• Comunicados

    • Gabriel Torres

      Seja um moderador do Clube do Hardware!   12-02-2016

      Prezados membros do Clube do Hardware, Está aberto o processo de seleção de novos moderadores para diversos setores ou áreas do Clube do Hardware. Os requisitos são:   Pelo menos 500 posts e um ano de cadastro; Boa frequência de participação; Ser respeitoso, cordial e educado com os demais membros; Ter bom nível de português; Ter razoável conhecimento da área em que pretende atuar; Saber trabalhar em equipe (com os moderadores, coordenadores e administradores).   Os interessados deverão enviar uma mensagem privada para o usuário @Equipe Clube do Hardware com o título "Candidato a moderador". A mensagem deverá conter respostas às perguntas abaixo:   Qual o seu nome completo? Qual sua data de nascimento? Qual sua formação/profissão? Já atuou como moderador em algo outro fórum, se sim, qual? De forma sucinta, explique o porquê de querer ser moderador do fórum e conte-nos um pouco sobre você.   OBS: Não se trata de função remunerada. Todos que fazem parte do staff são voluntários.

Felipe A.

Membros Juniores
  • Total de itens

    1
  • Registro em

  • Última visita

  • Qualificações

    N/D

Reputação

0

Sobre Felipe A.

Informações gerais

  • Cidade e Estado Porto Alegre/RS
  • Sexo Masculino
  1. Uso Avast antivirus, e hoje ele bloqueou a instalação de algo do gênero "[...]SysWow64.exe". Passei Malwarebytes e ComboFix que gerou um relatório, o qual copio abaixo e aguardo apoio dos Analistas de segurança, Obrigado. RELATÓRIO COMBOFIX: ---------------------------------------------------------------------- ComboFix 17-04-16.01 - Felipe 20/04/2017 17:38:32.1.2 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.55.1046.18.3966.2517 [GMT -3:00] Executando de: c:\users\Felipe\Desktop\ComboFix.exe AV: Avast Antivirus *Disabled/Updated* {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AV: Malwarebytes *Disabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B} SP: Avast Antivirus *Disabled/Updated* {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} SP: Malwarebytes *Disabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} SP: Spybot - Search and Destroy *Disabled/Outdated* {A16C3F68-9280-E053-1818-342707FECF4D} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((( Arquivos/Ficheiros criados de 2017-03-20 to 2017-04-20 )))))))))))))))))))))))))))) . . 2017-04-20 21:12 . 2017-04-20 21:12 -------- d-----w- c:\users\Default\AppData\Local\temp 2017-04-20 20:32 . 2017-04-20 20:32 16712 ----a-w- c:\windows\system32\drivers\PROCEXP113.SYS 2017-04-20 20:31 . 2017-04-20 20:31 -------- d-----w- c:\programdata\SWCUTemp 2017-04-20 20:15 . 2017-04-20 20:27 82208 ----a-w- c:\windows\system32\drivers\mwac.sys 2017-04-20 19:59 . 2013-09-20 13:49 21040 ----a-w- c:\windows\system32\sdnclean64.exe 2017-04-20 19:59 . 2017-04-20 19:59 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2017-04-20 19:59 . 2017-04-20 20:13 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2 2017-04-20 19:45 . 2017-04-20 20:27 186304 ----a-w- c:\windows\system32\drivers\MBAMChameleon.sys 2017-04-20 19:45 . 2017-04-20 20:27 111544 ----a-w- c:\windows\system32\drivers\farflt.sys 2017-04-20 19:45 . 2017-04-20 20:27 43968 ----a-w- c:\windows\system32\drivers\mbam.sys 2017-04-20 19:45 . 2017-04-20 20:27 251840 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2017-04-20 19:45 . 2017-02-24 09:23 77408 ----a-w- c:\windows\system32\drivers\mbae64.sys 2017-04-20 19:45 . 2017-04-20 19:45 -------- d-----w- c:\program files\Malwarebytes 2017-04-20 19:41 . 2017-04-20 19:41 -------- d-----w- c:\windows\SysWow64\config\systemprofile\opera autoupdate 2017-04-13 11:54 . 2017-04-13 11:54 -------- d-----w- c:\program files (x86)\Skillbrains 2017-04-09 16:17 . 2017-04-10 22:38 -------- d-----w- c:\users\Felipe\VirtualBox VMs 2017-04-09 16:16 . 2017-04-12 14:52 -------- d-----w- c:\users\Felipe\.VirtualBox 2017-04-05 11:50 . 2017-04-05 11:50 399944 ----a-w- c:\windows\system32\aswBoot.exe 2017-03-30 12:50 . 2017-04-10 21:46 -------- d-----w- c:\users\Felipe\AppData\Roaming\Ventrilo 2017-03-30 12:49 . 2017-03-30 12:49 -------- d-----w- c:\program files\Ventrilo 2017-03-30 12:49 . 2017-03-30 12:49 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard 2017-03-22 14:16 . 2017-04-11 10:55 527816 ----a-w- c:\program files (x86)\Mozilla Firefox\minidump-analyzer.exe 2017-03-22 13:11 . 2017-03-22 13:11 -------- d-----r- C:\ESD 2017-03-22 12:56 . 2017-03-22 12:56 -------- d-----w- C:\$Windows.~WS 2017-03-22 12:49 . 2017-03-22 12:49 -------- d-----w- C:\$WINDOWS.~BT . . . ((((((((((((((((((((((((((((((((((((( Relatório Find3M )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2017-04-05 11:50 . 2016-06-22 11:02 339696 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2017-04-05 11:50 . 2016-06-22 11:02 164064 ----a-w- c:\windows\system32\drivers\aswStm.sys 2017-04-05 11:50 . 2016-06-22 11:02 556784 ----a-w- c:\windows\system32\drivers\aswSP.sys 2017-04-05 11:50 . 2016-06-22 11:02 75704 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2017-04-05 11:50 . 2016-06-22 11:02 127112 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2017-04-05 11:50 . 2016-06-22 11:02 38296 ----a-w- c:\windows\system32\drivers\aswHwid.sys 2017-04-05 11:50 . 2016-06-22 11:02 101152 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2017-04-05 11:49 . 2016-06-22 11:05 32600 ----a-w- c:\windows\system32\drivers\aswKbd.sys 2017-04-05 11:49 . 2016-06-22 11:02 1005048 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2017-04-05 11:49 . 2017-02-07 11:40 48528 ----a-w- c:\windows\system32\drivers\aswbuniva.sys 2017-04-05 11:49 . 2017-02-07 11:40 334088 ----a-w- c:\windows\system32\drivers\aswbloga.sys 2017-04-05 11:49 . 2017-02-07 11:40 189768 ----a-w- c:\windows\system32\drivers\aswbidsha.sys 2017-04-05 11:49 . 2017-02-07 11:40 307736 ----a-w- c:\windows\system32\drivers\aswbidsdrivera.sys 2017-03-17 12:53 . 2016-05-23 20:54 802904 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2017-03-17 12:53 . 2016-05-23 20:54 144472 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2017-03-15 19:17 . 2017-03-15 19:17 205440 ----a-w- c:\windows\system32\drivers\VBoxNetLwf.sys 2017-03-15 19:17 . 2017-03-15 19:17 131144 ----a-w- c:\windows\system32\drivers\VBoxNetAdp6.sys . . (((((((((((((((((((((((((( Pontos de Carregamento do Registro ))))))))))))))))))))))))))))))))))))))) . . *Nota* entradas vazias e legítimas por padrão não são apresentadas. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PAexec] @="Service" . R1 VBoxNetAdp;VirtualBox NDIS 6.0 Miniport Service;c:\windows\system32\DRIVERS\VBoxNetAdp6.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp6.sys [x] R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [x] R3 aswbIDSAgent;aswbIDSAgent;c:\program files\AVAST Software\Avast\x64\aswidsagenta.exe;c:\program files\AVAST Software\Avast\x64\aswidsagenta.exe [x] R3 aswHdsKe;aswHdsKe;c:\windows\system32\drivers\aswHdsKe.sys;c:\windows\SYSNATIVE\drivers\aswHdsKe.sys [x] R3 aswHwid;aswHwid;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 PAExec;PAExec;c:\windows\PAExec.exe;c:\windows\PAExec.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Serviço de Tecnologias de Ativação do Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 FoxitReaderService;Foxit Reader Service;c:\program files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe;c:\program files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [x] S0 aswbidsh;aswbidsh;c:\windows\\SystemRoot\system32\drivers\aswbidsha.sys;c:\windows\\SystemRoot\system32\drivers\aswbidsha.sys [x] S0 aswblog;aswblog;c:\windows\\SystemRoot\system32\drivers\aswbloga.sys;c:\windows\\SystemRoot\system32\drivers\aswbloga.sys [x] S0 aswbuniv;aswbuniv;c:\windows\\SystemRoot\system32\drivers\aswbuniva.sys;c:\windows\\SystemRoot\system32\drivers\aswbuniva.sys [x] S0 aswRvrt;aswRvrt;c:\windows\\SystemRoot\system32\drivers\aswRvrt.sys;c:\windows\\SystemRoot\system32\drivers\aswRvrt.sys [x] S0 aswVmm;aswVmm;c:\windows\\SystemRoot\system32\drivers\aswVmm.sys;c:\windows\\SystemRoot\system32\drivers\aswVmm.sys [x] S1 aswbidsdriver;aswbidsdriver;c:\windows\system32\drivers\aswbidsdrivera.sys;c:\windows\SYSNATIVE\drivers\aswbidsdrivera.sys [x] S1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys;c:\windows\SYSNATIVE\drivers\aswKbd.sys [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x] S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x] S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . --- =Outros Serviços/Drivers Na Memória --- . *Deregistered* - ESProtectionDriver . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2017-03-17 12:58 1319256 ----a-w- c:\program files (x86)\Google\Chrome\Application\57.0.2987.110\Installer\chrmstp.exe . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw] @="{472083B0-C522-11CF-8763-00608CC02F24}" . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2017-04-05 11:50 1529352 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw] @="{472083B0-C522-11CF-8763-00608CC02F24}" . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2017-04-05 11:50 1529352 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvLaunch.exe" [2017-04-05 213824] . ------- Scan Suplementar ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 10.0.0.1 FF - ProfilePath - c:\users\Felipe\AppData\Roaming\Mozilla\Firefox\Profiles\62zk7gn7.default\ . - - - - ORFÃOS REMOVIDOS - - - - . Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe Notify-SDWinLogon - SDWinLogon.dll . . . --------------------- CHAVES DO REGISTRO BLOQUEADAS --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Tempo para conclusão: 2017-04-20 18:15:59 ComboFix-quarantined-files.txt 2017-04-20 21:15 . Pré-execução: 56.678.445.056 bytes disponíveis Pós execução: 56.519.098.368 bytes disponíveis . - - End Of File - - BAC26A9549EFB81EB37F3461EA2CC951 EA923EB0EC0060F1451E9AD7B5762CFE