Logo Hardware.com.br
Andreatta
Andreatta Tô em todas Registrado
2.4K Mensagens 39 Curtidas

Ola , estou infectado.

#1 Por Andreatta 27/06/2013 - 18:14
joram disse:
Bom Dia! Andreatta

< C:\_OTL\MovedFiles\*.log << Eis o caminho ao relatório!

|- O log da OTL que foi pedido,não é o de diagnóstico.
|- Poste o log que resultou,após a execução do script.

|- Baixe: < Imagem > ( ... by sUBs )
|- Salve-o no desktop! ( Área de trabalho! )
|- Ps: Desabilite seu antivírus,antispywares e/ou firewall. ( Menos o do Windows! )
|- Feche algum programa/arquivo que esteja aberto.
|- Feche,também,seu navegador! ( IE,Firefox,Opera ou Google Chrome )
|- Ps: Esteja conectado(a) à Internet. <- Importante!
|- É preciso estar logado no sistema com privilégios de administrador.
|- Execute ComboFix.exe,com um duplo clique.
|- Ps: Instale o "Console de Recuperação",caso seja solicitado! <- Somente XP!
|- Ps: Ficará,portanto,à seu critério optar por sua instalação.

Imagem

|- Surgindo alguma mensagem de erro,execute ComboFix.exe em Modo de Segurança com rede.
|- Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador.
|- Abrir-se-á a janela Auto Scan.

Imagem

|- Aguarde a finalização de todas as Etapas.
|- Durante o scan,evite utilizar o mouse ou teclado!
|- Concluindo,poste: C:\ComboFix.txt

|- Ao ocorrer este erro,basta reiniciar o computador!
|- "ComboFix é uma ferramenta que pode danificar o sistema. Utilize-o,somente,sob supervisão de analistas de segurança."

-/-

|- Baixe: < Complete Internet Repair >
|- Extraia o conteúdo e execute o arquivo "CIntRep.exe".

Imagem

|- Marque,apenas,as checkbox:

Reset Internet Protocol (TCP/IP)
Repair Winsock (Reset Catalog)
Renew Internet Connections
Flush DNS Resolver Cache
Restore the default hosts file


|- Clique "Go!".
|- Ao concluir,reinicie o computador!
|- À seguir,acesse a pasta "Complete Internet Repair" >> "Logging".
|- Duplo-clique em "CIntRep.log".
|- Poste o log resultante!
|- Ps: Verifique se já pode ter acesso ao jogo!

A+
O log do OTL, e estou executando os outros programas.


All processes killed========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-160635771-3247580687-3712117055-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{472734EA-242A-422b-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422b-ADF8-83D1E48CC825}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\Adobe Reader\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@fancyguo.com/FancyGame,version=1.0.0.1\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95525BD9-6136-4A26-8263-9CEE295D442D}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95525BD9-6136-4A26-8263-9CEE295D442D}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{326E768D-4182-46FD-9C16-1449A49795F4}\ not found.
Registry value HKEY_USERS\S-1-5-21-160635771-3247580687-3712117055-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E0301295-AB3E-4AF3-979F-3D453C5F9F48} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0301295-AB3E-4AF3-979F-3D453C5F9F48}\ not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully.
File Protocol\Handler\msdaipp - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\0x00000001\ not found.
File Protocol\Handler\msdaipp\0x00000001 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\oledb\ not found.
File Protocol\Handler\msdaipp\oledb - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\mso-offdap\ deleted successfully.
File Protocol\Handler\mso-offdap - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\mso-offdap11\ deleted successfully.
File Protocol\Handler\mso-offdap11 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.
File Protocol\Handler\skype4com - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value found not found.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29\sysopt folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29\Run\Disable folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29\Run folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29\Plugins\Plugin.LeakRepair\Hotfix folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29\Plugins\Plugin.LeakRepair folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29\Plugins folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29 folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster folder moved successfully.
C:\ProgramData\Baidu Security folder moved successfully.
Folder C:\Users\wagner\AppData\Roaming\Baidu\ not found.
Folder C:\ProgramData\Baidu\ not found.
C:\Users\wagner\AppData\Roaming\Awesomium\Default\Cache folder moved successfully.
C:\Users\wagner\AppData\Roaming\Awesomium\Default folder moved successfully.
C:\Users\wagner\AppData\Roaming\Awesomium folder moved successfully.
Folder C:\Users\wagner\AppData\Roaming\Baidu\ not found.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Uninstall\Baidu PC Faster Uninstall HK\0 folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Uninstall\Baidu PC Faster Uninstall HK folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Uninstall\Baidu PC Faster Uninstall\0 folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Uninstall\Baidu PC Faster Uninstall folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Uninstall folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Run\Disable folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Run folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\RpData folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\PopMsg folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29 folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\1.19.0.2\RpData folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\1.19.0.2 folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security folder moved successfully.
Folder C:\Users\wagner\AppData\Roaming\Awesomium\ not found.
Folder C:\Users\wagner\AppData\Roaming\Baidu\ not found.
Folder C:\Users\wagner\AppData\Roaming\Baidu Security\ not found.
C:\Users\wagner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\Windows\4F64A46D67F74497AEA2313D4305A5F6.TMP\WiseCustomCall.dll deleted successfully.
C:\Windows\4F64A46D67F74497AEA2313D4305A5F6.TMP\WiseCustomCalla.dll deleted successfully.
C:\Windows\4F64A46D67F74497AEA2313D4305A5F6.TMP\WiseData.ini deleted successfully.
C:\Windows\4F64A46D67F74497AEA2313D4305A5F6.TMP folder deleted successfully.
C:\Windows\msdownld.tmp folder deleted successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\"Gopher"|"gopher://" /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\""|""%1" %*" /E : value set successfully!
========== FILES ==========
< type C:\AdwCleaner[S1].txt /C >
C:\Users\wagner\Desktop\cmd.bat deleted successfully.
C:\Users\wagner\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point

[EMPTYTEMP]

User: All Users

User: Default
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 57472 bytes

User: Default User
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Todos os Usuários

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: UpdatusUser.wagner-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Usuário Padrão
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: wagner
->Temp folder emptied: 297725 bytes
->Temporary Internet Files folder emptied: 8841220 bytes
->Java cache emptied: 8196 bytes
->FireFox cache emptied: 6012543 bytes
->Google Chrome cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 60884 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1224754 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 16,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 06282013_164855

Files\Folders moved on Reboot...
C:\Users\wagner\AppData\Local\Temp\Low\JavaDeployReg.log moved successfully.
C:\Users\wagner\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\wagner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QMM3C7VM\1309004[1].htm moved successfully.
C:\Users\wagner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\wagner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
C:\Users\wagner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\SuggestedSites.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
Andreatta
Andreatta Tô em todas Registrado
2.4K Mensagens 39 Curtidas
#16 Por Andreatta
29/06/2013 - 09:29
joram disse:
Bom Dia! Andreatta

< C:\_OTL\MovedFiles\*.log << Eis o caminho ao relatório!

|- O log da OTL que foi pedido,não é o de diagnóstico.
|- Poste o log que resultou,após a execução do script.

|- Baixe: < Imagem > ( ... by sUBs )
|- Salve-o no desktop! ( Área de trabalho! )
|- Ps: Desabilite seu antivírus,antispywares e/ou firewall. ( Menos o do Windows! )
|- Feche algum programa/arquivo que esteja aberto.
|- Feche,também,seu navegador! ( IE,Firefox,Opera ou Google Chrome )
|- Ps: Esteja conectado(a) à Internet. <- Importante!
|- É preciso estar logado no sistema com privilégios de administrador.
|- Execute ComboFix.exe,com um duplo clique.
|- Ps: Instale o "Console de Recuperação",caso seja solicitado! <- Somente XP!
|- Ps: Ficará,portanto,à seu critério optar por sua instalação.

Imagem

|- Surgindo alguma mensagem de erro,execute ComboFix.exe em Modo de Segurança com rede.
|- Ps: Para completar as remoções,talvez haja necessidade da ferramenta reiniciar o computador.
|- Abrir-se-á a janela Auto Scan.

Imagem

|- Aguarde a finalização de todas as Etapas.
|- Durante o scan,evite utilizar o mouse ou teclado!
|- Concluindo,poste: C:\ComboFix.txt

|- Ao ocorrer este erro,basta reiniciar o computador!
|- "ComboFix é uma ferramenta que pode danificar o sistema. Utilize-o,somente,sob supervisão de analistas de segurança."

-/-

|- Baixe: < Complete Internet Repair >
|- Extraia o conteúdo e execute o arquivo "CIntRep.exe".

Imagem

|- Marque,apenas,as checkbox:

Reset Internet Protocol (TCP/IP)
Repair Winsock (Reset Catalog)
Renew Internet Connections
Flush DNS Resolver Cache
Restore the default hosts file


|- Clique "Go!".
|- Ao concluir,reinicie o computador!
|- À seguir,acesse a pasta "Complete Internet Repair" >> "Logging".
|- Duplo-clique em "CIntRep.log".
|- Poste o log resultante!
|- Ps: Verifique se já pode ter acesso ao jogo!

A+
O log do OTL, e estou executando os outros programas.


All processes killed========== OTL ==========
Registry value HKEY_USERS\S-1-5-21-160635771-3247580687-3712117055-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{472734EA-242A-422b-ADF8-83D1E48CC825} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{472734EA-242A-422b-ADF8-83D1E48CC825}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\Adobe Reader\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@fancyguo.com/FancyGame,version=1.0.0.1\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95525BD9-6136-4A26-8263-9CEE295D442D}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95525BD9-6136-4A26-8263-9CEE295D442D}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{326E768D-4182-46FD-9C16-1449A49795F4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{326E768D-4182-46FD-9C16-1449A49795F4}\ not found.
Registry value HKEY_USERS\S-1-5-21-160635771-3247580687-3712117055-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E0301295-AB3E-4AF3-979F-3D453C5F9F48} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0301295-AB3E-4AF3-979F-3D453C5F9F48}\ not found.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully.
File Protocol\Handler\msdaipp - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\0x00000001\ not found.
File Protocol\Handler\msdaipp\0x00000001 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\oledb\ not found.
File Protocol\Handler\msdaipp\oledb - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\mso-offdap\ deleted successfully.
File Protocol\Handler\mso-offdap - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\mso-offdap11\ deleted successfully.
File Protocol\Handler\mso-offdap11 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.
File Protocol\Handler\skype4com - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value found not found.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29\sysopt folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29\Run\Disable folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29\Run folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29\Plugins\Plugin.LeakRepair\Hotfix folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29\Plugins\Plugin.LeakRepair folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29\Plugins folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster\3.2.0.29 folder moved successfully.
C:\ProgramData\Baidu Security\PC Faster folder moved successfully.
C:\ProgramData\Baidu Security folder moved successfully.
Folder C:\Users\wagner\AppData\Roaming\Baidu\ not found.
Folder C:\ProgramData\Baidu\ not found.
C:\Users\wagner\AppData\Roaming\Awesomium\Default\Cache folder moved successfully.
C:\Users\wagner\AppData\Roaming\Awesomium\Default folder moved successfully.
C:\Users\wagner\AppData\Roaming\Awesomium folder moved successfully.
Folder C:\Users\wagner\AppData\Roaming\Baidu\ not found.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Uninstall\Baidu PC Faster Uninstall HK\0 folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Uninstall\Baidu PC Faster Uninstall HK folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Uninstall\Baidu PC Faster Uninstall\0 folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Uninstall\Baidu PC Faster Uninstall folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Uninstall folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Run\Disable folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\Run folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\RpData folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29\PopMsg folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\3.2.0.29 folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\1.19.0.2\RpData folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster\1.19.0.2 folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security\PC Faster folder moved successfully.
C:\Users\wagner\AppData\Roaming\Baidu Security folder moved successfully.
Folder C:\Users\wagner\AppData\Roaming\Awesomium\ not found.
Folder C:\Users\wagner\AppData\Roaming\Baidu\ not found.
Folder C:\Users\wagner\AppData\Roaming\Baidu Security\ not found.
C:\Users\wagner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini moved successfully.
C:\Windows\4F64A46D67F74497AEA2313D4305A5F6.TMP\WiseCustomCall.dll deleted successfully.
C:\Windows\4F64A46D67F74497AEA2313D4305A5F6.TMP\WiseCustomCalla.dll deleted successfully.
C:\Windows\4F64A46D67F74497AEA2313D4305A5F6.TMP\WiseData.ini deleted successfully.
C:\Windows\4F64A46D67F74497AEA2313D4305A5F6.TMP folder deleted successfully.
C:\Windows\msdownld.tmp folder deleted successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\"Gopher"|"gopher://" /E : value set successfully!
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\""|""%1" %*" /E : value set successfully!
========== FILES ==========
< type C:\AdwCleaner[S1].txt /C >
C:\Users\wagner\Desktop\cmd.bat deleted successfully.
C:\Users\wagner\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point

[EMPTYTEMP]

User: All Users

User: Default
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 57472 bytes

User: Default User
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Todos os Usuários

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: UpdatusUser.wagner-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Usuário Padrão
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: wagner
->Temp folder emptied: 297725 bytes
->Temporary Internet Files folder emptied: 8841220 bytes
->Java cache emptied: 8196 bytes
->FireFox cache emptied: 6012543 bytes
->Google Chrome cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 60884 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1224754 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 16,00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 06282013_164855

Files\Folders moved on Reboot...
C:\Users\wagner\AppData\Local\Temp\Low\JavaDeployReg.log moved successfully.
C:\Users\wagner\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\wagner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\QMM3C7VM\1309004[1].htm moved successfully.
C:\Users\wagner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\wagner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
C:\Users\wagner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\SuggestedSites.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
Andreatta
Andreatta Tô em todas Registrado
2.4K Mensagens 39 Curtidas
#18 Por Andreatta
29/06/2013 - 10:22
joram disse:
Olá! Andreatta

|- Tentei obter seu log de Supressão da ferramenta AdwCleaner,mas ele já foi removido de seu PC.
|- Aguardarei os outros relatórios.
|- Bom trabalho!

A+
Segue o log do Combo fix :
e acho que baixei programa errado, o tweaking.com windows repair.....


ComboFix 13-06-28.02 - wagner 29/06/2013 9:33.1.2 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.55.1046.18.3327.2357 [GMT -3:00]
Executando de: c:\users\wagner\Desktop\ComboFix.exe
AV: Panda Cloud Antivirus *Disabled/Updated* {3456760B-FDAA-FFFD-06C2-7BB528D2066C}
FW: Cloud Antivirus Firewall *Disabled* {0C6DF72E-B7C5-FEA5-2D9D-D280D6014117}
SP: Panda Cloud Antivirus *Disabled/Updated* {8F3797EF-DB90-F073-3C72-40C753554CD1}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((( Outras Exclusões )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Windows Live\Messenger\msacm32.dll
c:\users\wagner\AppData\Roaming\83A6.5B3
c:\users\wagner\AppData\Roaming\Anti-Malware Lab
c:\users\wagner\AppData\Roaming\app
c:\users\wagner\AppData\Roaming\app\Jerakine_lang.dat
c:\users\wagner\AppData\Roaming\app\Jerakine_lang_vesrion.dat
c:\windows\SysWow64\drivers\ati2xhxx.sys
c:\windows\SysWow64\drivers\ati4irxx.sys
c:\windows\SysWow64\logs
c:\windows\SysWow64\SvcWatch.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Serviços )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SvcWatch
.
.
(((((((((((((((( Arquivos/Ficheiros criados de 2013-05-28 to 2013-06-29 ))))))))))))))))))))))))))))
.
.
2013-06-29 12:06 . 2013-04-29 12:17 58808 ----a-w- c:\windows\system32\drivers\PSKMAD.sys
2013-06-28 19:48 . 2013-06-28 19:48 -------- d-----w- C:\_OTL
2013-06-28 17:39 . 2013-06-29 12:53 -------- d-----w- c:\users\wagner\AppData\Local\Temp
2013-06-28 17:39 . 2013-06-28 17:26 24064 ----a-w- c:\windows\zoek-delete.exe
2013-06-28 17:17 . 2013-06-28 17:17 -------- d-----w- c:\windows\ERUNT
2013-06-28 17:17 . 2013-06-28 17:17 -------- d-----w- C:\JRT
2013-06-28 17:11 . 2013-06-28 17:11 -------- d-----w- c:\users\wagner\AppData\Local\VS Revo Group
2013-06-28 17:11 . 2013-06-28 17:11 -------- d-----w- c:\programdata\VS Revo Group
2013-06-28 04:00 . 2013-06-28 04:00 -------- d-----w- c:\program files\CCleaner
2013-06-27 20:09 . 2013-06-27 20:09 -------- d-----w- c:\windows\SysWow64\Adobe
2013-06-27 17:25 . 2013-06-27 17:25 -------- d-----w- c:\users\wagner\AppData\Local\CrashRpt
2013-06-27 17:25 . 2013-06-28 22:36 -------- d-----w- c:\users\wagner\AppData\Roaming\DawngateData
2013-06-27 17:25 . 2013-06-27 17:25 -------- d-----w- c:\users\wagner\AppData\Local\Electronic Arts
2013-06-27 15:55 . 2013-06-27 15:55 -------- d-----w- c:\users\wagner\AppData\Local\Apple
2013-06-27 15:55 . 2013-06-27 15:55 -------- d-----w- c:\programdata\Apple
2013-06-25 18:41 . 2013-06-12 03:08 9552976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E6142CB7-9E85-40AE-A546-9D13F5F601C9}\mpengine.dll
2013-06-25 16:51 . 2013-06-25 16:51 -------- d-----w- c:\program files (x86)\Activision
2013-06-25 04:08 . 2013-06-25 20:55 -------- d-----w- c:\program files (x86)\StarCraft II
2013-06-25 03:23 . 2013-06-25 03:23 -------- d-----w- C:\Games
2013-06-24 17:08 . 2013-06-24 17:07 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-06-20 20:25 . 2013-06-20 20:25 -------- d-----w- c:\programdata\Steam
2013-06-20 20:21 . 2013-06-20 21:44 -------- d-----w- c:\program files (x86)\Age of Empires II HD
2013-06-19 02:56 . 2013-06-19 02:56 -------- d-----w- c:\users\wagner\AppData\Roaming\DofusTesting
2013-06-19 02:54 . 2013-06-19 02:54 -------- d-----w- c:\users\wagner\AppData\Roaming\AnkamaCertificates
2013-06-19 02:53 . 2013-06-19 02:53 -------- d-----w- c:\users\wagner\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
2013-06-19 02:53 . 2013-06-19 03:20 -------- d-----w- c:\users\wagner\AppData\Roaming\Dofus2
2013-06-19 02:53 . 2013-06-19 02:53 -------- d-----w- c:\users\wagner\AppData\Roaming\DofusTesting-2
2013-06-08 18:59 . 2013-06-25 17:34 -------- d-----w- c:\program files (x86)\GameVicio
2013-06-06 16:21 . 2013-06-06 16:21 -------- d-----w- c:\program files (x86)\Common Files\Java
2013-06-06 00:10 . 2013-06-06 00:10 -------- d-----w- c:\users\wagner\AppData\Local\TeknoGods
2013-05-31 23:40 . 2013-05-31 23:52 -------- d-----w- c:\program files (x86)\EVGA Precision X
2013-05-31 23:36 . 2013-05-31 23:38 -------- d-----w- c:\users\wagner\AppData\Roaming\Nico Mak Computing
.
.
.
((((((((((((((((((((((((((((((((((((( Relatório Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-27 19:45 . 2013-01-08 20:13 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-27 19:45 . 2013-01-08 20:13 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-24 17:07 . 2012-07-29 04:20 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll
2013-06-24 17:07 . 2011-02-15 22:11 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-06-17 19:13 . 2013-05-23 16:56 5488 ----a-w- c:\programdata\NanoRepository.bin
2013-05-29 20:16 . 2013-05-29 20:16 137448 ----a-w- c:\windows\system32\drivers\PSINProt.sys
2013-05-29 08:55 . 2013-05-29 08:55 246504 ----a-w- c:\windows\system32\drivers\NNSStrm.sys
2013-05-29 08:55 . 2013-05-29 08:55 106216 ----a-w- c:\windows\system32\drivers\NNStlsc.sys
2013-05-29 08:55 . 2013-05-29 08:55 118504 ----a-w- c:\windows\system32\drivers\NNSPrv.sys
2013-05-29 08:55 . 2013-05-29 08:55 114920 ----a-w- c:\windows\system32\drivers\NNSSmtp.sys
2013-05-29 08:55 . 2013-05-29 08:55 69864 ----a-w- c:\windows\system32\drivers\NNSPihsw.sys
2013-05-29 08:55 . 2013-05-29 08:55 305896 ----a-w- c:\windows\system32\drivers\NNSProt.sys
2013-05-29 08:55 . 2013-05-29 08:55 119016 ----a-w- c:\windows\system32\drivers\NNSPop3.sys
2013-05-29 08:55 . 2013-05-29 08:55 95464 ----a-w- c:\windows\system32\drivers\NNSpicc.sys
2013-05-29 08:55 . 2013-05-29 08:55 114920 ----a-w- c:\windows\system32\drivers\NNSIds.sys
2013-05-29 08:55 . 2013-05-29 08:55 109288 ----a-w- c:\windows\system32\drivers\NNSHttps.sys
2013-05-29 08:55 . 2013-05-29 08:55 91368 ----a-w- c:\windows\system32\drivers\NNSAlpc.sys
2013-05-29 08:55 . 2013-05-29 08:55 122088 ----a-w- c:\windows\system32\drivers\NNSHttp.sys
2013-05-28 14:25 . 2013-05-28 14:25 105704 ----a-w- c:\windows\system32\drivers\PSINReg.sys
2013-05-28 14:25 . 2013-05-28 14:25 205544 ----a-w- c:\windows\system32\drivers\PSINKNC.sys
2013-05-28 14:25 . 2013-05-28 14:25 124648 ----a-w- c:\windows\system32\drivers\PSINProc.sys
2013-05-28 14:25 . 2013-05-28 14:25 122088 ----a-w- c:\windows\system32\drivers\PSINFile.sys
2013-05-28 14:25 . 2013-05-28 14:25 168680 ----a-w- c:\windows\system32\drivers\PSINAflt.sys
2013-05-11 12:56 . 2010-06-24 14:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-08 12:52 . 2011-03-07 21:52 49536 ----a-w- c:\windows\SysWow64\drivers\gbpkm.sys
2013-05-07 17:29 . 2013-05-07 17:29 36584 ----a-w- c:\windows\system32\drivers\NNSNAHSL.sys
2013-05-02 05:06 . 2011-02-07 23:24 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-04-19 04:24 . 2013-04-24 05:21 443168 ----a-w- c:\windows\SysWow64\NvFBC.dll
2013-04-19 04:24 . 2013-04-24 05:21 421152 ----a-w- c:\windows\SysWow64\NvIFR.dll
2013-04-19 04:24 . 2013-04-24 05:21 2937120 ----a-w- c:\windows\system32\nvcuvid.dll
2013-04-19 04:24 . 2013-04-24 05:21 266960 ----a-w- c:\windows\system32\nvinitx.dll
2013-04-19 04:24 . 2013-04-24 05:21 2361120 ----a-w- c:\windows\system32\nvcuvenc.dll
2013-04-19 04:24 . 2013-04-24 05:21 214448 ----a-w- c:\windows\SysWow64\nvinit.dll
2013-04-19 04:24 . 2013-04-24 05:21 17560352 ----a-w- c:\windows\SysWow64\nvcompiler.dll
2013-04-19 04:24 . 2013-04-24 05:21 9362432 ----a-w- c:\windows\system32\nvcuda.dll
2013-04-19 04:24 . 2013-04-24 05:21 922576 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2013-04-19 04:24 . 2013-04-24 05:21 7820504 ----a-w- c:\windows\SysWow64\nvcuda.dll
2013-04-19 04:24 . 2013-04-24 05:21 7578984 ----a-w- c:\windows\system32\nvopencl.dll
2013-04-19 04:24 . 2013-04-24 05:21 6276504 ----a-w- c:\windows\SysWow64\nvopencl.dll
2013-04-19 04:24 . 2013-04-24 05:21 550176 ----a-w- c:\windows\system32\NvFBC64.dll
2013-04-19 04:24 . 2013-04-24 05:21 518944 ----a-w- c:\windows\system32\NvIFR64.dll
2013-04-19 04:24 . 2013-04-24 05:21 2921288 ----a-w- c:\windows\system32\nvapi64.dll
2013-04-19 04:24 . 2013-04-24 05:21 27765536 ----a-w- c:\windows\system32\nvoglv64.dll
2013-04-19 04:24 . 2013-04-24 05:21 2749216 ----a-w- c:\windows\SysWow64\nvcuvid.dll
2013-04-19 04:24 . 2013-04-24 05:21 2585496 ----a-w- c:\windows\SysWow64\nvapi.dll
2013-04-19 04:24 . 2013-04-24 05:21 25256224 ----a-w- c:\windows\system32\nvcompiler.dll
2013-04-19 04:24 . 2013-04-24 05:21 218592 ----a-w- c:\windows\system32\nvoglshim64.dll
2013-04-19 04:24 . 2013-04-24 05:21 21088032 ----a-w- c:\windows\SysWow64\nvoglv32.dll
2013-04-19 04:24 . 2013-04-24 05:21 1999136 ----a-w- c:\windows\SysWow64\nvcuvenc.dll
2013-04-19 04:24 . 2013-04-24 05:21 1832224 ----a-w- c:\windows\system32\nvdispco6432000.dll
2013-04-19 04:24 . 2013-04-24 05:21 181488 ----a-w- c:\windows\SysWow64\nvoglshim32.dll
2013-04-19 04:24 . 2013-04-24 05:21 15876728 ----a-w- c:\windows\system32\nvwgf2umx.dll
2013-04-19 04:24 . 2013-04-24 05:21 15135152 ----a-w- c:\windows\system32\nvd3dumx.dll
2013-04-19 04:24 . 2013-04-24 05:21 1511712 ----a-w- c:\windows\system32\nvdispgenco6432000.dll
2013-04-19 04:24 . 2013-04-24 05:21 13382056 ----a-w- c:\windows\SysWow64\nvwgf2um.dll
2013-04-19 04:24 . 2013-04-24 05:21 12417464 ----a-w- c:\windows\SysWow64\nvd3dum.dll
2013-04-19 04:24 . 2013-04-24 05:21 11195168 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2013-04-19 04:24 . 2013-04-24 05:21 1055952 ----a-w- c:\windows\system32\nvumdshimx.dll
2013-04-19 04:24 . 2013-04-24 05:18 61216 ----a-w- c:\windows\system32\OpenCL.dll
2013-04-19 04:24 . 2013-04-24 05:18 53024 ----a-w- c:\windows\SysWow64\OpenCL.dll
2013-04-19 02:46 . 2013-04-24 05:18 6488352 ----a-w- c:\windows\system32\nvcpl.dll
2013-04-19 02:46 . 2013-04-24 05:18 3511072 ----a-w- c:\windows\system32\nvsvc64.dll
2013-04-19 02:46 . 2013-04-24 05:18 884512 ----a-w- c:\windows\system32\nvvsvc.exe
2013-04-19 02:46 . 2013-04-24 05:18 63776 ----a-w- c:\windows\system32\nvshext.dll
2013-04-19 02:46 . 2013-04-24 05:18 2555680 ----a-w- c:\windows\system32\nvsvcr.dll
2013-04-19 02:46 . 2013-04-24 05:18 237856 ----a-w- c:\windows\system32\nvmctray.dll
2013-04-19 01:16 . 2013-04-19 01:16 563488 ----a-w- c:\windows\SysWow64\nvStreaming.exe
2013-04-17 17:30 . 2013-04-24 05:18 3122645 ----a-w- c:\windows\system32\nvcoproc.bin
.
.
(((((((((((((((((((((((((( Pontos de Carregamento do Registro )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por padrão não são apresentadas.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"PSUAMain"="c:\program files (x86)\Panda Security\Panda Cloud Antivirus\PSUAMain.exe" [2013-05-28 32736]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginBb]
2013-05-23 13:47 1389096 ----a-w- c:\program files (x86)\GbPlugin\gbieh.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginCef]
2012-12-26 15:03 1652584 ------w- c:\program files (x86)\GbPlugin\gbiehcef.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NanoServiceMain]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSUAService]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AutoUpdateDisableNotify"=dword:00000001
.
R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys;c:\windows\SYSNATIVE\drivers\gbpkm.sys [x]
R1 SASDIFSV;SASDIFSV; [x]
R1 SASKUTIL;SASKUTIL; [x]
R2 Browser Defender Update Service;Browser Defender Update Service; [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 GGSAFERDriver;GGSAFER Driver; [x]
R3 Lavasoft Kernexplorer;Lavasoft helper driver; [x]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\DRIVERS\lgbtpt64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtpt64.sys [x]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\DRIVERS\lgbtbs64.sys;c:\windows\SYSNATIVE\DRIVERS\lgbtbs64.sys [x]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\DRIVERS\lgvmdm64.sys;c:\windows\SYSNATIVE\DRIVERS\lgvmdm64.sys [x]
R3 nmwcdnsux64;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsux64.sys;c:\windows\SYSNATIVE\drivers\nmwcdnsux64.sys [x]
R3 PSINReg;PSINReg;c:\windows\system32\DRIVERS\PSINReg.sys;c:\windows\SYSNATIVE\DRIVERS\PSINReg.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Serviço de Tecnologias de Ativação do Windows;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys;c:\windows\SYSNATIVE\DRIVERS\Lbd.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 NNSALPC;NNSALPC;c:\windows\system32\DRIVERS\NNSAlpc.sys;c:\windows\SYSNATIVE\DRIVERS\NNSAlpc.sys [x]
S1 NNSHTTP;NNSHTTP;c:\windows\system32\DRIVERS\NNSHttp.sys;c:\windows\SYSNATIVE\DRIVERS\NNSHttp.sys [x]
S1 NNSHTTPS;NNSHTTPS;c:\windows\system32\DRIVERS\NNSHttps.sys;c:\windows\SYSNATIVE\DRIVERS\NNSHttps.sys [x]
S1 NNSIDS;NNSIDS;c:\windows\system32\DRIVERS\NNSIds.sys;c:\windows\SYSNATIVE\DRIVERS\NNSIds.sys [x]
S1 NNSNAHSL;Network Activity Hook Server LightWeight Filter Driver;c:\windows\system32\DRIVERS\NNSNAHSL.sys;c:\windows\SYSNATIVE\DRIVERS\NNSNAHSL.sys [x]
S1 NNSPICC;NNSPICC;c:\windows\system32\DRIVERS\NNSPicc.sys;c:\windows\SYSNATIVE\DRIVERS\NNSPicc.sys [x]
S1 NNSPIHSW;NNSPIHSW;c:\windows\system32\DRIVERS\NNSPihsw.sys;c:\windows\SYSNATIVE\DRIVERS\NNSPihsw.sys [x]
S1 NNSPOP3;NNSPOP3;c:\windows\system32\DRIVERS\NNSPop3.sys;c:\windows\SYSNATIVE\DRIVERS\NNSPop3.sys [x]
S1 NNSPROT;NNSPROT;c:\windows\system32\DRIVERS\NNSProt.sys;c:\windows\SYSNATIVE\DRIVERS\NNSProt.sys [x]
S1 NNSPRV;NNSPRV;c:\windows\system32\DRIVERS\NNSPrv.sys;c:\windows\SYSNATIVE\DRIVERS\NNSPrv.sys [x]
S1 NNSSMTP;NNSSMTP;c:\windows\system32\DRIVERS\NNSSmtp.sys;c:\windows\SYSNATIVE\DRIVERS\NNSSmtp.sys [x]
S1 NNSSTRM;NNSSTRM;c:\windows\system32\DRIVERS\NNSStrm.sys;c:\windows\SYSNATIVE\DRIVERS\NNSStrm.sys [x]
S1 NNSTLSC;NNSTLSC;c:\windows\system32\DRIVERS\NNSTlsc.sys;c:\windows\SYSNATIVE\DRIVERS\NNSTlsc.sys [x]
S1 PSINKNC;PSINKNC;c:\windows\system32\DRIVERS\psinknc.sys;c:\windows\SYSNATIVE\DRIVERS\psinknc.sys [x]
S2 GbpSv;Gbp Service;c:\progra~2\GbPlugin\GbpSv.exe;c:\progra~2\GbPlugin\GbpSv.exe [x]
S2 MSSQL$BWDATOOLSET;SQL Server (BWDATOOLSET);c:\program files (x86)\DAODB\MSSQL.1\MSSQL\Binn\sqlservr.exe;c:\program files (x86)\DAODB\MSSQL.1\MSSQL\Binn\sqlservr.exe [x]
S2 NanoServiceMain;Panda Cloud Antivirus Service;c:\program files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe;c:\program files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe [x]
S2 PSINAflt;PSINAflt;c:\windows\system32\DRIVERS\PSINAflt.sys;c:\windows\SYSNATIVE\DRIVERS\PSINAflt.sys [x]
S2 PSINFile;PSINFile;c:\windows\system32\DRIVERS\PSINFile.sys;c:\windows\SYSNATIVE\DRIVERS\PSINFile.sys [x]
S2 PSINProc;PSINProc;c:\windows\system32\DRIVERS\PSINProc.sys;c:\windows\SYSNATIVE\DRIVERS\PSINProc.sys [x]
S2 PSINProt;PSINProt;c:\windows\system32\DRIVERS\PSINProt.sys;c:\windows\SYSNATIVE\DRIVERS\PSINProt.sys [x]
S2 PSUAService;Panda Product Service;c:\program files (x86)\Panda Security\Panda Cloud Antivirus\PSUAService.exe;c:\program files (x86)\Panda Security\Panda Cloud Antivirus\PSUAService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 PSKMAD;PSKMAD;c:\windows\system32\DRIVERS\PSKMAD.sys;c:\windows\SYSNATIVE\DRIVERS\PSKMAD.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- =Outros Serviços/Drivers Na Memória ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-06-28 21:07 1165776 ----a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe
.
Conteúdo da pasta 'Tarefas Agendadas'
.
2013-06-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-01-08 19:45]
.
2013-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore1ce7358bfc49a0.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-27 20:22]
.
2013-06-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-27 20:22]
.
.
--------- X64 Entries -----------
.
.
------- Scan Suplementar -------
.
uStart Page = hxxp://www.ig.com.br/
mDefault_Page_URL = about:blank
mStart Page = about:blank
mLocal Page = c:\windows\system32\blank.htm
uInternet Settings,ProxyOverride = *.local
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.254.254
.
- - - - ORFÃOS REMOVIDOS - - - -
.
ShellIconOverlayIdentifiers-{2012DE06-50C0-48BD-ACDE-88F95D4CAD1F} - (no file)
ShellIconOverlayIdentifiers-{C72C6188-BEF2-46E5-A89A-52F0ED75219E} - (no file)
ShellIconOverlayIdentifiers-{C92F6BC2-AF61-4C0E-80E0-939B8282DDB7} - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
.
[HKEY_USERS\S-1-5-21-160635771-3247580687-3712117055-1001\Software\7-Zip\FM\Columns]
@DACL=(02 0000)
"7-Zip.zip"=hex:01,00,00,00,00,00,00,00,01,00,00,00,04,00,00,00,01,00,00,00,64,
00,00,00,07,00,00,00,01,00,00,00,64,00,00,00,08,00,00,00,01,00,00,00,64,00,\
"FSFolder"=hex:01,00,00,00,00,00,00,00,01,00,00,00,04,00,00,00,01,00,00,00,64,
00,00,00,07,00,00,00,01,00,00,00,64,00,00,00,0c,00,00,00,01,00,00,00,64,00,\
.
[HKEY_USERS\S-1-5-21-160635771-3247580687-3712117055-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:29,c7,05,42,84,34,3b,bf,3e,4b,e0,b8,34,ae,54,f3,2c,f2,c8,66,41,78,7c,
5c,e3,4b,56,a2,a3,8f,0e,d0,a6,cb,ec,e1,70,b3,25,37,bb,18,0c,6c,49,df,5d,3c,\
"??"=hex:11,f2,85,59,a5,1e,8c,e4,64,fb,df,68,a2,22,08,57
.
[HKEY_USERS\S-1-5-21-160635771-3247580687-3712117055-1001\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:54,77,7a,4f,5f,4d,4f,55,e5,d7,88,f0,10,de,47,00,91,a1,ed,17,96,
dd,b1,4d,46,3a,e5,67,f0,6b,9f,63,b8,d7,a6,f3,71,6b,84,15,0c,9b,39,14,15,80,\
"rkeysecu"=hex:f1,08,2c,79,91,bc,92,fe,1d,05,2e,02,ca,16,fa,e6
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\086118FFECEA53F39AC8B1486B0E1986\SourceList\Media]
@DACL=(02 0000)
"108"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\18A997D716659513FB29571416EC6D6E\SourceList\Media]
@DACL=(02 0000)
"101"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\2D0058F6F08A743309184BE1178C95B2\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"100"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\4712B95E429EF1135894DA17C44166D4\SourceList\Media]
@DACL=(02 0000)
"109"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\4A48104E16A4E2D30953BCE6E116E070\SourceList\Media]
@DACL=(02 0000)
"115"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\4D54076CED4F5BA32BBD3E5FAD1CD4C9\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"100"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\52CE121365979F2449539816E7B8C192\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="Microsoft's Silverlight Installation [1]"
"104"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\5E2C63AD43B6A6A3C9A0D7C11C5C7A86\SourceList\Media]
@DACL=(02 0000)
"116"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\645BC568E92815C458A6C140B262F43E\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="Microsoft's Silverlight Installation [1]"
"103"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\79EB7C9295ED2A736A78A2DD351249A8\SourceList\Media]
@DACL=(02 0000)
"100"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\7CD6922331248314F9770AC26567A1F7\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="Microsoft's Silverlight Installation [1]"
"105"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\A15A28B7B867B7A3DAAF7F7790A70897\SourceList\Media]
@DACL=(02 0000)
"113"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\A28754D59901E713BACCFF365D2B3168\SourceList\Media]
@DACL=(02 0000)
"109"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\E1F31DDFB6C9E1130A9D6D1E27CF82FF\SourceList\Media]
@DACL=(02 0000)
"112"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\E26C6FA6D3E4FB335A19E9D435DB2FF2\SourceList\Media]
@DACL=(02 0000)
"111"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Patches\E6E126D9010E08C30A55318519317405\SourceList\Media]
@DACL=(02 0000)
"100"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\091E66107D29A2842A02EDB8374583A3\SourceList\Media]
@DACL=(02 0000)
"MediaPackage"="\\Users\\wagner\\AppData\\Local\\Temp\\miaA791.tmp\\"
"1"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\0D756077321A70C3E844C138CE981581\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"=";1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\0ED9D238CFA898648991D4BBEDDBE3F4\SourceList\Media]
@DACL=(02 0000)
"1"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\153AA053AF120723B8A73845437E66DA\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"=";1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\1926E8D15D0BCE53481466615F760A7F\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"=";1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\1af2a8da7e60d0b429d7e6453b3d0182\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"2"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"3"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"4"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"5"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"6"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"7"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"8"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"9"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"10"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"11"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\1D5E3C0FEDA1E123187686FED06E995A\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"=";1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\254796BF4AC84B64891B61C529A2E23F\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"="DISK1;1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\4340C4778499EED41AE496DC3D613EC6\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"="DISK1;1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\4EA42A62D9304AC4784BF238120613FF\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"="DISK1;1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\547B38670606DF14AA57B0BB83F3AE4D\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"="DISK1;1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\6E8A266FCD4F2A1409E1C8110F44DBCE\SourceList\Media]
@DACL=(02 0000)
"1"=";"
"2"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\6F9E66FF7E38E3A3FA41D89E8A906A4A\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"=";1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\84b9c17023c712640acaf308593282f8\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"2"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"3"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"4"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"5"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"6"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"7"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"8"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"9"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"10"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
"11"=";Microsoft Visual C++ 2005 Redistributable (x64) [Disk 1]"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\87039105355FABE4AA77469CAF1AF289\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"="DISK1;1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\b25099274a207264182f8181add555d0\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"2"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"3"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"4"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"5"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"6"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"7"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"8"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"9"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"10"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"11"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\C28643E881181F13CBC489DC69571E2C\SourceList\Media]
@DACL=(02 0000)
"1"=";1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"=";1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\D376330603527854A80DBE50F92C369F\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"="Disc1;Crysis® 2"
"2"="Disc1;Crysis® 2"
"3"="Disc1;Crysis® 2"
"4"="Disc1;Crysis® 2"
"5"="Disc1;Crysis® 2"
"6"="Disc1;Crysis® 2"
"7"="Disc1;Crysis® 2"
"8"="Disc1;Crysis® 2"
"9"="Disc1;Crysis® 2"
"10"="Disc1;Crysis® 2"
"11"="Disc1;Crysis® 2"
"12"="Disc1;Crysis® 2"
"13"="Disc1;Crysis® 2"
"14"="Disc1;Crysis® 2"
"15"="Disc1;Crysis® 2"
"16"="Disc1;Crysis® 2"
"17"="Disc1;Crysis® 2"
"18"="Disc1;Crysis® 2"
"19"="Disc1;Crysis® 2"
"20"="Disc1;Crysis® 2"
"21"="Disc1;Crysis® 2"
"22"="Disc1;Crysis® 2"
"23"="Disc1;Crysis® 2"
"24"="Disc1;Crysis® 2"
"25"="Disc1;Crysis® 2"
"26"="Disc1;Crysis® 2"
"27"="Disc1;Crysis® 2"
"28"="Disc1;Crysis® 2"
"29"="Disc1;Crysis® 2"
"30"="Disc1;Crysis® 2"
"31"="Disc1;Crysis® 2"
"32"="Disc1;Crysis® 2"
"33"="Disc1;Crysis® 2"
"34"="Disc1;Crysis® 2"
"35"="Disc1;Crysis® 2"
"36"="Disc1;Crysis® 2"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\D5D054AEAE590DF48B0BD6E886BF2E7C\SourceList\Media]
@DACL=(02 0000)
"MediaPackage"="\\Users\\wagner\\AppData\\Local\\Temp\\miaD9EB.tmp\\"
"1"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\D64A46F47F767944EA2A13D334505A6F\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[ProductName] [1]"
"1"=";"
"2"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\DDA39468D428E8B4DB27C8D5DC5CA217\SourceList\Media]
@DACL=(02 0000)
"1"=";"
"2"=";"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\DDE7F2BCF1D91C3409CFF425AE1E271A\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"=";Microsoft .NET Framework 1.1 [Disk 1]"
"2"=";Microsoft .NET Framework 1.1 [Disk 1]"
"3"=";Microsoft .NET Framework 1.1 [Disk 1]"
"4"=";Microsoft .NET Framework 1.1 [Disk 1]"
"5"=";Microsoft .NET Framework 1.1 [Disk 1]"
"6"=";Microsoft .NET Framework 1.1 [Disk 1]"
"7"=";Microsoft .NET Framework 1.1 [Disk 1]"
"8"=";Microsoft .NET Framework 1.1 [Disk 1]"
"9"=";Microsoft .NET Framework 1.1 [Disk 1]"
"10"=";Microsoft .NET Framework 1.1 [Disk 1]"
"11"=";Microsoft .NET Framework 1.1 [Disk 1]"
"12"=";Microsoft .NET Framework 1.1 [Disk 1]"
"13"=";Microsoft .NET Framework 1.1 [Disk 1]"
"14"=";Microsoft .NET Framework 1.1 [Disk 1]"
"15"=";Microsoft .NET Framework 1.1 [Disk 1]"
"16"=";Microsoft .NET Framework 1.1 [Disk 1]"
"17"=";Microsoft .NET Framework 1.1 [Disk 1]"
"18"=";Microsoft .NET Framework 1.1 [Disk 1]"
"19"=";Microsoft .NET Framework 1.1 [Disk 1]"
"20"=";Microsoft .NET Framework 1.1 [Disk 1]"
"21"="URTSTDD1;Microsoft .NET Framework 1.1 [Disk 1]"
.
[HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\F942F94A19C0F79468FD2B85E5E8677B\SourceList\Media]
@DACL=(02 0000)
"DiskPrompt"="[1]"
"1"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"2"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"3"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"4"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"5"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"6"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"7"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"8"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"9"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"10"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
"11"=";Microsoft Visual C++ 2005 Redistributable [Disk 1]"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Outros Processos em Execução ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\windows\SysWOW64\PnkBstrA.exe
.
**************************************************************************
.
Tempo para conclusão: 2013-06-29 10:04:23 - Máquina reiniciou
ComboFix-quarantined-files.txt 2013-06-29 13:04
.
Pré-execução: 277.519.273.984 bytes disponíveis
Pós execução: 276.997.038.080 bytes disponíveis
.
- - End Of File - - 06D4D8062448D3D4B916BDB779F4D508
A36C5E4F47E84449FF07ED3517B43A31

Consegui baixar o programa p reparo da internet, segue o log :



./
(o o)
--------------------------------------oOOo-(_)-oOOo--------------------------------------
[29/06/2013 10:25:48] Resetting all TCP/IP Interfaces, Please wait.....
-----------------------------------------------------------------------------------------
[29/06/2013 10:25:52] TCP/IP interfaces reset successful.
[29/06/2013 10:25:52] TCP/IP v6 interfaces reset successful.
[29/06/2013 10:25:52] You may need to restart your computer for the settings to take effect.
[29/06/2013 10:25:52] Finished resetting the Internet Protocol (TCP/IP).

-----------------------------------------------------------------------------------------
[29/06/2013 10:25:52] Attempting to reset Winsock catalog, Please wait.....
-----------------------------------------------------------------------------------------
[29/06/2013 10:25:52] Successfully reset the Winsock Catalog.
[29/06/2013 10:25:52] Finished repairing Winsock

-----------------------------------------------------------------------------------------
[29/06/2013 10:25:52] Releasing TCP/IP connections, Please wait.....
-----------------------------------------------------------------------------------------
[29/06/2013 10:25:53] Successfully released TCP/IP connections.

-----------------------------------------------------------------------------------------
[29/06/2013 10:25:53] Renewing TCP/IP connections, Please wait.....
-----------------------------------------------------------------------------------------
[29/06/2013 10:25:56] Successfully renewed TCP/IP adapters.

-----------------------------------------------------------------------------------------
[29/06/2013 10:25:56] Configuring the Windows Event Log Service, Please wait.....
-----------------------------------------------------------------------------------------
[29/06/2013 10:25:57] Windows Event Log Service Configured.
[29/06/2013 10:25:57] Starting the Windows Event Log Service.....
[29/06/2013 10:25:57] Windows Event Log Service Started Successfully.

-----------------------------------------------------------------------------------------
[29/06/2013 10:25:57] Flushing DNS Resolver Cache, Please wait.....
-----------------------------------------------------------------------------------------
[29/06/2013 10:25:57] Successfully flushed DNS Resolver Cache.
[29/06/2013 10:25:57] Refreshing all DHCP leases and re-registering DNS names, Please wait.....
[29/06/2013 10:26:00] Registration of the DNS resource records has been initiated.
[29/06/2013 10:26:00] Note: Any errors will be reported in the 'Event Viewer' in about 15 minutes.
[29/06/2013 10:26:00] Note: Click on 'File' and then 'Event Viewer...' to open the Event Viewer.

-----------------------------------------------------------------------------------------
[29/06/2013 10:26:00] Repairing Internet Explorer 9.0.8112, Please wait.....
-----------------------------------------------------------------------------------------
[29/06/2013 10:26:01] RegSvr32.exe: 'actxprxy.dll' registration succeeded.
[29/06/2013 10:26:01] RegSvr32.exe: 'asctrls.ocx' Specified module not found
[29/06/2013 10:26:01] RegSvr32.exe: 'browseui.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:01] RegSvr32.exe: 'cdfview.dll' Specified module not found
[29/06/2013 10:26:02] RegSvr32.exe: 'comcat.dll' registration succeeded.
[29/06/2013 10:26:02] RegSvr32.exe: 'comctl32.dll' registration succeeded.
[29/06/2013 10:26:02] RegSvr32.exe: 'corpol.dll' Specified module not found
[29/06/2013 10:26:02] RegSvr32.exe: 'cryptdlg.dll' registration succeeded.
[29/06/2013 10:26:02] RegSvr32.exe: '"C:\Program Files (x86)\Internet Explorer\custsat.dll"' Specified module not found
[29/06/2013 10:26:02] RegSvr32.exe: 'digest.dll' Specified module not found
[29/06/2013 10:26:03] RegSvr32.exe: 'dispex.dll' registration succeeded.
[29/06/2013 10:26:03] RegSvr32.exe: 'dxtmsft.dll' registration succeeded.
[29/06/2013 10:26:03] RegSvr32.exe: 'dxtrans.dll' registration succeeded.
[29/06/2013 10:26:03] RegSvr32.exe: 'extmgr.dll' Specified module not found
[29/06/2013 10:26:03] RegSvr32.exe: '"C:\Program Files (x86)\Internet Explorer\hmmapi.dll"' Specified module not found
[29/06/2013 10:26:04] RegSvr32.exe: 'hlink.dll' registration succeeded.
[29/06/2013 10:26:04] RegSvr32.exe: 'ieaksie.dll' registration succeeded.
[29/06/2013 10:26:04] RegSvr32.exe: 'ieapfltr.dll' Error number: 0x80070005
[29/06/2013 10:26:04] RegSvr32.exe: 'iedkcs32.dll' registration succeeded.
[29/06/2013 10:26:05] RegSvr32.exe: '"C:\Program Files (x86)\Internet Explorer\iedvtool.dll"' registration succeeded.
[29/06/2013 10:26:05] RegSvr32.exe: 'iedvtool.dll' Specified module not found
[29/06/2013 10:26:05] RegSvr32.exe: 'ieframe.dll' registration succeeded.
[29/06/2013 10:26:06] RegSvr32.exe: 'iepeers.dll' registration succeeded.
[29/06/2013 10:26:06] RegSvr32.exe: '"C:\Program Files (x86)\Internet Explorer\ieproxy.dll"' registration succeeded.
[29/06/2013 10:26:07] RegSvr32.exe: 'ieproxy.dll' Specified module not found
[29/06/2013 10:26:07] RegSvr32.exe: 'iesetup.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:07] RegSvr32.exe: 'imgutil.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:07] RegSvr32.exe: 'inetcpl.cpl' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:08] RegSvr32.exe: 'inetcpl.cpl' registration succeeded.
[29/06/2013 10:26:08] RegSvr32.exe: 'initpki.dll' Specified module not found
[29/06/2013 10:26:08] RegSvr32.exe: 'inseng.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:08] RegSvr32.exe: 'jscript.dll' registration succeeded.
[29/06/2013 10:26:08] RegSvr32.exe: 'licmgr10.dll' registration succeeded.
[29/06/2013 10:26:09] RegSvr32.exe: 'mlang.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:09] RegSvr32.exe: 'mobsync.dll' Specified module not found
[29/06/2013 10:26:09] RegSvr32.exe: 'msapsspc.dll' Specified module not found
[29/06/2013 10:26:10] RegSvr32.exe: 'mscoree.dll' registration succeeded.
[29/06/2013 10:26:12] RegSvr32.exe: 'mscorier.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:12] RegSvr32.exe: 'mscories.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:12] RegSvr32.exe: 'msdbg2.dll' Specified module not found
[29/06/2013 10:26:12] RegSvr32.exe: 'mshta.exe' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:13] RegSvr32.exe: 'mshtml.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:13] RegSvr32.exe: 'mshtmled.dll' registration succeeded.
[29/06/2013 10:26:13] RegSvr32.exe: 'msident.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:13] RegSvr32.exe: 'msieftp.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:13] RegSvr32.exe: 'msnsspc.dll' Specified module not found
[29/06/2013 10:26:14] RegSvr32.exe: 'msr2c.dll' Specified module not found
[29/06/2013 10:26:14] RegSvr32.exe: 'msrating.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:14] RegSvr32.exe: 'mstime.dll' Specified module not found
[29/06/2013 10:26:14] RegSvr32.exe: 'msxml.dll' Specified module not found
[29/06/2013 10:26:15] RegSvr32.exe: 'ole32.dll' registration succeeded.
[29/06/2013 10:26:15] RegSvr32.exe: 'oleacc.dll' registration succeeded.
[29/06/2013 10:26:15] RegSvr32.exe: 'occache.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:17] RegSvr32.exe: 'oleaut32.dll' registration succeeded.
[29/06/2013 10:26:17] RegSvr32.exe: '"C:\Program Files (x86)\Internet Explorer\pdm.dll"' registration succeeded.
[29/06/2013 10:26:17] RegSvr32.exe: 'plugin.ocx' Specified module not found
[29/06/2013 10:26:17] RegSvr32.exe: 'pngfilt.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:18] RegSvr32.exe: 'proctexe.ocx' Specified module not found
[29/06/2013 10:26:18] RegSvr32.exe: 'scrobj.dll' Error number: 0x80070005
[29/06/2013 10:26:18] RegSvr32.exe: 'sendmail.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:18] RegSvr32.exe: 'setupwbv.dll' Specified module not found
[29/06/2013 10:26:19] RegSvr32.exe: 'shdocvw.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:19] RegSvr32.exe: 'tdc.ocx' registration succeeded.
[29/06/2013 10:26:19] RegSvr32.exe: 'url.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:20] RegSvr32.exe: 'urlmon.dll' registration succeeded.
[29/06/2013 10:26:20] RegSvr32.exe: 'urlmon.dll,NI,HKLM' Specified module not found
[29/06/2013 10:26:21] RegSvr32.exe: 'vbscript.dll' registration succeeded.
[29/06/2013 10:26:21] RegSvr32.exe: '"C:\Program Files (x86)\microsoft shared\vgx\vgx.dll"' Specified module not found
[29/06/2013 10:26:21] RegSvr32.exe: 'webcheck.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:21] Finished repairing Internet Explorer 9.0.8112

-----------------------------------------------------------------------------------------
[29/06/2013 10:26:21] Repairing Windows Update / Automatic Updates, Please wait.....
-----------------------------------------------------------------------------------------
[29/06/2013 10:26:21] Stopping the BITS Service.....
[29/06/2013 10:26:21] BITS Stopped Successfully.
[29/06/2013 10:26:21] Stopping the Automatic Updates (wuauserv) Service.....
[29/06/2013 10:26:21] Automatic Updates (wuauserv) Service Stopped Successfully.
[29/06/2013 10:26:21] Clearing File Stores (Update History).....
[29/06/2013 10:26:21] Clearing [C:\Windows\SoftwareDistribution\Download].....
[29/06/2013 10:26:21] [C:\Windows\SoftwareDistribution\Download] Cleared.
[29/06/2013 10:26:22] Clearing [C:\Windows\SoftwareDistribution\DataStore].....
[29/06/2013 10:26:22] [C:\Windows\SoftwareDistribution\DataStore] Cleared.
[29/06/2013 10:26:22] Clearing [C:\Windows\SysWOW64\CatRoot2].....
[29/06/2013 10:26:22] [C:\Windows\SysWOW64\CatRoot2] Cleared.
[29/06/2013 10:26:22] Setting BITS Security Descriptor.....
[29/06/2013 10:26:22] BITS Security Descriptor Set.
[29/06/2013 10:26:22] Setting Automatic Updates (wuauserv) Service Security Descriptor.....
[29/06/2013 10:26:22] Automatic Updates (wuauserv) Security Descriptor Set.
[29/06/2013 10:26:22] Configuring the Automatic Updates (wuauserv) Service.....
[29/06/2013 10:26:22] Automatic Updates (wuauserv) Service Configured.
[29/06/2013 10:26:22] Configuring BITS.....
[29/06/2013 10:26:22] BITS Configured.
[29/06/2013 10:26:22] Registering WUAU DLLs.....
[29/06/2013 10:26:23] RegSvr32.exe: 'actxprxy.dll' registration succeeded.
[29/06/2013 10:26:23] RegSvr32.exe: 'atl.dll' registration succeeded.
[29/06/2013 10:26:23] RegSvr32.exe: 'browseui.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:24] RegSvr32.exe: 'corpol.dll' Specified module not found
[29/06/2013 10:26:24] RegSvr32.exe: 'cryptdlg.dll' registration succeeded.
[29/06/2013 10:26:24] RegSvr32.exe: 'dispex.dll' registration succeeded.
[29/06/2013 10:26:24] RegSvr32.exe: 'dssenh.dll' registration succeeded.
[29/06/2013 10:26:24] RegSvr32.exe: 'gpkcsp.dll' Specified module not found
[29/06/2013 10:26:25] RegSvr32.exe: 'initpki.dll' Specified module not found
[29/06/2013 10:26:25] RegSvr32.exe: 'jscript.dll' registration succeeded.
[29/06/2013 10:26:25] RegSvr32.exe: 'mshtml.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:25] RegSvr32.exe: 'msscript.ocx' registration succeeded.
[29/06/2013 10:26:25] RegSvr32.exe: 'msxml.dll' Specified module not found
[29/06/2013 10:26:26] RegSvr32.exe: 'msxml2.dll' Specified module not found
[29/06/2013 10:26:26] RegSvr32.exe: 'msxml3.dll' registration succeeded.
[29/06/2013 10:26:27] RegSvr32.exe: 'msxml4.dll' registration succeeded.
[29/06/2013 10:26:27] RegSvr32.exe: 'msxml6.dll' registration succeeded.
[29/06/2013 10:26:28] RegSvr32.exe: 'muweb.dll' Specified module not found
[29/06/2013 10:26:28] RegSvr32.exe: 'ole.dll' Specified module not found
[29/06/2013 10:26:28] RegSvr32.exe: 'ole32.dll' registration succeeded.
[29/06/2013 10:26:28] RegSvr32.exe: 'oleaut.dll' Specified module not found
[29/06/2013 10:26:29] RegSvr32.exe: 'oleaut32.dll' registration succeeded.
[29/06/2013 10:26:30] RegSvr32.exe: 'qmgr.dll' Specified module not found
[29/06/2013 10:26:30] RegSvr32.exe: 'qmgrprxy.dll' registration succeeded.
[29/06/2013 10:26:30] RegSvr32.exe: 'gpkcsp.dll' Specified module not found
[29/06/2013 10:26:30] RegSvr32.exe: 'rsaenh.dll' registration succeeded.
[29/06/2013 10:26:30] RegSvr32.exe: 'sccbase.dll' Specified module not found
[29/06/2013 10:26:31] RegSvr32.exe: 'scrobj.dll' registration succeeded.
[29/06/2013 10:26:31] RegSvr32.exe: 'scrrun.dll' registration succeeded.
[29/06/2013 10:26:31] RegSvr32.exe: 'shdocvw.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:31] RegSvr32.exe: 'shell.dll' Specified module not found
[29/06/2013 10:26:31] RegSvr32.exe: 'shell32.dll' registration succeeded.
[29/06/2013 10:26:31] RegSvr32.exe: 'slbcsp.dll' Specified module not found
[29/06/2013 10:26:32] RegSvr32.exe: 'softpub.dll' registration succeeded.
[29/06/2013 10:26:32] RegSvr32.exe: 'urlmon.dll' registration succeeded.
[29/06/2013 10:26:32] RegSvr32.exe: 'vbscript.dll' registration succeeded.
[29/06/2013 10:26:32] RegSvr32.exe: 'winhttp.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:32] RegSvr32.exe: 'wintrust.dll' registration succeeded.
[29/06/2013 10:26:33] RegSvr32.exe: 'wshext.dll' Error number: 0x80070005
[29/06/2013 10:26:33] RegSvr32.exe: 'wuapi.dll' registration succeeded.
[29/06/2013 10:26:33] RegSvr32.exe: 'wuaueng.dll' Specified module not found
[29/06/2013 10:26:33] RegSvr32.exe: 'wuaueng1.dll' Specified module not found
[29/06/2013 10:26:33] RegSvr32.exe: 'wucltui.dll' Specified module not found
[29/06/2013 10:26:34] RegSvr32.exe: 'wucltux.dll' Specified module not found
[29/06/2013 10:26:34] RegSvr32.exe: 'wups.dll' registration succeeded.
[29/06/2013 10:26:34] RegSvr32.exe: 'wups2.dll' Specified module not found
[29/06/2013 10:26:34] RegSvr32.exe: 'wuweb.dll' Specified module not found
[29/06/2013 10:26:34] RegSvr32.exe: 'wuwebv.dll' registration succeeded.
[29/06/2013 10:26:34] WUAU DLLs Reregistered.
[29/06/2013 10:26:34] Resetting proxy settings.....
[29/06/2013 10:26:35] Proxy settings reset successfully.
[29/06/2013 10:26:35] Restarting the Automatic Updates (wuauserv) Service.....
[29/06/2013 10:26:35] Automatic Updates (wuauserv) Service Restarted.
[29/06/2013 10:26:35] Restarting the BITS Service.....
[29/06/2013 10:26:35] BITS Service Restarted.
[29/06/2013 10:26:35] Clearing the BITS queue.....
[29/06/2013 10:26:36] BITS queue cleared.
[29/06/2013 10:26:36] Initiating Windows Updates detection right away.....
[29/06/2013 10:26:42] Finished repairing Windows Update / Automatic Updates.

-----------------------------------------------------------------------------------------
[29/06/2013 10:26:42] Repairing SSL / HTTPS / Cryptography service, Please wait.....
-----------------------------------------------------------------------------------------
[29/06/2013 10:26:42] Configuring the Cryptographic Service.....
[29/06/2013 10:26:42] Cryptographic Service Configured.
[29/06/2013 10:26:42] Stopping the Cryptographic Service.....
[29/06/2013 10:26:42] Cryptographic service was not started in the first place.
[29/06/2013 10:26:42] Clearing [C:\Windows\system32\CatRoot].....
[29/06/2013 10:26:43] [C:\Windows\system32\CatRoot] cleared.
[29/06/2013 10:26:43] Re-registering SSL / HTTPS / Cryptography DLLs.....
[29/06/2013 10:26:43] RegSvr32.exe: 'cryptdlg.dll' registration succeeded.
[29/06/2013 10:26:44] RegSvr32.exe: 'cryptext.dll' registration succeeded.
[29/06/2013 10:26:44] RegSvr32.exe: 'cryptui.dll' registration succeeded.
[29/06/2013 10:26:44] RegSvr32.exe: 'dssenh.dll' registration succeeded.
[29/06/2013 10:26:44] RegSvr32.exe: 'gpkcsp.dll' Specified module not found
[29/06/2013 10:26:44] RegSvr32.exe: 'initpki.dll' Specified module not found
[29/06/2013 10:26:44] RegSvr32.exe: 'licdll.dll' Specified module not found
[29/06/2013 10:26:45] RegSvr32.exe: 'mssign32.dll' registration succeeded.
[29/06/2013 10:26:45] RegSvr32.exe: 'mssip32.dll' registration succeeded.
[29/06/2013 10:26:45] RegSvr32.exe: 'regwizc.dll' Specified module not found
[29/06/2013 10:26:45] RegSvr32.exe: 'rsaenh.dll' registration succeeded.
[29/06/2013 10:26:45] RegSvr32.exe: 'scardssp.dll' Specified module not found
[29/06/2013 10:26:46] RegSvr32.exe: 'sccbase.dll' Specified module not found
[29/06/2013 10:26:46] RegSvr32.exe: 'scecli.dll' registration succeeded.
[29/06/2013 10:26:46] RegSvr32.exe: 'slbcsp.dll' Specified module not found
[29/06/2013 10:26:47] RegSvr32.exe: 'softpub.dll' registration succeeded.
[29/06/2013 10:26:47] RegSvr32.exe: 'winhttp.dll' Module loaded but entry-point DllRegisterServer was not found.
[29/06/2013 10:26:47] RegSvr32.exe: 'wintrust.dll' registration succeeded.
[29/06/2013 10:26:47] SSL / HTTPS / Cryptography DLLs re-registered.
[29/06/2013 10:26:48] Restarting the Cryptographic Service.....
[29/06/2013 10:26:48] Cryptographic Service restarted.
[29/06/2013 10:26:48] Finished repairing SSL / HTTPS / Cryptography service.

-----------------------------------------------------------------------------------------
[29/06/2013 10:26:48] Resetting the Windows Firewall configuraton, Please wait.....
-----------------------------------------------------------------------------------------
[29/06/2013 10:26:48] Windows Firewall configuration reset successful.
[29/06/2013 10:26:48] Finished resetting the Windows Firewall configuraton.

-----------------------------------------------------------------------------------------
[29/06/2013 10:26:49] Restoring the default Windows HOSTS file, Please wait.....
-----------------------------------------------------------------------------------------
[29/06/2013 10:26:49] Writing data to the HOSTS file.....
[29/06/2013 10:26:49] HOSTS file created successfully.

-----------------------------------------------------------------------------------------
[29/06/2013 10:26:49] Repairing Workgroup Computers view, Please wait.....
-----------------------------------------------------------------------------------------
[29/06/2013 10:26:49] Finished repairing Workgroup Computers view.

-----------------------------------------------------------------------------------------
[29/06/2013 10:26:49] You will need to reboot your computer before the settings will take effect.
-----------------------------------------------------------------------------------------
[29/06/2013 10:26:54] Your computer is restarting now.....

-----------------------------------------------------------------------------------------

Agora veja o jogo EU do the settlers :

http://prntscr.com/1clavh

e veja o the settlers BR no meu pc. como está.....

http://prntscr.com/1clb97

Agora não sei se é problema lá no jogo, ainda não consigo logar no game
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#19 Por joram
29/06/2013 - 10:45
Olá! Andreatta

Segue o log do Combo fix :
e acho que baixei programa errado, o tweaking.com windows repair.....
|- Também é uma boa ferramenta de correções ao Windows. Mas...,por ora,utilize a "Complete Internet Repair",nas opções que lhe passei.

... editando!

|- Ok! Já realizado!
|- Ps: Você possui o software "Advanced SystemCare 6.2" instalado em seu PC? Caso,ainda,o tenha,procure executar correções do Windows com o mesmo.
Informe os resultados!

A+
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#21 Por joram
29/06/2013 - 11:24
Olá! Andreatta

Desculpe, ai, mas agora q fiz o procedimento, do repair internet, e postei log, e postei também screens, do jogo, ainda não está funcionando. Pode ser que seja do jogo, mas tem um colega aqui, que disse que consegue logar, como vc pode ver, eu consigo logar, o servidor Europeu e o br, fica sem aparecer as imagens.
flw obrigado.
|- O acesso pode estar sendo bloqueado por algum software que possui ou antivírus.
|- Ps: Tente colocar o link do servidor Brasileiro,como preferencial ou confiável,no IE. Reinicie o navegador e veja se funciona.
|- Otimize o computador com o software Advanced SystemCare 6.2 que possui aì instalado.

Imagem

|- Repare problemas que sejam encontrados,em seu scan.

Imagem

|- Deixe o status de correção,segundo a screenshot.

Imagem

|- Esta será,portanto,a avaliação final da "Central de Ação".

A+
Andreatta
Andreatta Tô em todas Registrado
2.4K Mensagens 39 Curtidas
#22 Por Andreatta
29/06/2013 - 11:32
joram disse:
Olá! Andreatta

|- O acesso pode estar sendo bloqueado por algum software que possui ou antivírus.
|- Ps: Tente colocar o link do servidor Brasileiro,como preferencial ou confiável,no IE. Reinicie o navegador e veja se funciona.
|- Otimize o computador com o software Advanced SystemCare 6.2 que possui aì instalado.

Imagem

|- Repare problemas que sejam encontrados,em seu scan.

Imagem

|- Deixe o status de correção,segundo a screenshot.

Imagem

|- Esta será,portanto,a avaliação final da "Central de Ação".

A+
Desculpe mas não tenho instalado o advanced system care, eu tinha, e desinstalei, a uns tempos, então ele está aparecendo ai em algum relatório, tenho o CCleaner, e como coloco o link do servidor br como preferencial no IE ? Não sei como faço isso........Eu uso o Panda Cloud faz um bom, tempo, e jogo o game the settlers com ele, já faz mais de 6 meses.........ja deu esse erro uma vez, quando fui infectado, a uns tempos atras, e depois de rodar vários programas, eu consegui logar no jogo, eu tenho outro tópico, e foi solucionado, já faz uns 2 meses atras....... Estou querendo te dizer que tive este mesmo problema a uns tempos atras entende ?
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#23 Por joram
29/06/2013 - 11:42
Olá! Andreatta

Desculpe mas não tenho instalado o advanced system care, eu tinha, e desinstalei, a uns tempos, então ele está aparecendo ai em algum relatório, tenho o CCleaner, e como coloco o link do servidor br como preferencial no IE ? Não sei como faço isso........Eu uso o Panda Cloud faz um bom, tempo, e jogo o game the settlers com ele, já faz mais de 6 meses.........ja deu esse erro uma vez, quando fui infectado, a uns tempos atras, e depois de rodar vários programas, eu consegui logar no jogo, eu tenho outro tópico, e foi solucionado, já faz uns 2 meses atras.......
|- E vc se lembra,especificamente,qual foi a ferramenta ou software que lhe ajudou?

-/-

|- Baixe: < ZHPDiag2 > ( ... de Nicolas Coolman )

|- Salve-o no desktop!

Imagem

|- Desabilite seu antivírus e execute "ZHPDiag2.exe",para instalar a ferramenta.

Imagem

|- Confirme todos os passos,ao instalar ZHPDiag.
|- Conclua a instalação,clicando em "Termine".

Imagem

|- Para Windows Vista,Windows 7 e 8,clique OK ao acionar ZHPDiag Setup.

Imagem

|- Ps: Após a instalação,além de ZHPScript,estarão disponíveis no desktop:

|- <1> MBRCheck
|- <2> ZHPDiag2
|- <3> ZHPFix

Imagem

|- Clique no ícone do pergaminho. ( ZHPScript )

Imagem

|- Clique na seta verde para atualizá-la e/ou baixar sua definição mais recente. ( Your version is update. )
|- Habilite todas as opções de diagnóstico,clicando em "Options".

Imagem

|- Clique em All.
|- Desmarque,à seguir,as caixinhas de n° O45,O61,O62,O65,O82.

|- Imagem

|- Clique em "Calendar" e escolha 30 dias!

Imagem

|- Clique no botão UAC,para desabilitar essa proteção.

Imagem

|- Dê início ao scan,clicando no ícone da lupa. ( Start Diagnosis )
|- Ao concluir,clique em "Save Report".
|- Salve-o em um local conveniente! ( ZHPDiag.txt )

Imagem << Log

|- Ps: Não poste,diretamente,esse arquivo texto.

|- Envie-o à Pjjoint.malekal,clicando na seta azul! < Imagem >

|- Ou acesse: Imagem << Link!

|- Ou acesse: Imagem << Link!

|- Maiores informações: < |Link| >

A+
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#25 Por joram
29/06/2013 - 11:59
Andreatta disse:
Foi neste tópico em que o panda cloud acusa um arquivo do steam como virus, e neste dia, não funcionou o the settlers também,

https://www.hardware.com.br/comunidade/errado/1302039/

E teve um antes também, em que usei OTL, ADwcleaner, e um outro programa q vc manda usar ai. Neste tópico acima, a página da internet também congelou como neste tópico que comecei aqui....... E Foi várias Ferramentas que usei, como vou saber qual é a correta ??? a certa que resolveu meu problema ?

Ok! Siga com ZHPDiag,onde farei script de limpeza. À seguir,executaremos procedimentos de correção automática com a ferramenta Pre_Scan.
Ps: Seria interessante,também,vc desinstalar o Panda Cloud Antivirus.

.... editando!


|- Feche programas/pastas que estejam abertas.
|- Para Windows Vista,desabilite a UAC.

Imagem

|- Dê um duplo clique em ZHPFix.

|- Clique no menu,H < Imagem >

[code=rich]O43 - CFD: 05/04/2012 - 18:09:01 - [0] ----D C:\Users\wagner\AppData\Local\Ares
O43 - CFD: 07/02/2011 - 19:56:12 - [0] ---AD C:\Users\wagner\AppData\Local\Dados de aplicativos
O43 - CFD: 07/02/2011 - 19:56:12 - [0] ---AD C:\Users\wagner\AppData\Local\Histórico
O43 - CFD: 12/03/2012 - 20:56:07 - [0] ----D C:\Users\wagner\AppData\Local\NitroPC
O43 - CFD: 14/11/2012 - 23:20:47 - [0] ----D C:\Users\wagner\AppData\Local\Programs
O43 - CFD: 08/03/2013 - 02:07:01 - [0] ----D C:\Users\wagner\AppData\Local\Targem
O44 - LFC:[MD5.470072E71DF2B2D5856ED1576D162419] - 28/06/2013 - 16:01:39 ---A- . (...) -- C:\zoek-results.log [36968]
O53 - SMSR:HKLM\...\startupreg\PSafeTray [Key] . (...) -- C:\Program Files (x86)\PSafe\PSafeSysTray.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\PSafeWDS [Key] . (...) -- C:\Program Files (x86)\PSafe\PSafeWDS.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\WebCake Desktop [Key] . (...) -- C:\Users\wagner\AppData\Roaming\WebCake\WebCakeDesktop.exe (.not file.)

[HKCR\VirtualStore\MACHINE\Software\CToolbar] => Toolbar.Crawler
[HKLM\Software\Wow6432Node\360Safe] => Infection Diverse (Lozavita.Troj)

proxyfix
emptytemp
emptyflash
firewallraz
sysrestore
[/code]|- Copie e cole estas informações,que estão em vermelho,para o campo "amarelo claro" de ZHPFix.
|- Ps: Procure deixar o campo limpo,antes de colar as informações que estão na Quote.
|- Clique em GO -> Oui.
|- Poste o relatório: C:\ZHP\ZHPFix[R1].txt

A+
Andreatta
Andreatta Tô em todas Registrado
2.4K Mensagens 39 Curtidas
#26 Por Andreatta
29/06/2013 - 12:24
joram disse:
Ok! Siga com ZHPDiag,onde farei script de limpeza. À seguir,executaremos procedimentos de correção automática com a ferramenta Pre_Scan.
Ps: Seria interessante,também,vc desinstalar o Panda Cloud Antivirus.

A+
Clico no ZHP Diag, já desinstalei o Panda Cloud, e depois vc me fala qual antivirus free, devo usar, gostava do Avira, o que devo fazer no ZHP ? e os relatórios e os programas OTL, depois excluo tudo ?
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#27 Por joram
29/06/2013 - 12:31
Boa Tarde! Andreatta

... repetindo!!

------
------

|- Feche programas/pastas que estejam abertas.
|- Para Windows Vista,desabilite a UAC.

Imagem

|- Dê um duplo clique em ZHPFix.

|- Clique no menu,H < Imagem >

[code=rich]O43 - CFD: 05/04/2012 - 18:09:01 - [0] ----D C:\Users\wagner\AppData\Local\Ares
O43 - CFD: 07/02/2011 - 19:56:12 - [0] ---AD C:\Users\wagner\AppData\Local\Dados de aplicativos
O43 - CFD: 07/02/2011 - 19:56:12 - [0] ---AD C:\Users\wagner\AppData\Local\Histórico
O43 - CFD: 12/03/2012 - 20:56:07 - [0] ----D C:\Users\wagner\AppData\Local\NitroPC
O43 - CFD: 14/11/2012 - 23:20:47 - [0] ----D C:\Users\wagner\AppData\Local\Programs
O43 - CFD: 08/03/2013 - 02:07:01 - [0] ----D C:\Users\wagner\AppData\Local\Targem
O44 - LFC:[MD5.470072E71DF2B2D5856ED1576D162419] - 28/06/2013 - 16:01:39 ---A- . (...) -- C:\zoek-results.log [36968]
O53 - SMSR:HKLM\...\startupreg\PSafeTray [Key] . (...) -- C:\Program Files (x86)\PSafe\PSafeSysTray.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\PSafeWDS [Key] . (...) -- C:\Program Files (x86)\PSafe\PSafeWDS.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\WebCake Desktop [Key] . (...) -- C:\Users\wagner\AppData\Roaming\WebCake\WebCakeDesktop.exe (.not file.)

[HKCR\VirtualStore\MACHINE\Software\CToolbar] => Toolbar.Crawler
[HKLM\Software\Wow6432Node\360Safe] => Infection Diverse (Lozavita.Troj)

proxyfix
emptytemp
emptyflash
firewallraz
sysrestore
[/code]|- Copie e cole estas informações,que estão em vermelho,para o campo "amarelo claro" de ZHPFix.
|- Ps: Procure deixar o campo limpo,antes de colar as informações que estão na Quote.
|- Clique em GO -> Oui.
|- Poste o relatório: C:\ZHP\ZHPFix[R1].txt
-------
-------
|- Outro modo de rodar o script!

|- Estando com o Bloco de Notas aberto,acione os atalhos: "Ctrl+A" -> "Ctrl+C"
|- Minimize o Bloco de Notas.

70ca55ea4d3ec54710107b53a65646d7

|- Clique no menu,"Paste ClipBoard".

493c6850b36d9189f11a26ef6892d6f8

|- Clique "GO" -> Oui.

67c5cc338df2d52238a5fee10f0bc855

|- Ps: Temos,àcima,sequência de imagens para maior exclarecimento.
|- Poste o relatório: C:\ZHP\ZHPFix[R1].txt

47ed56c43e04436834a8e6590d00fb59

|- Ps: Para obter o relatório,basta clicar no ícone "Report of suppression".

0cebe5055a4904e1a45f2535d8cb8070

|- À seguir,abra o Bloco de Notas e clique no ícone "Copy ClipBoard". << Colar!

A+
Andreatta
Andreatta Tô em todas Registrado
2.4K Mensagens 39 Curtidas
#28 Por Andreatta
29/06/2013 - 12:40
joram disse:
Boa Tarde! Andreatta

... repetindo!!

------
------

|- Feche programas/pastas que estejam abertas.
|- Para Windows Vista,desabilite a UAC.

Imagem

|- Dê um duplo clique em ZHPFix.

|- Clique no menu,H < Imagem >

[code=rich]O43 - CFD: 05/04/2012 - 18:09:01 - [0] ----D C:\Users\wagner\AppData\Local\Ares
O43 - CFD: 07/02/2011 - 19:56:12 - [0] ---AD C:\Users\wagner\AppData\Local\Dados de aplicativos
O43 - CFD: 07/02/2011 - 19:56:12 - [0] ---AD C:\Users\wagner\AppData\Local\Histórico
O43 - CFD: 12/03/2012 - 20:56:07 - [0] ----D C:\Users\wagner\AppData\Local\NitroPC
O43 - CFD: 14/11/2012 - 23:20:47 - [0] ----D C:\Users\wagner\AppData\Local\Programs
O43 - CFD: 08/03/2013 - 02:07:01 - [0] ----D C:\Users\wagner\AppData\Local\Targem
O44 - LFC:[MD5.470072E71DF2B2D5856ED1576D162419] - 28/06/2013 - 16:01:39 ---A- . (...) -- C:\zoek-results.log [36968]
O53 - SMSR:HKLM\...\startupreg\PSafeTray [Key] . (...) -- C:\Program Files (x86)\PSafe\PSafeSysTray.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\PSafeWDS [Key] . (...) -- C:\Program Files (x86)\PSafe\PSafeWDS.exe (.not file.)
O53 - SMSR:HKLM\...\startupreg\WebCake Desktop [Key] . (...) -- C:\Users\wagner\AppData\Roaming\WebCake\WebCakeDesktop.exe (.not file.)

[HKCR\VirtualStore\MACHINE\Software\CToolbar] => Toolbar.Crawler
[HKLM\Software\Wow6432Node\360Safe] => Infection Diverse (Lozavita.Troj)

proxyfix
emptytemp
emptyflash
firewallraz
sysrestore
[/code]|- Copie e cole estas informações,que estão em vermelho,para o campo "amarelo claro" de ZHPFix.
|- Ps: Procure deixar o campo limpo,antes de colar as informações que estão na Quote.
|- Clique em GO -> Oui.
|- Poste o relatório: C:\ZHP\ZHPFix[R1].txt
-------
-------
|- Outro modo de rodar o script!

|- Estando com o Bloco de Notas aberto,acione os atalhos: "Ctrl+A" -> "Ctrl+C"
|- Minimize o Bloco de Notas.

Imagem

|- Clique no menu,"Paste ClipBoard".

Imagem

|- Clique "GO" -> Oui.

Imagem

|- Ps: Temos,àcima,sequência de imagens para maior exclarecimento.
|- Poste o relatório: C:\ZHP\ZHPFix[R1].txt

Imagem

|- Ps: Para obter o relatório,basta clicar no ícone "Report of suppression".

Imagem

|- À seguir,abra o Bloco de Notas e clique no ícone "Copy ClipBoard". << Colar!

A+
Pera ai vc já mudou ai, estou postando o log la da resposta acima, não fiz esse ai q pede....ainda

Rapport de ZHPFix 2013.6.12.3 par Nicolas Coolman, Update du 12/06/2013
Fichier d'export Registre :
Run by wagner at 29/06/2013 12:38:08
High Elevated Privileges : OK
Windows 7 Ultimate Edition, 64-bit Service Pack 1 (Build 7601)

Recycle Files Deleted

========== Software ==========
DELETED O63 - Logiciel: ComboFix - (sUBs)
DELETED O63 - Logiciel: OTL - (OldTimer)

========== Repertory ==========
DELETE on Reboot Folder**: C:\Qoobox

========== File ==========
DELETED File: c:\combofix.txt
DELETED File: c:\users\wagner\desktop\otl.exe
DELETED File: c:\users\wagner\desktop\otl.txt
DELETED File: c:\users\wagner\desktop\extras.txt


========== Summary ==========
1 : Repertory
4 : File
2 : Software


End of clean in 00mn 16s

========== Report File ==========
C:\ZHP\ZHPFix[R1].txt - 29/06/2013 12:36:23 [525]
C:\ZHP\ZHPFix[R2].txt - 29/06/2013 12:37:30 [814]
C:\ZHP\ZHPFix[R3].txt - 29/06/2013 12:38:08 [905]


E não TEM nenhum H. lá no programa não....tem A, e Q


segue o relatório no C: ZHP

Rapport de ZHPFix 2013.6.12.3 par Nicolas Coolman, Update du 12/06/2013
Fichier d'export Registre :
Run by wagner at 29/06/2013 12:36:23
High Elevated Privileges : OK
Windows 7 Ultimate Edition, 64-bit Service Pack 1 (Build 7601)

Recycle Files Deleted

========== Hosts file ==========
Hosts File not cleaned (Please Deactivate your Antivirus)


========== Summary ==========
1 : Hosts file


End of clean in 36mn 23s

========== Report File ==========
C:\ZHP\ZHPFix[R1].txt - 29/06/2013 12:36:23 [474]
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#29 Por joram
29/06/2013 - 12:55
Olá! Andreatta

Pera ai vc já mudou ai, estou postando o log la da resposta acima, não fiz esse ai q pede....ainda
|- É o mesmo procedimento,mas que utiliza o Bloco de Notas,como auxílio.
|- Ps: Repita o procedimento,colando as informações,em vermelho,ao Bloco de Notas.
|- Não se preocupe com a profusão de ferramentas,pois serão removidas à seu tempo.

-/-

|- Baixe: < Pre_Scan > ( ... par g3n-h@ckm@n & Saachaa )

Imagem

|- Ou aqui: < Pre-Scan > Mirror!

|- Ou aqui: < Pre_Scan.pif > Caso ocorra impedimentos por malwares!

|- Estando na página,clique na seta verde ou Mirror 1.

|- Salve-o no desktop! < Imagem ( winlogon ) >

|- Desabilite seu antivírus,antispyware,sandbox e/ou firewall.
|- Feche programas que estejam abertos e execute a ferramenta!

< Imagem >

|- Duplo-clique em Pre_scan.exe.
|- Ps: Durante o scan,sua área de trabalho irá desaparecer e janelas pretas irão surgir na tela. Tudo isso é normal e faz parte do funcionamento da ferramenta.

Imagem

|- Encontrando infecções,pode ocorrer reinicialização e aparecer essa tela,logo àcima.
|- Ps: Caso apareça e não mostre nenhuma solicitação,clique em "Kill".
|- Neste caso,haverá novo scan e,ao final,será disponibilizado o relatório.
|- Poderá haver reboot(s) e prosseguimento do scan. << Aguarde!
|- Poste ao concluir,o relatório! ( Pre_Scan.txt ) << Link ao relatório!

|- Para enviar,acesse!: Imagem

|- Ou...1fichier.com

|- Ou...myfile.tk

A+
Andreatta
Andreatta Tô em todas Registrado
2.4K Mensagens 39 Curtidas
#30 Por Andreatta
29/06/2013 - 14:07
joram disse:
Olá! Andreatta

|- É o mesmo procedimento,mas que utiliza o Bloco de Notas,como auxílio.
|- Ps: Repita o procedimento,colando as informações,em vermelho,ao Bloco de Notas.
|- Não se preocupe com a profusão de ferramentas,pois serão removidas à seu tempo.

-/-

|- Baixe: < Pre_Scan > ( ... par g3n-h@ckm@n & Saachaa )

Imagem

|- Ou aqui: < Pre-Scan > Mirror!

|- Ou aqui: < Pre_Scan.pif > Caso ocorra impedimentos por malwares!

|- Estando na página,clique na seta verde ou Mirror 1.

|- Salve-o no desktop! < Imagem ( winlogon ) >

|- Desabilite seu antivírus,antispyware,sandbox e/ou firewall.
|- Feche programas que estejam abertos e execute a ferramenta!

< Imagem >

|- Duplo-clique em Pre_scan.exe.
|- Ps: Durante o scan,sua área de trabalho irá desaparecer e janelas pretas irão surgir na tela. Tudo isso é normal e faz parte do funcionamento da ferramenta.

Imagem

|- Encontrando infecções,pode ocorrer reinicialização e aparecer essa tela,logo àcima.
|- Ps: Caso apareça e não mostre nenhuma solicitação,clique em "Kill".
|- Neste caso,haverá novo scan e,ao final,será disponibilizado o relatório.
|- Poderá haver reboot(s) e prosseguimento do scan. << Aguarde!
|- Poste ao concluir,o relatório! ( Pre_Scan.txt ) << Link ao relatório!

|- Para enviar,acesse!: Imagem

|- Ou...1fichier.com

|- Ou...myfile.tk

A+
o link do pré scan :


http://cjoint.com/data3/3FDtgM5Ia3l.htm

e apareceu o ícone Free Disinfection.....SOS com letra verde.
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal