Logo Hardware.com.br
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas

[Resolvido] Vírus que não sai do chrome

#1 Por joram 01/12/2015 - 19:45
/!\ Olá! G@BR!EL LUPP& /!\

> Baixe: < Chrome_FixPolicies >
> Salve este batchfile ao desktop!
> Clique direito e execute-o como administrador!
> Aguarde a conclusão!
> Abra seu navegador Google Chrome e na barra de endereços,digite:
chromeolicy
>> Aperte Enter!

Imagem
> Clique no botão "Atualizar políticas".
> Feche o Chrome e abra-o novamente!
> Vá em "Personalizar e controlar o Google Chrome" >> Configurações.
> Estando em Configurações,acesse "Pesquisar".
> Clique: "Gerenciar mecanismos de pesquisa..."
> Indo em "Configurações padrão de pesquisa",exclua o mecanismo malicioso.

... editando em conformidade com suas informações!

Set Search Settings;chromelook;
express-player;a
express-player;z
shortcutfix;


> Execute este script na Zoek e poste o relatório!

A+
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#16 Por joram
02/12/2015 - 16:52
/!\ Olá! G@BR!EL LUPP& /!\

> Baixe: < Chrome_FixPolicies >
> Salve este batchfile ao desktop!
> Clique direito e execute-o como administrador!
> Aguarde a conclusão!
> Abra seu navegador Google Chrome e na barra de endereços,digite:
chromeolicy
>> Aperte Enter!

Imagem
> Clique no botão "Atualizar políticas".
> Feche o Chrome e abra-o novamente!
> Vá em "Personalizar e controlar o Google Chrome" >> Configurações.
> Estando em Configurações,acesse "Pesquisar".
> Clique: "Gerenciar mecanismos de pesquisa..."
> Indo em "Configurações padrão de pesquisa",exclua o mecanismo malicioso.

... editando em conformidade com suas informações!

Set Search Settings;chromelook;
express-player;a
express-player;z
shortcutfix;


> Execute este script na Zoek e poste o relatório!

A+
G@BR!&L
G@BR!&L Geek Registrado
1.8K Mensagens 197 Curtidas
#18 Por G@BR!&L
02/12/2015 - 19:49
Ta ae:

Zoek.exe v5.0.0.1 Updated 01-December-2015
Tool run by Gabriel on 02/12/2015 at 19:22:19,85.
Microsoft Windows 8.1 Pro 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Gabriel\Downloads\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2015-12-01-223346.log 40627 bytes
C:\zoek-results2015-12-02-182351.log 746 bytes

==== Folders Found ======================


==== Files Found ======================


==== Registry Search Results for "express-player" ======================

No instances of string "express-player" found.

==== Chromium Look ======================

Google Slides - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
Google Docs - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
selector is not a valid CSS selector - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb
Google Search - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Ultimas atualizacoes - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\deniojjaaghemnlplaehonnpkbemehkh
Google Sheets - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap
Google Docs Offline - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi
Chrome Web Store Payments - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

==== Chromium Fix ======================

C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_toolbar.yahoo.com_0.localstorage deleted successfully
C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_toolbar.yahoo.com_0.localstorage-journal deleted successfully
C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi deleted successfully

==== shortcuts on Users Desktops ======================

C:\Users\Gabriel\Desktop\Format Factory.lnk - C:\Program Files (x86)\FormatFactory\FormatFactory.exe
C:\Users\Gabriel\Desktop\MPC-HC.lnk - C:\Program Files (x86)\MPC-HC\mpc-hc.exe
C:\Users\Gabriel\Desktop\PhotoFiltre Studio X.lnk - C:\Program Files (x86)\PhotoFiltre Studio X\pfstudiox.exe

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\CPUID CPU-Z.lnk - C:\Program Files\CPUID\CPU-Z\cpuz.exe
C:\Users\Public\Desktop\CyberLink PowerDVD 14.lnk - C:\Program Files (x86)\CyberLink\PowerDVD14\PDVDLP.exe
C:\Users\Public\Desktop\DS3 Tool.lnk - C:\Program Files (x86)\MotioninJoy\ds3\DS3_Tool.exe
C:\Users\Public\Desktop\EasyBCD 2.3.lnk - C:\Program Files (x86)\NeoSmart Technologies\EasyBCD\EasyBCD.exe
C:\Users\Public\Desktop\Firefox Developer Edition.lnk - C:\Program Files\Firefox Developer Edition\firefox.exe
C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Public\Desktop\Guitar Rig 5.lnk - C:\Program Files (x86)\Native Instruments\Guitar Rig 5\Guitar Rig 5.exe

==== shortcuts in Users Start Menu ======================

C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Command Prompt.lnk - C:\WINDOWS\system32\cmd.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk - C:\WINDOWS\system32\magnify.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk - C:\WINDOWS\system32\narrator.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk - C:\WINDOWS\system32\osk.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk - C:\WINDOWS\system32\notepad.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flashtool\Flashtool.lnk - C:\Flashtool\FlashTool.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flashtool\Flashtool64.lnk - C:\Flashtool\FlashTool64.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flashtool\Uninstall Flashtool.lnk - C:\Flashtool\uninstall.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\FormatFactory.lnk - C:\Program Files (x86)\FormatFactory\FormatFactory.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\Help.lnk - C:\Program Files (x86)\FormatFactory\FormatFactory.exe /help
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\Uninstall.lnk - C:\Program Files (x86)\FormatFactory\uninst.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan\Help and HOW-TO.lnk - C:\Program Files (x86)\SpeedFan\speedfan.chm
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan\Release info.lnk - C:\Program Files (x86)\SpeedFan\speedfan.txt
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan\SpeedFan.lnk - C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan\Uninstall SpeedFan.lnk - C:\Program Files (x86)\SpeedFan\uninstall.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk - C:\WINDOWS\system32\cmd.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Help.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Windows.Defender.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinAVI Video Converter\WinAVI Video Converter Web Site.lnk - C:\Program Files (x86)\Video Converter\website.url
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinAVI Video Converter\WinAVI Video Converter.lnk - C:\Program Files (x86)\Video Converter\WinAVI.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Ajuda do WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.chm
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Manual do Console RAR.lnk - C:\Program Files (x86)\WinRAR\Rar.txt
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\O que há de novo na última versão.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.exe

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk - C:\Program Files (x86)\Audacity\audacity.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Developer Edition.lnk - C:\Program Files\Firefox Developer Edition\firefox.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk - C:\Program Files (x86)\ImgBurn\ImgBurn.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files (x86)\Opera\launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk - C:\WINDOWS\Speech\Common\sapisvr.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk - C:\WINDOWS\system32\calc.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk - C:\WINDOWS\system32\mspaint.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk - C:\WINDOWS\system32\mstsc.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk - C:\WINDOWS\system32\psr.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk - C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk - C:\WINDOWS\system32\xpsrchvw.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk - C:\WINDOWS\system32\charmap.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk - C:\WINDOWS\system32\comexp.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk - C:\WINDOWS\system32\compmgmt.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk - C:\WINDOWS\system32\dfrgui.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk - C:\WINDOWS\system32\cleanmgr.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk - C:\WINDOWS\system32\eventvwr.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk - C:\WINDOWS\system32\iscsicpl.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk - C:\WINDOWS\syswow64\odbcad32.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk - C:\WINDOWS\system32\odbcad32.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk - C:\WINDOWS\system32\perfmon.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk - C:\WINDOWS\system32\perfmon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk - C:\WINDOWS\system32\services.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk - C:\WINDOWS\system32\msinfo32.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk - C:\WINDOWS\system32\taskschd.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk - C:\WINDOWS\system32\WF.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell (x86).lnk - C:\WINDOWS\syswow64\WindowsPowerShell\v1.0\powershell.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell ISE (x86).lnk - C:\WINDOWS\syswow64\WindowsPowerShell\v1.0\PowerShell_ISE.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell ISE.lnk - C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\About.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\about.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Ainvo Registry Defrag.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\registrydefrag.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Check for Updates....lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\update.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Contact.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\contact.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Feedback.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\feedback.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Technical Support.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\support.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Uninstall.lnk - C:\Program Files (x86)\Ainvo\Ainvo Registry Defrag\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Visit Company Web Site.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\home.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Visit Program Web Site.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\product.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Video\How safe the registry defragmentation procedure is.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\video\How safe the registry defragmentation procedure is.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Video\How to install a software program.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\video\How to install a software program.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvsoft\Any Video Converter\Any Video Converter na Internet.lnk - C:\Program Files (x86)\Anvsoft\Any Video Converter\AVCFree.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvsoft\Any Video Converter\Any Video Converter.lnk - C:\Program Files (x86)\Anvsoft\Any Video Converter\AVCFree.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvsoft\Any Video Converter\Desinstalar Any Video Converter.lnk - C:\Program Files (x86)\Anvsoft\Any Video Converter\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\DiskDefrag\Auslogics DiskDefrag.lnk - C:\Program Files (x86)\Auslogics\DiskDefrag\DiskDefrag.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Registry Defrag\Auslogics Registry Defrag.lnk - C:\Program Files (x86)\Auslogics\Registry Defrag\RegistryDefrag.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell\Classic Shell Help.lnk - C:\Program Files (x86)\Classic Shell\ClassicShell.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell\Classic Shell Readme.lnk - C:\Program Files (x86)\Classic Shell\ClassicShellReadme.rtf
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell\Classic Shell Update.lnk - C:\Program Files (x86)\Classic Shell\ClassicShellUpdate.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell\Classic Start Menu Settings.lnk - C:\Program Files (x86)\Classic Shell\ClassicStartMenu.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\CPU-Z.lnk - C:\Program Files\CPUID\CPU-Z\cpuz.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\Edit CPU-Z Config File.lnk - C:\Program Files\CPUID\CPU-Z\cpuz.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\Uninstall CPU-Z.lnk - C:\Program Files\CPUID\CPU-Z\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 14\CyberLink PowerDVD 14.lnk - C:\Program Files (x86)\CyberLink\PowerDVD14\PDVDLP.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD-lab PRO 2\DVD-lab PRO 2 Help.lnk - C:\Program Files (x86)\DVDlabPro2\Help\DVDlabPRO.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD-lab PRO 2\DVD-lab PRO 2.lnk - C:\Program Files (x86)\DVDlabPro2\DVDlabPRO.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD-lab PRO 2\Web page.lnk - C:\Program Files (x86)\DVDlabPro2\DVDlab.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FinalWire\AIDA64 Extreme\AIDA64 Extreme documentação.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FinalWire\AIDA64 Extreme\AIDA64 Extreme na Internet.lnk - C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FinalWire\AIDA64 Extreme\AIDA64 Extreme.lnk - C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\HD Tune Pro Drive Status Manual.lnk - C:\Program Files (x86)\HD Tune Pro\hdtuneprodrivestatus.pdf
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\HD Tune Pro Drive Status.lnk - C:\Program Files (x86)\HD Tune Pro\HDTuneProDriveStatus.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\HD Tune Pro Manual.lnk - C:\Program Files (x86)\HD Tune Pro\hdtunepro.pdf
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\HD Tune Pro on the Web.lnk - C:\Program Files (x86)\HD Tune Pro\HDTunePro.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\HD Tune Pro.lnk - C:\Program Files (x86)\HD Tune Pro\HDTunePro.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\Uninstall HD Tune Pro.lnk - C:\Program Files (x86)\HD Tune Pro\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDD Low Level Format Tool\Hard Disk Low Level Format Tool on the Web.lnk - C:\Program Files (x86)\HDDGURU LLF Tool\LLFTOOL.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDD Low Level Format Tool\Hard Disk Low Level Format Tool.lnk - C:\Program Files (x86)\HDDGURU LLF Tool\LLFTOOL.EXE
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDD Low Level Format Tool\Uninstall Hard Disk Low Level Format Tool.lnk - C:\Program Files (x86)\HDDGURU LLF Tool\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn\ImgBurn Read Me.lnk - C:\Program Files (x86)\ImgBurn\ReadMe.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn\ImgBurn.lnk - C:\Program Files (x86)\ImgBurn\ImgBurn.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn\Uninstall.lnk - C:\Program Files (x86)\ImgBurn\uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingo ROOT\Kingo ROOT.lnk - C:\Program Files (x86)\Kingo ROOT\Kingo Root.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingo ROOT\Uninstall Kingo ROOT.lnk - C:\Program Files (x86)\Kingo ROOT\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Desinstalar Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware Notifications.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus\Desinstalar.lnk - C:\Program Files (x86)\McAfee Security Scan\uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus\McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\3.11.149\McUICnt.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Megacubo\Megacubo.lnk - C:\Program Files (x86)\Megacubo\megacubo.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Megacubo\Sleepr.lnk - C:\Program Files (x86)\Megacubo\megacubo.exe -load:sleepr
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Access 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\accicons.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Excel 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\xlicons.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Designer 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\inficon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Filler 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\inficon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft OneNote 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\joticon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Outlook 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\outicon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft PowerPoint 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\pptico.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Publisher 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\pubs.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft SharePoint Workspace 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\grvicons.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Word 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\wordicon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Ferramentas do Microsoft Office 2010\Centro de Carregamento do Microsoft Office 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\msouc.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Ferramentas do Microsoft Office 2010\Certificado Digital para Projetos do VBA.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\misc.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Ferramentas do Microsoft Office 2010\Microsoft Media Gallery.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\cagicon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Ferramentas do Microsoft Office 2010\Microsoft Office Picture Manager.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\oisicon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Ferramentas do Microsoft Office 2010\Preferências de Idioma do Microsoft Office 2010.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy\DS3 Tool.lnk - C:\Program Files (x86)\MotioninJoy\ds3\DS3_Tool.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy\Uninstall.lnk - C:\Program Files (x86)\MotioninJoy\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC\Changelog.lnk - C:\Program Files (x86)\MPC-HC\Changelog.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC\Desinstalar MPC-HC.lnk - C:\Program Files (x86)\MPC-HC\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC\MPC-HC.lnk - C:\Program Files (x86)\MPC-HC\mpc-hc.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Controller Editor\Controller Editor.lnk - C:\Program Files (x86)\Native Instruments\Controller Editor\Controller Editor.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig 5\Guitar Rig 5.lnk - C:\Program Files (x86)\Native Instruments\Guitar Rig 5\Guitar Rig 5.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Session IO\Guitar Rig Session IO Control Panel.lnk - C:\Program Files (x86)\Native Instruments\Guitar Rig Session IO Driver\sesscpl.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Service Center.lnk - C:\Program Files (x86)\Native Instruments\Service Center\ServiceCenter.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies\EasyBCD\EasyBCD 2.3.lnk - C:\Program Files (x86)\NeoSmart Technologies\EasyBCD\EasyBCD.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies\EasyBCD\Online Documentation.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies\EasyBCD\Uninstall EasyBCD.lnk - C:\Program Files (x86)\NeoSmart Technologies\EasyBCD\uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Studio X\PhotoFiltre Studio information.lnk - C:\Program Files (x86)\PhotoFiltre Studio X\PhotoFiltre Studio.htm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Studio X\PhotoFiltre Studio X.lnk - C:\Program Files (x86)\PhotoFiltre Studio X\pfstudiox.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Studio X\PhotoMasque information.lnk - C:\Program Files (x86)\PhotoFiltre Studio X\PhotoMasque.htm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Studio X\Uninstall PhotoFiltre Studio X.lnk - C:\Program Files (x86)\PhotoFiltre Studio X\Uninst.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint\Microsoft SharePoint Workspace 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\grvicons.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 3\Desinstalar Smart Defrag 3.lnk - C:\Program Files (x86)\IObit\Smart Defrag 3\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 3\Smart Defrag 3.lnk - C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony\Sony PC Companion\Sony PC Companion 2.1.lnk - C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Default Programs.lnk - C:\WINDOWS\system32\control.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk - C:\WINDOWS\system32\taskmgr.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows Easy Transfer.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows PowerShell.lnk - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK\Uninstall - TP-LINK TL-WN821N(C)_TL-WN822N_TL-WN823N Driver.lnk - C:\Program Files (x86)\InstallShield Installation Information\{852E893E-E4FD-45BB-8B17-72ADDF686974}\setup.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO\UltraISO Help.lnk - C:\Program Files (x86)\UltraISO\ultraiso.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO\UltraISO Readme.lnk - C:\Program Files (x86)\UltraISO\Readme.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO\UltraISO Revision History.lnk - C:\Program Files (x86)\UltraISO\History.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO\UltraISO.lnk - C:\Program Files (x86)\UltraISO\UltraISO.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO\Uninstall UltraISO.lnk - C:\Program Files (x86)\UltraISO\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unified Remote 3\Unified Remote.lnk - C:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unified Remote 3\Uninstall Unified Remote.lnk - C:\Program Files (x86)\Unified Remote 3\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Ajuda do WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Manual do Console RAR.lnk - C:\Program Files (x86)\WinRAR\Rar.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\O que há de novo na última versão.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.exe

==== shortcuts in Quick Launch ======================

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk - C:\Program Files (x86)\ImgBurn\ImgBurn.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Megacubo.lnk - C:\Program Files (x86)\Megacubo\megacubo.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox Developer Edition.lnk - C:\Program Files\Firefox Developer Edition\firefox.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -

==== C:\zoek_backup content ======================

C:\zoek_backup (files=56 folders=43 45817709 bytes)

==== After Reboot ======================

==== Deleting Files / Folders ======================

"C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cfhdojbkjhnklbpkdaibdccddilifddb" deleted

==== EOF on 02/12/2015 at 19:26:03,04 ======================

Também não surtiu efeito, mal abri o Chrome e já abriu essa porcaria de newpoptab.com e redirecionou para um site de publicidade...

Tmfeijo disse:
Boa tarde !

Ok então . No aguardo do log do eset on line .

E execute o malwarebytes seguindo este tutorial :

http://www.caixadedicas.com/2009/10/tutorial-do-malwarebytes-anti-malware.html



Abraços


Acha mesmo que devo reexecutar o Malwarebytes de novo? Já escanei com ele duas vezes e nada...
TmfeijoMMonroe
TmfeijoMMonr... Cyber Highlander Registrado
13.7K Mensagens 4.2K Curtidas
#19 Por TmfeijoMMonr...
02/12/2015 - 19:54
Boa noite !

Ok . Compreendo . Mas e o eset on line ? Às vezes rodo :


Anexo do post


Anexo do post


Anexo do post


Anexo do post



Execute também !

Adware removal tool

http://secsecurity.forumbrasil.net/t158-adware-removal-tool-by-techsupportall-com

PS :
Espere o padronizado scan, a devida limpeza e no final dê um reset no navegador mencionado ; com este programa .



Abraços

G@BR!EL LUPP& disse:
Ta ae:

Zoek.exe v5.0.0.1 Updated 01-December-2015
Tool run by Gabriel on 02/12/2015 at 19:22:19,85.
Microsoft Windows 8.1 Pro 6.3.9600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Gabriel\Downloads\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2015-12-01-223346.log 40627 bytes
C:\zoek-results2015-12-02-182351.log 746 bytes

==== Folders Found ======================


==== Files Found ======================


==== Registry Search Results for "express-player" ======================

No instances of string "express-player" found.

==== Chromium Look ======================

Google Slides - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
Google Docs - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
selector is not a valid CSS selector - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb
Google Search - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Ultimas atualizacoes - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\deniojjaaghemnlplaehonnpkbemehkh
Google Sheets - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap
Google Docs Offline - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi
Chrome Web Store Payments - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Gabriel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

==== Chromium Fix ======================

C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_toolbar.yahoo.com_0.localstorage deleted successfully
C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_toolbar.yahoo.com_0.localstorage-journal deleted successfully
C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi deleted successfully

==== shortcuts on Users Desktops ======================

C:\Users\Gabriel\Desktop\Format Factory.lnk - C:\Program Files (x86)\FormatFactory\FormatFactory.exe
C:\Users\Gabriel\Desktop\MPC-HC.lnk - C:\Program Files (x86)\MPC-HC\mpc-hc.exe
C:\Users\Gabriel\Desktop\PhotoFiltre Studio X.lnk - C:\Program Files (x86)\PhotoFiltre Studio X\pfstudiox.exe

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\CPUID CPU-Z.lnk - C:\Program Files\CPUID\CPU-Z\cpuz.exe
C:\Users\Public\Desktop\CyberLink PowerDVD 14.lnk - C:\Program Files (x86)\CyberLink\PowerDVD14\PDVDLP.exe
C:\Users\Public\Desktop\DS3 Tool.lnk - C:\Program Files (x86)\MotioninJoy\ds3\DS3_Tool.exe
C:\Users\Public\Desktop\EasyBCD 2.3.lnk - C:\Program Files (x86)\NeoSmart Technologies\EasyBCD\EasyBCD.exe
C:\Users\Public\Desktop\Firefox Developer Edition.lnk - C:\Program Files\Firefox Developer Edition\firefox.exe
C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Public\Desktop\Guitar Rig 5.lnk - C:\Program Files (x86)\Native Instruments\Guitar Rig 5\Guitar Rig 5.exe

==== shortcuts in Users Start Menu ======================

C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Command Prompt.lnk - C:\WINDOWS\system32\cmd.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk - C:\WINDOWS\system32\magnify.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk - C:\WINDOWS\system32\narrator.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk - C:\WINDOWS\system32\osk.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk - C:\WINDOWS\system32\notepad.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flashtool\Flashtool.lnk - C:\Flashtool\FlashTool.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flashtool\Flashtool64.lnk - C:\Flashtool\FlashTool64.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flashtool\Uninstall Flashtool.lnk - C:\Flashtool\uninstall.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\FormatFactory.lnk - C:\Program Files (x86)\FormatFactory\FormatFactory.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\Help.lnk - C:\Program Files (x86)\FormatFactory\FormatFactory.exe /help
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory\Uninstall.lnk - C:\Program Files (x86)\FormatFactory\uninst.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan\Help and HOW-TO.lnk - C:\Program Files (x86)\SpeedFan\speedfan.chm
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan\Release info.lnk - C:\Program Files (x86)\SpeedFan\speedfan.txt
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan\SpeedFan.lnk - C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedFan\Uninstall SpeedFan.lnk - C:\Program Files (x86)\SpeedFan\uninstall.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk - C:\WINDOWS\system32\cmd.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Help.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Windows.Defender.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinAVI Video Converter\WinAVI Video Converter Web Site.lnk - C:\Program Files (x86)\Video Converter\website.url
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinAVI Video Converter\WinAVI Video Converter.lnk - C:\Program Files (x86)\Video Converter\WinAVI.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Ajuda do WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.chm
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Manual do Console RAR.lnk - C:\Program Files (x86)\WinRAR\Rar.txt
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\O que há de novo na última versão.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.exe

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk - C:\Program Files (x86)\Audacity\audacity.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox Developer Edition.lnk - C:\Program Files\Firefox Developer Edition\firefox.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk - C:\Program Files (x86)\ImgBurn\ImgBurn.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk - C:\Program Files (x86)\Opera\launcher.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk - C:\WINDOWS\Speech\Common\sapisvr.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk - C:\WINDOWS\system32\calc.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk - C:\WINDOWS\system32\mspaint.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk - C:\WINDOWS\system32\mstsc.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk - C:\WINDOWS\system32\psr.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk - C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk - C:\WINDOWS\system32\xpsrchvw.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk - C:\WINDOWS\system32\charmap.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk - C:\WINDOWS\system32\comexp.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk - C:\WINDOWS\system32\compmgmt.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk - C:\WINDOWS\system32\dfrgui.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk - C:\WINDOWS\system32\cleanmgr.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk - C:\WINDOWS\system32\eventvwr.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk - C:\WINDOWS\system32\iscsicpl.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (32-bit).lnk - C:\WINDOWS\syswow64\odbcad32.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources (64-bit).lnk - C:\WINDOWS\system32\odbcad32.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk - C:\WINDOWS\system32\perfmon.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk - C:\WINDOWS\system32\perfmon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk - C:\WINDOWS\system32\services.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk - C:\WINDOWS\system32\msinfo32.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk - C:\WINDOWS\system32\taskschd.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk - C:\WINDOWS\system32\WF.msc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell (x86).lnk - C:\WINDOWS\syswow64\WindowsPowerShell\v1.0\powershell.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell ISE (x86).lnk - C:\WINDOWS\syswow64\WindowsPowerShell\v1.0\PowerShell_ISE.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell ISE.lnk - C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\About.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\about.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Ainvo Registry Defrag.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\registrydefrag.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Check for Updates....lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\update.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Contact.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\contact.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Feedback.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\feedback.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Technical Support.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\support.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Uninstall.lnk - C:\Program Files (x86)\Ainvo\Ainvo Registry Defrag\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Visit Company Web Site.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\home.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Visit Program Web Site.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\product.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Video\How safe the registry defragmentation procedure is.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\video\How safe the registry defragmentation procedure is.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ainvo\Registry Defrag\Video\How to install a software program.lnk - C:\Program Files\Ainvo\Ainvo Registry Defrag\help\en\video\How to install a software program.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvsoft\censurado.png\censurado.png na Internet.lnk - C:\Program Files (x86)\Anvsoft\censurado.png\AVCFree.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvsoft\censurado.png\censurado.png.lnk - C:\Program Files (x86)\Anvsoft\censurado.png\AVCFree.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvsoft\censurado.png\Desinstalar censurado.png.lnk - C:\Program Files (x86)\Anvsoft\censurado.png\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\DiskDefrag\Auslogics DiskDefrag.lnk - C:\Program Files (x86)\Auslogics\DiskDefrag\DiskDefrag.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics\Registry Defrag\Auslogics Registry Defrag.lnk - C:\Program Files (x86)\Auslogics\Registry Defrag\RegistryDefrag.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell\Classic Shell Help.lnk - C:\Program Files (x86)\Classic Shell\ClassicShell.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell\Classic Shell Readme.lnk - C:\Program Files (x86)\Classic Shell\ClassicShellReadme.rtf
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell\Classic Shell Update.lnk - C:\Program Files (x86)\Classic Shell\ClassicShellUpdate.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell\Classic Start Menu Settings.lnk - C:\Program Files (x86)\Classic Shell\ClassicStartMenu.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\CPU-Z.lnk - C:\Program Files\CPUID\CPU-Z\cpuz.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\Edit CPU-Z Config File.lnk - C:\Program Files\CPUID\CPU-Z\cpuz.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\Uninstall CPU-Z.lnk - C:\Program Files\CPUID\CPU-Z\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 14\CyberLink PowerDVD 14.lnk - C:\Program Files (x86)\CyberLink\PowerDVD14\PDVDLP.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD-lab PRO 2\DVD-lab PRO 2 Help.lnk - C:\Program Files (x86)\DVDlabPro2\Help\DVDlabPRO.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD-lab PRO 2\DVD-lab PRO 2.lnk - C:\Program Files (x86)\DVDlabPro2\DVDlabPRO.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD-lab PRO 2\Web page.lnk - C:\Program Files (x86)\DVDlabPro2\DVDlab.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FinalWire\AIDA64 Extreme\AIDA64 Extreme documentação.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FinalWire\AIDA64 Extreme\AIDA64 Extreme na Internet.lnk - C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FinalWire\AIDA64 Extreme\AIDA64 Extreme.lnk - C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\HD Tune Pro Drive Status Manual.lnk - C:\Program Files (x86)\HD Tune Pro\hdtuneprodrivestatus.pdf
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\HD Tune Pro Drive Status.lnk - C:\Program Files (x86)\HD Tune Pro\HDTuneProDriveStatus.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\HD Tune Pro Manual.lnk - C:\Program Files (x86)\HD Tune Pro\hdtunepro.pdf
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\HD Tune Pro on the Web.lnk - C:\Program Files (x86)\HD Tune Pro\HDTunePro.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\HD Tune Pro.lnk - C:\Program Files (x86)\HD Tune Pro\HDTunePro.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune Pro\Uninstall HD Tune Pro.lnk - C:\Program Files (x86)\HD Tune Pro\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDD Low Level Format Tool\Hard Disk Low Level Format Tool on the Web.lnk - C:\Program Files (x86)\HDDGURU LLF Tool\LLFTOOL.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDD Low Level Format Tool\Hard Disk Low Level Format Tool.lnk - C:\Program Files (x86)\HDDGURU LLF Tool\LLFTOOL.EXE
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HDD Low Level Format Tool\Uninstall Hard Disk Low Level Format Tool.lnk - C:\Program Files (x86)\HDDGURU LLF Tool\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn\ImgBurn Read Me.lnk - C:\Program Files (x86)\ImgBurn\ReadMe.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn\ImgBurn.lnk - C:\Program Files (x86)\ImgBurn\ImgBurn.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn\Uninstall.lnk - C:\Program Files (x86)\ImgBurn\uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingo ROOT\Kingo ROOT.lnk - C:\Program Files (x86)\Kingo ROOT\Kingo Root.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingo ROOT\Uninstall Kingo ROOT.lnk - C:\Program Files (x86)\Kingo ROOT\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Desinstalar Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware Notifications.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus\Desinstalar.lnk - C:\Program Files (x86)\McAfee Security Scan\uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus\McAfee Security Scan Plus.lnk - C:\Program Files (x86)\McAfee Security Scan\3.11.149\McUICnt.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Megacubo\Megacubo.lnk - C:\Program Files (x86)\Megacubo\megacubo.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Megacubo\Sleepr.lnk - C:\Program Files (x86)\Megacubo\megacubo.exe -load:sleepr
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Access 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\accicons.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Excel 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\xlicons.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Designer 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\inficon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft InfoPath Filler 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\inficon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft OneNote 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\joticon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Outlook 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\outicon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft PowerPoint 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\pptico.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Publisher 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\pubs.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft SharePoint Workspace 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\grvicons.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Word 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\wordicon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Ferramentas do Microsoft Office 2010\Centro de Carregamento do Microsoft Office 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\msouc.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Ferramentas do Microsoft Office 2010\Certificado Digital para Projetos do VBA.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\misc.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Ferramentas do Microsoft Office 2010\Microsoft Media Gallery.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\cagicon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Ferramentas do Microsoft Office 2010\Microsoft Office Picture Manager.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\oisicon.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Ferramentas do Microsoft Office 2010\Preferências de Idioma do Microsoft Office 2010.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy\DS3 Tool.lnk - C:\Program Files (x86)\MotioninJoy\ds3\DS3_Tool.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MotioninJoy\Uninstall.lnk - C:\Program Files (x86)\MotioninJoy\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC\Changelog.lnk - C:\Program Files (x86)\MPC-HC\Changelog.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC\Desinstalar MPC-HC.lnk - C:\Program Files (x86)\MPC-HC\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC\MPC-HC.lnk - C:\Program Files (x86)\MPC-HC\mpc-hc.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Controller Editor\Controller Editor.lnk - C:\Program Files (x86)\Native Instruments\Controller Editor\Controller Editor.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig 5\Guitar Rig 5.lnk - C:\Program Files (x86)\Native Instruments\Guitar Rig 5\Guitar Rig 5.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Guitar Rig Session IO\Guitar Rig Session IO Control Panel.lnk - C:\Program Files (x86)\Native Instruments\Guitar Rig Session IO Driver\sesscpl.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments\Service Center\Service Center.lnk - C:\Program Files (x86)\Native Instruments\Service Center\ServiceCenter.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies\EasyBCD\EasyBCD 2.3.lnk - C:\Program Files (x86)\NeoSmart Technologies\EasyBCD\EasyBCD.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies\EasyBCD\Online Documentation.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies\EasyBCD\Uninstall EasyBCD.lnk - C:\Program Files (x86)\NeoSmart Technologies\EasyBCD\uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Studio X\PhotoFiltre Studio information.lnk - C:\Program Files (x86)\PhotoFiltre Studio X\PhotoFiltre Studio.htm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Studio X\PhotoFiltre Studio X.lnk - C:\Program Files (x86)\PhotoFiltre Studio X\pfstudiox.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Studio X\PhotoMasque information.lnk - C:\Program Files (x86)\PhotoFiltre Studio X\PhotoMasque.htm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Studio X\Uninstall PhotoFiltre Studio X.lnk - C:\Program Files (x86)\PhotoFiltre Studio X\Uninst.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint\Microsoft SharePoint Workspace 2010.lnk - C:\WINDOWS\Installer\{90140000-0011-0000-1000-0000000FF1CE}\grvicons.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 3\Desinstalar Smart Defrag 3.lnk - C:\Program Files (x86)\IObit\Smart Defrag 3\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 3\Smart Defrag 3.lnk - C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony\Sony PC Companion\Sony PC Companion 2.1.lnk - C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Default Programs.lnk - C:\WINDOWS\system32\control.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk - C:\WINDOWS\system32\taskmgr.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows Easy Transfer.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows PowerShell.lnk - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK\Uninstall - TP-LINK TL-WN821N(C)_TL-WN822N_TL-WN823N Driver.lnk - C:\Program Files (x86)\InstallShield Installation Information\{852E893E-E4FD-45BB-8B17-72ADDF686974}\setup.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO\UltraISO Help.lnk - C:\Program Files (x86)\UltraISO\ultraiso.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO\UltraISO Readme.lnk - C:\Program Files (x86)\UltraISO\Readme.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO\UltraISO Revision History.lnk - C:\Program Files (x86)\UltraISO\History.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO\UltraISO.lnk - C:\Program Files (x86)\UltraISO\UltraISO.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraISO\Uninstall UltraISO.lnk - C:\Program Files (x86)\UltraISO\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unified Remote 3\Unified Remote.lnk - C:\Program Files (x86)\Unified Remote 3\RemoteServerWin.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unified Remote 3\Uninstall Unified Remote.lnk - C:\Program Files (x86)\Unified Remote 3\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Ajuda do WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Manual do Console RAR.lnk - C:\Program Files (x86)\WinRAR\Rar.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\O que há de novo na última versão.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk - C:\Program Files (x86)\WinRAR\WinRAR.exe

==== shortcuts in Quick Launch ======================

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ImgBurn.lnk - C:\Program Files (x86)\ImgBurn\ImgBurn.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Megacubo.lnk - C:\Program Files (x86)\Megacubo\megacubo.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk -
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox Developer Edition.lnk - C:\Program Files\Firefox Developer Edition\firefox.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -

==== C:\zoek_backup content ======================

C:\zoek_backup (files=56 folders=43 45817709 bytes)

==== After Reboot ======================

==== Deleting Files / Folders ======================

"C:\Users\Gabriel\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cfhdojbkjhnklbpkdaibdccddilifddb" deleted

==== EOF on 02/12/2015 at 19:26:03,04 ======================

Também não surtiu efeito, mal abri o Chrome e já abriu essa porcaria de newpoptab.com e redirecionou para um site de publicidade...



Acha mesmo que devo reexecutar o Malwarebytes de novo? Já escanei com ele duas vezes e nada...

Anexos

G@BR!&L
G@BR!&L Geek Registrado
1.8K Mensagens 197 Curtidas
#20 Por G@BR!&L
02/12/2015 - 23:06
Tmeijo, executei o ESET foram encontradas poucas ameaças e removi elas, agora vamos ver se pelo menos dessa vez me livrei desse vírus.
E quanto ao ADWRemoval Tool não encontrou nada, creio que meu pc está livre de qualquer tipo de vírus, e se esse newpoptab.com abri mais uma vez eu volto aqui para tentar outra solução, porque tá difícl...rs
Se caso não tiver mais o que fazer, acho que vou reinstalar o Chrome, mas com o Revo para apagar todos os rastros do navegador e fazer uma instalação limpa...wink.png
TmfeijoMMonroe
TmfeijoMMonr... Cyber Highlander Registrado
13.7K Mensagens 4.2K Curtidas
#21 Por TmfeijoMMonr...
02/12/2015 - 23:16
Boa noite !

É . Talvez desinstalando o navegador ; resolva ! Depois reinstale . rsrsrs
Mas antes rode a ADWRemoval Tool novamente e reset o navegador google chrome .

https://www.hardware.com.br/comunidade/ie-estranho/1391598/#post7311578


Abraços

G@BR!EL LUPP& disse:
Tmeijo, executei o ESET foram encontradas poucas ameaças e removi elas, agora vamos ver se pelo menos dessa vez me livrei desse vírus.
E quanto ao ADWRemoval Tool não encontrou nada, creio que meu pc está livre de qualquer tipo de vírus, e se esse newpoptab.com abri mais uma vez eu volto aqui para tentar outra solução, porque tá difícl...rs
Se caso não tiver mais o que fazer, acho que vou reinstalar o Chrome, mas com o Revo para apagar todos os rastros do navegador e fazer uma instalação limpa...wink.png
G@BR!&L
G@BR!&L Geek Registrado
1.8K Mensagens 197 Curtidas
#22 Por G@BR!&L
03/12/2015 - 01:01
Bom, não resolveu ainda, mas...fiz algo básico, apenas desinstalei sem apagar dados de navegação como opção, e reinstalei, e não é que agora finalmente essa praga sumiu de vez?
Vai lá se saber o que era de tão impossível de remover do navegador, mesmo usando ferramentas avançadas, nunca vi nada igual...
Pelo menos resolveu parcialmente, mas amanhã eu vejo melhor, se caso não voltar, então PROBLEMA RESOLVIDO.
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#23 Por joram
03/12/2015 - 04:56
/!\ Olá! G@BR!EL LUPP& /!\
"G@BR!EL LUPP&"
Vai lá se saber o que era de tão impossível de remover do navegador, mesmo usando ferramentas avançadas, nunca vi nada igual...

> Caso sui generis,onde nenhuma das ferramentas empregadas mostraram a presença do hijacker,após a limpeza inicial.
> Apenas um detalhe para a galera que gosta do uso de ferramentas. A Adware Removal Tool,em sua operação,já reseta os navegadores.

Abs!
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#25 Por joram
03/12/2015 - 08:12
/!\ Olá! Tmfeijo /!\

> Ah! Sim. Ela tornou o reset opcional,onde em alguns poucos casos não há necessidade do mesmo.
> Já em infestações como top8844.com;navegaki.com;321oyun.com e 123rede.com,este reset faz-se preemente.
> Ps: Cabe-lhe relatar que nosso acordo de não-interferência continua valendo,onde este Tópico pertence ao edutango que,com certeza ,chegaria à solução do mesmo.

Abs!
#Leandro#
#Leandro# Super Participante Registrado
235 Mensagens 103 Curtidas
#26 Por #Leandro#
03/12/2015 - 12:37
G@BR!EL LUPP& disse:
Bom, não resolveu ainda, mas...fiz algo básico, apenas desinstalei sem apagar dados de navegação como opção, e reinstalei, e não é que agora finalmente essa praga sumiu de vez?
Vai lá se saber o que era de tão impossível de remover do navegador, mesmo usando ferramentas avançadas, nunca vi nada igual...
Pelo menos resolveu parcialmente, mas amanhã eu vejo melhor, se caso não voltar, então PROBLEMA RESOLVIDO.



Veja Tmfeijo, no tutorial quais as ferramentas são utilizadas para remover o newpoptab.com
https://malwaretips.com/blogs/remove-newpoptab-com-ads/


No inicio o Edutando adicionou os scripts no Zoek, para resetar os navegadores que remove todos os hijackthis, e Adwares, e utilizando as ferramentas Adwcleaner, Junkware Removal Tool, resolveriam o problema!

Uma coisa, recomendo ao analista profissional Joram, que oriente ao autor do tópico remover todas ferramentas utilizadas nesse caso do suposto adware newpoptab.com


Abra os olhos Tmfeijo, fica esperto com esses novos membros cadastrados nesse Fórum.
G@BR!&L
G@BR!&L Geek Registrado
1.8K Mensagens 197 Curtidas
#27 Por G@BR!&L
03/12/2015 - 15:28
É pelo jeito não resolveu ainda...Liguei o PC hoje e fui abrir o Chrome e já abriu essa aba de novo: newpoptab.com/watch?key=60fd53c3a2cbae821bd2f3056f84047d
Já usei várias ferramentas e esse vírus ainda persiste no navegador. Reinstalei apenas sem apagar dados de navegação e mesmo assim continua o problema....Será que reinstalação mais limpa, resolveria?
caxorroloko
caxorroloko Ubbergeek Registrado
1K Mensagens 1.1K Curtidas
#28 Por caxorroloko
03/12/2015 - 15:33
G@BR!EL LUPP& disse:
É pelo jeito não resolveu ainda...Liguei o PC hoje e fui abrir o Chrome e já abriu essa aba de novo: newpoptab.com/watch?key=60fd53c3a2cbae821bd2f3056f84047d
Já usei várias ferramentas e esse vírus ainda persiste no navegador. Reinstalei apenas sem apagar dados de navegação e mesmo assim continua o problema....Será que reinstalação mais limpa, resolveria?


Se você for no regedit e pesquisar por newpoptab.com ele traz algum resultado?
caxorroloko
caxorroloko Ubbergeek Registrado
1K Mensagens 1.1K Curtidas
#30 Por caxorroloko
03/12/2015 - 15:53
G@BR!EL LUPP& disse:
Já tentei isso também, não encontra nada...


Se ainda quiser fazer mais um teste, roda o Security Task Manager como administrador http://www.neuber.com/taskmanager/portuguese/

Verifica se tem algum serviço suspeito, organiza por fabricante e verifica se tem algum nome estranho, tipo chinês ou algo assim.
Normalmente ele mostra avisos de segurança em vermelho, verifica se não tem super-coockies e extensões maliciosas

Como já foi executado uma batelada de programas, é apenas um teste para ver se não ficou nada pra trás...
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal