Logo Hardware.com.br
JorgeG
JorgeG Novo Membro Registrado
4 Mensagens 4 Curtidas

Notebook infectado com vírus, nem formatar dá

#1 Por JorgeG 25/07/2013 - 19:55
Já tentei formatar e não dá nao_quero_nem_ver.png
Usei o AdwCleaner e esses são os resultados (Não sei se adianta de alguma coisa, se não adiantar me mandem algum outro programa pra usar):

# AdwCleaner v2.306 - Relatório criado em 19/10/2011 às 21:28:44
# Atualizado em 19/07/2013 por Xplode
# Sistema Operacional : Windows 7 Home Premium Service Pack 1 (64 bits)
# Usuário : Jorginho - JORGINHO-PC
# Modo de Boot : Normal
# Executado de : C:\Users\Jorginho\Desktop\AdwCleaner.exe
# Opção [Verificar]


***** [Serviços] *****


***** [Arquivos/Pastas] *****

Arquivo Encontrado : C:\END
Pasta Encontrado : C:\Program Files (x86)\Conduit
Pasta Encontrado : C:\Program Files (x86)\DealPly
Pasta Encontrado : C:\Program Files (x86)\Softonic_ES
Pasta Encontrado : C:\Program Files (x86)\TornTV.com
Pasta Encontrado : C:\Program Files (x86)\Yontoo
Pasta Encontrado : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bywifi
Pasta Encontrado : C:\ProgramData\Tarma Installer
Pasta Encontrado : C:\Users\Jorginho\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc
Pasta Encontrado : C:\Users\Jorginho\AppData\Local\Ilivid Player
Pasta Encontrado : C:\Users\Jorginho\AppData\Roaming\DealPly
Pasta Encontrado : C:\Users\Jorginho\AppData\Roaming\Funmoods
Pasta Encontrado : C:\Users\Jorginho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
Pasta Encontrado : C:\Users\Jorginho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
Pasta Encontrado : C:\Users\Jorginho\AppData\Roaming\Mozilla\Firefox\Profiles\vnnlh8h1.default\extensions\amo@dealplyshopping.com
Pasta Encontrado : C:\Users\Jorginho\AppData\Roaming\Mozilla\Firefox\Profiles\vnnlh8h1.default\jetpack

***** [Registro] *****

Chave Encontrada : HKCU\Software\1ClickDownload
Chave Encontrada : HKCU\Software\APN PIP
Chave Encontrada : HKCU\Software\AppDataLow\Software\Conduit
Chave Encontrada : HKCU\Software\AppDataLow\Software\Softonic_ES
Chave Encontrada : HKCU\Software\DealPly
Chave Encontrada : HKCU\Software\Funmoods
Chave Encontrada : HKCU\Software\InstallCore
Chave Encontrada : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}
Chave Encontrada : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Chave Encontrada : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Chave Encontrada : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Chave Encontrada : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}
Chave Encontrada : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Chave Encontrada : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Chave Encontrada : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Chave Encontrada : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Chave Encontrada : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DealPly
Chave Encontrada : HKCU\Software\Softonic
Chave Encontrada : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Chave Encontrada : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Chave Encontrada : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Chave Encontrada : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Chave Encontrada : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Chave Encontrada : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Chave Encontrada : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Chave Encontrada : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Chave Encontrada : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Chave Encontrada : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
Chave Encontrada : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
Chave Encontrada : HKLM\Software\Conduit
Chave Encontrada : HKLM\Software\DealPly
Chave Encontrada : HKLM\Software\Iminent
Chave Encontrada : HKLM\Software\InstallCore
Chave Encontrada : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{09E90109-A9AA-4980-BCEF-76F8D924E902}
Chave Encontrada : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Chave Encontrada : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Chave Encontrada : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Chave Encontrada : HKLM\Software\PIP
Chave Encontrada : HKLM\Software\Softonic_ES
Chave Encontrada : HKLM\Software\V9Software
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DealPly
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IM
Chave Encontrada : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Softonic_ES Toolbar
Chave Encontrada : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Chave Encontrada : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Chave Encontrada : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Chave Encontrada : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Chave Encontrada : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Chave Encontrada : HKLM\SOFTWARE\Tarma Installer
Chave Encontrada : HKU\S-1-5-21-2501159022-4194044501-4189696482-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Valor Encontrada : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}]
Valor Encontrada : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}]
Valor Encontrada : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}]

***** [Navegadores] *****

-\\ Internet Explorer v9.0.8112.16446

[OK] Registro está limpo.

-\\ Mozilla Firefox v19.0.2 (pt-BR)

Arquivo : C:\Users\Jorginho\AppData\Roaming\Mozilla\Firefox\Profiles\vnnlh8h1.default\prefs.js

Encontrada : user_pref("extensions.funmoods.aflt", "01543");
Encontrada : user_pref("extensions.funmoods.appId", "{EA28B360-05E0-4F93-8150-02891F1D8D3C}");
Encontrada : user_pref("extensions.funmoods.brwsrsrc", "ietlbr");
Encontrada : user_pref("extensions.funmoods.cntry", "BR");
Encontrada : user_pref("extensions.funmoods.cv", "cv5");
Encontrada : user_pref("extensions.funmoods.dfltLng", "");
Encontrada : user_pref("extensions.funmoods.dfltSrch", false);
Encontrada : user_pref("extensions.funmoods.dfltlng", "en");
Encontrada : user_pref("extensions.funmoods.dfltsrch", "false");
Encontrada : user_pref("extensions.funmoods.dnsErr", true);
Encontrada : user_pref("extensions.funmoods.envrmnt", "production");
Encontrada : user_pref("extensions.funmoods.excTlbr", false);
Encontrada : user_pref("extensions.funmoods.hdrMd5", "B9595EEA59F520BF49AF5F75D50C23C5");
Encontrada : user_pref("extensions.funmoods.hmpg", true);
Encontrada : user_pref("extensions.funmoods.hmpgUrl", "hxxp://searchfunmoods.com/?f=1&a=01543&cd=2XzuyEtN2Y1L1Qzu[...]
Encontrada : user_pref("extensions.funmoods.hrdid", "74F06D965A815588");
Encontrada : user_pref("extensions.funmoods.id", "74F06D965A815588");
Encontrada : user_pref("extensions.funmoods.instlDay", "15771");
Encontrada : user_pref("extensions.funmoods.instlRef", "");
Encontrada : user_pref("extensions.funmoods.instlday", "15771");
Encontrada : user_pref("extensions.funmoods.instlref", "");
Encontrada : user_pref("extensions.funmoods.isdcmntcmplt", "false");
Encontrada : user_pref("extensions.funmoods.keywordurl", "");
Encontrada : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");
Encontrada : user_pref("extensions.funmoods.monitorreport", true);
Encontrada : user_pref("extensions.funmoods.newTabUrl", "hxxp://searchfunmoods.com/?f=2&a=01543&cd=2XzuyEtN2Y1L1Q[...]
Encontrada : user_pref("extensions.funmoods.newtab", "false");
Encontrada : user_pref("extensions.funmoods.newtaburl", "hxxp://searchfunmoods.com/?f=2&a=01543&cd=2XzuyEtN2Y1L1Q[...]
Encontrada : user_pref("extensions.funmoods.prdct", "funmoods");
Encontrada : user_pref("extensions.funmoods.prtnrId", "funmoods");
Encontrada : user_pref("extensions.funmoods.prtnrid", "funmoods");
Encontrada : user_pref("extensions.funmoods.savedVrsnTs", "1");
Encontrada : user_pref("extensions.funmoods.sg", "none");
Encontrada : user_pref("extensions.funmoods.smplgrp", "free");
Encontrada : user_pref("extensions.funmoods.srch", "");
Encontrada : user_pref("extensions.funmoods.srchPrvdr", "Funmoods");
Encontrada : user_pref("extensions.funmoods.srchprvdr", "Funmoods");
Encontrada : user_pref("extensions.funmoods.tlbrId", "base");
Encontrada : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://searchfunmoods.com/?f=3&a=01543&cd=2XzuyEtN2Y1L[...]
Encontrada : user_pref("extensions.funmoods.tlbrid", "base");
Encontrada : user_pref("extensions.funmoods.tlbrsrchurl", "hxxp://searchfunmoods.com/?f=3&a=01543&cd=2XzuyEtN2Y1L[...]
Encontrada : user_pref("extensions.funmoods.vrsn", "1.8.11.0");
Encontrada : user_pref("extensions.funmoods.vrsni", "1.8.11.0");
Encontrada : user_pref("extensions.funmoods.vrsnts", "");
Encontrada : user_pref("extensions.funmoods.xpestat\\xpereportdata", "8-2-2013");
Encontrada : user_pref("extensions.funmoods_i.hmpg", true);
Encontrada : user_pref("extensions.funmoods_i.newTab", false);
Encontrada : user_pref("extensions.funmoods_i.smplGrp", "none");
Encontrada : user_pref("extensions.funmoods_i.vrsnTs", "1.8.11.023:57:49");
Encontrada : user_pref("extentions.y2layers.defaultEnableAppsList", "DropDownDeals,buzzdock,YontooNewOffers");
Encontrada : user_pref("extentions.y2layers.installId", "863b1b69-dcca-4ae8-bb5d-fa832b345de9");
Encontrada : user_pref("keyword.keywordURL", "hxxp://search.hotspotshield.com/g/results.php?c=s&q=");

-\\ Google Chrome v28.0.1500.72

Arquivo : C:\Users\Jorginho\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Arquivo está limpo.

*************************

AdwCleaner[R1].txt - [12456 octets] - [19/10/2011 21:28:44]

########## EOF - C:\AdwCleaner[R1].txt - [12517 octets] ##########




E esse depois que eu cliquei em Remover

# AdwCleaner v2.306 - Relatório criado em 19/10/2011 às 21:29:48
# Atualizado em 19/07/2013 por Xplode
# Sistema Operacional : Windows 7 Home Premium Service Pack 1 (64 bits)
# Usuário : Jorginho - JORGINHO-PC
# Modo de Boot : Normal
# Executado de : C:\Users\Jorginho\Desktop\AdwCleaner.exe
# Opção [Remover]


***** [Serviços] *****


***** [Arquivos/Pastas] *****

Arquivo Removido : C:\END
Pasta Removido : C:\Program Files (x86)\Conduit
Pasta Removido : C:\Program Files (x86)\DealPly
Pasta Removido : C:\Program Files (x86)\Softonic_ES
Pasta Removido : C:\Program Files (x86)\TornTV.com
Pasta Removido : C:\Program Files (x86)\Yontoo
Pasta Removido : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bywifi
Pasta Removido : C:\ProgramData\Tarma Installer
Pasta Removido : C:\Users\Jorginho\AppData\Local\Google\Chrome\User Data\Default\Extensions\niapdbllcanepiiimjjndipklodoedlc
Pasta Removido : C:\Users\Jorginho\AppData\Local\Ilivid Player
Pasta Removido : C:\Users\Jorginho\AppData\Roaming\DealPly
Pasta Removido : C:\Users\Jorginho\AppData\Roaming\Funmoods
Pasta Removido : C:\Users\Jorginho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
Pasta Removido : C:\Users\Jorginho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com
Pasta Removido : C:\Users\Jorginho\AppData\Roaming\Mozilla\Firefox\Profiles\vnnlh8h1.default\extensions\amo@dealplyshopping.com
Pasta Removido : C:\Users\Jorginho\AppData\Roaming\Mozilla\Firefox\Profiles\vnnlh8h1.default\jetpack

***** [Registro] *****

Chave Removida : HKCU\Software\1ClickDownload
Chave Removida : HKCU\Software\APN PIP
Chave Removida : HKCU\Software\AppDataLow\Software\Conduit
Chave Removida : HKCU\Software\AppDataLow\Software\Softonic_ES
Chave Removida : HKCU\Software\DealPly
Chave Removida : HKCU\Software\Funmoods
Chave Removida : HKCU\Software\InstallCore
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\DealPly
Chave Removida : HKCU\Software\Softonic
Chave Removida : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Chave Removida : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Chave Removida : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Chave Removida : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Chave Removida : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
Chave Removida : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
Chave Removida : HKLM\Software\Conduit
Chave Removida : HKLM\Software\DealPly
Chave Removida : HKLM\Software\Iminent
Chave Removida : HKLM\Software\InstallCore
Chave Removida : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{09E90109-A9AA-4980-BCEF-76F8D924E902}
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Chave Removida : HKLM\Software\PIP
Chave Removida : HKLM\Software\Softonic_ES
Chave Removida : HKLM\Software\V9Software
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{99066096-8989-4612-841F-621A01D54AD7}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DealPly
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IM
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Softonic_ES Toolbar
Chave Removida : HKLM\SOFTWARE\Classes\CLSID\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Chave Removida : HKLM\SOFTWARE\Tarma Installer
Valor Removida : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}]
Valor Removida : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}]
Valor Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{C2ED826E-8903-4A9D-B0DF-3A8FB8EA918A}]

***** [Navegadores] *****

-\\ Internet Explorer v9.0.8112.16446

[OK] Registro está limpo.

-\\ Mozilla Firefox v19.0.2 (pt-BR)

Arquivo : C:\Users\Jorginho\AppData\Roaming\Mozilla\Firefox\Profiles\vnnlh8h1.default\prefs.js

C:\Users\Jorginho\AppData\Roaming\Mozilla\Firefox\Profiles\vnnlh8h1.default\user.js ... Removido !

Removida : user_pref("extensions.funmoods.aflt", "01543");
Removida : user_pref("extensions.funmoods.appId", "{EA28B360-05E0-4F93-8150-02891F1D8D3C}");
Removida : user_pref("extensions.funmoods.brwsrsrc", "ietlbr");
Removida : user_pref("extensions.funmoods.cntry", "BR");
Removida : user_pref("extensions.funmoods.cv", "cv5");
Removida : user_pref("extensions.funmoods.dfltLng", "");
Removida : user_pref("extensions.funmoods.dfltSrch", false);
Removida : user_pref("extensions.funmoods.dfltlng", "en");
Removida : user_pref("extensions.funmoods.dfltsrch", "false");
Removida : user_pref("extensions.funmoods.dnsErr", true);
Removida : user_pref("extensions.funmoods.envrmnt", "production");
Removida : user_pref("extensions.funmoods.excTlbr", false);
Removida : user_pref("extensions.funmoods.hdrMd5", "B9595EEA59F520BF49AF5F75D50C23C5");
Removida : user_pref("extensions.funmoods.hmpg", true);
Removida : user_pref("extensions.funmoods.hmpgUrl", "hxxp://searchfunmoods.com/?f=1&a=01543&cd=2XzuyEtN2Y1L1Qzu[...]
Removida : user_pref("extensions.funmoods.hrdid", "74F06D965A815588");
Removida : user_pref("extensions.funmoods.id", "74F06D965A815588");
Removida : user_pref("extensions.funmoods.instlDay", "15771");
Removida : user_pref("extensions.funmoods.instlRef", "");
Removida : user_pref("extensions.funmoods.instlday", "15771");
Removida : user_pref("extensions.funmoods.instlref", "");
Removida : user_pref("extensions.funmoods.isdcmntcmplt", "false");
Removida : user_pref("extensions.funmoods.keywordurl", "");
Removida : user_pref("extensions.funmoods.mntrvrsn", "1.3.0");
Removida : user_pref("extensions.funmoods.monitorreport", true);
Removida : user_pref("extensions.funmoods.newTabUrl", "hxxp://searchfunmoods.com/?f=2&a=01543&cd=2XzuyEtN2Y1L1Q[...]
Removida : user_pref("extensions.funmoods.newtab", "false");
Removida : user_pref("extensions.funmoods.newtaburl", "hxxp://searchfunmoods.com/?f=2&a=01543&cd=2XzuyEtN2Y1L1Q[...]
Removida : user_pref("extensions.funmoods.prdct", "funmoods");
Removida : user_pref("extensions.funmoods.prtnrId", "funmoods");
Removida : user_pref("extensions.funmoods.prtnrid", "funmoods");
Removida : user_pref("extensions.funmoods.savedVrsnTs", "1");
Removida : user_pref("extensions.funmoods.sg", "none");
Removida : user_pref("extensions.funmoods.smplgrp", "free");
Removida : user_pref("extensions.funmoods.srch", "");
Removida : user_pref("extensions.funmoods.srchPrvdr", "Funmoods");
Removida : user_pref("extensions.funmoods.srchprvdr", "Funmoods");
Removida : user_pref("extensions.funmoods.tlbrId", "base");
Removida : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://searchfunmoods.com/?f=3&a=01543&cd=2XzuyEtN2Y1L[...]
Removida : user_pref("extensions.funmoods.tlbrid", "base");
Removida : user_pref("extensions.funmoods.tlbrsrchurl", "hxxp://searchfunmoods.com/?f=3&a=01543&cd=2XzuyEtN2Y1L[...]
Removida : user_pref("extensions.funmoods.vrsn", "1.8.11.0");
Removida : user_pref("extensions.funmoods.vrsni", "1.8.11.0");
Removida : user_pref("extensions.funmoods.vrsnts", "");
Removida : user_pref("extensions.funmoods.xpestat\\xpereportdata", "8-2-2013");
Removida : user_pref("extensions.funmoods_i.hmpg", true);
Removida : user_pref("extensions.funmoods_i.newTab", false);
Removida : user_pref("extensions.funmoods_i.smplGrp", "none");
Removida : user_pref("extensions.funmoods_i.vrsnTs", "1.8.11.023:57:49");
Removida : user_pref("extentions.y2layers.defaultEnableAppsList", "DropDownDeals,buzzdock,YontooNewOffers");
Removida : user_pref("extentions.y2layers.installId", "863b1b69-dcca-4ae8-bb5d-fa832b345de9");
Removida : user_pref("keyword.keywordURL", "hxxp://search.hotspotshield.com/g/results.php?c=s&q=");

-\\ Google Chrome v28.0.1500.72

Arquivo : C:\Users\Jorginho\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] Arquivo está limpo.

*************************

AdwCleaner[R1].txt - [12573 octets] - [19/10/2011 21:28:44]
AdwCleaner[S1].txt - [12179 octets] - [19/10/2011 21:29:48]

########## EOF - C:\AdwCleaner[S1].txt - [12240 octets] ##########



To usando meu pc pra entrar aqui no fórum porque o notebook ta IMPOSSÍVEL de entrar na maioria dos sites.
O vírus não deixa abrir o gerenciador de tarefas também ;-;
Naldo Volpe
Naldo Volpe Cyber Highlander Registrado
20.8K Mensagens 3.5K Curtidas
#2 Por Naldo Volpe
25/07/2013 - 20:59
Baixe o urple">Kaspersky AVP Tool de um desses 2 links:
http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/
http://dnl-us6.kaspersky-labs.com/devbuilds/AVPTool/

Você será conduzido a uma página da Kaspersky, solicitando um email para cadastro, nome e sobrenome. Somente o campo "email" é obrigatório.
Informe seu email depois clique no botão Submit Form.
A página será recarregada. Clique no botão Download

Salve-o em sua área de trabalho.

Execute o arquivo e aguarde a instalação.
** Usuários do Windows Vista e Windows 7:
Clique com o direito sobre o arquivo, depois clique em Executar como administrador


Na tela do contrato de licença, marque a opção I accept the license agreement e depois clique no botão Start. Aparentemente o programa congela e nada acontece. É normal, apenas aguarde até aparecer a tela inicial do programa, e então clique no ícone Settings:

Imagem Clique aqui para ver no tamanho original.Imagem

Nesta tela, marque a caixa ao lado de:
  • Meu Computador
  • Disco local (Csmile.png
Marque também todas as unidades que aparecem abaixo de Disco Local, caso houverem. Depois clique na aba Automatic Scan

Imagem Clique aqui para ver no tamanho original.Imagem

De volta à tela inicial do programa, clique no botão Start scanning

Tenha paciência, é um pouco demorado.

Quando terminar, caso tenha detectado algo, o programa irá lhe perguntar o que fazer.

Marque o quadradinho ao lado de Apply to all objects e depois clique em Skip (queremos apenas o log).

Imagem Clique aqui para ver no tamanho original.Imagem


Enquanto durar o exame, a tela inicial exibirá uma barra de progresso. Quando terminar, o programa exibirá o status concluído e um botão que ficará na cor laranja, caso nada tenha sido detectado, e na cor vermelha, caso tenha encontrado algo.

Caso tenha detectado algo, o programa também exibirá uma tela de alerta, avisando que o seu sistema está desprotegido e sugerindo um produto da Kaspersky. Clique no botão No, thanks.


De volta à tela principal, caso tenha sido detectado algo, então salve o log. Se você fechar o programa e esquecer de salvar o log, terá que repetir todo o scan novamente.

Para salvar o log, clique no ícone Reports (ao lado do ícone "Settings"). Na próxima janela, clique em Detected Threats, depois clique no ícone de disquete para salvar o log.

Escolha um local de fácil acesso e salve como log.txt

Copie todo o conteúdo desse bloco de notas e cole na sua próxima resposta.

Se nada for detectado, então não precisa salvar o log. Apenas poste aqui avisando.

Para sair do programa, basta clicar no X no canto superior direito
Brazilian Game Player:| Brawl Stars BR |
- Atenção:Não seja um idiota, não saia de casa sem máscara.!.
- Continue utilizando máscara em ambientes abertos e fechados.!.
- A Pandemia não acabou, não faça festas / não faça aglomeração / 
não fique em lugares com muitas pessoas próximas /
Brasil: +22.590 novos casos. Situação atual. | Japão: +53.911 novos casos | Cachaceiro L detonando o Brasil |
JorgeG
JorgeG Novo Membro Registrado
4 Mensagens 4 Curtidas
#3 Por JorgeG
26/07/2013 - 02:47
Acredito que os hacks de Grand Chase não sejam o problema, já que antes o notebook funcionava normalmente comigo (mas fica a dúvida, esses vírus desses hacks prejudicam estão prejudicado o pc também?) , depois que vendi o note que veio esse maldito vírus (que não deixa abrir o gerenciador de tarefas, entrar em alguns sites e nem formatar).

Status: Detected (events: 32)
19/10/2011 23:52:59 Detected Trojan program Trojan-Dropper.Win32.FrauDrop.zzpp C:\Documents and Settings\Jorginho\AppData\Local\Temp\050313_d2.exe High
19/10/2011 23:53:05 Detected adware not-a-virus:AdWare.Win32.Agent.zmw C:\Documents and Settings\Jorginho\AppData\Local\Temp\050313_y.exe Medium
19/10/2011 23:57:35 Detected Trojan program Trojan-Dropper.Win32.FrauDrop.zzpp C:\Documents and Settings\Jorginho\Configurações locais\Temp\050313_d2.exe High
20/10/2011 01:18:02 Detected adware not-a-virus:AdWare.Win32.Agent.zmw C:\Documents and Settings\Jorginho\Configurações locais\Temp\050313_y.exe Medium
20/10/2011 01:48:11 Detected Trojan program Trojan.Win32.VBKrypt.mgke C:\Documents and Settings\Jorginho\Downloads\HMu\MasterGc - ExpertGH 18-07.rar//Hack by Limdomar/MasterGC - ExpertGH.exe High
20/10/2011 01:48:13 Detected Trojan program Trojan.Win32.VBKrypt.mgsj C:\Documents and Settings\Jorginho\Downloads\HMu\MasterGC - ExpertGH [25-07].rar//MasterGC - ExpertGH.exe High
20/10/2011 01:48:22 Detected Trojan program Packed.Win32.Black.a C:\Documents and Settings\Jorginho\Downloads\HMu\PCheats Chaos BGC v29.0.zip/PCheats Chaos BGC v29.0.exe High
20/10/2011 01:48:22 Detected Trojan program Trojan.Win32.VBKrypt.mgsj C:\Documents and Settings\Jorginho\Downloads\HMu\MasterGC - ExpertGH.exe High
20/10/2011 01:48:23 Detected Trojan program Trojan.Win32.Genome.ahzrb C:\Documents and Settings\Jorginho\Downloads\HMu\WebCheats Trainer 5.0.rar//WebCheats Trainer.exe High
20/10/2011 01:48:24 Detected Trojan program Packed.Win32.Black.a C:\Documents and Settings\Jorginho\Downloads\HMu\PCheats Chaos BGC v31.0.zip/PCheats Chaos BGC v31.0.exe High
20/10/2011 01:48:43 Detected Trojan program Trojan.Win32.Genome.ahzrb C:\Documents and Settings\Jorginho\Downloads\HMu\WebCheats Trainer.exe High
20/10/2011 01:49:02 Detected Trojan program Trojan.Win32.VBKrypt.mgke C:\Documents and Settings\Jorginho\Downloads\HMu\Hack by Limdomar\MasterGC - ExpertGH.exe High
20/10/2011 01:49:02 Detected Trojan program Trojan.Win32.VBKrypt.mgsu C:\Documents and Settings\Jorginho\Downloads\HMu\New\MasterGC - ExpertGH [26-07].rar//MasterGC - ExpertGH.exe High
20/10/2011 01:49:13 Detected Trojan program Trojan.Win32.Genome.aiadm C:\Documents and Settings\Jorginho\Downloads\HMu\New wc\WebCheats Trainer 6.0.rar//WebCheats Trainer.exe High
20/10/2011 01:49:13 Detected Trojan program Trojan.Win32.VBKrypt.mgsu C:\Documents and Settings\Jorginho\Downloads\HMu\New\MasterGC - ExpertGH.exe High
20/10/2011 01:49:23 Detected Trojan program Trojan.Win32.Genome.aiadm C:\Documents and Settings\Jorginho\Downloads\HMu\New wc\WebCheats Trainer.exe High
20/10/2011 02:14:04 Detected adware not-a-virus:AdWare.Win32.Agent.zmw C:\Users\Jorginho\AppData\Local\Temp\050313_y.exe Medium
20/10/2011 02:14:04 Detected Trojan program Trojan-Dropper.Win32.FrauDrop.zzpp C:\Users\Jorginho\AppData\Local\Temp\050313_d2.exe High
20/10/2011 02:16:52 Detected adware not-a-virus:AdWare.Win32.Agent.zmw C:\Users\Jorginho\Configurações locais\Temp\050313_y.exe Medium
20/10/2011 02:16:52 Detected Trojan program Trojan-Dropper.Win32.FrauDrop.zzpp C:\Users\Jorginho\Configurações locais\Temp\050313_d2.exe High
20/10/2011 02:20:48 Detected Trojan program Trojan.Win32.VBKrypt.mgke C:\Users\Jorginho\Downloads\HMu\MasterGc - ExpertGH 18-07.rar//Hack by Limdomar/MasterGC - ExpertGH.exe High
20/10/2011 02:20:49 Detected Trojan program Trojan.Win32.VBKrypt.mgsj C:\Users\Jorginho\Downloads\HMu\MasterGC - ExpertGH [25-07].rar//MasterGC - ExpertGH.exe High
20/10/2011 02:20:50 Detected Trojan program Packed.Win32.Black.a C:\Users\Jorginho\Downloads\HMu\PCheats Chaos BGC v29.0.zip/PCheats Chaos BGC v29.0.exe High
20/10/2011 02:20:51 Detected Trojan program Trojan.Win32.VBKrypt.mgsj C:\Users\Jorginho\Downloads\HMu\MasterGC - ExpertGH.exe High
20/10/2011 02:20:51 Detected Trojan program Trojan.Win32.Genome.ahzrb C:\Users\Jorginho\Downloads\HMu\WebCheats Trainer 5.0.rar//WebCheats Trainer.exe High
20/10/2011 02:20:52 Detected Trojan program Packed.Win32.Black.a C:\Users\Jorginho\Downloads\HMu\PCheats Chaos BGC v31.0.zip/PCheats Chaos BGC v31.0.exe High
20/10/2011 02:20:53 Detected Trojan program Trojan.Win32.Genome.ahzrb C:\Users\Jorginho\Downloads\HMu\WebCheats Trainer.exe High
20/10/2011 02:20:53 Detected Trojan program Trojan.Win32.VBKrypt.mgsu C:\Users\Jorginho\Downloads\HMu\New\MasterGC - ExpertGH [26-07].rar//MasterGC - ExpertGH.exe High
20/10/2011 02:20:53 Detected Trojan program Trojan.Win32.VBKrypt.mgke C:\Users\Jorginho\Downloads\HMu\Hack by Limdomar\MasterGC - ExpertGH.exe High
20/10/2011 02:20:56 Detected Trojan program Trojan.Win32.Genome.aiadm C:\Users\Jorginho\Downloads\HMu\New wc\WebCheats Trainer 6.0.rar//WebCheats Trainer.exe High
20/10/2011 02:20:57 Detected Trojan program Trojan.Win32.VBKrypt.mgsu C:\Users\Jorginho\Downloads\HMu\New\MasterGC - ExpertGH.exe High
20/10/2011 02:20:57 Detected Trojan program Trojan.Win32.Genome.aiadm C:\Users\Jorginho\Downloads\HMu\New wc\WebCheats Trainer.exe High
Naldo Volpe
Naldo Volpe Cyber Highlander Registrado
20.8K Mensagens 3.5K Curtidas
#4 Por Naldo Volpe
26/07/2013 - 15:46
Seu PC esta cheio de Trojans , aconselho a repetir o
procedimento , só que ao invés de clicar em skip clique
em delete , cole novamente o LOG gerado.
Brazilian Game Player:| Brawl Stars BR |
- Atenção:Não seja um idiota, não saia de casa sem máscara.!.
- Continue utilizando máscara em ambientes abertos e fechados.!.
- A Pandemia não acabou, não faça festas / não faça aglomeração / 
não fique em lugares com muitas pessoas próximas /
Brasil: +22.590 novos casos. Situação atual. | Japão: +53.911 novos casos | Cachaceiro L detonando o Brasil |
Wings
Wings Cyber Highlander Registrado
20.3K Mensagens 1.2K Curtidas
#6 Por Wings
26/07/2013 - 19:19
Olá JorgeG


veja.png Baixe o Zoek (...de Smeenk) e salve-o no Desktop (Área de Trabalho)

*Mantenha-se conectado com a Internet

*Clique com o botão direito do mouse no Zoek e selecione Executar como administrador

*Cole as linhas em marrom no espaço

startupall;
autoclean;
filesrcm;
installedprogs;
emptyalltemp;

*Feche o seu navegador e clique [Run Script]

*Durante o scan serão apresentadas as seguintes informações:

Zoek.exe is running now.
Do not start any browser windows, they will be closed automatically.
Please wait! This window will close when finished.
A logfile will open afterwards and can also be found on your systemdrive as zoek-results.log


*Aguarde o término. Caso a reinicialização do PC seja solicitada, clique [OK]



veja.png Acesse este link

*Clique [Selecionar arquivo...]

*Localize o relatório C:\zoek-results.txt e clique [Abrir]

*Selecione 4 jours

*Clique [Créer le lien Cjoint]

Imagem

*Cole o link criado ao lado de Le lien a été créé:

Imagem
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal