Professional Documents
Culture Documents
Combo Fix 2014
Combo Fix 2014
2 - x64
Microsoft Windows 7 Enterprise 6.1.7601.1.1252.55.1046.18.7893.6260 [GMT -2:00
]
Executando de: j:\arquivos - sadrak backup\PROGRAMAS\ComboFix.exe
AV: Avira Desktop *Disabled/Outdated* {4D041356-F94D-285F-8768-AAE50FA36859}
SP: Avira Desktop *Disabled/Outdated* {F665F2B2-DF77-27D1-BDD8-9197742422E4}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Outras Excluses )))))))))))))))))))))))
))))))))))))))))))))))))))))
.
.
c:\program files (x86)\SupTab\SuPTab.dll
c:\programdata\IePluginServices
c:\programdata\IePluginServices\PluginService.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Servios )))))))))))))))))))))
))))))))))))))))))))))))))))
.
.
-------\Service_IePluginServices
-------\Service_IePluginServices
.
.
(((((((((((((((( Arquivos/Ficheiros criados de 2014-12-03 to 2015-01-03 )))))
)))))))))))))))))))))))
.
.
2015-01-03 01:13 . 2015-01-03 01:13
-------d-----wc:\progr
am files\PopDeals
2015-01-02 23:14 . 2015-01-02 23:14
-------d-----wc:\progr
amdata\Microsoft Toolkit
2015-01-02 22:54 . 2015-01-02 22:54
-------d-----wc:\progr
am files (x86)\Common Files\Intel
2015-01-02 22:53 . 2015-01-02 22:53
-------d-----wc:\progr
am files\Common Files\Corel
2015-01-02 22:52 . 2015-01-02 22:52
-------d-----wc:\progr
am files\Common Files\Protexis
2015-01-02 22:51 . 2015-01-02 22:51
-------d-----wc:\progr
am files\Corel
2015-01-02 22:23 . 2015-01-02 22:23
-------d-----wc:\progr
amdata\Protexis
2015-01-02 22:03 . 2015-01-02 23:02
-------d-----wc:\progr
amdata\Corel
2015-01-02 22:03 . 2015-01-02 22:03
-------d-----wc:\progr
am files (x86)\Common Files\Protexis
2015-01-02 22:02 . 2010-11-16 18:24
15672 ----a-wc:\windows\syste
m32\drivers\regi.sys
2015-01-02 22:02 . 2015-01-02 22:02
-------d-----wc:\progr
am files (x86)\Corel
2015-01-02 20:48 . 2015-01-02 20:48
701616 ----a-wc:\windows\SysWo
w64\FlashPlayerApp.exe
2015-01-02 20:48 . 2015-01-02 20:48
71344 ----a-wc:\windows\SysWo
w64\FlashPlayerCPLApp.cpl
2015-01-02 20:48 . 2015-01-02 20:48
-------d-----wc:\windo
ws\system32\Macromed
2015-01-02 20:01 . 2015-01-02 20:01
-------d-----wc:\windo
ws\system32\appmgmt
w64\GEARAspi.dll
2015-01-01 17:11 . 2015-01-02 11:00
-------d-----wc:\windo
ws\SysWow64\C2MP
2015-01-01 16:25 . 2015-01-01 16:25
-------d-----wc:\progr
am files (x86)\iNTERNET Turbo
2015-01-01 16:24 . 2015-01-01 16:24
-------dc-h--wc:\progr
amdata\{2E9C94ED-C152-4D5D-8E21-AAE23373844C}
2015-01-01 16:19 . 2015-01-02 20:27
-------d-----wc:\progr
am files (x86)\Vstplugins
2015-01-01 16:19 . 2015-01-01 16:19
-------d-----wc:\progr
am files (x86)\Common Files\Digidesign
2015-01-01 16:18 . 2015-01-01 16:18
-------dc-h--wc:\progr
amdata\{95B4F0ED-951F-4D36-B068-5EC1C4C19C14}
2015-01-01 16:18 . 2015-01-02 13:58
-------d-----wc:\progr
am files\Common Files\Native Instruments
2015-01-01 16:18 . 2015-01-02 13:58
-------d-----wc:\progr
am files\Native Instruments
2015-01-01 16:18 . 2015-01-02 13:31
-------d-----wc:\progr
amdata\Native Instruments
2015-01-01 16:03 . 2015-01-01 16:03
-------d-----wc:\progr
amdata\Sony
2015-01-01 16:03 . 2015-01-01 16:03
-------d-----wc:\progr
am files (x86)\Sony
2015-01-01 15:49 . 2015-01-02 13:59
-------dc-h--wc:\progr
amdata\{582004F3-DAC7-4390-A43F-80AE1C8362C5}
2015-01-01 15:19 . 2015-01-01 15:19
-------d-----wc:\progr
am files (x86)\ASIO4ALL v2
2015-01-01 14:33 . 2015-01-01 14:34
-------d-----wc:\progr
am files (x86)\Common Files\Adobe
2015-01-01 14:32 . 2015-01-01 14:32
-------d-----wc:\progr
am files\WinRAR
2015-01-01 01:46 . 2015-01-01 01:46
-------d-----wC:\Boot
2015-01-01 01:27 . 2015-01-01 01:27
-------d-----wc:\progr
am files (x86)\Common Files\Propellerhead Software
2015-01-01 01:27 . 2015-01-01 01:27
-------d-----wc:\progr
am files\Common Files\VST3
2015-01-01 01:27 . 2015-01-01 01:27
-------d-----wc:\progr
am files\Common Files\VST2
2015-01-01 01:27 . 2015-01-01 01:27
-------d-----wc:\progr
am files (x86)\Common Files\VST3
2015-01-01 01:27 . 2015-01-01 01:27
-------d-----wc:\progr
am files\Common Files\Avid
2015-01-01 01:27 . 2015-01-01 01:27
-------d-----wc:\progr
am files\Celemony
2015-01-01 01:27 . 2015-01-01 01:27
-------d-----wc:\progr
am files (x86)\Celemony
2015-01-01 01:27 . 2014-12-31 19:53
-------d-----wc:\progr
amdata\Celemony Software GmbH
2015-01-01 01:27 . 2015-01-01 01:27
-------d--h--wc:\progr
am files (x86)\InstallShield Installation Information
2015-01-01 01:26 . 2015-01-01 01:27
-------d-----wc:\progr
am files (x86)\Common Files\Celemony
2015-01-01 01:26 . 2015-01-01 01:27
-------d-----wc:\progr
am files\Common Files\Celemony
2015-01-01 01:26 . 2012-02-17 06:38
1112064 ----a-wc:\windows\syste
m32\rdpcorets.dll
2015-01-01 01:26 . 2012-02-17 06:38
1031680 ----a-wc:\windows\syste
m32\rdpcore.dll
2015-01-01 01:26 . 2012-02-17 05:34
826880 ----a-wc:\windows\SysWo
w64\rdpcore.dll
:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft
.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\driver
s\dmvsc.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\
Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engi
ne\OSE.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\dri
vers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Microsoft Virtual 3D Video Transport Driver;c:\windows\system32\dr
ivers\Synth3dVsc.sys;c:\windows\SYSNATIVE\drivers\Synth3dVsc.sys [x]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\te
rminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATI
VE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys;
c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 tsusbhub;Remote Deskotop USB Hub;c:\windows\system32\drivers\tsusbhub.sys;c:\
windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\driver
s\rdvgkmd.sys [x]
R4 AntiVirWebService;Avira Web Protection;c:\program files (x86)\Avira\AntiVir D
esktop\avwebg7.exe;c:\program files (x86)\Avira\AntiVir Desktop\avwebg7.exe [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRI
VERS\avkmgr.sys [x]
S1 netfilter64;netfilter64;c:\windows\system32\drivers\netfilter64.sys;c:\window
s\SYSNATIVE\drivers\netfilter64.sys [x]
S2 AntiVirSchedulerService;Avira Agendamento;c:\program files (x86)\Avira\AntiVi
r Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x]
S2 avnetflt;avnetflt;c:\windows\system32\DRIVERS\avnetflt.sys;c:\windows\SYSNATI
VE\DRIVERS\avnetflt.sys [x]
S2 CouponarificService64;CouponarificService64;c:\program files (x86)\99B3576D-8
4E8-4C6C-A897-DAC84657D541\xtloowpkjv64.exe;c:\program files (x86)\99B3576D-84E8
-4C6C-A897-DAC84657D541\xtloowpkjv64.exe [x]
S2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Inst
ruments\Hardware\NIHardwareService.exe;c:\program files\Common Files\Native Inst
ruments\Hardware\NIHardwareService.exe [x]
S2 PSI_SVC_2_x64;Corel License Validation Service V2 x64, Powered by arvato;c:\p
rogram files\Common Files\Protexis\License Service\PsiService_2.exe;c:\program f
iles\Common Files\Protexis\License Service\PsiService_2.exe [x]
S2 raKXTtGYm;raKXTtGYm;c:\programdata\nDvmvxsRAjQ\raKXTtGYm.exe;c:\programdata\n
DvmvxsRAjQ\raKXTtGYm.exe [x]
S2 regi;regi;c:\windows\system32\drivers\regi.sys;c:\windows\SYSNATIVE\drivers\r
egi.sys [x]
S2 WindowsMangerProtect;WindowsMangerProtect Service;c:\programdata\WindowsMange
rProtect\ProtectWindowsManager.exe;c:\programdata\WindowsMangerProtect\ProtectWi
ndowsManager.exe [x]
S3 IntcDAud;udio Intel(R) para telas;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\
windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controlle
r;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64
.sys [x]
.
.
--- =Outros Servios/Drivers Na Memria --.
*NewlyCreated* - WS2IFSL
.
Contedo da pasta 'Tarefas Agendadas'
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.16"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8
F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8
F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8
F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Outros Processos em Execuo -----------------------.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
.
**************************************************************************
.
Tempo para concluso: 2015-01-02 23:44:23 - Mquina reiniciou
ComboFix-quarantined-files.txt 2015-01-03 01:44
ComboFix2.txt 2013-12-17 11:06
ComboFix3.txt 2013-12-10 23:44
.
Pr-execuo: 139.364.507.648 bytes disponveis
Ps execuo: 138.590.281.728 bytes disponveis
.
- - End Of File - - C577D824B767F2BFCA89C77B8D7BE449
A36C5E4F47E84449FF07ED3517B43A31