Logo Hardware.com.br
GabsBraga28
GabsBraga28 Novo Membro Registrado
46 Mensagens 0 Curtidas

[Resolvido] Programas abrindo sozinhos

#1 Por GabsBraga28 16/06/2017 - 15:14
Olá.
Isso vem acontecendo desde hoje pela manhã. Até desinstalei o UC Browser (era um dos apps que abriam sozinhos) porém, durante a desinstalação, o Outlook 2013 começou a abrir. E, enquanto eu digito isso, ele já abriu mais de sete páginas sem eu nem ter clicado. Há alguma coisa que eu possa estar fazendo? Muito obrigada desde já.
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#2 Por joram
16/06/2017 - 16:04
/_ Boa Tarde! GabsBraga28 _\
Imagem

Imagem
https://www.hardware.com.br/comunidade/v-t/1226830/

Siga as recomendações oficiais deste Tópico e poste: FRST.txt + Addition.txt
Disponibilize os relatórios em Cjoint.com ou utilize spoiler,cuja instrução está ao final daquela página.
Outra opçãohospedar os relatórios em Hébergement de fichiers, Security-x.fr.

[Abs]
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#6 Por joram
16/06/2017 - 21:22
/_ Boa Noite! GabsBraga28 _\

> Copie estas informações que estão no spoiler,para o Bloco de Notas.
> Salve-as com o nome fixlist. << Texto e codificação Unicode,caso solicite!
> Salve-as no desktop! ( Área de trabalho ... )

"fixlist"
start
CloseProcesses:
ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Adilson_18-07-2016\AppData\Local\MEGAsync\ShellExtX64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Adilson_18-07-2016\AppData\Local\MEGAsync\ShellExtX64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Adilson_18-07-2016\AppData\Local\MEGAsync\ShellExtX64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Adilson_18-07-2016\AppData\Local\MEGAsync\ShellExtX32.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Adilson_18-07-2016\AppData\Local\MEGAsync\ShellExtX32.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Adilson_18-07-2016\AppData\Local\MEGAsync\ShellExtX32.dll -> Nenhum Arquivo
Startup: C:\Users\Adilson_18-07-2016\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2016-07-28]
ShortcutTarget: MEGAsync.lnk -> C:\Users\Family\AppData\Local\MEGAsync\MEGAsync.exe (Nenhum Arquivo)
GroupPolicy: Restrição <======= ATENÇÃO
CHR StartupUrls: Default -> "hxxp://br.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_15_29¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EtD0C0ByE0E0A0C0CtCtByDzz0AyEtDtN0D0Tzu0StCtBzzzztN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyB0DtBtByByB0CtDtGyD0E0DyEtGyE0Fzz0DtGtDyC0F0BtG0CyCtBtDtB0EtC0B0EtB0AyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtAyEtAzzyDzzzztGtDzzyEyBtGyEtA0FzztG0ByEyE0FtG0EzzyBzy0EyC0CzzyB0A0DtC2QtN0A0LzuyE%26cr%3D2128263556%26a%3Dwncy_ir_15_29%26os%3DWindows 7 Ultimate","hxxp://www.oursurfing.com/?type=hp&ts=1437085486&z=d49a1ab1adcd791ef580ab9g2z1c8m3e1bdw4z3meb&from=advt&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330","hxxp://www.mystartsearch.com/?type=hp&ts=1437086423&z=4115474349a439cf1ca5d2cgfzdc7m6eab8qccdtfw&from=cmi&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330","hxxp://www.oursurfing.com/?type=hppp&ts=1437085535&z=1852e33d355c108873f77c2gfzfcbm9eeb8w4w7o3b&from=advt&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330","hxxp://www.mystartsearch.com/?type=hp&ts=1437313033&z=867906645827a50a0c0ba07g8zbc0m5ccg9c5ebeaz&from=cmi&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330","hxxp://search.iminent.com/?appId=9563392b-95be-463f-a0c5-0dbc55bc57d1","hxxp://www.yoursearching.com/?type=hp&ts=1449449169&z=03269db4660f99abc29f041g4z4z8t6z1z4teg6qcb&from=face&uid=ST1000DM003-1ER162_Z4Y6CDA3XXXXZ4Y6CDA3","hxxp://www.istartpageing.com/?type=hp&ts=1449451836&z=71ebfbd9c48f7b715811396gbz2z0t7z0w6g1bac4q&from=cmi&uid=ST1000DM003-1ER162_Z4Y6CDA3XXXXZ4Y6CDA3","hxxp://www.google.com"
S4 KMS-R@1n; C:\Windows\[email]KMS-R@1n.exe[/email] [26112 2017-05-28] () [Arquivo não assinado]
2017-05-28 10:07 - 2017-05-28 10:07 - 00000000 ____D C:\WINDOWS\System32\Tasks\R@1n-KMS
2017-05-28 10:07 - 2017-05-28 10:07 - 00000000 ____D C:\Users\Family\AppData\Local\mpress
2017-05-28 10:06 - 2017-05-28 10:06 - 00026112 _____ C:\WINDOWS\[email]KMS-R@1n.exe[/email]
2017-05-28 10:06 - 2017-05-28 10:06 - 00003584 _____ C:\WINDOWS\KMS-QADhook.dll
2017-05-27 15:38 - 2017-05-27 15:38 - 00000000 ____H C:\Users\Todos os Usuários\DP45977C.lfl
2017-05-27 15:38 - 2017-05-27 15:38 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2017-05-31 16:50 - 2017-02-13 16:46 - 00000000 ___HD C:\WINDOWS\msdownld.tmp
2017-06-16 13:02 - 2017-02-06 14:39 - 00000000 ____D C:\Users\Todos os Usuários\IObit
2017-06-16 13:02 - 2017-02-06 14:39 - 00000000 ____D C:\ProgramData\IObit
2017-06-16 13:01 - 2017-02-06 14:40 - 00000000 ____D C:\Users\Todos os Usuários\ProductData
2017-06-16 13:01 - 2017-02-06 14:40 - 00000000 ____D C:\ProgramData\ProductData
2017-05-28 16:40 - 2016-07-16 08:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-05-28 16:40 - 2016-07-16 08:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-05-27 15:38 - 2017-05-27 15:38 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2017-01-30 15:23 - 2016-03-09 15:53 - 5144256 _____ (Foxit Corporation) C:\Users\Adilson_18-07-2016\AppData\Local\Temp\FoxitUpdater.exe
2017-01-04 17:03 - 2017-01-04 17:03 - 2864736 _____ (Hola Networks Ltd.) C:\Users\Adilson_18-07-2016\AppData\Local\Temp\Hola-Setup-x64-1.26.859.exe
2017-02-06 15:53 - 2017-02-06 15:53 - 1844640 _____ (File Lite Fast ) C:\Users\Adilson_18-07-2016\AppData\Local\Temp\ICReinstall_Baixaki_3d-analyze_VBlKiE.exe
2017-03-22 16:59 - 2017-03-22 16:59 - 00025600 ____H C:\Users\Adilson_18-07-2016\Downloads\~WRL0001.tmp
2016-09-03 17:41 - 2016-09-03 17:42 - 31717016 _____ () C:\Users\Adilson_18-07-2016\AppData\Local\Temp\vlc-2.2.4-win64.exe
2015-08-02 20:58 - 2015-08-02 20:58 - 0118784 _____ () C:\Users\Adilson_18-07-2016\AppData\Local\Temp\xmlUpdater.exe
2017-06-12 13:52 - 2017-06-16 13:38 - 00000000 ____D C:\Program Files\Common Files\McAfee
2017-06-12 13:52 - 2017-06-14 14:34 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-06-14 14:56 - 2017-06-16 13:01 - 00000000 ____D C:\Users\Family\AppData\LocalLow\IObit
2017-06-16 12:57 - 2017-05-24 03:56 - 0785464 _____ (BlueStack Systems, Inc.) C:\Users\Family\AppData\Local\Temp\HD-Common.dll
2017-06-16 12:57 - 2017-05-24 03:57 - 0464952 _____ (BlueStack Systems, Inc.) C:\Users\Family\AppData\Local\Temp\HD-InstallerUtils.dll
2017-06-16 12:57 - 2017-05-24 03:54 - 0187416 _____ (BlueStack Systems) C:\Users\Family\AppData\Local\Temp\HD-LibraryHandler.dll
2017-06-16 12:57 - 2017-05-24 03:53 - 0246808 _____ (BlueStack Systems) C:\Users\Family\AppData\Local\Temp\HD-Logger-Native.dll
2017-06-16 12:57 - 2017-05-24 03:56 - 0385080 _____ (BlueStack Systems, Inc.) C:\Users\Family\AppData\Local\Temp\HD-Uninstaller.exe
2017-06-16 20:01 - 2014-01-23 15:54 - 0150600 _____ (Microsoft Corporation) C:\Users\Family\AppData\Local\Temp\ose00000.exe
Task: {C6018F55-8D4D-443C-8C33-BCC30CCF8FF7} - \Driver Booster SkipUAC (Family) -> Nenhum Arquivo <==== ATENÇÃO
Task: {FED5E894-D96C-47AA-9370-86DFF20BB9C8} - System32\Tasks\R@1n-KMS\Windows64Professional => wmic [Argument = path SoftwareLicensingProduct where (ID="2de67392-b7a7-462a-b1ca-108dd189f588") call Activate]
ShortcutWithArgument: C:\Users\Family\Desktop\Play iWin Games.lnk -> C:\Users\Family\AppData\Local\GamesManager\GamesManager.exe (iWin Inc) -> -config.channel=00000000 -config.uri=hxxp://gm/iwin/index.html
ShortcutWithArgument: C:\Users\Family\Desktop\Samantha Swift and the Hidden Roses of Athena.lnk -> C:\Users\Family\AppData\Local\GamesManager\GamesManager.exe (iWin Inc) -> -config.channel=00000000 -config.sku=1737461924486933609 -config.uri=hxxp://gm/iwin/index.html
AlternateDataStreams: C:\Users\Family\Downloads\cfw_installer.exe:BDU [0]
AlternateDataStreams: C:\Users\Family\Downloads\cispremium_installer_6100_08.exe:BDU [0]
AlternateDataStreams: C:\Users\Family\Downloads\Dreaming Mary.exe:BDU [0]
FirewallRules: [{8C246017-0EAB-47D1-AFFA-0CAA307B5532}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
FirewallRules: [{4001C67F-AE69-4ED9-A879-DC98D56DDE5E}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
FirewallRules: [{E9461E24-2D87-4FDF-AB88-00C3B6D37A8E}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{3CF4260C-8F9E-4912-8A48-3C941D7A4A46}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{F31D5235-34EB-4220-B58F-76F424E002E2}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{7C6AEB1A-C435-4E78-8CA2-F796EFEBC480}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [UDP Query User{63CCCAF8-4804-4188-9054-23834F1FDF53}C:\users\adilson_18-07-2016\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe] => (Allow) C:\users\adilson_18-07-2016\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe
FirewallRules: [TCP Query User{639E023D-7C08-403A-91CD-30DD562C230A}C:\users\adilson_18-07-2016\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe] => (Allow) C:\users\adilson_18-07-2016\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe
FirewallRules: [UDP Query User{C446A7E5-1E44-4240-BCEA-0083EA8319B8}C:\users\adilson_18-07-2016\appdata\local\popcorn-time\nw.exe] => (Allow) C:\users\adilson_18-07-2016\appdata\local\popcorn-time\nw.exe
FirewallRules: [TCP Query User{1DA58F0C-04A0-4C9E-B986-109DBBA514B3}C:\users\adilson_18-07-2016\appdata\local\popcorn-time\nw.exe] => (Allow) C:\users\adilson_18-07-2016\appdata\local\popcorn-time\nw.exe
FirewallRules: [{0A8CAE47-5823-4923-9E9D-B8DCD5B3AA23}] => (Allow) C:\Windows\[email]KMS-R@1n.exe[/email]
FirewallRules: [{B2EFC2C8-4C29-4401-991E-9E23EE83C4FC}] => (Allow) C:\Windows\[email]KMS-R@1n.exe[/email]
FirewallRules: [TCP Query User{3ED77C2A-4308-44E9-B491-811A9002035D}C:\users\family\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe] => (Allow) C:\users\family\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe
FirewallRules: [UDP Query User{9446A380-4F0B-48AA-AF43-22A8BF6D3A34}C:\users\family\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe] => (Allow) C:\users\family\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe
RemoveProxy:
EmptyTemp:
Hosts:
Reboot:
end


> Execute FRST/FRST64 >> Clique "Corrigir" << Aguarde!
> Poste o relatório "Resultado da Correção pela Farbar Recovery Scan Tool". (Fixlog.txt)
> Este e outros relatórios,podem ser encontrados na pasta: Disco Local (C) > FRST > Logs

Imagem
< Peço aos visitantes que não utilizem este script em outros computadores,sob risco de danos aos mesmos! >

[Abs]
GabsBraga28
GabsBraga28 Novo Membro Registrado
46 Mensagens 0 Curtidas
#7 Por GabsBraga28
16/06/2017 - 21:59
"Fixlog.txt"

Resultado da Correção pela Farbar Recovery Scan Tool (x64) Versão: 15-06-2017 01
Executado por Family (16-06-2017 21:36:25) Run:1
Executando a partir de C:\Users\Family\Desktop
Perfis Carregados: Family (Perfis Disponíveis: Family & Administrador)
Modo da Inicialização: Normal
==============================================

fixlist Conteúdo:
*****************
start
CloseProcesses:
ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Adilson_18-07-2016\AppData\Local\MEGAsync\ShellExtX64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Adilson_18-07-2016\AppData\Local\MEGAsync\ShellExtX64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Adilson_18-07-2016\AppData\Local\MEGAsync\ShellExtX64.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Nenhum Arquivo
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Adilson_18-07-2016\AppData\Local\MEGAsync\ShellExtX32.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Adilson_18-07-2016\AppData\Local\MEGAsync\ShellExtX32.dll -> Nenhum Arquivo
ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Adilson_18-07-2016\AppData\Local\MEGAsync\ShellExtX32.dll -> Nenhum Arquivo
Startup: C:\Users\Adilson_18-07-2016\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2016-07-28]
ShortcutTarget: MEGAsync.lnk -> C:\Users\Family\AppData\Local\MEGAsync\MEGAsync.exe (Nenhum Arquivo)
GroupPolicy: Restrição <======= ATENÇÃO
CHR StartupUrls: Default -> "hxxp://br.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_15_29¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EtD0C0ByE0E0A0C0CtCtByDzz0AyEtDtN0D0Tzu0StCtBzzzztN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyB0DtBtByByB0CtDtGyD0E0DyEtGyE0Fzz0DtGtDyC0F0BtG0CyCtBtDtB0EtC0B0EtB0AyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtAyEtAzzyDzzzztGtDzzyEyBtGyEtA0FzztG0ByEyE0FtG0EzzyBzy0EyC0CzzyB0A0DtC2QtN0A0LzuyE%26cr%3D2128263556%26a%3Dwncy_ir_15_29%26os%3DWindows 7 Ultimate","hxxp://www.oursurfing.com/?type=hp&ts=1437085486&z=d49a1ab1adcd791ef580ab9g2z1c8m3e1bdw4z3meb&from=advt&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330","hxxp://www.mystartsearch.com/?type=hp&ts=1437086423&z=4115474349a439cf1ca5d2cgfzdc7m6eab8qccdtfw&from=cmi&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330","hxxp://www.oursurfing.com/?type=hppp&ts=1437085535&z=1852e33d355c108873f77c2gfzfcbm9eeb8w4w7o3b&from=advt&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330","hxxp://www.mystartsearch.com/?type=hp&ts=1437313033&z=867906645827a50a0c0ba07g8zbc0m5ccg9c5ebeaz&from=cmi&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330","hxxp://search.iminent.com/?appId=9563392b-95be-463f-a0c5-0dbc55bc57d1","hxxp://www.yoursearching.com/?type=hp&ts=1449449169&z=03269db4660f99abc29f041g4z4z8t6z1z4teg6qcb&from=face&uid=ST1000DM003-1ER162_Z4Y6CDA3XXXXZ4Y6CDA3","hxxp://www.istartpageing.com/?type=hp&ts=1449451836&z=71ebfbd9c48f7b715811396gbz2z0t7z0w6g1bac4q&from=cmi&uid=ST1000DM003-1ER162_Z4Y6CDA3XXXXZ4Y6CDA3","hxxp://www.google.com"
S4 KMS-R@1n; C:\Windows\[email]KMS-R@1n.exe[/email] [26112 2017-05-28] () [Arquivo não assinado]
2017-05-28 10:07 - 2017-05-28 10:07 - 00000000 ____D C:\WINDOWS\System32\Tasks\R@1n-KMS
2017-05-28 10:07 - 2017-05-28 10:07 - 00000000 ____D C:\Users\Family\AppData\Local\mpress
2017-05-28 10:06 - 2017-05-28 10:06 - 00026112 _____ C:\WINDOWS\[email]KMS-R@1n.exe[/email]
2017-05-28 10:06 - 2017-05-28 10:06 - 00003584 _____ C:\WINDOWS\KMS-QADhook.dll
2017-05-27 15:38 - 2017-05-27 15:38 - 00000000 ____H C:\Users\Todos os Usuários\DP45977C.lfl
2017-05-27 15:38 - 2017-05-27 15:38 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2017-05-31 16:50 - 2017-02-13 16:46 - 00000000 ___HD C:\WINDOWS\msdownld.tmp
2017-06-16 13:02 - 2017-02-06 14:39 - 00000000 ____D C:\Users\Todos os Usuários\IObit
2017-06-16 13:02 - 2017-02-06 14:39 - 00000000 ____D C:\ProgramData\IObit
2017-06-16 13:01 - 2017-02-06 14:40 - 00000000 ____D C:\Users\Todos os Usuários\ProductData
2017-06-16 13:01 - 2017-02-06 14:40 - 00000000 ____D C:\ProgramData\ProductData
2017-05-28 16:40 - 2016-07-16 08:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-05-28 16:40 - 2016-07-16 08:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-05-27 15:38 - 2017-05-27 15:38 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2017-01-30 15:23 - 2016-03-09 15:53 - 5144256 _____ (Foxit Corporation) C:\Users\Adilson_18-07-2016\AppData\Local\Temp\FoxitUpdater.exe
2017-01-04 17:03 - 2017-01-04 17:03 - 2864736 _____ (Hola Networks Ltd.) C:\Users\Adilson_18-07-2016\AppData\Local\Temp\Hola-Setup-x64-1.26.859.exe
2017-02-06 15:53 - 2017-02-06 15:53 - 1844640 _____ (File Lite Fast ) C:\Users\Adilson_18-07-2016\AppData\Local\Temp\ICReinstall_Baixaki_3d-analyze_VBlKiE.exe
2017-03-22 16:59 - 2017-03-22 16:59 - 00025600 ____H C:\Users\Adilson_18-07-2016\Downloads\~WRL0001.tmp
2016-09-03 17:41 - 2016-09-03 17:42 - 31717016 _____ () C:\Users\Adilson_18-07-2016\AppData\Local\Temp\vlc-2.2.4-win64.exe
2015-08-02 20:58 - 2015-08-02 20:58 - 0118784 _____ () C:\Users\Adilson_18-07-2016\AppData\Local\Temp\xmlUpdater.exe
2017-06-12 13:52 - 2017-06-16 13:38 - 00000000 ____D C:\Program Files\Common Files\McAfee
2017-06-12 13:52 - 2017-06-14 14:34 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-06-14 14:56 - 2017-06-16 13:01 - 00000000 ____D C:\Users\Family\AppData\LocalLow\IObit
2017-06-16 12:57 - 2017-05-24 03:56 - 0785464 _____ (BlueStack Systems, Inc.) C:\Users\Family\AppData\Local\Temp\HD-Common.dll
2017-06-16 12:57 - 2017-05-24 03:57 - 0464952 _____ (BlueStack Systems, Inc.) C:\Users\Family\AppData\Local\Temp\HD-InstallerUtils.dll
2017-06-16 12:57 - 2017-05-24 03:54 - 0187416 _____ (BlueStack Systems) C:\Users\Family\AppData\Local\Temp\HD-LibraryHandler.dll
2017-06-16 12:57 - 2017-05-24 03:53 - 0246808 _____ (BlueStack Systems) C:\Users\Family\AppData\Local\Temp\HD-Logger-Native.dll
2017-06-16 12:57 - 2017-05-24 03:56 - 0385080 _____ (BlueStack Systems, Inc.) C:\Users\Family\AppData\Local\Temp\HD-Uninstaller.exe
2017-06-16 20:01 - 2014-01-23 15:54 - 0150600 _____ (Microsoft Corporation) C:\Users\Family\AppData\Local\Temp\ose00000.exe
Task: {C6018F55-8D4D-443C-8C33-BCC30CCF8FF7} - \Driver Booster SkipUAC (Family) -> Nenhum Arquivo <==== ATENÇÃO
Task: {FED5E894-D96C-47AA-9370-86DFF20BB9C8} - System32\Tasks\R@1n-KMS\Windows64Professional => wmic [Argument = path SoftwareLicensingProduct where (ID="2de67392-b7a7-462a-b1ca-108dd189f588") call Activate]
ShortcutWithArgument: C:\Users\Family\Desktop\Play iWin Games.lnk -> C:\Users\Family\AppData\Local\GamesManager\GamesManager.exe (iWin Inc) -> -config.channel=00000000 -config.uri=hxxp://gm/iwin/index.html
ShortcutWithArgument: C:\Users\Family\Desktop\Samantha Swift and the Hidden Roses of Athena.lnk -> C:\Users\Family\AppData\Local\GamesManager\GamesManager.exe (iWin Inc) -> -config.channel=00000000 -config.sku=1737461924486933609 -config.uri=hxxp://gm/iwin/index.html
AlternateDataStreams: C:\Users\Family\Downloads\cfw_installer.exe:BDU [0]
AlternateDataStreams: C:\Users\Family\Downloads\cispremium_installer_6100_08.exe:BDU [0]
AlternateDataStreams: C:\Users\Family\Downloads\Dreaming Mary.exe:BDU [0]
FirewallRules: [{8C246017-0EAB-47D1-AFFA-0CAA307B5532}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
FirewallRules: [{4001C67F-AE69-4ED9-A879-DC98D56DDE5E}] => (Allow) C:\Program Files (x86)\Popcorn Time\chromecast\node.exe
FirewallRules: [{E9461E24-2D87-4FDF-AB88-00C3B6D37A8E}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{3CF4260C-8F9E-4912-8A48-3C941D7A4A46}] => (Allow) C:\Program Files (x86)\Popcorn Time\PopcornTimeDesktop.exe
FirewallRules: [{F31D5235-34EB-4220-B58F-76F424E002E2}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [{7C6AEB1A-C435-4E78-8CA2-F796EFEBC480}] => (Allow) C:\Program Files (x86)\Popcorn Time\Updater.exe
FirewallRules: [UDP Query User{63CCCAF8-4804-4188-9054-23834F1FDF53}C:\users\adilson_18-07-2016\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe] => (Allow) C:\users\adilson_18-07-2016\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe
FirewallRules: [TCP Query User{639E023D-7C08-403A-91CD-30DD562C230A}C:\users\adilson_18-07-2016\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe] => (Allow) C:\users\adilson_18-07-2016\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe
FirewallRules: [UDP Query User{C446A7E5-1E44-4240-BCEA-0083EA8319B8}C:\users\adilson_18-07-2016\appdata\local\popcorn-time\nw.exe] => (Allow) C:\users\adilson_18-07-2016\appdata\local\popcorn-time\nw.exe
FirewallRules: [TCP Query User{1DA58F0C-04A0-4C9E-B986-109DBBA514B3}C:\users\adilson_18-07-2016\appdata\local\popcorn-time\nw.exe] => (Allow) C:\users\adilson_18-07-2016\appdata\local\popcorn-time\nw.exe
FirewallRules: [{0A8CAE47-5823-4923-9E9D-B8DCD5B3AA23}] => (Allow) C:\Windows\[email]KMS-R@1n.exe[/email]
FirewallRules: [{B2EFC2C8-4C29-4401-991E-9E23EE83C4FC}] => (Allow) C:\Windows\[email]KMS-R@1n.exe[/email]
FirewallRules: [TCP Query User{3ED77C2A-4308-44E9-B491-811A9002035D}C:\users\family\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe] => (Allow) C:\users\family\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe
FirewallRules: [UDP Query User{9446A380-4F0B-48AA-AF43-22A8BF6D3A34}C:\users\family\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe] => (Allow) C:\users\family\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe
RemoveProxy:
EmptyTemp:
Hosts:
Reboot:
end
*****************

Processos fechados com sucesso.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Pending) => invalid subkey removed.
HKLM\Software\Classes\CLSID\{056D528D-CE28-4194-9BA3-BA2E9197FF8C} => chave removido (a) com sucesso.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Synced) => invalid subkey removed.
HKLM\Software\Classes\CLSID\{05B38830-F4E9-4329-978B-1DD28605D202} => chave removido (a) com sucesso.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Syncing) => invalid subkey removed.
HKLM\Software\Classes\CLSID\{0596C850-7BDD-4C9D-AFDF-873BE6890637} => chave removido (a) com sucesso.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => chave removido (a) com sucesso.
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => chave não encontrado (a).
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => chave removido (a) com sucesso.
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => chave não encontrado (a).
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Pending) => invalid subkey removed.
HKLM\Software\Wow6432Node\Classes\CLSID\{056D528D-CE28-4194-9BA3-BA2E9197FF8C} => chave removido (a) com sucesso.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Synced) => invalid subkey removed.
HKLM\Software\Wow6432Node\Classes\CLSID\{05B38830-F4E9-4329-978B-1DD28605D202} => chave removido (a) com sucesso.
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ MEGA (Syncing) => invalid subkey removed.
HKLM\Software\Wow6432Node\Classes\CLSID\{0596C850-7BDD-4C9D-AFDF-873BE6890637} => chave removido (a) com sucesso.
C:\Users\Adilson_18-07-2016\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk => movido com sucesso
C:\Users\Family\AppData\Local\MEGAsync\MEGAsync.exe => não encontrado (a).
C:\WINDOWS\system32\GroupPolicy\Machine => movido com sucesso
C:\WINDOWS\system32\GroupPolicy\GPT.ini => movido com sucesso
Chrome StartupUrls => removido (a) com sucesso.
HKLM\System\CurrentControlSet\Services\KMS-R@1n => chave removido (a) com sucesso.
KMS-R@1n => serviço removido (a) com sucesso.
C:\WINDOWS\System32\Tasks\R@1n-KMS => movido com sucesso
C:\Users\Family\AppData\Local\mpress => movido com sucesso
C:\WINDOWS\[email]KMS-R@1n.exe[/email] => movido com sucesso
C:\WINDOWS\KMS-QADhook.dll => movido com sucesso
C:\Users\Todos os Usuários\DP45977C.lfl => movido com sucesso
"C:\ProgramData\DP45977C.lfl" => não encontrado (a).
C:\WINDOWS\msdownld.tmp => movido com sucesso
C:\Users\Todos os Usuários\IObit => movido com sucesso
"C:\ProgramData\IObit" => não encontrado (a).
C:\Users\Todos os Usuários\ProductData => movido com sucesso
"C:\ProgramData\ProductData" => não encontrado (a).
C:\WINDOWS\SysWOW64\F12 => movido com sucesso
C:\WINDOWS\system32\F12 => movido com sucesso
"C:\ProgramData\DP45977C.lfl" => não encontrado (a).
C:\Users\Adilson_18-07-2016\AppData\Local\Temp\FoxitUpdater.exe => movido com sucesso
C:\Users\Adilson_18-07-2016\AppData\Local\Temp\Hola-Setup-x64-1.26.859.exe => movido com sucesso
C:\Users\Adilson_18-07-2016\AppData\Local\Temp\ICReinstall_Baixaki_3d-analyze_VBlKiE.exe => movido com sucesso
C:\Users\Adilson_18-07-2016\Downloads\~WRL0001.tmp => movido com sucesso
C:\Users\Adilson_18-07-2016\AppData\Local\Temp\vlc-2.2.4-win64.exe => movido com sucesso
C:\Users\Adilson_18-07-2016\AppData\Local\Temp\xmlUpdater.exe => movido com sucesso
C:\Program Files\Common Files\McAfee => movido com sucesso
C:\Program Files (x86)\McAfee => movido com sucesso
C:\Users\Family\AppData\LocalLow\IObit => movido com sucesso
C:\Users\Family\AppData\Local\Temp\HD-Common.dll => movido com sucesso
C:\Users\Family\AppData\Local\Temp\HD-InstallerUtils.dll => movido com sucesso
C:\Users\Family\AppData\Local\Temp\HD-LibraryHandler.dll => movido com sucesso
C:\Users\Family\AppData\Local\Temp\HD-Logger-Native.dll => movido com sucesso
C:\Users\Family\AppData\Local\Temp\HD-Uninstaller.exe => movido com sucesso
C:\Users\Family\AppData\Local\Temp\ose00000.exe => movido com sucesso
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C6018F55-8D4D-443C-8C33-BCC30CCF8FF7} => chave removido (a) com sucesso.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C6018F55-8D4D-443C-8C33-BCC30CCF8FF7} => chave removido (a) com sucesso.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (Family) => chave removido (a) com sucesso.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FED5E894-D96C-47AA-9370-86DFF20BB9C8} => chave removido (a) com sucesso.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FED5E894-D96C-47AA-9370-86DFF20BB9C8} => chave removido (a) com sucesso.
C:\WINDOWS\System32\Tasks\R@1n-KMS\Windows64Professional => não encontrado (a).
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\R@1n-KMS\Windows64Professional => chave removido (a) com sucesso.
C:\Users\Family\Desktop\Play iWin Games.lnk => Atalho argumento removido (a) com sucesso..
C:\Users\Family\Desktop\Samantha Swift and the Hidden Roses of Athena.lnk => Atalho argumento removido (a) com sucesso..
C:\Users\Family\Downloads\cfw_installer.exe => ":BDU" ADS removido (a) com sucesso..
C:\Users\Family\Downloads\cispremium_installer_6100_08.exe => ":BDU" ADS removido (a) com sucesso..
C:\Users\Family\Downloads\Dreaming Mary.exe => ":BDU" ADS removido (a) com sucesso..
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{8C246017-0EAB-47D1-AFFA-0CAA307B5532} => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4001C67F-AE69-4ED9-A879-DC98D56DDE5E} => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E9461E24-2D87-4FDF-AB88-00C3B6D37A8E} => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3CF4260C-8F9E-4912-8A48-3C941D7A4A46} => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F31D5235-34EB-4220-B58F-76F424E002E2} => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7C6AEB1A-C435-4E78-8CA2-F796EFEBC480} => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{63CCCAF8-4804-4188-9054-23834F1FDF53}C:\users\adilson_18-07-2016\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{639E023D-7C08-403A-91CD-30DD562C230A}C:\users\adilson_18-07-2016\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C446A7E5-1E44-4240-BCEA-0083EA8319B8}C:\users\adilson_18-07-2016\appdata\local\popcorn-time\nw.exe => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{1DA58F0C-04A0-4C9E-B986-109DBBA514B3}C:\users\adilson_18-07-2016\appdata\local\popcorn-time\nw.exe => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0A8CAE47-5823-4923-9E9D-B8DCD5B3AA23} => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B2EFC2C8-4C29-4401-991E-9E23EE83C4FC} => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{3ED77C2A-4308-44E9-B491-811A9002035D}C:\users\family\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe => valor removido (a) com sucesso.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{9446A380-4F0B-48AA-AF43-22A8BF6D3A34}C:\users\family\appdata\local\ucbrowser\user data_i18n\thunder\1.0.0.0\download\minithunderplatform.exe => valor removido (a) com sucesso.

========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => valor removido (a) com sucesso.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => valor removido (a) com sucesso.
HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => valor removido (a) com sucesso.
HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => valor removido (a) com sucesso.
HKU\S-1-5-21-3065097816-1042799985-2737777570-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => valor removido (a) com sucesso.
HKU\S-1-5-21-3065097816-1042799985-2737777570-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => valor removido (a) com sucesso.


========= Fim de RemoveProxy: =========

C:\Windows\System32\Drivers\etc\hosts => movido com sucesso
Hosts restaurado com sucesso.

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 40454289 B
Java, Flash, Steam htmlcache => 6198 B
Windows/system/drivers => 136510553 B
Edge => 237015696 B
Chrome => 112994041 B
Firefox => 392630480 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 128 B
LocalService => 325588 B
NetworkService => 1264774 B
Family => 167077311 B
Administrador.000 => 9343 B

RecycleBin => 10605206 B
EmptyTemp: => 1 GB de dados temporários Removidos.

================================


O sistema precisou ser reiniciado.

==== Fim de Fixlog 21:42:26 ====
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#8 Por joram
16/06/2017 - 22:17
/_ Boa Noite! GabsBraga28 _\

> Baixe: < Imagem > ( Imagem ... de Nicolas Coolman )

> Ou |Aqui!| << Mirror!

> Estando na página,clique Imagem

> Salve-a no desktop! ( ZHPCleaner.exe )
> Desabilite seu antivírus e execute ZHPCleaner.exe <<

Imagem

> Clique "Eu".

Imagem

> Clique Scanner.

Imagem

> Aguarde a conclusão!

Imagem

> Ao concluir,clique Reparar.

Imagem

> Surgirão guias que estarão em vermelho,indicando problemas a serem reparados.
> Clique Reparar.

Imagem

> Ao concluir,clique Relatório!
> Poste o log de reparo: ~ Type : Reparo

[Abs]
GabsBraga28
GabsBraga28 Novo Membro Registrado
46 Mensagens 0 Curtidas
#9 Por GabsBraga28
16/06/2017 - 22:56
Reparo:
"reparo"

~ ZHPCleaner v2017.6.15.99 by Nicolas Coolman (2017/06/15)
~ Run by Family (Administrator) (16/06/2017 22:51:39)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Certificate: Legal
~ Type : Reparo
~ Report : C:\Users\Family\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Family\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 14393)


---\\ Serviços (0)


---\\ Navegadores de Internet (7)
SUBSTITUIDO Google Chrome Secure Preferences: "http://www.oursurfing.com/?type=hp&ts=1437085486&z=d49a1ab1adcd791ef580ab9g2z1c8m3e1bdw4z3meb&from=advt&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330" =>PUP.Optional.OurSurfing
SUBSTITUIDO Google Chrome Secure Preferences: "http://www.mystartsearch.com/?type=hp&ts=1437086423&z=4115474349a439cf1ca5d2cgfzdc7m6eab8qccdtfw&from=cmi&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330" =>PUP.Optional.StartSearch
SUBSTITUIDO Google Chrome Secure Preferences: "http://www.oursurfing.com/?type=hppp&ts=1437085535&z=1852e33d355c108873f77c2gfzfcbm9eeb8w4w7o3b&from=advt&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330" =>PUP.Optional.OurSurfing
SUBSTITUIDO Google Chrome Secure Preferences: "http://www.mystartsearch.com/?type=hp&ts=1437313033&z=867906645827a50a0c0ba07g8zbc0m5ccg9c5ebeaz&from=cmi&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330" =>PUP.Optional.StartSearch
SUBSTITUIDO Google Chrome Secure Preferences: "http://search.iminent.com/?appId=9563392b-95be-463f-a0c5-0dbc55bc57d1" =>PUP.Optional.IMBooster
SUBSTITUIDO Google Chrome Secure Preferences: "http://www.yoursearching.com/?type=hp&ts=1449449169&z=03269db4660f99abc29f041g4z4z8t6z1z4teg6qcb&from=face&uid=ST1000DM003-1ER162_Z4Y6CDA3XXXXZ4Y6CDA3" =>PUP.Optional.YourSearching
SUBSTITUIDO Google Chrome Secure Preferences: "http://www.istartpageing.com/?type=hp&ts=1449451836&z=71ebfbd9c48f7b715811396gbz2z0t7z0w6g1bac4q&from=cmi&uid=ST1000DM003-1ER162_Z4Y6CDA3XXXXZ4Y6CDA3" =>PUP.Optional.IstartPageing


---\\ Arquivo hosts (1)
~ O arquivo hosts é legítimo (1)


---\\ Tarefas automáticas agendadas. (0)
~ Nenhum ítem malicioso o desnecessários foi encontrado.


---\\ Explorer ( Arquivos, Pastas) (52)
MOVIDO pasta: C:\Windows\Prefetch\[email]KMS-R@1NHOOK.EXE[/email]-95CFB3BC.pf =>HackTool.AutoKMS
MOVIDO pasta: C:\Windows\Installer\MSI16E1.tmp =>.Superfluous.MSIInstaller
MOVIDO pasta: C:\Windows\Installer\MSI1D2B.tmp =>.Superfluous.MSIInstaller
MOVIDO pasta: C:\Windows\Installer\MSI5AD9.tmp =>.Superfluous.MSIInstaller
MOVIDO pasta: C:\Windows\Installer\MSI7FAE.tmp =>.Superfluous.MSIInstaller
MOVIDO pasta: C:\Windows\Installer\MSI8B96.tmp =>.Superfluous.MSIInstaller
MOVIDO pasta: C:\Windows\Installer\MSI8CB0.tmp =>.Superfluous.MSIInstaller
MOVIDO pasta: C:\Windows\Installer\MSI8ED4.tmp =>.Superfluous.MSIInstaller
MOVIDO pasta: C:\Windows\Installer\MSI94DB.tmp =>.Superfluous.MSIInstaller
MOVIDO pasta: C:\Windows\Installer\MSI99BE.tmp =>.Superfluous.MSIInstaller
MOVIDO pasta: C:\Windows\Installer\MSI9C4F.tmp =>.Superfluous.MSIInstaller
MOVIDO pasta: C:\Users\Family\Desktop\Play iWin Games.lnk =>PUP.Optional.iWinArcade
MOVIDO pasta^: C:\Users\Family\AppData\Local\Temp\etilqs_27mJME0kRf0gZp9 =>.Superfluous.Temporary.Empty
MOVIDO pasta^: C:\Users\Family\AppData\Local\Temp\etilqs_6FU1deuUmcdP23n =>.Superfluous.Temporary.Empty
MOVIDO pasta^: C:\Users\Family\AppData\Local\Temp\etilqs_lLjZ3ezgQh71Jad =>.Superfluous.Temporary.Empty
MOVIDO pasta^: C:\Users\Family\AppData\Local\Temp\etilqs_Mk12fpUbJvy2DgE =>.Superfluous.Temporary.Empty
MOVIDO pasta^: C:\Users\Family\AppData\Local\Temp\etilqs_njWemmvfzK4CsdL =>.Superfluous.Temporary.Empty
MOVIDO pasta^: C:\Users\Family\AppData\Local\Temp\etilqs_SpVDrzTgX3LrNqU =>.Superfluous.Temporary.Empty
MOVIDO pasta: C:\Windows\SECOH-QAD.exe =>HackTool.KMSpico
MOVIDO arquivo: C:\Program Files (x86)\Popcorn Time =>.Superfluous.PopcornTime
MOVIDO arquivo: C:\Program Files (x86)\TorrentsTime Media Player =>.Superfluous.TorrentsTime
MOVIDO arquivo: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TorrentsTime Media Player =>.Superfluous.TorrentsTime
MOVIDO arquivo: C:\WINDOWS\Installer\MSI10B2.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI149C.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI16E1.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI266F.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI27DA.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI2825.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI2B34.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI2E14.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI3672.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI370C.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI397F.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI3BD3.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI3DF8.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI3EF0.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI4120.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI423E.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI4445.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI5A38.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI66BF.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI6856.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI6AF3.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI6F6D.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI7054.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI7192.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI7316.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI7482.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI76C7.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSI92E.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSIF92D.tmp- =>.Superfluous.Empty
MOVIDO arquivo: C:\WINDOWS\Installer\MSIFF1A.tmp- =>.Superfluous.Empty


---\\ Registro ( Chaves, Valores, Dados ) (15)
SUPRIMIDO chave*: HKLM\SYSTEM\CurrentControlSet\Services\TTService [C:\Program Files (x86)\TorrentsTime Media Player\bin\TTService.exe (Not File)] =>.Superfluous.TorrentsTime
SUPRIMIDO chave*: HKEY_USERS\S-1-5-21-3065097816-1042799985-2737777570-1001\SOFTWARE\iWinArcade [] =>PUP.Optional.iWinArcade
SUPRIMIDO chave*: HKEY_USERS\.DEFAULT\Software\iWinArcade [] =>PUP.Optional.iWinArcade
SUPRIMIDO chave: HKCU\Software\iWinArcade [] =>PUP.Optional.iWinArcade
SUPRIMIDO chave*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\ad-aware.en.softonic.com [] =>.Superfluous.Softonic
SUPRIMIDO chave*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\softonic.com [] =>.Superfluous.Softonic
SUPRIMIDO chave*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\ad-aware.en.softonic.com [] =>.Superfluous.Softonic
SUPRIMIDO chave*: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\softonic.com [] =>.Superfluous.Softonic
SUPRIMIDO chave*: HKCU\Software\UCBrowserPID [] =>.Superfluous.UCBrowser
SUPRIMIDO chave*: HKCU\Software\undefined [] =>.Superfluous.Downloader
SUPRIMIDO chave*: HKLM\SOFTWARE\Wow6432Node\UCBrowserPID [] =>.Superfluous.UCBrowser
SUPRIMIDO chave: HKLM\SOFTWARE\UCBrowserPID [] =>.Superfluous.UCBrowser
SUPRIMIDO chave*: HKLM\SOFTWARE\TTime [] =>.Superfluous.TorrentsTime
SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\iWinArcade [] =>PUP.Optional.iWinArcade
SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Wow6432Node\iWinArcade [] =>PUP.Optional.iWinArcade


---\\ Resumo dos elementos encontrados na sua estação de trabalho (16)
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.OurSurfing
https://www.nicolascoolman.com/fr/pup-optional-startsearch/ =>PUP.Optional.StartSearch
https://www.nicolascoolman.com/fr/adware-imbooster/ =>PUP.Optional.IMBooster
https://www.nicolascoolman.com/fr/pup-optional-yoursearching =>PUP.Optional.YourSearching
https://www.nicolascoolman.com/fr/pup-optional-istartpageing/ =>PUP.Optional.IstartPageing
https://nicolascoolman.eu/2017/02/02/hacktool-autokms/ =>HackTool.AutoKMS
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.MSIInstaller
https://www.nicolascoolman.com/fr/adware-iwinarcade/ =>PUP.Optional.iWinArcade
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Temporary.Empty
https://nicolascoolman.eu/2017/02/16/hacktool-kmspico/ =>HackTool.KMSpico
https://nicolascoolman.eu/2017/02/26/superfluous-popcorntime/ =>.Superfluous.PopcornTime
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.TorrentsTime
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Empty
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Softonic
https://nicolascoolman.eu/2017/03/04/superfluous-ucbrowser/ =>.Superfluous.UCBrowser
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Downloader


---\\ Dodatkowe oczyszczenie. (23)
~ Chave de registro Tracing Supprimido (23)
~ Remover os relatórios antigos ZHPCleaner. (0)


---\\ Resultado de reparação
Reparação efectuada com sucesso
~ Este navegador está faltando ! (Opera Software)
~ O sistema foi reiniciado.


---\\ Estatísticas
~ Items scan : 757
~ Items encontrado : 0
~ items cancelados : 0
~ Items réparo : 75


~ End of clean in 00h01mn36s
~====================
ZHPCleaner-[R]-16062017-22_53_15.txt
ZHPCleaner-[S]-16062017-22_33_51.txt
ZHPCleaner-[S]-16062017-22_42_01.txt

[/S][/S]
[S][S][/s][/s]
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#10 Por joram
16/06/2017 - 23:02
/_ Boa Noite! GabsBraga28 _\

> Baixe: < Imagem > ( ... par Xplode )

> Ou daqui: < AdwCleaner > << Link!
> Ao acessar,clique em "Download Now".

> Salve-o no desktop!
> Desabilite seu antivírus!

< Imagem >

> Clique direito em adwcleaner.exe,e escolha sua execução como administrador.

Imagem

> Clique "Ferramentas" >> "Opções".

Imagem

> Estando em "Opções",deixe as configurações conforme este banner.
> Clique "Ok".

Imagem

> Ps: Dê início ao scan,clicando em "Verificar".

Imagem

> Ao concluir,clique "Limpar" ou "Cleaning" >> Ok >> Ok >> Ok.
> Copie o log ou clique "Relatorio".
> Poste: < C:\AdwCleaner\AdwCleaner[C0].txt >

[Abs]
GabsBraga28
GabsBraga28 Novo Membro Registrado
46 Mensagens 0 Curtidas
#11 Por GabsBraga28
16/06/2017 - 23:16
[SPOILER]
# AdwCleaner v6.047 - Relatório criado 16/06/2017 às 23:10:32
# Atualizado em 19/05/2017 por Malwarebytes
# Banco de dados : 2017-06-16.2 [Servidor]
# Sistema operacional : Windows 10 Pro (X64)
# Usuário : Family - ADILSON
# Executando de : C:\Users\Family\Desktop\AdwCleaner.exe
# Modo: Limpo
# Apoio : https://www.malwarebytes.com/support

***** [ Serviços ] *****

***** [ Pastas ] *****

***** [ Arquivos ] *****

***** [ DLL ] *****

***** [ WMI ] *****

***** [ Atalhos ] *****

***** [ Atividades agendadas ] *****

***** [ Registro ] *****
[-] Chave excluída:HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\geekbuddyrsp
[#] Chave excluída na reinicialização:[x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\geekbuddyrsp

***** [ Verificando navegadores ... ] *****
[-] [C:\Users\Family\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Eliminado:hxxp://br.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_15_29&param1=1&param2=f%3D7%26b%3DChrome%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0EtD0C0ByE0E0A0C0CtCtByDzz0AyEtDtN0D0Tzu0StCtBzzzztN1L2XzutAtFtCtDtFtCtDtFtCtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyB0DtBtByByB0CtDtGyD0E0DyEtGyE0Fzz0DtGtDyC0F0BtG0CyCtBtDtB0EtC0B0EtB0AyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtAyEtAzzyDzzzztGtDzzyEyBtGyEtA0FzztG0ByEyE0FtG0EzzyBzy0EyC0CzzyB0A0DtC2QtN0A0LzuyE%26cr%3D2128263556%26a%3Dwncy_ir_15_29%26os%3DWindows 7 Ultimate
[-] [C:\Users\Family\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Eliminado:hxxp://www.oursurfing.com/?type=hp&ts=1437085486&z=d49a1ab1adcd791ef580ab9g2z1c8m3e1bdw4z3meb&from=advt&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330
[-] [C:\Users\Family\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Eliminado:hxxp://www.mystartsearch.com/?type=hp&ts=1437086423&z=4115474349a439cf1ca5d2cgfzdc7m6eab8qccdtfw&from=cmi&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330
[-] [C:\Users\Family\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Eliminado:hxxp://www.oursurfing.com/?type=hppp&ts=1437085535&z=1852e33d355c108873f77c2gfzfcbm9eeb8w4w7o3b&from=advt&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330
[-] [C:\Users\Family\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Eliminado:hxxp://www.mystartsearch.com/?type=hp&ts=1437313033&z=867906645827a50a0c0ba07g8zbc0m5ccg9c5ebeaz&from=cmi&uid=WDCXWD10EARS-00Y5B1_WD-WCAV5692133021330
[-] [C:\Users\Family\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Eliminado:hxxp://search.iminent.com/?appId=9563392b-95be-463f-a0c5-0dbc55bc57d1
[-] [C:\Users\Family\AppData\Local\Google\Chrome\User Data\Default] [startup_urls] Eliminado:hxxp://www.yoursearching.com/?type=hp&ts=1449449169&z=03269db4660f99abc29f041g4z4z8t6z1z4teg6qcb&from=face&uid=ST1000DM003-1ER162_Z4Y6CDA3XXXXZ4Y6CDA3

*************************
:: Configurações Winsock restauradas
:: "Image File Execution Options" chaves excluídas
:: Configurações Proxy restauradas
:: Políticas do IE excluídas
:: Políticas do Chrome excluídas
:: As preferências do Chrome são redefinidas:C:\Users\Family\AppData\Local\Google\Chrome\User Data\Default
:: Arquivo de hosts cancelado
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [6009 Bytes] - [16/06/2017 12:43:10]
C:\AdwCleaner\AdwCleaner[C2].txt - [3363 Bytes] - [16/06/2017 23:10:32]
C:\AdwCleaner\AdwCleaner[S0].txt - [5718 Bytes] - [16/06/2017 12:42:00]
C:\AdwCleaner\AdwCleaner[S1].txt - [3311 Bytes] - [16/06/2017 23:09:21]
########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [3582 Bytes] ##########
[/SPOILER]
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#12 Por joram
16/06/2017 - 23:28
/_ Boa Noite! GabsBraga28 _\

> Agora seguem estas duas ferramentas,nesta sequência: JRT >> SFTGC

> Baixe: < Imagem > ( ... by Malwarebytes.org )

> Ou aqui! < JRT.exe >
> Salve-o no desktop!
> Desabilite seu antivírus!
> Para Windows 7,clique direito em JRT.exe e execute-o ...

Imagem

> Tendo dificuldades,pode executá-lo em Modo de Segurança com Rede.

Imagem

> Aguarde a conclusão e poste o relatório. ( JRT.txt )

> Baixe: < Imagem SFTGC > ( ... de Pierre13 )

< Ou Aqui > << Link!

> Descompacte-o e salve-o ao desktop!
> Desabilite seu antivírus!
> Tendo dificuldades no download,utilize o navegador Internet Explorer.
> Para Windows 10,8.1 e 7,execute "SFTGC.exe" como administrador!

Imagem

> Execute-o e clique "Go".
> Aguarde seu término,que é rápido.
> Poste o relatório! ( SFT.txt )
> Ps: De acordo com o tamanho do relatório,não poste-o diretamente!

> Acesse,para esta tarefa! < Imagem >

[Abs]
GabsBraga28
GabsBraga28 Novo Membro Registrado
46 Mensagens 0 Curtidas
#15 Por GabsBraga28
16/06/2017 - 23:53
O do JRT:

[SPOILER]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 10 Pro x64
Ran by Family (Administrator) on 16/06/2017 at 23:34:52,22
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 7

Successfully deleted: C:\ProgramData\thunder network (Folder)
Successfully deleted: C:\Users\Family\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio (Folder)
Successfully deleted: C:\Users\Family\AppData\Roaming\Mozilla\Firefox\Profiles\wubmo4ne.default\extensions\trash (Folder)
Successfully deleted: C:\Users\Public\thunder network (Folder)
Successfully deleted: C:\WINDOWS\wininit.ini (File)
Successfully deleted: C:\WINDOWS\SysWOW64\REN676C.tmp (File)
Successfully deleted: C:\WINDOWS\SysWOW64\RENECCE.tmp (File)



Registry: 1

Successfully deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_D90C5706286675FC8B0BA3E2C80E28DB (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16/06/2017 at 23:49:10,74
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

[/SPOILER]


E o do SFTGC: http://www.cjoint.com/c/GFrc1nZR8Mf
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal