See the log below!
ComboFix 13-05-11.01 - Jorgen 11/05/2013 1:30.9.2 - x86
Executando de: c:\documents and settings\Jorgen\Desktop\ComboFix.exe
Comandos utilizados :: c:\documents and settings\Jorgen\Desktop\CFScript.txt
* Criado um novo ponto de restauração
.
.
(((((((((((((((( Arquivos/Ficheiros criados de 2013-04-11 to 2013-05-11 ))))))))))))))))))))))))))))
.
.
2013-05-11 04:03 . 2013-05-11 04:05 -------- d-----w- c:\arquivos de programas\Google
2013-05-11 03:50 . 2013-05-11 03:50 -------- d-----w- c:\documents and settings\Jorgen\Dados de aplicativos\No Company Name
2013-05-11 02:54 . 2013-05-11 02:54 -------- d-----w- c:\windows\ERUNT
2013-05-11 02:53 . 2013-05-11 02:53 -------- d-----w- C:\JRT
2013-05-11 00:22 . 2013-05-11 00:22 -------- d-----w- c:\documents and settings\Default User\Dados de aplicativos\TuneUp Software
2013-05-11 00:22 . 2013-05-11 00:22 -------- d-----w- c:\windows\LastGood
2013-05-09 02:24 . 2013-05-09 02:24 -------- d-----w- c:\arquivos de programas\Unlocker
2013-05-09 01:40 . 2013-05-09 01:44 -------- d-----w- c:\arquivos de programas\GUME.tmp
2013-05-09 01:13 . 2013-05-09 01:13 -------- d-----w- c:\documents and settings\Jorgen\Dados de aplicativos\Mipony Download Manager Packages
2013-05-09 01:12 . 2013-05-09 01:12 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\BrowserProtect
2013-05-09 01:10 . 2013-05-09 01:10 -------- d-----w- c:\arquivos de programas\MiPony
2013-05-09 01:10 . 2013-05-09 01:10 -------- d-----w- c:\documents and settings\Jorgen\Dados de aplicativos\DSite
2013-05-05 16:01 . 2013-05-05 16:01 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Corel
2013-05-05 15:59 . 2013-05-05 15:59 -------- d-----w- c:\arquivos de programas\Arquivos comuns\Protexis
2013-05-05 15:44 . 2013-05-05 15:44 -------- d-----w- c:\arquivos de programas\Corel
2013-05-05 15:38 . 2013-05-05 16:35 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\CorelDRAW Graphics Suite X6
2013-05-02 10:36 . 2013-05-02 10:35 94112 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-04-20 22:48 . 2013-04-20 22:48 -------- d-----w- c:\documents and settings\Jorgen\Dados de aplicativos\WinPatrol
2013-04-20 22:48 . 2013-04-20 22:48 -------- d-----w- c:\arquivos de programas\BillP Studios
2013-04-18 04:29 . 2013-04-18 04:29 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\Sonos,_Inc
2013-04-18 03:20 . 2013-04-18 03:20 -------- d-----w- c:\arquivos de programas\CCleaner
2013-04-18 02:44 . 2013-04-18 02:44 -------- d-----w- c:\arquivos de programas\VS Revo Group
2013-04-16 20:00 . 2013-04-16 20:02 -------- dc-h--w- c:\windows\ie8
2013-04-16 20:00 . 2013-04-16 20:04 -------- d--h--w- c:\windows\msdownld.tmp
2013-04-16 17:14 . 2013-04-16 17:14 -------- d-----w- c:\documents and settings\Jorgen\Dados de aplicativos\AVG2013
2013-04-16 17:14 . 2013-04-16 17:14 -------- d-----w- c:\windows\system32\config\systemprofile\Dados de aplicativos\AVG2013
2013-04-16 17:14 . 2013-04-16 17:14 -------- d-----w- c:\documents and settings\Jorgen\Configurações locais\Dados de aplicativos\AVG SafeGuard toolbar
2013-04-16 17:13 . 2013-04-16 17:13 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\AVG SafeGuard toolbar
2013-04-16 17:13 . 2013-04-16 17:13 -------- d-----w- c:\documents and settings\Jorgen\Dados de aplicativos\AVG SafeGuard toolbar
2013-04-16 17:13 . 2013-04-16 17:13 -------- d-----w- c:\arquivos de programas\AVG SafeGuard toolbar
2013-04-16 17:10 . 2013-05-11 00:23 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\MFAData
2013-04-16 17:10 . 2013-04-16 17:17 -------- d-----w- c:\documents and settings\Jorgen\Configurações locais\Dados de aplicativos\Avg2013
2013-04-16 17:10 . 2013-04-16 17:10 -------- d-----w- c:\documents and settings\Jorgen\Configurações locais\Dados de aplicativos\MFAData
2013-04-16 17:06 . 2013-04-16 19:37 4126720 ----a-w- c:\arquivos de programas\GUT92.tmp
2013-04-16 17:06 . 2013-04-16 17:06 -------- d-----w- c:\arquivos de programas\GUM91.tmp
2013-04-16 16:58 . 2013-04-16 16:58 -------- d-----w- c:\documents and settings\Jorgen\Configurações locais\Dados de aplicativos\Mozilla
2013-04-16 13:13 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2013-04-16 13:13 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023.sys
2013-04-16 13:07 . 2012-11-02 02:04 375296 -c----w- c:\windows\system32\dllcache\dpnet.dll
2013-04-16 12:25 . 2013-04-16 12:37 33624 ----a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-04-16 12:14 . 2013-04-16 12:14 -------- d-----w- c:\arquivos de programas\FileASSASSIN
2013-04-16 11:37 . 2013-04-16 11:37 -------- d-----w- c:\arquivos de programas\Malwarebytes' Anti-Malware
2013-04-16 11:37 . 2013-04-04 17:50 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-04-16 11:13 . 2012-10-02 18:04 58368 -c----w- c:\windows\system32\dllcache\synceng.dll
2013-04-15 22:02 . 2013-04-15 22:02 -------- d-----w- c:\documents and settings\Jorgen\Dados de aplicativos\TuneUp Software
2013-04-15 22:01 . 2013-04-15 22:01 -------- d-----w- C:\$AVG
2013-04-15 22:01 . 2013-04-16 19:36 -------- d-----w- c:\documents and settings\All Users\Dados de aplicativos\AVG2013
2013-04-15 21:39 . 2013-04-17 03:00 -------- d-----w- c:\documents and settings\Jorgen\Configurações locais\Dados de aplicativos\Deployment
.
.
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-05 16:05 . 2010-10-05 16:13 348256 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Microsoft\VSTAHost\CorelPHOTOPAINT\9.0\1033\ResourceCache.dll
2013-05-05 16:02 . 2010-10-05 16:12 348256 ----a-w- c:\documents and settings\All Users\Dados de aplicativos\Microsoft\VSTAHost\CorelDRAW\9.0\1033\ResourceCache.dll
2013-05-02 10:35 . 2012-07-06 23:32 866720 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-05-02 10:35 . 2010-05-18 02:05 788896 ----a-w- c:\windows\system32\deployJava1.dll
2013-05-02 10:35 . 2008-01-30 04:08 144896 ----a-w- c:\windows\system32\javacpl.cpl
2013-03-29 05:53 . 2013-02-27 02:40 208184 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2013-03-21 06:08 . 2013-02-14 06:52 182072 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2013-03-13 01:49 . 2012-11-18 02:30 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-13 01:49 . 2012-11-18 02:30 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-08 08:36 . 2004-08-04 03:45 293888 ----a-w- c:\windows\system32\winsrv.dll
2013-03-07 15:56 . 2004-08-04 03:40 2153984 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-07 15:56 . 2004-08-04 00:40 2032640 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-02 01:58 . 2004-08-04 03:38 1867392 ----a-w- c:\windows\system32\win32k.sys
2013-03-01 13:32 . 2013-03-01 13:32 22328 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys
2013-02-19 05:30 . 2013-02-19 05:30 664 ----a-w- c:\documents and settings\Jorgen\Configurações locais\Dados de aplicativos\d3d9caps.tmp
2013-02-12 00:32 . 2008-04-13 18:56 12928 ------w- c:\windows\system32\drivers\usb8023x.sys
2013-02-12 00:32 . 2004-08-04 02:04 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
.
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por padrão não são apresentadas.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2013-04-04 00:51 383328 ----a-w- c:\arquivos de programas\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2013-04-04 00:51 383328 ----a-w- c:\arquivos de programas\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2013-04-04 00:51 383328 ----a-w- c:\arquivos de programas\SugarSync\SugarSyncShellExt.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2013-04-04 00:51 383328 ----a-w- c:\arquivos de programas\SugarSync\SugarSyncShellExt.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SugarSync"="c:\arquivos de programas\SugarSync\SugarSyncManager.exe" [2013-04-04 11262304]
"Skype"="c:\arquivos de programas\Skype\Phone\Skype.exe" [2010-10-11 16856968]
"WinFLTray"="c:\windows\system32\WinFLTray.exe" [2012-07-20 321736]
"FLBackup"="c:\arquivos de programas\NewSoftware's\Folder Lock\FLComServCtrl.exe" [2012-07-20 276168]
"FreeRAM XP"="c:\arquivos de programas\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2012-09-14 1591808]
"gStart"="c:\garmin\gStart.exe" [2008-08-13 1891416]
"ANT Agent"="c:\arquivos de programas\Garmin\ANT Agent\ANT Agent.exe" [2012-03-23 14749544]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelAudioStudio"="c:\arquivos de programas\Intel Audio Studio\IntelAudioStudio.exe" [2006-09-21 9138176]
"LanguageShortcut"="c:\arquivos de programas\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"AtomTime"="c:\arquivos de programas\AtomTime Pro\AtomTime.EXE" [2004-12-03 396316]
"AppleSyncNotifier"="c:\arquivos de programas\Arquivos comuns\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-08 47904]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"VirtualCloneDrive"="c:\arquivos de programas\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-06-17 85160]
"CertificateRegistration"="aetcrss1.exe" [2010-07-20 151552]
"APSDaemon"="c:\arquivos de programas\Arquivos comuns\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"LogMeIn GUI"="c:\arquivos de programas\LogMeIn\x86\LogMeInSystray.exe" [2011-09-16 63048]
"DivXMediaServer"="c:\arquivos de programas\DivX\DivX Media Server\DivXMediaServer.exe" [2012-11-13 450560]
"DivXUpdate"="c:\arquivos de programas\DivX\DivX Update\DivXUpdate.exe" [2012-11-01 1263512]
"iTunesHelper"="c:\arquivos de programas\iTunes\iTunesHelper.exe" [2013-02-20 152392]
"Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"AVG_UI"="c:\arquivos de programas\AVG\AVG2013\avgui.exe" [2013-04-29 4408368]
"WinPatrol"="c:\arquivos de programas\BillP Studios\WinPatrol\winpatrol.exe" [2013-04-17 422632]
"SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2013-03-12 253816]
"UnlockerAssistant"="c:\arquivos de programas\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\Jorgen\Menu Iniciar\Programas\Inicializar\
ddbd5.LNK - c:\arquivos de programas\Internet Explorer\ddbd5.exe [2013-3-29 370688]
.
c:\documents and settings\All Users\Menu Iniciar\Programas\Inicializar\
BTTray.lnk - c:\arquivos de programas\ANYCOM\Blue USB-200-250\BTTray.exe [2005-9-6 581693]
CineForm Status.lnk - c:\arquivos de programas\CineForm\Tools\GoProCineFormStatusViewer.exe [2012-10-28 152064]
HP Digital Imaging Monitor.lnk - c:\arquivos de programas\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-11-21 17:16 92072 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ c:\arquiv~1\AVG\AVG2013\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gStart]
2008-08-13 17:34 1891416 ----a-w- c:\garmin\gStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-17 00:12 3872080 ----a-w- c:\arquivos de programas\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ScreenPrint32]
2003-05-15 23:36 446464 ----a-w- c:\arquivos de programas\ScreenPrint32 v3\ScreenPrint32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2012-08-06 16:04 1353080 ----a-w- c:\arquivos de programas\Steam\steam.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Arquivos de programas\\Skype\\Phone\\Skype.exe"=
"c:\\Arquivos de programas\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
"c:\\Arquivos de programas\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\All Users\\Dados de aplicativos\\NexonUS\\NGM\\NGM.exe"=
"c:\\Documents and Settings\\Jorgen\\Dados de aplicativos\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Arquivos de programas\\Steam\\steamapps\\common\\il 2 sturmovik 1946\\il2fb.exe"=
"c:\\Arquivos de programas\\Steam\\steamapps\\common\\silent hunter 3\\sh3.exe"=
"c:\\WINDOWS\\system32\\hasplms.exe"=
"c:\\Arquivos de programas\\Arquivos comuns\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Arquivos de programas\\Bonjour\\mDNSResponder.exe"=
"c:\\Arquivos de programas\\iTunes\\iTunes.exe"=
"c:\\Arquivos de programas\\Bitcoin\\bitcoin-qt.exe"=
"c:\\Arquivos de programas\\AVG\\AVG2013\\avgmfapx.exe"=
"c:\\Arquivos de programas\\AVG\\AVG2013\\avgnsx.exe"=
"c:\\Arquivos de programas\\AVG\\AVG2013\\avgdiagex.exe"=
"c:\\Arquivos de programas\\AVG\\AVG2013\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1034:TCP"= 1034:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R2 AdvancedSystemCareService6;Advanced SystemCare Service 6;c:\arquivos de programas\IObit\Advanced SystemCare 6\ASCService.exe [x]
R2 BBSvc;BingBar Service;c:\arquivos de programas\Microsoft\BingBar\7.1.391.0\BBSvc.exe [x]
R2 Marvell RAID;Marvell RAID Event Agent;c:\arquivos de programas\Marvell\61xx\svc\mvraidsvc.exe [x]
R2 MBAMScheduler;MBAMScheduler;c:\arquivos de programas\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
R2 MBAMService;MBAMService;c:\arquivos de programas\Malwarebytes' Anti-Malware\mbamservice.exe [x]
R2 vToolbarUpdater15.0.0;vToolbarUpdater15.0.0;c:\arquivos de programas\Arquivos comuns\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 GemCCID;GemCCID;c:\windows\system32\Drivers\GemCCID.sys [x]
R3 Ipodtuv1d;Ipodtuv1d; [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\system32\DRIVERS\SWUSBFLT.sys [x]
R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\DRIVERS\tapoas.sys [x]
S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [x]
S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [x]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [x]
S0 mv61xx;mv61xx;c:\windows\system32\DRIVERS\mv61xx.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [x]
S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [x]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [x]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [x]
S1 WinFLAdrv;WinFLAdrv;c:\windows\system32\WinFLAdrv.sys [x]
S2 AVGIDSAgent;AVGIDSAgent;c:\arquivos de programas\AVG\AVG2013\avgidsagent.exe [x]
S2 avgwd;Watchdog do AVG;c:\arquivos de programas\AVG\AVG2013\avgwdsvc.exe [x]
S2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\DRIVERS\EAPPkt.sys [x]
S2 FLService;FLService;c:\windows\system32\WinFLService.exe [x]
S2 hasplms;Sentinel Local License Manager;c:\windows\system32\hasplms.exe -run [x]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\arquivos de programas\LogMeIn\x86\LMIGuardianSvc.exe [x]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\arquivos de programas\LogMeIn\x86\RaInfo.sys [x]
S2 MRUWebService;MRU Web Service;c:\arquivos de programas\Marvell\61xx\Apache2\bin\Apache.exe [x]
S2 WinVDEDrv;WinVDEDrv;c:\windows\system32\WinVDEdrv.sys [x]
S3 BBUpdate;BBUpdate;c:\arquivos de programas\Microsoft\BingBar\7.1.391.0\SeaPort.exe [x]
S3 libusb0;LibUsb-Win32 - Kernel Driver 07/07/2009, 0.1.12.2;c:\windows\system32\DRIVERS\libusb0.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\aetsprov]
2010-08-01 01:55 81920 ----a-w- c:\windows\system32\aetsprov.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-05-11 04:05 1642448 ----a-w- c:\arquivos de programas\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Conteúdo da pasta 'Tarefas Agendadas'
.
2013-05-11 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-18 01:49]
.
2013-05-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\arquivos de programas\Apple Software Update\SoftwareUpdate.exe [2011-06-01 20:57]
.
2013-05-11 c:\windows\Tasks\avast! Emergency Update.job
- c:\arquivos de programas\AVAST Software\Avast\AvastEmUpdate.exe [2012-08-25 09:12]
.
2013-05-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2013-05-11 04:03]
.
2013-05-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2013-05-11 04:03]
.
2013-04-29 c:\windows\Tasks\videopadShakeIcon.job
- c:\arquivos de programas\NCH Software\VideoPad\videopad.exe [2012-12-23 01:54]
.
2012-07-10 c:\windows\Tasks\WavePadReminder.job
- c:\arquivos de programas\NCH Software\WavePad\wavepad.exe [2012-06-30 00:25]
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.google.com.br
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyServer = 80.84.34.175:9000
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\arquiv~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Enviar para &Bluetooth - c:\arquivos de programas\ANYCOM\Blue USB-200-250\btsendto_ie_ctx.htm
IE: Save YouTube Video
Trusted Zone: cybertrust.com\shrweb7.idm
TCP: DhcpNameServer = 192.168.0.1
DPF: {9EC30204-384D-11D3-9CA3-00A024F0AF03} - hxxps://cpne.bradesco.com.br/certifexp.cab
DPF: {B3D3825B-2120-4B0E-8C45-80ECC1D3E70D} - hxxps://cpne.bradesco.com.br/CA.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-05-11 01:44
Windows 5.1.2600 Service Pack 3 NTFS
.
Procurando processos ocultos ...
.
Procurando entradas auto inicializáveis ocultas ...
.
Procurando ficheiros/arquivos ocultos ...
.
Varredura completada com sucesso
arquivos/ficheiros ocultos: 0
.
**************************************************************************
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:60,05,ee,30,4e,e9,ce,99,d2,b8,7d,f0,5e,5d,c7,fb,bc,fe,2c,60,21,
89,ac,77,e8,ed,b0,1a,00,70,ea,5f,4f,ec,40,2a,d5,dd,5f,37,63,f4,d2,df,4e,a5,\
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:60,05,ee,30,4e,e9,ce,99,d2,b8,7d,f0,5e,5d,c7,fb,bc,fe,2c,60,21,
89,ac,77,e8,ed,b0,1a,00,70,ea,5f,4f,ec,40,2a,d5,dd,5f,37,63,f4,d2,df,4e,a5,\
.
--------------------- DLLs Carregadas Sob os Processos em Execução ---------------------
.
- - - - - - - > 'winlogon.exe'(1092)
c:\windows\system32\LMIinit.dll
.
- - - - - - - > 'explorer.exe'(6612)
c:\arquivos de programas\SugarSync\SugarSyncShellExt.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msi.dll
c:\arquivos de programas\Arquivos comuns\Microsoft Shared\INK\SKCHUI.DLL
c:\windows\system32\webcheck.dll
c:\arquivos de programas\Scpad\scpLIB.dll
c:\arquivos de programas\Scpad\scpMIB.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Tempo para conclusão: 2013-05-11 01:49:10
ComboFix-quarantined-files.txt 2013-05-11 04:48
ComboFix2.txt 2013-05-11 03:32
.
Pré-execução: 2.907.648.000 bytes disponíveis
Pós execução: 2.904.322.048 bytes disponíveis
.
- - End Of File - - 485F582F1844923695217265C8EE25CE