Deixa eu te mostrar:
ComboFix 13-05-07.02 - Thiago 07/05/2013 22:30:12.1.2 - x86 NETWORK
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.55.1033.18.1789.1163 [GMT -3:00]
Executando de: c:\users\Thiago\Downloads\ComboFix.exe
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Criado um novo ponto de restauração
.
.
(((((((((((((((( Arquivos/Ficheiros criados de 2013-04-08 to 2013-05-08 ))))))))))))))))))))))))))))
.
.
2013-05-08 03:32 . 2013-05-07 22:38 -------- d-----w- c:\windows\Panther
2013-05-08 01:33 . 2013-05-08 01:33 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-05-08 01:20 . 2013-05-08 01:20 -------- d-----w- c:\program files\PokerStars
2013-05-08 01:19 . 2013-05-08 01:19 -------- d-----w- c:\program files\Microsoft
2013-05-08 01:18 . 2013-05-08 01:18 -------- d-----w- c:\program files\Windows Live SkyDrive
2013-05-08 01:18 . 2013-05-08 01:19 -------- d-----w- c:\program files\Windows Live
2013-05-08 01:18 . 2013-05-08 01:18 -------- d-----w- c:\windows\PCHEALTH
2013-05-08 01:00 . 2013-05-08 01:00 -------- d-----w- c:\program files\Common Files\Windows Live
2013-05-08 00:32 . 2013-05-08 00:32 -------- d-----w- C:\HM2Archive
2013-05-08 00:29 . 2013-05-08 00:29 -------- d-----w- c:\programdata\XHEO INC
2013-05-08 00:29 . 2013-05-08 00:33 -------- d-----w- c:\program files\Holdem Manager 2
2013-05-08 00:07 . 2009-11-25 15:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2013-05-08 00:07 . 2009-11-25 15:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2013-05-08 00:07 . 2009-11-25 15:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2013-05-08 00:07 . 2009-11-25 15:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2013-05-08 00:07 . 2009-11-25 15:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2013-05-07 23:56 . 2013-05-07 23:56 -------- d-----w- C:\b72aad946fcd5016abbe348c960984e0
2013-05-07 23:56 . 2013-05-08 00:13 -------- d-----w- c:\users\postgres
2013-05-07 23:53 . 2013-05-07 23:56 -------- d-----w- C:\postgreSQL
2013-05-07 23:25 . 2013-05-07 23:24 84744 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2013-05-07 23:25 . 2013-05-07 23:24 37352 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2013-05-07 23:25 . 2013-05-07 23:24 135136 ----a-w- c:\windows\system32\drivers\avipbb.sys
2013-05-07 23:25 . 2013-05-07 23:25 -------- d-----w- c:\programdata\Avira
2013-05-07 23:25 . 2013-05-07 23:25 -------- d-----w- c:\program files\Avira
2013-05-07 23:19 . 2013-05-08 00:29 -------- d-----w- c:\program files\PSQLINSTALL
2013-05-07 22:55 . 2013-05-07 22:55 -------- d-----w- c:\programdata\NVIDIA
2013-05-07 22:52 . 2013-05-08 01:19 -------- d-sh--w- c:\windows\Installer
2013-05-07 22:52 . 2009-07-21 03:48 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2013-05-07 22:45 . 2013-05-07 22:45 -------- d-----w- c:\program files\Google
2013-05-07 22:42 . 2013-05-08 01:20 -------- d-----w- c:\windows\system32\wbem\Performance
2013-05-07 22:38 . 2013-05-08 01:20 -------- d-----w- c:\users\Thiago
2013-05-07 22:38 . 2013-05-07 22:38 -------- d-----w- C:\Recovery
.
.
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por padrão não são apresentadas.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-18 13797920]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2013-05-07 345312]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
R1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
R2 AntiVirSchedulerService;Avira Agendamento;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
R2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;c:/postgreSQL/bin/pg_ctl.exe runservice -N postgresql-8.4 -D c:/postgreSQL/data -w [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-05-07 22:45 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Conteúdo da pasta 'Tarefas Agendadas'
.
2013-05-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-05-07 22:45]
.
.
------- Scan Suplementar -------
.
TCP: DhcpNameServer = 192.168.25.1
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4]
"ImagePath"="c:/postgreSQL/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"c:/postgreSQL/data\" -w"
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG*]
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
"Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d,
bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Tempo para conclusão: 2013-05-07 22:35:00
ComboFix-quarantined-files.txt 2013-05-08 01:35
.
Pré-execução: 302.210.228.224 bytes free
Pós execução: 301.966.221.312 bytes free
.
- - End Of File - - 726E94483554F3DBE2A82DC89A4D37D8