ComboFix 13-06-20.01 - lojassl 20/06/2013 9:51.7.4 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.55.1033.18.3965.2615 [GMT -3:00] Executando de: c:\users\usuario\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((( Outras Exclusões ))))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\usuario\AppData\Local\Temp\_MEI23802\_ctypes.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\_elementtree.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\_hashlib.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\_multiprocessing.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\_socket.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\_ssl.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\pyexpat.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\pysqlite2._sqlite.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\python27.dll c:\users\usuario\AppData\Local\Temp\_MEI23802\pythoncom27.dll c:\users\usuario\AppData\Local\Temp\_MEI23802\PyWinTypes27.dll c:\users\usuario\AppData\Local\Temp\_MEI23802\select.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\unicodedata.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\win32api.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\win32com.shell.shell.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\win32crypt.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\win32event.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\win32file.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\win32inet.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\win32pdh.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\win32process.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\win32profile.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\win32security.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\win32ts.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\windows._cacheinvalidation.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\wx._controls_.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\wx._core_.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\wx._gdi_.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\wx._html2.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\wx._misc_.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\wx._windows_.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\wx._wizard.pyd c:\users\usuario\AppData\Local\Temp\_MEI23802\wxbase294u_net_vc90.dll c:\users\usuario\AppData\Local\Temp\_MEI23802\wxbase294u_vc90.dll c:\users\usuario\AppData\Local\Temp\_MEI23802\wxmsw294u_adv_vc90.dll c:\users\usuario\AppData\Local\Temp\_MEI23802\wxmsw294u_core_vc90.dll c:\users\usuario\AppData\Local\Temp\_MEI23802\wxmsw294u_html_vc90.dll c:\users\usuario\AppData\Local\Temp\_MEI23802\wxmsw294u_webview_vc90.dll . . (((((((((((((((( Arquivos/Ficheiros criados de 2013-05-20 to 2013-06-20 )))))))))))))))))))))))))))) . . 2013-06-20 12:55 . 2013-06-20 12:55 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-06-20 11:27 . 2013-06-20 11:27 -------- d-----w- c:\program files (x86)\Common Files\Java 2013-06-20 11:27 . 2013-06-20 11:26 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-06-20 11:21 . 2013-06-20 11:21 -------- d-----w- c:\windows\system32\appmgmt 2013-06-18 12:34 . 2013-06-18 12:34 -------- d-----w- c:\windows\pt-BR 2013-06-18 12:34 . 2013-06-18 12:34 -------- d-----w- c:\windows\SysWow64\XPSViewer 2013-06-18 12:34 . 2013-06-18 12:34 -------- d-----w- c:\windows\SysWow64\drivers\pt-BR 2013-06-18 12:34 . 2013-06-18 12:34 -------- d-----w- c:\windows\system32\drivers\UMDF\pt-BR 2013-06-18 12:34 . 2013-06-18 12:34 -------- d-----w- c:\windows\system32\drivers\pt-BR 2013-06-18 12:26 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7D7D8480-1E89-4CEF-AF13-A029A497FDAA}\mpengine.dll 2013-06-18 12:16 . 2013-06-08 12:28 2706432 ----a-w- c:\windows\system32\mshtml.tlb 2013-06-18 12:12 . 2013-03-19 05:53 48640 ----a-w- c:\windows\system32\wwanprotdim.dll 2013-06-18 12:11 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2013-06-18 12:11 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2013-06-18 12:09 . 2013-03-31 22:52 1887232 ----a-w- c:\windows\system32\d3d11.dll 2013-06-18 12:09 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll 2013-06-17 19:04 . 2013-05-11 22:27 262552 ----a-w- c:\program files (x86)\Mozilla Firefox\browser\components\browsercomps.dll 2013-05-31 11:36 . 2013-05-31 11:36 -------- d-----w- c:\program files (x86)\Geovision 2013-05-31 11:34 . 2013-05-31 11:35 -------- d-----w- c:\program files (x86)\DMMultiView 2013-05-31 11:34 . 2013-05-31 11:36 -------- d-----w- c:\windows\v8330 . . . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-06-20 11:26 . 2013-04-02 01:32 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-06-20 11:26 . 2013-04-02 01:31 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-06-18 12:24 . 2013-04-02 00:18 75825640 ----a-w- c:\windows\system32\MRT.exe 2013-06-13 19:20 . 2013-04-02 03:07 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-13 19:20 . 2013-04-02 03:07 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-05-09 08:59 . 2013-04-22 12:33 378432 ----a-w- c:\windows\system32\drivers\aswSP.sys 2013-05-09 08:59 . 2013-04-22 12:33 72016 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-05-09 08:59 . 2013-04-22 12:33 64288 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2013-05-09 08:59 . 2013-04-22 12:33 189936 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-05-09 08:59 . 2013-04-22 12:33 1025808 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2013-05-09 08:59 . 2013-04-22 12:33 65336 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-05-09 08:59 . 2013-04-22 12:33 33400 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-05-09 08:59 . 2013-04-22 12:33 80816 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-05-09 08:58 . 2013-04-22 12:32 41664 ----a-w- c:\windows\avastSS.scr 2013-05-09 08:58 . 2013-04-22 12:33 287840 ----a-w- c:\windows\system32\aswBoot.exe 2013-05-02 05:06 . 2010-11-21 03:27 278800 ------w- c:\windows\system32\MpSigStub.exe 2013-04-13 05:49 . 2013-06-18 12:12 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll 2013-04-13 05:49 . 2013-06-18 12:12 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll 2013-04-13 05:49 . 2013-06-18 12:12 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll 2013-04-13 05:49 . 2013-06-18 12:12 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll 2013-04-13 04:45 . 2013-06-18 12:12 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2013-04-13 04:45 . 2013-06-18 12:12 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll 2013-04-12 14:45 . 2013-05-20 12:13 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys 2013-04-10 06:01 . 2013-05-20 12:13 265064 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2013-04-10 06:01 . 2013-05-20 12:13 983400 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2013-04-10 03:30 . 2013-05-20 12:13 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-04-03 18:52 . 2013-04-03 18:52 97280 ----a-w- c:\windows\system32\mshtmled.dll 2013-04-03 18:52 . 2013-04-03 18:52 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-04-03 18:52 . 2013-04-03 18:52 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-04-03 18:52 . 2013-04-03 18:52 81408 ----a-w- c:\windows\system32\icardie.dll 2013-04-03 18:52 . 2013-04-03 18:52 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-04-03 18:52 . 2013-04-03 18:52 762368 ----a-w- c:\windows\system32\ieapfltr.dll 2013-04-03 18:52 . 2013-04-03 18:52 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-04-03 18:52 . 2013-04-03 18:52 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-04-03 18:52 . 2013-04-03 18:52 62976 ----a-w- c:\windows\system32\pngfilt.dll 2013-04-03 18:52 . 2013-04-03 18:52 61952 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-04-03 18:52 . 2013-04-03 18:52 599552 ----a-w- c:\windows\system32\vbscript.dll 2013-04-03 18:52 . 2013-04-03 18:52 523264 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-04-03 18:52 . 2013-04-03 18:52 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-04-03 18:52 . 2013-04-03 18:52 51200 ----a-w- c:\windows\system32\imgutil.dll 2013-04-03 18:52 . 2013-04-03 18:52 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-04-03 18:52 . 2013-04-03 18:52 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-04-03 18:52 . 2013-04-03 18:52 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2013-04-03 18:52 . 2013-04-03 18:52 441856 ----a-w- c:\windows\system32\html.iec 2013-04-03 18:52 . 2013-04-03 18:52 38400 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-04-03 18:52 . 2013-04-03 18:52 361984 ----a-w- c:\windows\SysWow64\html.iec 2013-04-03 18:52 . 2013-04-03 18:52 281600 ----a-w- c:\windows\system32\dxtrans.dll 2013-04-03 18:52 . 2013-04-03 18:52 27648 ----a-w- c:\windows\system32\licmgr10.dll 2013-04-03 18:52 . 2013-04-03 18:52 270848 ----a-w- c:\windows\system32\iedkcs32.dll 2013-04-03 18:52 . 2013-04-03 18:52 247296 ----a-w- c:\windows\system32\webcheck.dll 2013-04-03 18:52 . 2013-04-03 18:52 235008 ----a-w- c:\windows\system32\url.dll 2013-04-03 18:52 . 2013-04-03 18:52 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-04-03 18:52 . 2013-04-03 18:52 226304 ----a-w- c:\windows\system32\elshyph.dll 2013-04-03 18:52 . 2013-04-03 18:52 216064 ----a-w- c:\windows\system32\msls31.dll 2013-04-03 18:52 . 2013-04-03 18:52 197120 ----a-w- c:\windows\system32\msrating.dll 2013-04-03 18:52 . 2013-04-03 18:52 185344 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-04-03 18:52 . 2013-04-03 18:52 173568 ----a-w- c:\windows\system32\ieUnatt.exe 2013-04-03 18:52 . 2013-04-03 18:52 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-04-03 18:52 . 2013-04-03 18:52 158720 ----a-w- c:\windows\SysWow64\msls31.dll 2013-04-03 18:52 . 2013-04-03 18:52 1509376 ----a-w- c:\windows\system32\inetcpl.cpl 2013-04-03 18:52 . 2013-04-03 18:52 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-04-03 18:52 . 2013-04-03 18:52 149504 ----a-w- c:\windows\system32\occache.dll 2013-04-03 18:52 . 2013-04-03 18:52 144896 ----a-w- c:\windows\system32\wextract.exe 2013-04-03 18:52 . 2013-04-03 18:52 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-04-03 18:52 . 2013-04-03 18:52 1400416 ----a-w- c:\windows\system32\ieapfltr.dat 2013-04-03 18:52 . 2013-04-03 18:52 138752 ----a-w- c:\windows\SysWow64\wextract.exe 2013-04-03 18:52 . 2013-04-03 18:52 13824 ----a-w- c:\windows\system32\mshta.exe 2013-04-03 18:52 . 2013-04-03 18:52 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-04-03 18:52 . 2013-04-03 18:52 136192 ----a-w- c:\windows\system32\iepeers.dll 2013-04-03 18:52 . 2013-04-03 18:52 135680 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-04-03 18:52 . 2013-04-03 18:52 12800 ----a-w- c:\windows\SysWow64\mshta.exe 2013-04-03 18:52 . 2013-04-03 18:52 12800 ----a-w- c:\windows\system32\msfeedssync.exe 2013-04-03 18:52 . 2013-04-03 18:52 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-04-03 18:52 . 2013-04-03 18:52 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-04-03 18:52 . 2013-04-03 18:52 102912 ----a-w- c:\windows\system32\inseng.dll 2013-04-03 18:50 . 2013-04-03 18:50 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 648192 ----a-w- c:\windows\system32\d3d10level9.dll 2013-04-03 18:50 . 2013-04-03 18:50 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2013-04-03 18:50 . 2013-04-03 18:50 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-04-03 18:50 . 2013-04-03 18:50 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-04-03 18:50 . 2013-04-03 18:50 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-04-03 18:50 . 2013-04-03 18:50 3928064 ----a-w- c:\windows\system32\d2d1.dll 2013-04-03 18:50 . 2013-04-03 18:50 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-04-03 18:50 . 2013-04-03 18:50 363008 ----a-w- c:\windows\system32\dxgi.dll 2013-04-03 18:50 . 2013-04-03 18:50 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll 2013-04-03 18:50 . 2013-04-03 18:50 333312 ----a-w- c:\windows\system32\d3d10_1core.dll 2013-04-03 18:50 . 2013-04-03 18:50 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-04-03 18:50 . 2013-04-03 18:50 296960 ----a-w- c:\windows\system32\d3d10core.dll . . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por padrão não são apresentadas. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DIMBaixando a sua atualização...1338924290338"="c:\program files (x86)\Corel\CorelDRAW Graphics Suite X6\Draw\DIM.eexe" [X] "GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2013-04-16 19662744] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-05-21 291648] "331BigDog"="c:\program files (x86)\USB Camera\VM331_STI.EXE" [2011-11-24 548864] "SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . R3 AMPPALP;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x] R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 tsusbhub;tsusbhub;tsusbhub [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S0 iusb3hcs;Intel(R) USB 3.0 Host Controller Switch Driver;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x] S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 AMPPALR3;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x] S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys;c:\windows\SYSNATIVE\DRIVERS\AcpiVpc.sys [x] S3 AMPPAL;Intel® Centrino® Wireless Bluetooth® 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-06-05 19:45 1165776 ----a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.110\Installer\chrmstp.exe . Conteúdo da pasta 'Tarefas Agendadas' . 2013-06-20 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-04-02 19:20] . 2013-06-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-04-02 01:29] . 2013-06-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-04-02 01:29] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}] 2013-04-16 19:10 776144 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}] 2013-04-16 19:10 776144 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}] 2013-04-16 19:10 776144 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay] @="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}" [HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}] 2013-04-16 19:10 776144 ----a-w- c:\program files (x86)\Google\Drive\googledrivesync64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2013-04-02 8079408] "EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2013-04-02 6199128] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 172144] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 399984] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 441968] . ------- Scan Suplementar ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm IE: &Enviar para o OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: E&xportar para o Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 Trusted Zone: myvnc.com\smx TCP: DhcpNameServer = 201.6.2.165 201.6.2.45 201.6.4.116 DPF: {FEC048AB-277A-460C-BF50-1A4193AEF148} - hxxp://172.11.252.115/cab/DownloadCenter_8300.cab FF - ProfilePath - c:\users\usuario\AppData\Roaming\Mozilla\Firefox\Profiles\bba5p0pl.default\ FF - ExtSQL: 2013-05-31 08:32; wrc@avast.com; c:\program files\AVAST Software\Avast\WebRep\FF . . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Outros Processos em Execução ------------------------ . c:\program files\AVAST Software\Avast\AvastSvc.exe c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe . ************************************************************************** . Tempo para conclusão: 2013-06-20 10:00:15 - Máquina reiniciou ComboFix-quarantined-files.txt 2013-06-20 13:00 ComboFix2.txt 2013-06-18 13:51 ComboFix3.txt 2013-06-18 13:14 ComboFix4.txt 2013-06-18 13:06 ComboFix5.txt 2013-06-20 12:51 . Pré-execução: 268.968.726.528 bytes disponíveis Pós execução: 269.004.382.208 bytes disponíveis . - - End Of File - - BF78DB10663DDFF01DD0075CE11EBE86 A36C5E4F47E84449FF07ED3517B43A31