22 -------- d-----w- C:\HP Universal Print
Driver
2014-03-29 07:21 . 2014-03-29 07:21 -------- d-----w- C:\BASE DE DATOS
2014-03-29 07:20 . 2013-07-05 15:43 28672 ----a-w-
c:\windows\SysWow64\drivers\InstallSadpNpfApp.exe
2014-03-29 07:20 . 2012-06-16 20:55 35344 ----a-w-
c:\windows\SysWow64\drivers\sadp_npf64.sys
2014-03-29 07:20 . 2012-06-16 20:55 35088 ----a-w-
c:\windows\SysWow64\drivers\sadp_npf.sys
2014-03-29 07:19 . 2014-03-29 07:20 -------- d-----w- c:\program files\iVMS-
4200 Station
2014-03-29 07:18 . 2014-03-29 07:18 -------- d--h--w- c:\windows\msdownld.tmp
2014-03-29 07:07 . 2012-02-17 06:38 1031680 ----a-w-
c:\windows\system32\rdpcore.dll
2014-03-29 07:07 . 2012-02-17 05:34 826880 ----a-w-
c:\windows\SysWow64\rdpcore.dll
2014-03-29 07:07 . 2012-02-17 04:57 23552 ----a-w-
c:\windows\system32\drivers\tdtcp.sys
2014-03-29 07:00 . 2012-06-02 22:19 2428952 ----a-w-
c:\windows\system32\wuaueng.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M
Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-03-29 07:07 . 2010-06-24 17:33 22240 ----a-w-
c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-03-28 22:46 . 2014-03-28 22:46 2560 ----a-w-
c:\windows\SysWow64\drivers\es-ES\qwavedrv.sys.mui
2014-03-28 22:46 . 2014-03-28 22:46 31232 ----a-w-
c:\windows\SysWow64\drivers\es-ES\bfe.dll.mui
2014-03-28 22:46 . 2014-03-28 22:46 16384 ----a-w-
c:\windows\SysWow64\drivers\es-ES\pacer.sys.mui
2014-03-28 22:46 . 2014-03-28 22:46 2560 ----a-w-
c:\windows\SysWow64\drivers\es-ES\scfilter.sys.mui
2014-03-28 22:46 . 2014-03-28 22:46 6144 ----a-w-
c:\windows\SysWow64\drivers\es-ES\ndiscap.sys.mui
2014-03-28 22:46 . 2014-03-28 22:46 48640 ----a-w-
c:\windows\SysWow64\drivers\es-ES\tcpip.sys.mui
2013-10-14 02:44 . 2013-10-14 02:44 2174976 ----a-w- c:\program files
(x86)\Common Files\atimpenc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading
Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-
1111-1111-110511421148}]
2014-03-29 14:36 495104 ----a-w- c:\program files (x86)\Freeven
pro\Freeven pro-bho.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{F791D8AE-47E8-
40A5-A913-EB2D2AF29602}]
2014-03-29 08:14 288816 ----a-w- c:\program files (x86)\Coupon
Server\FrameworkBHO.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\users\Candiani
Movil\AppData\Local\Akamai\netsession_win.exe" [2013-06-05 4489472]
"swg"="c:\program files
(x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2014-03-29 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-
Static\CLIStart.exe" [2011-02-27 336384]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat
9.0\Acrobat\Acrobat_sl.exe" [2010-09-23 38840]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat
9.0\Acrobat\Acrotray.exe" [2010-09-23 640440]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2011-02-15
2757312]
"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2010-11-
27 648032]
"VAIO Boot Manager"="c:\program files (x86)\Sony\VAIO Boot
Manager\StartUpProcessDelayTool.exe" [2011-03-11 2096320]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application
Support\APSDaemon.exe" [2013-04-22 59720]
"BService"="c:\program files (x86)\Bench\BService\bservice.exe" [2014-03-27 49664]
"Wd"="c:\program files (x86)\Bench\Wd\wd.exe" [2014-03-27 60416]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Coupon Server-repairJob"="wscript.exe" [2013-10-12 141824]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-7-29
1132320]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows
nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\progra~2\SupTab\SearchProtect32.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows
nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
R1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-
85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20140319.001\BHDrvx64.sys;c:\progr
amdata\Norton\{0C55C096-0F1D-4F28-AAA2-
85EF591126E7}\NAV_20.1.0.24\Definitions\BASHDefs\20140319.001\BHDrvx64.sys [x]
R1 ccSet_NAV;Norton AntiVirus Settings
Manager;c:\windows\system32\drivers\NAVx64\1404000.028\ccSetx64.sys;c:\windows\SYSN
ATIVE\drivers\NAVx64\1404000.028\ccSetx64.sys [x]
R1 ccSet_NST;Norton Identity Safe Settings
Manager;c:\windows\system32\drivers\NSTx64\7DD01000.020\ccSetx64.sys;c:\windows\SYS
NATIVE\drivers\NSTx64\7DD01000.020\ccSetx64.sys [x]
R1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-
85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20140328.001\IDSvia64.sys;c:\progra
mdata\Norton\{0C55C096-0F1D-4F28-AAA2-
85EF591126E7}\NAV_20.1.0.24\Definitions\IPSDefs\20140328.001\IDSvia64.sys [x]
R1 SymIRON;Symantec Iron
Driver;c:\windows\system32\drivers\NAVx64\1404000.028\Ironx64.SYS;c:\windows\SYSNAT
IVE\drivers\NAVx64\1404000.028\Ironx64.SYS [x]
R2 AMD External Events Utility;AMD External Events
Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN
v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\wind
ows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 FPLService;TrueSuiteService;c:\program
files\TrueSuite\TrueSuite.Service.exe;c:\program
files\TrueSuite\TrueSuite.Service.exe [x]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files
(x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files
(x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
R2 IePluginService;IePlugin
Service;c:\programdata\IePluginService\PluginService.exe;c:\programdata\IePluginSer
vice\PluginService.exe [x]
R2 NAV;Norton AntiVirus;c:\program files (x86)\Norton
AntiVirus\Engine\20.4.0.40\ccSvcHst.exe;c:\program files (x86)\Norton
AntiVirus\Engine\20.4.0.40\ccSvcHst.exe [x]
R2 NCO;Norton Identity Safe;c:\program files (x86)\Norton Identity
Safe\Engine\2013.1.0.32\ccSvcHst.exe;c:\program files (x86)\Norton Identity
Safe\Engine\2013.1.0.32\ccSvcHst.exe [x]
R2 Oasis2Service;Oasis2Service;c:\program files (x86)\DDNi\Oasis2Service
1.0\Oasis2Service.exe;c:\program files (x86)\DDNi\Oasis2Service
1.0\Oasis2Service.exe [x]
R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files
(x86)\Sony\PMB\PMBDeviceInfoProvider.exe;c:\program files
(x86)\Sony\PMB\PMBDeviceInfoProvider.exe [x]
R2 SADP_NPF;Sadp Driver
(SADP_NPF);c:\windows\SysWOW64\drivers\sadp_npf64.sys;c:\windows\SysWOW64\drivers\s
adp_npf64.sys [x]
R2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO
Care\VCPerfService.exe;c:\program files\Sony\VAIO Care\VCPerfService.exe [x]
R2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects
2\uCamMonitor.exe;c:\program files (x86)\ArcSoft\Magic-i Visual Effects
2\uCamMonitor.exe [x]
R2 UNS;Intel(R) Management and Security Application User Notification
Service;c:\program files (x86)\Intel\Intel(R) Management Engine
Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine
Components\UNS\UNS.exe [x]
R2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power
Management\SPMService.exe;c:\program files\Sony\VAIO Power
Management\SPMService.exe [x]
R2 VSNService;VSNService;c:\program files\Sony\VAIO Smart
Network\VSNService.exe;c:\program files\Sony\VAIO Smart Network\VSNService.exe [x]
R2 Wpm;Wpm
Service;c:\programdata\WPM\wprotectmanager.exe;c:\programdata\WPM\wprotectmanager.e
xe [x]
R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual
Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys;c:\windows\SYSNATIVE\DRIVER
S\ArcSoftKsUFilter.sys [x]
R3 ATSwpWDF;AuthenTec TruePrint WBF
Driver;c:\windows\system32\DRIVERS\ATSwpWDF.sys;c:\windows\SYSNATIVE\DRIVERS\ATSwpW
DF.sys [x]
R3 btwampfl;Bluetooth AMP USB
Filter;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwamp
fl.sys [x]
R3 btwl2cap;Bluetooth L2CAP
Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2
cap.sys [x]
R3 e1yexpress;Intel(R) Gigabit Network Connections
Driver;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x
64.sys [x]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common
Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys;c:\program files (x86)\Common
Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
R3 IntcDAud;Sonido Intel(R) para
pantallas;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\Int
cDAud.sys [x]
R3
intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRI
VERS\igdpmd64.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program
files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe
[x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport
Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\driver
s\rdpvideominiport.sys [x]
R3 RSPCIESTOR;Realtek PCIE CardReader
Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPSt
or.sys [x]
R3 SOHCImp;VAIO Content Importer;c:\program files (x86)\Common Files\Sony
Shared\SOHLib\SOHCImp.exe;c:\program files (x86)\Common Files\Sony
Shared\SOHLib\SOHCImp.exe [x]
R3 SOHDs;VAIO Device Searcher;c:\program files (x86)\Common Files\Sony
Shared\SOHLib\SOHDs.exe;c:\program files (x86)\Common Files\Sony
Shared\SOHLib\SOHDs.exe [x]
R3 SpfService;VAIO Entertainment Common Service;c:\program files\Common Files\Sony
Shared\VAIO Entertainment Platform\SPF\SpfService64.exe;c:\program files\Common
Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [x]
R3 SymNetS;Symantec Network Security WFP
Driver;c:\windows\system32\drivers\NAVx64\1401000.018\SYMNETS.SYS;c:\windows\SYSNAT
IVE\drivers\NAVx64\1401000.018\SYMNETS.SYS [x]
R3
TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\dri
vers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB
Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD
.sys [x]
R3 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony
Shared\VAIO Content Folder Watcher\VCFw.exe;c:\program files (x86)\Common
Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [x]
R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program
files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe;c:\program
files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [x]
R3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;c:\program
files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe;c:\program
files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [x]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common
Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe;c:\program files\Common Files\Sony
Shared\VcmXml\VcmXmlIfHelper64.exe [x]
R3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe;c:\program
files\Sony\VAIO Care\VCService.exe [x]
R3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update 5\VUAgent.exe;c:\program
files\Sony\VAIO Update 5\VUAgent.exe [x]
R3 WatAdminSvc;Servicio de tecnologas de activacin de
Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSv
c.exe [x]
R3 wdkmd;Intel WiDi
KMD;c:\windows\system32\DRIVERS\WDKMD.sys;c:\windows\SYSNATIVE\DRIVERS\WDKMD.sys
[x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows
Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 SymDS;Symantec Data
Store;c:\windows\system32\drivers\NAVx64\1404000.028\SYMDS64.SYS;c:\windows\SYSNATI
VE\drivers\NAVx64\1404000.028\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File
Attributes;c:\windows\system32\drivers\NAVx64\1404000.028\SYMEFA64.SYS;c:\windows\S
YSNATIVE\drivers\NAVx64\1404000.028\SYMEFA64.SYS [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub
Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3h
ub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller
Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3x
hc.sys [x]
S3 RTL8167;Realtek 8167 NT
Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64wi
n7.sys [x]
S3 SFEP;Sony Firmware Extension
Parser;c:\windows\system32\DRIVERS\SFEP.sys;c:\windows\SYSNATIVE\DRIVERS\SFEP.sys
[x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed
components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-03-29 14:54 1150280 ----a-w- c:\program files
(x86)\Google\Chrome\Application\33.0.1750.154\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-03-30 c:\windows\Tasks\03f7dc28-52c9-452a-802a-c94ea081aa20-3.job
- c:\program files (x86)\Freeven pro\03f7dc28-52c9-452a-802a-c94ea081aa20-3.exe
[2014-03-29 14:35]
.
2014-03-30 c:\windows\Tasks\bench-S-1-5-21-151900760-3747262441-2935349-1000.job
- c:\program files (x86)\Bench\Updater\updater.exe [2014-03-27 19:59]
.
2014-03-30 c:\windows\Tasks\bench-sys.job
- c:\program files (x86)\Bench\Updater\updater.exe [2014-03-27 19:59]
.
2014-03-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-03-29 13:35]
.
2014-03-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-03-29 13:35]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11111111-1111-1111-1111-
110511421148}]
2014-03-29 14:36 660992 ----a-w- c:\program files (x86)\Freeven
pro\Freeven pro-bho64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-02-23 11490408]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-02-23 2179688]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-04-06 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-04-06 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-04-06 418328]
"ClientAppLogon"="c:\program files\TrueSuite\TrueSuite.ClientAppLogonExe.exe"
[2011-02-14 421192]
"ClientAppLogon32"="c:\program files\TrueSuite\x86\TrueSuite.ClientAppLogonExe.exe"
[2011-02-14 308040]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\progra~2\SupTab\SearchProtect64.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://istart.webssearches.com/web/?
type=ds&ts=1396103745&from=tugs&uid=WDCXWD6400BPVT-55HXZT2_WD-
WXA1A513140431404&q={searchTerms}
mDefault_Page_URL = hxxp://istart.webssearches.com/?
type=hp&ts=1396103745&from=tugs&uid=WDCXWD6400BPVT-55HXZT2_WD-WXA1A513140431404
mStart Page = hxxp://istart.webssearches.com/?
type=hp&ts=1396103745&from=tugs&uid=WDCXWD6400BPVT-55HXZT2_WD-WXA1A513140431404
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://istart.webssearches.com/web/?
type=ds&ts=1396103745&from=tugs&uid=WDCXWD6400BPVT-55HXZT2_WD-
WXA1A513140431404&q={searchTerms}
uInternet Settings,ProxyOverride = <local>;*.local
IE: &Enviar a OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xportar a Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.100.1
FF - ProfilePath - c:\users\Candiani
Movil\AppData\Roaming\Mozilla\Firefox\Profiles\o8w7hb5r.default\
FF - prefs.js: browser.search.selectedEngine - webssearches
FF - prefs.js: browser.startup.homepage - hxxp://istart.webssearches.com/?
type=hp&ts=1396103745&from=tugs&uid=WDCXWD6400BPVT-55HXZT2_WD-WXA1A513140431404
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} - c:\program files
(x86)\SupTab\SupTab.dll
Wow6432Node-HKCU-Run-lollipop - c:\users\candiani
movil\appdata\local\lollipop\lollipop.exe
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM-Run-Apoint - c:\program files (x86)\Apoint\Apoint.exe
AddRemove-lollipop - c:\users\candiani movil\appdata\local\lollipop\lollipop.bat
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NAV]
"ImagePath"="\"c:\program files (x86)\Norton
AntiVirus\Engine\20.4.0.40\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files
(x86)\Norton AntiVirus\Engine\20.4.0.40\diMaster.dll\" /prefetch:1"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NCO]
"ImagePath"="\"c:\program files (x86)\Norton Identity
Safe\Engine\2013.1.0.32\ccSvcHst.exe\" /s \"NCO\" /m \"c:\program files
(x86)\Norton Identity Safe\Engine\2013.1.0.32\diMaster.dll\" /prefetch:1"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO
Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/proc
interval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor
Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network
Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor
Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle
Time:1\" \"/expandcounter=\Processor(*)\% C1
Time:1\" \"/expandcounter=\Processor(*)\% C2
Time:1\" \"/expandcounter=\Processor(*)\% C3
Time:1\" \"/expandcounter=\Processor(*)\% Processor
Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-
872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.ex
e,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-
872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-
872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10m_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-
872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-
444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-
444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-
444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-
444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-
444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-
444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-
444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-
444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-
444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-
444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-
444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-
444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10m.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-
444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-
444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-
444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-
B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-
B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-
B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2014-03-30 01:49:52
ComboFix-quarantined-files.txt 2014-03-30 07:49
.
Pre-Run: 482,170,257,408 bytes libres
Post-Run: 483,248,754,688 bytes libres
.
- - End Of File - - 9ACD690DB70B573CC5CF4B069B1BFB20

Vous aimerez peut-être aussi