Olá.
[code=log ComboFix]
ComboFix 15-07-10.01 - GEDI 10/07/2015 10:18:16.2.6 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.55.1033.18.4094.2827 [GMT -3:00]
Executando de: c:\users\GEDI\Downloads\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Criado um novo ponto de restauração
.
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Skype\Phone\Skype.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_AdobeUpdateService
.
.
(((((((((((((((( Arquivos/Ficheiros criados de 2015-06-10 to 2015-07-10 ))))))))))))))))))))))))))))
.
.
2015-07-10 13:25 . 2015-07-10 13:25 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-07-10 12:57 . 2015-06-12 07:50 12221144 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{3428234C-39B2-4721-8979-7011027FA411}\mpengine.dll
2015-07-08 00:28 . 2015-07-10 12:59 113880 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-07-08 00:27 . 2015-07-08 00:28 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2015-07-08 00:27 . 2015-07-08 00:27 -------- d-----w- c:\programdata\Malwarebytes
2015-07-08 00:27 . 2015-06-18 11:41 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-07-08 00:27 . 2015-06-18 11:41 109272 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-07-08 00:27 . 2015-06-18 11:41 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-07-07 23:29 . 2015-07-07 23:29 -------- d-----w- c:\windows\MATS
2015-07-07 23:29 . 2015-07-07 23:29 -------- d-----w- c:\program files\Microsoft Fix it Center
2015-07-07 23:14 . 2015-07-07 23:14 -------- d-----w- c:\program files (x86)\VS Revo Group
2015-07-07 16:31 . 2015-07-07 16:30 364472 ----a-w- c:\windows\system32\aswBoot.exe
2015-07-07 16:30 . 2015-07-07 16:30 43112 ----a-w- c:\windows\avastSS.scr
2015-06-30 20:00 . 2015-06-30 20:00 -------- d-----w- c:\program files (x86)\Microsoft ASP.NET
2015-06-30 19:00 . 2015-06-30 19:00 -------- d-----w- c:\program files (x86)\Skillbrains
2015-06-30 14:36 . 2015-06-30 20:11 -------- d-----w- c:\program files\Reason
2015-06-29 14:40 . 2015-05-19 03:29 46768 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2015-06-29 14:40 . 2015-05-19 03:14 57520 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2015-06-29 14:19 . 2015-06-29 14:19 986368 ----a-w- c:\windows\system32\drivers\Rt64win7.sys
2015-06-29 14:19 . 2015-06-29 14:19 82544 ----a-w- c:\windows\system32\RtNicProp64.dll
2015-06-29 14:18 . 2015-06-29 14:18 11944 ----a-w- c:\windows\system32\drivers\amdide64.sys
2015-06-29 13:59 . 2015-06-29 13:59 -------- d-----w- c:\program files\Common Files\Bitdefender
2015-06-23 17:33 . 2015-06-23 17:33 -------- d-----w- c:\users\GEDI\AppData\Roaming\Sony Creative Software Inc
2015-06-17 18:33 . 2015-06-17 18:33 -------- d-----w- c:\users\GEDI\AppData\Local\YSearchUtil
2015-06-17 18:31 . 2015-06-17 18:31 -------- d-----w- c:\program files (x86)\Common Files\Java
2015-06-14 11:52 . 2015-06-14 11:52 -------- d-----w- C:\found.001
2015-06-12 00:05 . 2015-07-10 12:33 -------- d-----w- c:\programdata\boost_interprocess
2015-06-11 23:59 . 2015-06-24 17:18 778416 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2015-06-11 23:58 . 2015-06-11 23:58 -------- d-----w- c:\windows\system32\Macromed
2015-06-11 23:48 . 2015-06-11 23:48 -------- d-----w- c:\programdata\GAS Tecnologia
2015-06-11 23:48 . 2015-07-08 00:02 -------- d-----w- c:\program files (x86)\GbPlugin
2015-06-11 23:48 . 2015-06-12 10:19 -------- d-----w- c:\programdata\GbPlugin
.
.
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-07 16:31 . 2015-03-26 02:45 442264 ----a-w- c:\windows\system32\drivers\aswsp.sys
2015-07-07 16:30 . 2015-03-26 02:45 272248 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2015-07-07 16:30 . 2015-03-26 02:45 137288 ----a-w- c:\windows\system32\drivers\aswStm.sys
2015-07-07 16:30 . 2015-03-26 02:45 65736 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2015-07-07 16:30 . 2015-03-26 02:45 89944 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2015-07-07 16:30 . 2015-03-26 02:45 29168 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2015-07-07 16:30 . 2015-03-26 02:45 93528 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2015-07-07 16:30 . 2015-03-26 02:45 1047320 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2015-06-29 14:19 . 2015-03-26 02:23 116304 ----a-w- c:\windows\system32\RTNUninst64.dll
2015-06-24 17:18 . 2015-04-28 19:30 142512 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2015-06-24 11:36 . 2015-03-26 03:02 1316000 ----a-w- c:\windows\SysWow64\nvspbridge.dll
2015-06-24 11:36 . 2015-03-26 03:02 1571696 ----a-w- c:\windows\system32\nvspcap64.dll
2015-06-24 11:36 . 2015-03-26 03:02 1756424 ----a-w- c:\windows\system32\nvspbridge64.dll
2015-06-23 16:30 . 2010-11-21 03:27 300704 ------w- c:\windows\system32\MpSigStub.exe
2015-06-17 18:30 . 2015-03-26 02:35 97888 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2015-05-27 03:04 . 2015-03-28 04:34 140135120 ----a-w- c:\windows\system32\MRT.exe
2015-05-25 18:01 . 2015-06-10 15:15 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2015-05-19 03:14 . 2015-03-26 02:55 61616 ----a-w- c:\windows\system32\nvaudcap64v.dll
2015-05-16 22:36 . 2015-05-16 22:36 15416 ----a-w- c:\windows\system32\drivers\ASACPI.sys
2015-05-16 18:58 . 2015-05-16 18:58 26528 ----a-w- c:\windows\SysWow64\drivers\HWiNFO64A.SYS
2015-05-01 13:17 . 2015-05-12 18:56 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-01 13:16 . 2015-05-12 18:56 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2015-04-20 03:17 . 2015-05-12 18:33 1647104 ----a-w- c:\windows\system32\DWrite.dll
2015-04-20 03:17 . 2015-05-12 18:33 1179136 ----a-w- c:\windows\system32\FntCache.dll
2015-04-20 02:56 . 2015-05-12 18:33 1250816 ----a-w- c:\windows\SysWow64\DWrite.dll
2015-04-18 03:10 . 2015-05-12 18:36 460800 ----a-w- c:\windows\system32\certcli.dll
2015-04-18 02:56 . 2015-05-12 18:36 342016 ----a-w- c:\windows\SysWow64\certcli.dll
2015-04-14 06:38 . 2015-04-14 06:38 1217192 ----a-w- c:\windows\SysWow64\FM20.DLL
2015-04-13 03:28 . 2015-05-12 18:34 328704 ----a-w- c:\windows\system32\services.exe
2015-03-29 15:37 . 2015-03-29 15:37 506880 ----a-w- c:\program files\CustomHooks.dll
2015-03-29 15:33 . 2015-03-29 15:33 662208 ----a-w- c:\program files\updaternotifications.dll
2015-03-29 15:32 . 2015-03-29 15:32 2596864 ----a-w- c:\program files\libcurl.dll
2015-03-29 15:32 . 2015-03-29 15:32 13916672 ----a-w- c:\program files\icudt40.dll
2015-03-29 15:32 . 2015-03-29 15:32 1121792 ----a-w- c:\program files\icuuc40.dll
2015-03-29 15:32 . 2015-05-29 19:01 2736320 ----a-w- c:\program files\amtlib.dll.BAK
2015-03-29 15:32 . 2015-03-29 15:32 927232 ----a-w- c:\program files\boost_regex.dll
2015-03-29 15:32 . 2015-03-29 15:32 89600 ----a-w- c:\program files\boost_signals.dll
2015-03-29 15:32 . 2015-03-29 15:32 7888576 ----a-w- c:\program files\dvaui.dll
2015-03-29 15:32 . 2015-03-29 15:32 75776 ----a-w- c:\program files\boost_date_time.dll
2015-03-29 15:32 . 2015-03-29 15:32 4955328 ----a-w- c:\program files\dvaadameve.dll
2015-03-29 15:32 . 2015-03-29 15:32 2951360 ----a-w- c:\program files\dvacore.dll
2015-03-29 15:32 . 2015-03-29 15:32 2736320 ------w- c:\program files\amtlib.dll
2015-03-29 15:32 . 2015-03-29 15:32 24064 ----a-w- c:\program files\boost_system.dll
2015-03-29 15:32 . 2015-03-29 15:32 1614528 ----a-w- c:\program files\exo.dll
2015-03-29 15:32 . 2015-03-29 15:32 144384 ----a-w- c:\program files\boost_filesystem.dll
2015-03-29 15:32 . 2015-03-29 15:32 1410752 ----a-w- c:\program files\dvaworkspace.dll
2015-03-29 15:32 . 2015-03-29 15:32 132096 ----a-w- c:\program files\boost_threads.dll
2015-03-29 15:32 . 2015-03-29 15:32 115904 ----a-w- c:\program files\dvaflashview.dll
2015-03-29 15:32 . 2015-03-29 15:32 1028448 ----a-w- c:\program files\axlibv7.dll
2015-03-29 15:32 . 2015-03-29 15:32 6315200 ----a-w- c:\program files\WebKit.dll
2015-03-29 15:32 . 2015-03-29 15:32 43712 ----a-w- c:\program files\adbeape.dll
2015-03-29 15:32 . 2015-03-29 15:32 428224 ----a-w- c:\program files\adobe_caps.dll
2015-03-29 15:32 . 2015-03-29 15:32 2886496 ----a-w- c:\program files\adobe_oobelib.dll
2015-03-29 15:32 . 2015-03-29 15:32 179904 ----a-w- c:\program files\adbeapecore.dll
2015-03-29 15:32 . 2015-03-29 15:32 1406144 ----a-w- c:\program files\WRServices.dll
2015-03-29 15:32 . 2015-03-29 15:32 11759296 ----a-w- c:\program files\adbeapeengine.dll
2015-03-29 15:32 . 2015-03-29 15:32 1140576 ----a-w- c:\program files\adobe_upgrade.dll
2015-03-29 15:32 . 2015-03-29 15:32 6271680 ----a-w- c:\program files\NPSWF32.dll
2015-03-29 15:32 . 2015-03-29 15:32 34496 ----a-w- c:\program files\MuseOobeCall.exe
2015-03-29 15:32 . 2015-03-29 15:32 694976 ----a-w- c:\program files\LogSession.dll
2015-03-29 15:32 . 2015-03-29 15:32 473280 ----a-w- c:\program files\LogTransport2.exe
2015-03-29 15:32 . 2015-03-29 15:32 14320320 ----a-w- c:\program files\Muse.exe
2015-03-29 15:30 . 2015-03-29 15:30 12992 ----a-w- c:\program files\CustomAction.dll
2015-03-29 15:30 . 2015-03-29 15:30 678592 ----a-w- c:\program files\AdobeXMP.dll
2015-03-29 15:30 . 2015-03-29 15:30 482496 ----a-w- c:\program files\AdobePIP.dll
2015-03-29 15:30 . 2015-03-29 15:30 423104 ----a-w- c:\program files\BIB.dll
2015-03-29 15:30 . 2015-03-29 15:30 2284736 ----a-w- c:\program files\AdobeOwl.dll
2015-03-29 15:30 . 2015-03-29 15:30 224448 ----a-w- c:\program files\AXE8SharedExpat.dll
2015-03-29 15:30 . 2015-03-29 15:30 1689280 ----a-w- c:\program files\AdobeLinguistic.dll
2015-03-29 15:30 . 2015-03-29 15:30 1373376 ----a-w- c:\program files\AIDE.dll
.
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por padrão não são apresentadas.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner64.exe" [2014-11-21 7063832]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-07-07 5515496]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2015-07-02 2303152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"SoftwareSASGeneration"= 1 (0x1)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{E37CB5F0-51F5-4395-A808-5FA49E399017}"= "c:\program files (x86)\GbPlugin\gbiehbnt.dll" [2014-09-04 1722880]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBnt]
2014-09-04 19:17 1722880 ----a-w- c:\program files (x86)\GbPlugin\gbiehbnt.dll
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\DRIVERS\lgandnetdiag64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetdiag64.sys [x]
R3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\DRIVERS\lgandnetmodem64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetmodem64.sys [x]
R3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\DRIVERS\lgandnetndis64.sys;c:\windows\SYSNATIVE\DRIVERS\lgandnetndis64.sys [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys;c:\windows\SYSNATIVE\Drivers\ssadadb.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [x]
R3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtlitescsibus.sys;c:\windows\SYSNATIVE\DRIVERS\dtlitescsibus.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe;c:\program files\Microsoft Fix it Center\Matsvc.exe [x]
R3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssadserd.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;tsusbhub;tsusbhub [x]
R4 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe;c:\program files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe [x]
R4 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe;c:\program files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe [x]
R4 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
R4 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
R4 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
R4 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R4 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S0 amdide64;amdide64;c:\windows\system32\DRIVERS\amdide64.sys;c:\windows\SYSNATIVE\DRIVERS\amdide64.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS;c:\windows\SysWOW64\drivers\HWiNFO64A.SYS [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
S2 GbpSv;Gbp Service;c:\progra~2\GbPlugin\GbpSv.exe;c:\progra~2\GbPlugin\GbpSv.exe [x]
S2 RtDashPt;Realtek DASH Protocol Driver;c:\windows\system32\DRIVERS\RtDashPt.sys;c:\windows\SYSNATIVE\DRIVERS\RtDashPt.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-07-07 22:41 991048 ----a-w- c:\program files (x86)\Google\Chrome\Application\43.0.2357.132\Installer\chrmstp.exe
.
Conteúdo da pasta 'Tarefas Agendadas'
.
2015-07-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-11 17:18]
.
2015-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-03-26 02:28]
.
2015-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-03-26 02:28]
.
2015-07-10 c:\windows\Tasks\RtlDashSrvStart.job
- c:\program files (x86)\Realtek\RtkDashClientInstaller\RtkDashClient.exe [2011-09-22 18:21]
.
2015-07-09 c:\windows\Tasks\update-S-1-5-21-2262729717-3660117857-1048417266-1000.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2015-06-30 16:29]
.
2015-07-10 c:\windows\Tasks\update-sys.job
- c:\program files (x86)\Skillbrains\Updater\Updater.exe [2015-06-30 16:29]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2015-06-13 17:17 803488 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2015-06-13 17:17 803488 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2015-06-13 17:17 803488 ----a-w- c:\program files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2015-07-07 16:30 722400 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
------- Scan Suplementar -------
.
uLocal Page = c:\windows\system32\blank.htm
uDefault_Search_URL = www.google.com
uStart Page = https://br.yahoo.com/?fr=yset_ie_syc_oracle&type=orcl_hpset
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
Trusted Zone: banestes.com.br\seg
Trusted Zone: banestes.com.br\www
Trusted Zone: banestes.com.br\wwws
TCP: DhcpNameServer = 177.84.99.254 8.8.8.8 192.168.1.1
.
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
.
[HKEY_USERS\S-1-5-21-2262729717-3660117857-1048417266-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{7BFEA890-ACEA-CF76-9A42-C3ED97A02226}*]
"haepibjdlnpibhng"=hex:69,61,62,6f,6e,65,6d,6c,6c,6c,69,6f,63,70,62,69,6a,66,
00,77
"iagaomaiknfoloicbl"=hex:63,61,6e,6f,63,6a,00,01
"iakpockhndpnndaaoh"=hex:69,61,6e,6f,6a,6a,66,63,6d,61,69,6a,65,67,66,6b,6f,6b,
00,77
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_194_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_18_0_0_194_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_194_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_18_0_0_194_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_194.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.18"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_194.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_194.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_18_0_0_194.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Outros Processos em Execução ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
.
**************************************************************************
.
Tempo para conclusão: 2015-07-10 10:34:53 - Máquina reiniciou
ComboFix-quarantined-files.txt 2015-07-10 13:34
ComboFix2.txt 2015-07-07 13:50
.
Pré-execução: 210.690.363.392 bytes disponíveis
Pós execução: 210.883.743.744 bytes disponíveis
.
- - End Of File - - A52C809D4E405772810C7B820A66C443
A36C5E4F47E84449FF07ED3517B43A31
[/code]
Daniel Sadle...
Novo Membro
Registrado
6 Mensagens
0 Curtidas