Logo Hardware.com.br
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#2 Por joram
07/04/2016 - 15:42
/_ Boa Tarde! LucasPortelaa _\

Imagem
https://www.hardware.com.br/comunidade/v-t/1226830/

Siga as recomendações deste Tópico e poste: FRST.txt + Addition.txt
Disponibilize
os relatórios em Cjoint.com ou utilize spoiler,cuja instrução está ao final desta página.

A+
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#4 Por joram
07/04/2016 - 16:18
/_ Boa Tarde! LucasPortelaa _\

> Desinstale estes softwares: <16>

Advanced Calendar 2.0.0.11189 <<
Body Text Feathering <<
DNS Unlocker <<
MixVideoPlayer <<
MobilePCStarterKit 000.005030291 <<
MyBestOffersToday 000.037050289 <<
MyBestOffersToday Maintenance 000.247 <<
Primary Color <<
Satellite Comma <<
Setup <<
SpaceSoundPro <<
Wajam <<
The Desktop Weather 2.0.0.11150 <<
yessearches Uninstall (HKLM-x32\...\Uninstall sqr1) (Version: - ) <<
yessearches Uninstall (HKLM-x32\...\Uninstall wak) (Version: - ) <<
使命召唤Online (HKLM-x32\...\使命召唤Online) (Version: - Tencent) <<


> Após as desinstalações,limpe o registro com o CCleaner e poste novos logs da FRST.txt + Addition.txt

A+
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#8 Por joram
07/04/2016 - 18:27
/_ Boa Noite! LucasPortelaa _\

> Desinstale estes softwares: <4>

PriceFountain (remove only) <<
Selection Tools <<
Setup <<
WindApp <<


> Copie estas informações que estão no Spoiler,para o Bloco de Notas.
> Salve-as com o nome fixlist. << Texto!
> Salve-as ao desktop! ( Área de trabalho ... )
[spoiler]start
CloseProcesses:
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [rec_en_247] => [X]
HKLM\...\RunOnce: [WINDOWS_SCREEN_MANAGER_UPDATER_1] => C:\Program Files\Windows Screen Manager\Windows screen manage updater.exe [16896 2016-04-07] (Wizzservices)
HKLM-x32\...\RunOnce: [upmbot_en_037050289.exe] => C:\Users\porte\AppData\Local\mbot_en_037050289\upmbot_en_037050289.exe [3245744 2016-04-05] ()
HKLM-x32\...\RunOnce: [upmpck_en_005030291.exe] => C:\Users\porte\AppData\Local\mpck_en_005030291\upmpck_en_005030291.exe [3242672 2016-04-07] ()
HKU\S-1-5-21-1850922605-1822221301-2256374631-1001\...\Run: [osmsg] => C:\ProgramData\WindowsMsg\osmsg.exe [2055168 2016-04-07] ()
HKU\S-1-5-21-1850922605-1822221301-2256374631-1001\...\Run: [Pritc] => C:\Users\porte\AppData\Local\Temp\is-8FC93.tmp\print.exe [2955264 2016-03-03] (VLOME) <===== ATENÇÃO
HKU\S-1-5-21-1850922605-1822221301-2256374631-1001\...\Run: [Bubble Dock] => C:\Users\porte\AppData\Roaming\Nosibay\Bubble Dock\LBubble Dock.exe [666352 2016-02-12] (Nosibay)
HKU\S-1-5-21-1850922605-1822221301-2256374631-1001\...\Run: [Selection Tools] => C:\Users\porte\AppData\Roaming\WTools\Selection Tools\Selection Tools.exe [4083952 2016-03-14] (Nosibay)
HKU\S-1-5-21-1850922605-1822221301-2256374631-1003\...\Run: [msiql] => C:\ProgramData\msiql.exe [1917952 2016-04-01] ()
HKU\S-1-5-21-1850922605-1822221301-2256374631-1003\...\Run: [testLive] => C:\ProgramData\testLive.exe [1852928 2016-04-07] ()
Winsock: Catalog5 07 C:\ProgramData\System32\SafeGuard32.dll Nenhum Arquivo
Winsock: Catalog5-x64 07 C:\ProgramData\System32\SafeGuard64.dll [3587000 2016-04-07] ()
BHO-x32: PriceFountain -> {b608cc98-54de-4775-96c9-097de398500c} -> C:\Users\porte\AppData\Local\PriceFountain\PriceFountainIE.dll [2015-06-18] ()
FF DefaultSearchEngine: yessearches
FF DefaultSearchEngine.US: data:text/plain,browser.search.defaultenginename.US=yessearches
FF Keyword.URL: hxxp://www.yessearches.com/chrome.php?uid=8706BC30A2C9FF0F5CBDA48E266E86A0&ptid=sqr1&ts=AHEqA30pA3MpBk..&v=20160405&mode=ffexttoolbar&q=
FF user.js: detected! => C:\Users\porte\AppData\Roaming\Mozilla\Firefox\Profiles\zqxf6owl.default\user.js [2016-04-07]
FF user.js: detected! => C:\Users\porte\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\user.js [2016-04-07]
FF SearchPlugin: C:\Users\porte\AppData\Roaming\Mozilla\Firefox\Profiles\zqxf6owl.default\searchplugins\DD1B66D4.xml [2016-04-07]
FF SearchPlugin: C:\Users\porte\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\DD1B66D4.xml [2016-04-07]
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-19] [não assinado]
S2 Winsere; C:\Program Files (x86)\Winsere\Winsere\Winsere.exe [316400 2016-04-06] ()
R2 XBox; C:\Users\porte\AppData\Roaming\XBox\XBLive.exe [5906904 2016-02-27] (Microsoft Corporation)
S2 ggbugreport; "C:\Program Files (x86)\SearchesToYesbnd\bugreport.exe" {154DFF63-3402-4815-941A-AAD63AE8B428} [X]
S2 MPCProtectService; "C:\Program Files (x86)\MPC Cleaner\MPCProtectService.exe" [X]
S3 TesSafe; C:\WINDOWS\system32\TesSafe.sys [1101024 2016-03-25] (TENCENT)
S1 gbpddfac; system32\drivers\gbpddfac64.sys [X]
S0 gbpddreg; system32\drivers\gbpddreg64.sys [X]
S3 ohci1394; \SystemRoot\System32\drivers\ohci1394.sys [X]
2016-04-07 15:38 - 2016-04-07 15:38 - 00000000 ____D C:\Program Files (x86)\SearchesToYesbnd
2016-04-07 14:51 - 2016-04-07 14:51 - 00000043 _____ C:\Users\porte\AppData\Roaming\WB.CFG
2016-04-07 14:46 - 2016-04-07 16:27 - 00000544 _____ C:\WINDOWS\Tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B}.job
2016-04-07 14:46 - 2016-04-07 14:46 - 00003750 _____ C:\WINDOWS\System32\Tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B}
2016-04-07 14:46 - 2016-04-07 14:46 - 00000000 ____D C:\Users\Todos os Usuários\baidu
2016-04-07 14:46 - 2016-04-07 14:46 - 00000000 ____D C:\Users\porte\AppData\Roaming\WeatherTool
2016-04-07 14:46 - 2016-04-07 14:46 - 00000000 ____D C:\Users\porte\AppData\Roaming\Baidu
2016-04-07 14:34 - 2016-04-07 14:34 - 00000000 ____D C:\Users\Todos os Usuários\Uniblue
2016-04-07 14:16 - 2016-04-07 14:16 - 00000000 ____D C:\Users\pitte\AppData\Roaming\LightGate
2016-04-07 14:12 - 2016-04-07 14:12 - 00000000 ____T C:\WINDOWS\system32\mfsCCF7.tmp
2016-04-07 14:12 - 2016-04-07 14:12 - 00000000 ____T C:\WINDOWS\system32\mfsC65E.tmp
2016-04-07 14:12 - 2016-04-07 14:12 - 00000000 ____T C:\WINDOWS\system32\mfs7F13.tmp
2016-04-07 14:12 - 2016-04-07 14:12 - 00000000 ____T C:\WINDOWS\system32\mfs7D2E.tmp
2016-04-07 14:12 - 2016-04-07 14:12 - 00000000 ____D C:\Users\porte\AppData\Roaming\CalendarTool
2016-04-07 14:11 - 2016-04-07 14:12 - 00000000 ____T C:\WINDOWS\system32\mfsF877.tmp
2016-04-07 14:11 - 2016-04-07 14:12 - 00000000 ____T C:\WINDOWS\system32\mfsD31A.tmp
2016-04-07 14:11 - 2016-04-07 14:11 - 00000000 ____T C:\WINDOWS\system32\mfsD87A.tmp
2016-04-07 14:11 - 2016-04-07 14:11 - 00000000 ____T C:\WINDOWS\system32\mfsCC62.tmp
2016-04-07 14:11 - 2016-04-07 14:11 - 00000000 ____T C:\WINDOWS\system32\mfsCC51.tmp
2016-04-07 14:11 - 2016-04-07 14:11 - 00000000 ____T C:\WINDOWS\system32\mfsCABA.tmp
2016-04-07 14:11 - 2016-04-07 14:11 - 00000000 ____T C:\WINDOWS\system32\mfsC1B0.tmp
2016-04-07 14:11 - 2016-04-07 14:11 - 00000000 ____T C:\WINDOWS\system32\mfsC1AF.tmp
2016-04-07 14:11 - 2016-04-07 14:11 - 00000000 ____T C:\WINDOWS\system32\mfsBC7E.tmp
2016-04-07 14:11 - 2016-04-07 14:11 - 00000000 ____T C:\WINDOWS\system32\mfsBC6E.tmp
2016-04-07 14:11 - 2016-04-07 14:11 - 00000000 ____T C:\WINDOWS\system32\mfsA887.tmp
2016-04-07 14:11 - 2016-04-07 14:11 - 00000000 ____T C:\WINDOWS\system32\mfsA876.tmp
2016-04-07 14:09 - 2016-04-07 14:09 - 00000000 ____D C:\Program Files\NewExt
2016-04-07 14:09 - 2016-04-07 14:09 - 00000000 ____D C:\Program Files (x86)\SkypeUpdateEx
2016-04-07 14:08 - 2016-04-07 14:53 - 00000000 ____D C:\Users\Todos os Usuários\System32
2016-04-07 14:08 - 2016-04-07 14:08 - 00000000 ____D C:\Users\porte\AppData\Local\tuto_monetize_120160407
2016-04-07 14:08 - 2016-04-07 14:08 - 00000000 ____D C:\Users\porte\AppData\Local\csdi_monetize_220160407
2016-04-07 14:08 - 2016-04-07 14:08 - 00000000 ____D C:\Users\pitte\AppData\Roaming\CalendarTool
2016-04-07 14:08 - 2016-04-07 14:08 - 00000000 ____D C:\Program Files\Windows Screen Manager
2016-04-07 14:08 - 2016-04-07 14:08 - 00000000 ____D C:\Program Files (x86)\ComoBo
2016-04-07 14:07 - 2016-04-07 16:30 - 00000000 ____D C:\Users\porte\AppData\Local\mpck_en_005030291
2016-04-07 14:07 - 2016-04-07 13:45 - 01852928 _____ C:\Users\Todos os Usuários\testLive.exe
2016-04-07 14:07 - 2016-04-05 19:37 - 00114176 _____ C:\Users\Todos os Usuários\hp.exe
2016-04-07 14:07 - 2015-11-25 15:31 - 01100288 _____ C:\Users\Todos os Usuários\HomePage.exe
2016-04-07 14:06 - 2016-04-07 16:34 - 00000000 ____D C:\Users\porte\AppData\Local\mbot_en_037050289
2016-04-07 14:06 - 2016-04-07 15:06 - 00015229 _____ C:\Users\Todos os Usuários\webad.xml
2016-04-07 14:06 - 2016-04-07 14:09 - 00000000 ____D C:\Users\porte\AppData\Roaming\UPUpdata
2016-04-07 14:06 - 2016-04-07 14:06 - 01747456 _____ C:\Users\Todos os Usuários\service.exe
2016-04-07 14:06 - 2016-04-07 14:06 - 00000000 ____D C:\Users\porte\AppData\Local\csdi_monetize_120160407
2016-04-07 14:06 - 2016-04-01 14:51 - 01917952 _____ C:\Users\Todos os Usuários\msiql.exe
2016-04-07 14:06 - 2015-12-04 13:14 - 01081344 _____ C:\Users\Todos os Usuários\LightGate.exe
2016-04-07 14:05 - 2016-04-07 14:05 - 00000000 ____D C:\Users\porte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpaceSoundPro 1.0
2016-04-07 14:04 - 2016-04-07 15:00 - 00000000 ____D C:\Program Files\SpaceSoundPro
2016-04-07 14:03 - 2016-04-07 14:03 - 00000000 ____D C:\Users\porte\AppData\Roaming\XBox
2016-04-07 13:59 - 2016-04-07 14:00 - 00000000 ____T C:\WINDOWS\system32\mfs5FF8.tmp
2016-04-07 13:59 - 2016-04-07 14:00 - 00000000 ____T C:\WINDOWS\system32\mfs2AEB.tmp
2016-04-07 13:59 - 2016-04-07 13:59 - 00003830 _____ C:\WINDOWS\System32\Tasks\Selection Tools Update
2016-04-07 13:59 - 2016-04-07 13:59 - 00000000 ____T C:\WINDOWS\system32\mfs579B.tmp
2016-04-07 13:59 - 2016-04-07 13:59 - 00000000 ____T C:\WINDOWS\system32\mfs2A5D.tmp
2016-04-07 13:59 - 2016-04-07 13:59 - 00000000 ____D C:\Users\porte\AppData\Roaming\WTools
2016-04-07 13:57 - 2016-04-07 13:57 - 00000000 ____D C:\Users\porte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bubble Dock
2016-04-07 13:56 - 2016-04-07 13:56 - 00000000 ____D C:\Users\porte\AppData\Roaming\Nosibay
2016-04-07 13:56 - 2016-04-07 13:56 - 00000000 ____D C:\Users\porte\AppData\Local\mixvideoplayer
2016-04-07 13:55 - 2016-04-07 13:55 - 00003696 _____ C:\WINDOWS\System32\Tasks\DivXUpdate
2016-04-07 13:55 - 2016-04-07 13:55 - 00003194 _____ C:\WINDOWS\System32\Tasks\MixVideoPlayer Update
2016-04-07 13:55 - 2016-04-07 13:55 - 00000000 ____D C:\Users\porte\AppData\Local\BrowserWeb
2016-04-07 13:53 - 2016-04-07 16:45 - 00000000 ____D C:\Users\porte\AppData\Local\04A772F0-1460037217-11D5-B06C-999ED885C40A
2016-04-07 13:53 - 2016-04-07 13:53 - 00003830 _____ C:\WINDOWS\System32\Tasks\DNS Monitoring
2016-04-07 13:53 - 2016-04-07 13:52 - 00060136 _____ (DotC United Inc) C:\WINDOWS\system32\Drivers\MPCKpt.sys
2016-04-07 13:52 - 2016-04-07 14:39 - 00000000 ____D C:\Program Files (x86)\MPC Cleaner
2016-04-07 13:52 - 2016-04-07 13:48 - 00001006 _____ C:\WINDOWS\system32\Drivers\etc\hp.bak
2016-04-07 13:51 - 2016-04-07 16:51 - 00000316 _____ C:\WINDOWS\Tasks\Price Fountain.job
2016-04-07 13:51 - 2016-04-07 13:51 - 00002808 _____ C:\WINDOWS\System32\Tasks\Price Fountain
2016-04-07 13:51 - 2016-04-07 13:51 - 00000000 ____D C:\Users\porte\AppData\Roaming\PriceFountain
2016-04-07 13:51 - 2016-04-07 13:51 - 00000000 ____D C:\Program Files\DivX
2016-04-07 13:50 - 2016-04-07 14:48 - 00000000 ____D C:\Users\porte\AppData\Local\Setup Wizard
2016-04-07 13:50 - 2016-04-07 14:36 - 00000000 ____D C:\Users\porte\AppData\Roaming\DivX
2016-04-07 13:50 - 2016-04-07 13:51 - 00000000 ____D C:\Users\porte\AppData\Local\PriceFountain
2016-04-07 13:50 - 2016-04-07 13:50 - 00023114 _____ C:\WINDOWS\System32\Tasks\{08787E47-0A0D-7E79-0D11-0E080C0C110E}
2016-04-07 13:50 - 2016-04-07 13:50 - 00003650 _____ C:\WINDOWS\System32\Tasks\PFExe
2016-04-07 13:50 - 2016-04-07 13:50 - 00000000 ____D C:\Users\Todos os Usuários\b4419a38-1f71-1
2016-04-07 13:50 - 2016-04-07 13:50 - 00000000 ____D C:\Users\Todos os Usuários\2fd05bad-3ce1-1
2016-04-07 13:50 - 2016-04-07 13:50 - 00000000 ____D C:\Users\porte\AppData\Roaming\YSPackage
2016-04-07 13:50 - 2016-04-07 13:50 - 00000000 ____D C:\Users\porte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\YSPackage
2016-04-07 13:50 - 2016-04-07 13:50 - 00000000 ____D C:\Users\porte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PriceFountain
2016-04-07 13:48 - 2016-04-07 13:48 - 00003648 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2016-04-07 13:48 - 2016-04-07 13:48 - 00003008 _____ C:\WINDOWS\System32\Tasks\osTip
2016-04-07 13:48 - 2016-04-07 13:48 - 00000000 ____D C:\Users\Todos os Usuários\WindowsMsg
2016-04-07 13:46 - 2016-04-07 14:41 - 00000000 ____D C:\WINDOWS\system32\SSL
2016-04-07 13:46 - 2016-04-07 14:38 - 00015116 _____ C:\WINDOWS\System32\Tasks\WinTaske
2016-04-07 13:46 - 2016-04-07 13:47 - 00000000 ____D C:\Users\porte\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-04-07 13:46 - 2016-04-07 13:46 - 00000000 ____D C:\Program Files (x86)\Winsere
2016-04-07 13:45 - 2016-04-07 13:45 - 00000000 ____D C:\Program Files (x86)\WinTaske
2016-04-07 13:43 - 2016-04-07 13:55 - 00000000 ____D C:\Program Files (x86)\DivX
2016-04-07 13:43 - 2016-04-07 13:43 - 03966965 _____ C:\WINDOWS\chromebrowser.exe
2016-04-07 13:42 - 2016-04-07 13:55 - 00000000 ____D C:\Users\Todos os Usuários\DivX
2016-02-22 13:59 - 2016-02-22 13:59 - 00001024 _____ C:\.rnd
2016-04-07 14:51 - 2016-04-07 14:51 - 0000043 _____ () C:\Users\porte\AppData\Roaming\WB.CFG
2016-04-07 13:54 - 2016-04-07 13:54 - 0000097 _____ () C:\Users\porte\AppData\Roaming\WindApp.boostrap.log
2016-04-07 13:58 - 2016-04-07 13:58 - 0000078 _____ () C:\Users\porte\AppData\Roaming\WindApp.installation.log
2016-04-07 14:07 - 2015-11-25 15:31 - 1100288 _____ () C:\ProgramData\HomePage.exe
2016-04-07 14:07 - 2016-04-05 19:37 - 0114176 _____ () C:\ProgramData\hp.exe
2016-04-07 14:06 - 2015-12-04 13:14 - 1081344 _____ () C:\ProgramData\LightGate.exe
2016-04-07 14:06 - 2016-04-01 14:51 - 1917952 _____ () C:\ProgramData\msiql.exe
2016-04-07 14:06 - 2016-04-07 14:06 - 1747456 _____ () C:\ProgramData\service.exe
2016-04-07 14:07 - 2016-04-07 13:45 - 1852928 _____ () C:\ProgramData\testLive.exe
2016-04-07 14:06 - 2016-04-07 15:06 - 0015229 _____ () C:\ProgramData\webad.xml
2016-04-07 14:06 - 2016-04-01 14:51 - 01917952 _____ () C:\ProgramData\msiql.exe
2016-04-07 14:07 - 2016-04-07 13:45 - 01852928 _____ () C:\ProgramData\testLive.exe
2016-04-07 13:48 - 2016-04-07 12:34 - 02055168 _____ () C:\ProgramData\WindowsMsg\osmsg.exe
2016-04-07 14:08 - 2016-04-07 14:08 - 02771896 _____ () C:\ProgramData\System32\SafeGuard32.dll
2016-04-07 15:06 - 2016-04-07 15:06 - 00098816 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32api.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00110080 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\pywintypes27.dll
2016-04-07 15:06 - 2016-04-07 15:06 - 00364544 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\pythoncom27.dll
2016-04-07 15:06 - 2016-04-07 15:06 - 00320512 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32com.shell.shell.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00776704 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\_hashlib.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 01176576 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\wx._core_.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00806400 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\wx._gdi_.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00816128 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\wx._windows_.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 01067008 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\wx._controls_.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00733184 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\wx._misc_.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00682496 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\pysqlite2._sqlite.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00088064 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\_ctypes.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00119808 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32file.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00108544 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32security.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00007168 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\hashobjs_ext.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00017920 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\thumbnails_ext.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00088064 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\usb_ext.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00167936 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32gui.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00018432 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32event.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00046080 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\_socket.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 01208320 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\_ssl.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00128512 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\_elementtree.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00127488 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\pyexpat.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00013824 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\common.time34.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00038912 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32inet.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00036864 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\_psutil_windows.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00525208 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\windows._lib_cacheinvalidation.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00011264 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32crypt.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00077312 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\wx._html2.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00027136 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\_multiprocessing.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00020480 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\_yappi.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00035840 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32process.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00686080 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\unicodedata.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00078848 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\wx._animate.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00123392 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\wx._wizard.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00024064 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32pipe.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00010240 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\select.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00025600 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32pdh.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00017408 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32profile.pyd
2016-04-07 15:06 - 2016-04-07 15:06 - 00022528 _____ () C:\Users\pitte\AppData\Local\Temp\_MEI92322\win32ts.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00098816 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32api.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00110080 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\pywintypes27.dll
2016-04-07 16:28 - 2016-04-07 16:28 - 00364544 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\pythoncom27.dll
2016-04-07 16:28 - 2016-04-07 16:28 - 00320512 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32com.shell.shell.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00776704 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\_hashlib.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 01176576 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\wx._core_.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00806400 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\wx._gdi_.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00816128 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\wx._windows_.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 01067008 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\wx._controls_.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00733184 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\wx._misc_.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00682496 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\pysqlite2._sqlite.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00088064 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\_ctypes.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00119808 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32file.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00108544 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32security.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00007168 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\hashobjs_ext.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00017920 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\thumbnails_ext.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00088064 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\usb_ext.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00167936 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32gui.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00018432 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32event.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00046080 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\_socket.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 01208320 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\_ssl.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00128512 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\_elementtree.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00127488 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\pyexpat.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00013824 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\common.time34.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00038912 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32inet.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00036864 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\_psutil_windows.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00525208 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\windows._lib_cacheinvalidation.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00011264 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32crypt.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00077312 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\wx._html2.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00027136 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\_multiprocessing.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00020480 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\_yappi.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00035840 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32process.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00686080 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\unicodedata.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00078848 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\wx._animate.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00123392 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\wx._wizard.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00024064 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32pipe.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00010240 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\select.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00025600 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32pdh.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00017408 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32profile.pyd
2016-04-07 16:28 - 2016-04-07 16:28 - 00022528 _____ () C:\Users\porte\AppData\Local\Temp\_MEI69642\win32ts.pyd
AlternateDataStreams: C:\Program Files (x86)\GbPlugin:IncompleteStartProcessProtection.cnt [10]
AlternateDataStreams: C:\Program Files (x86)\GbPlugin:u6eBQrM0Z2K3FKLVBMG8dY3IkKT2rqFO+Sf68h8fDg== [32]
AlternateDataStreams: C:\WINDOWS\System32:B7515B31_Bb.gbp [2]
AlternateDataStreams: C:\WINDOWS\System32:B7515B31_Cef.gbp [2]
AlternateDataStreams: C:\WINDOWS\system32\Drivers\wsddfac.sys:X5ZN8aGXs4 [1434]
FirewallRules: [{94667923-5C5D-4A92-9611-9F08C4C674CA}] => (Allow) C:\Users\porte\AppData\Local\Temp\QQGameDownloader\codol_1456974210_64689\MiniQQDL.exe
FirewallRules: [{96325363-144B-4D09-A686-5CF179D2312D}] => (Allow) C:\Users\porte\AppData\Local\Temp\QQGameDownloader\codol_1456974210_64689\MiniQQDL.exe
FirewallRules: [TCP Query User{29AEA829-9AE2-41FB-9C04-99C6438F56CF}C:\users\porte\appdata\local\temp\qqgamedownloader\codol_1456974210_64689\teniodl.exe] => (Allow) C:\users\porte\appdata\local\temp\qqgamedownloader\codol_1456974210_64689\teniodl.exe
FirewallRules: [UDP Query User{471B54B3-45DE-4798-A661-4E7B111D16A3}C:\users\porte\appdata\local\temp\qqgamedownloader\codol_1456974210_64689\teniodl.exe] => (Allow) C:\users\porte\appdata\local\temp\qqgamedownloader\codol_1456974210_64689\teniodl.exe
FirewallRules: [{6AA45E66-E7A1-4D9D-9A4A-EB854539AA49}] => (Allow) C:\Users\porte\AppData\Roaming\Tencent\使命召唤Online\27C001DF1013AE7D3EF2013D914EB531\TenioDL\TenioDL.exe
FirewallRules: [{3FB007CC-6421-41A4-BC22-B9D2F5EC9BF2}] => (Allow) C:\Users\porte\AppData\Roaming\Tencent\使命召唤Online\27C001DF1013AE7D3EF2013D914EB531\TenioDL\TenioDL.exe
Task: {116D9918-967D-45B2-A1E7-A925E88FB38A} - System32\Tasks\PFExe => C:\Users\porte\AppData\Local\PriceFountain\pricefountain.exe [2016-02-03] (PAVVXA) <==== ATENÇÃO
Task: {4C4BAAD0-F388-4FF2-BDDD-CDA425206B44} - System32\Tasks\Price Fountain => C:\Users\porte\AppData\Roaming\PriceFountain\UpdateProc\UpdateTask.exe [2016-04-07] () <==== ATENÇÃO
Task: {50B1A570-66A9-45AE-84C9-9EE9D83B7E24} - System32\Tasks\WindApp Update => C:\Users\porte\AppData\Roaming\Store\WindApp\WindApp Update.exe [2016-02-11] (Nosibay) <==== ATENÇÃO
Task: {57E79DD5-F626-4B20-BBEA-471363CCBAF7} - System32\Tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B} => C:\Program Files (x86)\baidu\update\baidujp_update.exe
Task: {6346DB8A-783D-4B55-ADE4-67775D25573B} - System32\Tasks\osTip => C:\ProgramData\WindowsMsg\osmsg.exe [2016-04-07] ()
Task: {6C63D90D-B3B3-4572-B975-BD1106EE2B1D} - System32\Tasks\MixVideoPlayer Update => C:\Program Files (x86)\MixVideoPlayer\mixUpdater.exe <==== ATENÇÃO
Task: {C71FD4D2-5FE2-4904-A0B5-1621DB6A2A4B} - System32\Tasks\Selection Tools Update => C:\Users\porte\AppData\Roaming\WTools\Selection Tools\Selection Tools Update.exe [2016-03-14] (Nosibay) <==== ATENÇÃO
Task: C:\WINDOWS\Tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B}.job => C:\Program Files (x86)\baidu\update\baidujp_update.exe
Task: C:\WINDOWS\Tasks\Price Fountain.job =>
C:\Users\porte\AppData\Local\Temp\is-8FC93.tmp\print.exe
C:\Users\Todos os Usuários\HomePage.exe
C:\Users\Todos os Usuários\hp.exe
C:\Users\Todos os Usuários\LightGate.exe
C:\Users\Todos os Usuários\msiql.exe
C:\Users\Todos os Usuários\service.exe
C:\Users\Todos os Usuários\testLive.exe
C:\Users\pitte\AppData\Local\Temp\22447a1a-c331-4845-bb0a-efea2e2660ad.dll
C:\Users\pitte\AppData\Local\Temp\a9eb3da0-7376-4676-a908-daf9ca13c4aa.dll
C:\Users\porte\AppData\Local\Temp\1IXOG7TKZ5.exe
C:\Users\porte\AppData\Local\Temp\3KBE16PBHB.exe
C:\Users\porte\AppData\Local\Temp\7K9O2MZIU8.exe
C:\Users\porte\AppData\Local\Temp\7PV83P9E4M.exe
C:\Users\porte\AppData\Local\Temp\8RJ87W8GNT.exe
C:\Users\porte\AppData\Local\Temp\A443FE17-5C97-711F-43A5-7F5243D9D11B.dll
C:\Users\porte\AppData\Local\Temp\A443FE17-5C97-711F-43A5-7F5243D9D11B.exe
C:\Users\porte\AppData\Local\Temp\ASIns.exe
C:\Users\porte\AppData\Local\Temp\BFC3.tmp.exe
C:\Users\porte\AppData\Local\Temp\bitool.dll
C:\Users\porte\AppData\Local\Temp\CodecFixDivx.exe
C:\Users\porte\AppData\Local\Temp\dxdiag.exe
C:\Users\porte\AppData\Local\Temp\EA93.tmp.exe
C:\Users\porte\AppData\Local\Temp\fsd121E.exe
C:\Users\porte\AppData\Local\Temp\fsd89A.exe
C:\Users\porte\AppData\Local\Temp\HHRVJHB7QJ.exe
C:\Users\porte\AppData\Local\Temp\M6H3NRR8AC.exe
C:\Users\porte\AppData\Local\Temp\MediaPlayer__11819_il510835.exe
C:\Users\porte\AppData\Local\Temp\mesox.exe
C:\Users\porte\AppData\Local\Temp\MFXPRKJO7F.exe
C:\Users\porte\AppData\Local\Temp\msconfig.exe
C:\Users\porte\AppData\Local\Temp\set.exe
C:\Users\porte\AppData\Local\Temp\SP4Z63DS64.exe
C:\Users\porte\AppData\Local\Temp\SVEMSE572G.exe
C:\Users\porte\AppData\Local\Temp\ZOB9BFE3ST.exe
C:\Users\porte\AppData\Local\mbot_en_037050289\upmbot_en_037050289.exe
C:\Users\porte\AppData\Roaming\XBox\XBLive.exe
C:\ProgramData\msiql.exe
C:\ProgramData\testLive.exe
C:\Users\porte\AppData\Local\PriceFountain\pricefountain.exe
C:\ProgramData\WindowsMsg\osmsg.exe
CreateRestorePoint:
RemoveProxy:
EmptyTemp:
Reboot:
Hosts:
end
[/spoiler]
> Execute FRST/FRST64 >> Clique "Corrigir" << Aguarde!
> Na mensagem,clique Executar.
> Poste o relatório! (Fixlog.txt)

Imagem
< Peço aos visitantes que não utilizem este script em outros computadores,sob risco de danos aos mesmos! >

A+
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal