Logo Hardware.com.br
elciosouza
elciosouza Veterano Registrado
1.4K Mensagens 26 Curtidas

Análise de Log meu PC

#1 Por elciosouza 24/04/2013 - 01:57
Results of screen317's Security Check version 0.99.63
Windows 7 Service Pack 1 x64 (UAC is disabled!)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
avast! Antivirus
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware versão 1.75.0.1300
Java(TM) 6 Update 31
Java 7 Update 17
Java version out of Date!
Adobe Flash Player 11.7.700.169
Adobe Reader 10.1.6 Adobe Reader out of Date!
Mozilla Firefox (20.0.1)
Google Chrome 27.0.1453.47
Google Chrome 27.0.1453.56
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
AVAST Software Avast AvastUI.exe
AVAST Software Avast AvastSvc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: =
````````````````````End of Log``````````````````````



http://cjoint.com/?3Dyg16PkSTj
http://cjoint.com/?3Dyg2EGInHc
http://cjoint.com/?3Dyg1nOIvfw
Wings
Wings Cyber Highlander Registrado
20.3K Mensagens 1.2K Curtidas
#2 Por Wings
24/04/2013 - 08:21
Olá elciosouza



veja.png Execute o OTL

*Copie e cole as linhas em marrom no espaço abaixo de Exames Personalizados/Correções


:OTL
IE - HKU\S-1-5-21-1321702710-3613106056-3490970535-1001\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://search.babylon.com/?affID=113480&tt=120812_bandext_3212_6&babsrc=HP_ss&mntrId=94850119000000000000003067c1e603
IE - HKU\S-1-5-21-1321702710-3613106056-3490970535-1001\..\SearchScopes,Backup.Old.DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1321702710-3613106056-3490970535-1001\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-1321702710-3613106056-3490970535-1001\..\SearchScopes\{17624D33-5CB4-5C63-7ADA-04DAE8419430}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=113480&tt=120812_bandext_3212_6&babsrc=SP_ss&mntrId=94850119000000000000003067c1e603
O33 - MountPoints2\{f30d8695-e566-11e1-8aac-003067c1e603}\Shell - "" = AutoRun
O33 - MountPoints2\{f30d8695-e566-11e1-8aac-003067c1e603}\Shell\AutoRun\command - "" = D:\autorun.exe
O33 - MountPoints2\{f30d8695-e566-11e1-8aac-003067c1e603}\Shell\Option1\Command - "" = D:\autorun.exe
O33 - MountPoints2\{f30d869d-e566-11e1-8aac-003067c1e603}\Shell - "" = AutoRun
O33 - MountPoints2\{f30d869d-e566-11e1-8aac-003067c1e603}\Shell\AutoRun\command - "" = D:\autorun.exe
O33 - MountPoints2\{f30d869d-e566-11e1-8aac-003067c1e603}\Shell\Option1\Command - "" = D:\autorun.exe
[2012/04/22 17:36:28 | 000,000,000 | ---D | M] -- C:\Users\OK\AppData\Roaming\Babylon
[2013/02/07 18:52:19 | 000,000,000 | ---D | M] -- C:\Users\OK\AppData\Roaming\baidu

:Commands
[emptytemp]


*Clique [Consertar]

Imagem

*Clique [OK] para reiniciar o PC

Imagem

*Ao reiniciar, surgirá uma janela de Aviso de Segurança do Windows, perguntando se deseja executar o OTL. Clique [Executar]

Imagem

*Cole o relatório apresentado após a inicialização do Windows


veja.png Baixe o AdwCleaner (...de Xplode) e salve-o no Desktop (Área de Trabalho)

*Execute-o e clique [Remover]

Imagem

*Salve qualquer trabalho aberto e clique [OK]

Imagem

*Caso seja solicitada a reinicialização do PC, clique [OK] para reiniciar

*Cole o relatório apresentado
elciosouza
elciosouza Veterano Registrado
1.4K Mensagens 26 Curtidas
#3 Por elciosouza
24/04/2013 - 21:48
All processes killed
========== OTL ==========
HKU\S-1-5-21-1321702710-3613106056-3490970535-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\BrowserMngr Start Page| /E : value set successfully!
HKEY_USERS\S-1-5-21-1321702710-3613106056-3490970535-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKEY_USERS\S-1-5-21-1321702710-3613106056-3490970535-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-1321702710-3613106056-3490970535-1001\Software\Microsoft\Internet Explorer\SearchScopes\{17624D33-5CB4-5C63-7ADA-04DAE8419430}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{17624D33-5CB4-5C63-7ADA-04DAE8419430}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f30d8695-e566-11e1-8aac-003067c1e603}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f30d8695-e566-11e1-8aac-003067c1e603}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f30d8695-e566-11e1-8aac-003067c1e603}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f30d8695-e566-11e1-8aac-003067c1e603}\ not found.
File D:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f30d8695-e566-11e1-8aac-003067c1e603}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f30d8695-e566-11e1-8aac-003067c1e603}\ not found.
File D:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f30d869d-e566-11e1-8aac-003067c1e603}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f30d869d-e566-11e1-8aac-003067c1e603}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f30d869d-e566-11e1-8aac-003067c1e603}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f30d869d-e566-11e1-8aac-003067c1e603}\ not found.
File D:\autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f30d869d-e566-11e1-8aac-003067c1e603}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f30d869d-e566-11e1-8aac-003067c1e603}\ not found.
File D:\autorun.exe not found.
C:\Users\OK\AppData\Roaming\Babylon folder moved successfully.
C:\Users\OK\AppData\Roaming\baidu\hao123-br folder moved successfully.
C:\Users\OK\AppData\Roaming\baidu folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Diego - LordRock

User: OK
->Temp folder emptied: 396863538 bytes
->Temporary Internet Files folder emptied: 135541061 bytes
->Java cache emptied: 2189619 bytes
->FireFox cache emptied: 368824599 bytes
->Google Chrome cache emptied: 12460193 bytes
->Opera cache emptied: 38456273 bytes
->Flash cache emptied: 21799 bytes

User: Public

User: Todos os Usuários

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Usuário Padrão
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 102156139 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 104358 bytes
RecycleBin emptied: 170454 bytes

Total Files Cleaned = 1.008,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 04242013_212117

Files\Folders moved on Reboot...
C:\Users\OK\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\OK\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
C:\Windows\temp\CLDigitalHome\CLMS_AGENT_LOG1.txt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
elciosouza
elciosouza Veterano Registrado
1.4K Mensagens 26 Curtidas
#5 Por elciosouza
24/04/2013 - 21:50
# AdwCleaner v2.202 - Relatório criado em 24/04/2013 às 21:42:55
# Atualizado em 23/04/2013 por Xplode
# Sistema Operacional : Windows 7 Ultimate Service Pack 1 (64 bits)
# Usuário : OK - OK-PC
# Modo de Boot : Normal
# Executado de : C:\Users\OK\Desktop\AdwCleaner.exe
# Opção [Remover]


***** [Serviços] *****


***** [Arquivos/Pastas] *****

Arquivo Removido : C:\user.js
Pasta Removido : C:\Program Files (x86)\Mozilla Firefox\Extensions\quickstores@quickstores.de
Pasta Removido : C:\Program Files (x86)\Smartdl
Pasta Removido : C:\ProgramData\Ask
Pasta Removido : C:\ProgramData\Babylon
Pasta Removido : C:\ProgramData\Browser Manager
Pasta Removido : C:\Users\OK\AppData\LocalLow\AskToolbar
Pasta Removido : C:\Windows\assembly\GAC_MSIL\QuickStoresToolbar
Pasta Removido : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

***** [Registro] *****

Chave Removida : HKCU\Software\DataMngr
Chave Removida : HKCU\Software\InstallCore
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Chave Removida : HKCU\Software\Softonic
Chave Removida : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Chave Removida : HKLM\Software\AskToolbar
Chave Removida : HKLM\Software\Babylon
Chave Removida : HKLM\Software\BrowserMngr
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Chave Removida : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Chave Removida : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Chave Removida : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Chave Removida : HKLM\SOFTWARE\Classes\escort.escortIEPane
Chave Removida : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Chave Removida : HKLM\SOFTWARE\Classes\f
Chave Removida : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Chave Removida : HKLM\Software\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Chave Removida : HKLM\SOFTWARE\Classes\Prod.cap
Chave Removida : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Chave Removida : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Chave Removida : HKLM\Software\DataMngr
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}
Chave Removida : HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh
Chave Removida : HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
Chave Removida : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Valor Removida : HKCU\Software\Microsoft\Internet Explorer\Main [BrowserMngr Start Page]
Valor Removida : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [BrowserMngrDefaultScope]
Valor Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}]
Valor Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]

***** [Navegadores] *****

-\\ Internet Explorer v10.0.9200.16537

[OK] Registro está limpo.

-\\ Mozilla Firefox v20.0.1 (pt-BR)

Arquivo : C:\Users\OK\AppData\Roaming\Mozilla\Firefox\Profiles\rdqve1rc.default-1365941298565\prefs.js

[OK] Arquivo está limpo.

-\\ Google Chrome v27.0.1453.65

Arquivo : C:\Users\OK\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Arquivo está limpo.

-\\ Opera v12.15.1748.0

Arquivo : C:\Users\OK\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] Arquivo está limpo.

*************************

AdwCleaner[S1].txt - [8432 octets] - [24/04/2013 21:42:55]

########## EOF - C:\AdwCleaner[S1].txt - [8492 octets] ##########
Wings
Wings Cyber Highlander Registrado
20.3K Mensagens 1.2K Curtidas
#6 Por Wings
24/04/2013 - 21:56
veja.png Execute o AdwCleaner, clique [Desinstalar] > [Sim]


veja.png Delete o Security Check


veja.png Execute o OTL

*Clique [Limpeza] > [OK]

*O PC será reiniciado


veja.png Abra o Windows Explorer

*Clique Área de Trabalho

Imagem

*Clique Organizar > Opções de pasta e pesquisa

Imagem

*Clique [Modo de Exibição] e selecione Não mostrar arquivos, pastas ou unidades ocultas

Imagem

*Clique [Aplicar] > [OK]


veja.png Desinstale

Java(TM) 6 Update 31
Java 7 Update 17
Adobe Reader 10.1.6


veja.png Instale a última versão do Java


veja.png Instale a última versão do Adobe Reader


O PC está limpo.


Um abraço...tchau.gif
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal