HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AppSetup
HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup
HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon
HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logon
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunonceEx
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
+ Adobe Reader Speed Launcher Adobe Acrobat SpeedLauncher (Verified) Adobe Systems, Incorporated c:\archivos de programa\adobe\reader 8.0\reader\reader_sl.exe
+ LanzarL2007 File not found: C:\DOCUME~1\benja\CONFIG~1\Temp\{C62CF2A3-EDE5-4EEA-A1E5-C4E2EB6B7777}\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe
+ NeroFilterCheck NeroCheck (Not verified) Ahead Software Gmbh c:\windows\system32\nerocheck.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
C:\Documents and Settings\All Users\Menú Inicio\Programas\Inicio
+ Google Updater.lnk Google Updater (Verified) Google Inc c:\archivos de programa\google\google updater\googleupdater.exe
C:\Documents and Settings\benja\Menú Inicio\Programas\Inicio
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
+ BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} Nero Home (Not verified) Nero AG c:\archivos de programa\archivos comunes\ahead\lib\nmbgmonitor.exe
+ SpyBrowser
www.spyware-browser.com (Not verified)
www.spyware-browser.com c:\archivos de programa\spybro\spybro.exe
+ swg GoogleToolbarNotifier (Verified) Google Inc c:\archivos de programa\google\googletoolbarnotifier\googletoolbarnotifier.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Runonce
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\RunonceEx
HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\SOFTWARE\Classes\Protocols\Filter
+ application/octet-stream Microsoft .NET Runtime Execution Engine (Not verified) Microsoft Corporation c:\windows\system32\mscoree.dll
+ application/x-complus Microsoft .NET Runtime Execution Engine (Not verified) Microsoft Corporation c:\windows\system32\mscoree.dll
+ application/x-msdownload Microsoft .NET Runtime Execution Engine (Not verified) Microsoft Corporation c:\windows\system32\mscoree.dll
HKLM\SOFTWARE\Classes\Protocols\Handler
+ cetihpz HPCETIUI Protocol Handler Module (Not verified) Hewlett-Packard Company c:\archivos de programa\hp\hpcoretech\comp\hpuiprot.dll
HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components
+ 0 File not found: About:Home
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components
+ n/a Microsoft .NET IE SECURITY REGISTRATION (Not verified) Microsoft Corporation c:\windows\system32\mscories.dll
HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
+ NeroDigitalIconHandler Nero Digital Shell Extension (Not verified) Nero AG c:\archivos de programa\archivos comunes\ahead\lib\nerodigitalext.dll
+ NeroDigitalPropSheetHandler Nero Digital Shell Extension (Not verified) Nero AG c:\archivos de programa\archivos comunes\ahead\lib\nerodigitalext.dll
+ NOD32 Scanner Advanced Heuristic Shell Extension c:\archivos de programa\nod32se\nodse.dll
+ Shell Icon Handler for Application References Application Deployment Support Library (Not verified) Microsoft Corporation c:\windows\system32\dfshim.dll
+ ShellLink for Application References Application Deployment Support Library (Not verified) Microsoft Corporation c:\windows\system32\dfshim.dll
+ SolidConverter extension (Not verified) VoyagerSoft, LLC c:\archivos de programa\soliddocuments\solidconverterpdf\exploreextpdf.dll
+ UnlockerShellExtension c:\archivos de programa\unlocker\unlockercom.dll
HKCU\Software\Classes\Folder\Shellex\ColumnHandlers
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
+ NeroDigitalColumnHandler Class Nero Digital Shell Extension (Not verified) Nero AG c:\archivos de programa\archivos comunes\ahead\lib\nerodigitalext.dll
+ PDF Shell Extension PDF Shell Extension (Not verified) Adobe Systems, Inc. c:\archivos de programa\archivos comunes\adobe\acrobat\activex\pdfshell.dll
HKCU\Software\Microsoft\Ctf\LangBarAddin
HKLM\Software\Microsoft\Ctf\LangBarAddin
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
+ Aplicación auxiliar de vínculos de Adobe PDF Reader Adobe PDF Helper for Internet Explorer (Verified) Adobe Systems, Incorporated c:\archivos de programa\archivos comunes\adobe\acrobat\activex\acroiehelper.dll
+ CConverterExt Object (Not verified) VoyagerSoft, LLC c:\archivos de programa\soliddocuments\solidconverterpdf\exploreextpdf.dll
+ Google Toolbar Notifier BHO GoogleToolbarNotifier (Verified) Google Inc c:\archivos de programa\google\googletoolbarnotifier\2.1.615.5858\swg.dll
+ Multi_Media toolbar Conduit Toolbar (Verified) Conduit Ltd. c:\archivos de programa\multi_media\tbmul1.dll
+ SSVHelper Class Java(TM) 2 Platform Standard Edition binary (Not verified) Sun Microsystems, Inc. c:\archivos de programa\java\jre1.5.0_09\bin\ssv.dll
HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks
+ tbmul1.dll Conduit Toolbar (Verified) Conduit Ltd. c:\archivos de programa\multi_media\tbmul1.dll
HKLM\Software\Microsoft\Internet Explorer\Toolbar
+ Multi Media Toolbar Conduit Toolbar (Verified) Conduit Ltd. c:\archivos de programa\multi_media\tbmul1.dll
HKCU\Software\Microsoft\Internet Explorer\Explorer Bars
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars
HKCU\Software\Microsoft\Internet Explorer\Extensions
+ Show Trashcan Trash (Not verified) Agnitum Ltd. c:\archivos de programa\agnitum\outpost firewall\trash.exe
HKLM\Software\Microsoft\Internet Explorer\Extensions
Task Scheduler
HKLM\System\CurrentControlSet\Services
+ Acer Media Server Acer UPnP Media Server Service (Not verified) Acer Inc. c:\archivos de programa\acer\acer econsole\mediaserverservice.exe
+ aswUpdSv Brinda actualizaciones automáticas para el antivirus avast!. File not found: C:\Archivos de programa\Alwil Software\Avast4\aswUpdSv.exe
+ BlueSoleil Hid Service c:\archivos de programa\ivt corporation\bluesoleil\btntservice.exe
+ C-DillaCdaC11BA C-Dilla RTS Service (Not verified) C-Dilla Ltd c:\windows\system32\drivers\cdac11ba.exe
+ gusvc gusvc (Verified) Google Inc c:\archivos de programa\google\common\google updater\googleupdaterservice.exe
+ McShield Scans files for viruses and other threats when they are accessed by this computer. File not found: C:\ARCHIV~1\McAfee\VIRUSS~1\mcshield.exe
+ OutpostFirewall File not found: C:\ARCHIV~1\AGNITUM\OUTPOS~1\outpost.exe
HKLM\System\CurrentControlSet\Services
+ ADBLOCK.DLL Outpost Firewall kernel mode plugin (Not verified) Agnitum c:\archivos de programa\agnitum\outpost firewall\kernel\adblock.dll
+ Afc Arcsoft(R) ASPI Shell (Not verified) Arcsoft, Inc. c:\windows\system32\drivers\afc.sys
+ AVHybrid The Europa capture driver c:\windows\system32\drivers\avhybrid.sys
+ BlueletAudio Bluelet Audio Driver (Not verified) IVT Corporation c:\windows\system32\drivers\blueletaudio.sys
+ BT Bluetooth PAN Network Adapter Driver (Not verified) IVT Corporation c:\windows\system32\drivers\btnetdrv.sys
+ Btcsrusb Bluetooth USB Device Driver (Not verified) IVT Corporation c:\windows\system32\drivers\btcusb.sys
+ BTHidEnum c:\windows\system32\drivers\vbtenum.sys
+ BTHidMgr Bluetooth HID Manager driver (Not verified) IVT Corporation c:\windows\system32\drivers\bthidmgr.sys
+ BTNetFilter c:\windows\system32\drivers\btnetfilter.sys
+ CdaC15BA c:\windows\system32\drivers\cdac15ba.sys
+ CONTENT.DLL Outpost Firewall kernel mode plugin (Not verified) Agnitum c:\archivos de programa\agnitum\outpost firewall\kernel\content.dll
+ DNSCACHE.DLL Outpost Firewall kernel mode plugin (Not verified) Agnitum c:\archivos de programa\agnitum\outpost firewall\kernel\dnscache.dll
+ eeCtrl File not found: C:\Archivos de programa\Archivos comunes\Symantec Shared\EENGINE\eeCtrl.sys
+ FTPFILT.DLL Outpost Firewall kernel mode plugin (Not verified) Agnitum c:\archivos de programa\agnitum\outpost firewall\kernel\ftpfilt.dll
+ HCWBT8xx Hauppauge WDM Driver for Bt848, Bt878 (Not verified) Hauppauge Computer Works c:\windows\system32\drivers\hcwbt8xx.sys
+ HTMLFILT.DLL Outpost Firewall kernel mode plugin (Not verified) Agnitum c:\archivos de programa\agnitum\outpost firewall\kernel\htmlfilt.dll
+ HTTPFILT.DLL Outpost Firewall kernel mode plugin (Not verified) Agnitum c:\archivos de programa\agnitum\outpost firewall\kernel\httpfilt.dll
+ IMAPFILT.DLL Outpost Firewall kernel mode plugin (Not verified) Agnitum c:\archivos de programa\agnitum\outpost firewall\kernel\imapfilt.dll
+ InCDPass File not found: system32\drivers\InCDPass.sys
+ InCDRm File not found: system32\drivers\InCDRm.sys
+ klif Klif File not found: C:\WINDOWS\system32\drivers\klif.sys
+ MAILFILT.DLL Outpost Firewall kernel mode plugin (Not verified) Agnitum c:\archivos de programa\agnitum\outpost firewall\kernel\mailfilt.dll
+ NNTPFILT.DLL Outpost Firewall kernel mode plugin (Not verified) Agnitum c:\archivos de programa\agnitum\outpost firewall\kernel\nntpfilt.dll
+ NTIDrvr NTI CD-ROM Filter Driver (Not verified) NewTech Infosystems, Inc. c:\windows\system32\drivers\ntidrvr.sys
+ pci32 c:\windows\system32\drivers\pci32.sys
+ pcouffin low level access layer for CD/DVD/BD devices (Not verified) VSO Software c:\windows\system32\drivers\pcouffin.sys
+ POP3FILT.DLL Outpost Firewall kernel mode plugin (Not verified) Agnitum c:\archivos de programa\agnitum\outpost firewall\kernel\pop3filt.dll
+ PROTECT.DLL Outpost Firewall kernel mode plugin (Not verified) Agnitum c:\archivos de programa\agnitum\outpost firewall\kernel\protect.dll
+ PxHelp20 Px Engine Device Driver for Windows 2000/XP (Not verified) Sonic Solutions c:\windows\system32\drivers\pxhelp20.sys
+ srosa c:\windows\system32\drivers\srosa.sys
+ Tcpip Controlador de protocolo TCP/IP (Not verified) Microsoft Corporation c:\windows\system32\drivers\tcpip.sys
+ VComm Bluetooth Serial Port Driver (Not verified) IVT Corporation c:\windows\system32\drivers\vcomm.sys
+ VcommMgr Bluetooth VcommMgr driver (Not verified) IVT Corporation c:\windows\system32\drivers\vcommmgr.sys
+ VFILT Virtual Firewall driver (Not verified) Agnitum c:\archivos de programa\agnitum\outpost firewall\kernel\filtnt.sys
+ vsdatant File not found: C:\WINDOWS\system32\vsdatant.sys
+ WINIO File not found: C:\DOCUME~1\benja\CONFIG~1\Temp\Rar$EX02.031\Magic 2.2.1_230404\Magic 2.2.1\winio.sys
HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute
HKLM\System\CurrentControlSet\Control\Session Manager\SetupExecute
HKLM\System\CurrentControlSet\Control\Session Manager\Execute
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKLM\Software\Microsoft\Command Processor\Autorun
HKCU\Software\Microsoft\Command Processor\Autorun
HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command\(Default)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls
+ 26.dll File not found: 26.dll
HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UIHost
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GinaDLL
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman
HKCU\Control Panel\Desktop\Scrnsave.exe
+ C:\ARCHIV~1\ALWILS~1\Avast4\AVASTSS.scr File not found: C:\ARCHIV~1\ALWILS~1\Avast4\AVASTSS.scr
HKLM\System\CurrentControlSet\Control\BootVerificationProgram\ImageName
HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors
+ PDFConverter c:\windows\system32\prnmnt.dll
+ PrimoMon c:\windows\system32\primomonnt.dll
HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages
HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order