Combo Fix
Combo Fix
8 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.55.1046.18.8151.6084 [GMT -3:
00]
Executando de: c:\users\w7\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E
4E1F341F6}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B9
69A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Outras Excluses )))))))))))))))))))))))
))))))))))))))))))))))))))))
.
.
c:\users\w7\AppData\Local\Microsoft\Windows\Temporary Internet Files\plot.log
c:\windows\msxml4-KB954430-enu.LOG
c:\windows\msxml4-KB973688-enu.LOG
.
.
(((((((((((((((( Arquivos/Ficheiros criados de 2013-07-28 to 2013-08-30 )))))
)))))))))))))))))))))))
.
.
2013-08-30 19:41 . 2013-08-30 19:41
-------d-----wc:\users
\LogMeInRemoteUser\AppData\Local\temp
2013-08-30 19:41 . 2013-08-30 19:41
-------d-----wc:\users
\Default\AppData\Local\temp
2013-08-30 19:14 . 2013-08-30 19:28
-------d-----wC:\Progr
ama
2013-08-30 19:14 . 2013-08-30 19:14
76232 ----a-wc:\programdata\M
icrosoft\Microsoft Antimalware\Definition Updates\{3963838C-27B9-46F7-9A36-8C285
0EF7B96}\offreg.dll
2013-08-30 19:13 . 2013-08-30 19:13
-------d-----wC:\Ivone
2013-08-30 19:13 . 2013-08-30 19:13
-------d-----wC:\Dna.
Yvone
2013-08-30 19:13 . 2013-08-30 19:13
-------d-----wC:\Mario
2013-08-30 18:41 . 2013-08-06 08:58
9515512 ----a-wc:\programdata\M
icrosoft\Microsoft Antimalware\Definition Updates\{3963838C-27B9-46F7-9A36-8C285
0EF7B96}\mpengine.dll
2013-08-30 12:05 . 2013-08-30 12:20
-------d-----wc:\users
\w7\AppData\Local\Symbian-Toys.com
2013-08-30 12:05 . 2013-08-30 12:05
-------d-----wc:\users
\w7\AppData\Roaming\NaviFirmPlus
2013-08-30 11:51 . 2005-08-03 19:05
35892 ----a-wc:\windows\SysWo
w64\SER9PL.sys
2013-08-30 11:51 . 2005-08-03 19:04
26719 ----a-wc:\windows\SysWo
w64\SERSPL.VXD
2013-08-29 12:51 . 2013-08-06 08:58
9515512 ----a-wc:\programdata\M
icrosoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-08-28 14:29 . 2013-08-28 14:30
-------d-----wc:\users
\w7\AppData\Local\Nokia
2013-08-28 14:29 . 2013-08-30 11:45
-------d-----wc:\users
\w7\AppData\Roaming\PC Suite
2013-08-28 14:29 . 2013-08-28 14:29
-------d-----wc:\progr
amdata\PC Suite
2013-08-28 14:28 . 2013-08-30 12:03
-------d-----wc:\progr
amdata\Nokia
2013-08-28 14:28 . 2013-08-30 11:55
-------d-----wc:\progr
am files (x86)\Common Files\Nokia
-------26112
d-----w----a-w-
c:\progr
c:\windows\syste
--------
dc----w-
c:\windo
--------
d-----w-
c:\progr
66560
----a-w-
c:\windows\syste
--------
d-----w-
c:\progr
78185248
----a-w-
c:\windo
46080
----a-w-
c:\windows\syste
367616 ----a-w-
c:\windows\syste
295424 ----a-w-
c:\windows\SysWo
34304
----a-w-
c:\windows\SysWo
100864 ----a-w-
c:\windows\syste
70656
c:\windows\SysWo
----a-w-
Relatrio Find3M
)))))))))))))))))))))))
692104 ----a-w-
c:\windows\SysWo
71048
----a-w-
c:\windows\SysWo
274432 ----a-w-
c:\windows\SysWo
262144 ----a-w-
c:\windows\SysWo
253952 ----a-w-
c:\windows\SysWo
155648 ----a-w-
c:\windows\SysWo
469
----a-w-
c:\windows\del_h
867240 ----a-w-
c:\windows\SysWo
789416 ----a-w-
c:\windows\SysWo
96168
----a-w-
c:\windows\SysWo
8192
----a-w-
c:\windows\SysWo
77824
----a-w-
c:\windows\KMSer
107368 ----a-w-
c:\windows\syste
35656
c:\windows\syste
----a-w-
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800
_94_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_8_800_94_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C40800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_8_800_94.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B
0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B
0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B
0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC108002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Tempo para concluso: 2013-08-30 16:44:42
ComboFix-quarantined-files.txt 2013-08-30 19:44
.
Pr-execuo: 43.356.303.360 bytes disponveis
Ps execuo: 43.345.874.944 bytes disponveis
.
- - End Of File - - 9383C98C1420E2B24635E2ECB248B177
A36C5E4F47E84449FF07ED3517B43A31