Uma dúvida: fiz o procedimento do frst e addtion ocultando os arquivos protegidos do sistema operacional. Será que devo fazer desmarcando a opção de ocultação dos arquivos?
> Sem grandes prejuízos,posso aceitar do jeito que realizou.
> Copie estas informações que estão em vermelho,para o Bloco de Notas.
> Salve-as com o nome fixlist. << Texto!
> Salve-as no desktop! ( Área de trabalho ... ) -/- C:\Users\Alfredo\Desktop <<
start
CloseProcesses:
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HKU\S-1-5-21-2447171046-917324971-2953145129-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [aicancafipiklohohmoognddncljhkio] - C:\Users\Alfredo\AppData\Local\CRE\aicancafipiklohohmoognddncljhkio.crx <não encontrado (a)>
CHR HKU\S-1-5-21-2447171046-917324971-2953145129-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\\plugins\DVDVideoSoftBrowserExtension.crx [2014-07-23]
CHR HKU\S-1-5-21-2447171046-917324971-2953145129-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nnjbodopomfddehlalfilheomcahbpei] - C:\Users\Alfredo\AppData\Local\GAS Tecnologia\GBBD\cef\sf.crx [2013-06-18]
CHR HKLM-x32\...\Chrome\Extension: [aicancafipiklohohmoognddncljhkio] - C:\Users\Alfredo\AppData\Local\CRE\aicancafipiklohohmoognddncljhkio.crx <não encontrado (a)>
CHR HKLM-x32\...\Chrome\Extension: [amfclgbdpgndipgoegfpkkgobahigbcl] - C:\Users\Alfredo\AppData\Local\Smartbar/Application\1Extension.crx <não encontrado (a)>
CHR HKLM-x32\...\Chrome\Extension: [gbdabnfmdemcjjadpkpjibhhacggangd] - C:\Users\Alfredo\AppData\Local\Google\Chrome\User Data\Default\Extensions\novo_price_comparison.crx <não encontrado (a)>
CHR HKLM-x32\...\Chrome\Extension: [ijblflkdjdopkpdgllkmlbgcffjbnfda] - C:\Users\Alfredo\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx <não encontrado (a)>
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2012-06-12]
CHR HKLM-x32\...\Chrome\Extension: [lkemddiljapcmhicklfpcbpfffahfbja] - C:\Users\Alfredo\AppData\Local\Google\Chrome\User Data\Default\extensions\WebNavigation.crx <não encontrado (a)>
R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21136 2012-10-30] (AVAST Software)
S3 catchme; \??\C:\Users\Alfredo\AppData\Local\Temp\catchme.sys [X]
S0 gbpddreg; system32\drivers\gbpddreg64.sys [X]
2016-01-02 14:44 - 2016-01-02 14:49 - 00000000 ____D C:\AdwCleaner
2016-01-02 14:41 - 2016-01-02 14:42 - 01745920 _____ C:\Users\Alfredo\Desktop\AdwCleaner.exe
2016-01-02 00:17 - 2016-01-02 00:44 - 00000881 _____ C:\Users\Alfredo\Desktop\ZHPCleaner.lnk
2016-01-02 00:17 - 2016-01-02 00:17 - 01980928 _____ C:\Users\Alfredo\Desktop\ZHPCleaner.exe
2016-01-02 00:15 - 2016-01-02 00:15 - 01980928 _____ C:\Users\Alfredo\ZHPCleaner.exe
2016-01-01 23:17 - 2016-01-01 23:21 - 00000000 ____D C:\Program Files (x86)\ZHPFix
2016-01-01 23:17 - 2016-01-01 23:17 - 00001922 _____ C:\Users\Public\Desktop\ZHPFix.lnk
2016-01-01 23:17 - 2016-01-01 23:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
2016-01-01 23:15 - 2016-01-01 23:16 - 03521617 _____ (Nicolas Coolman ) C:\Users\Alfredo\Desktop\ZHPFix.exe
2016-01-01 17:11 - 2016-01-02 00:52 - 00000000 ____D C:\Users\Alfredo\AppData\Roaming\ZHP
2016-01-01 17:11 - 2016-01-01 17:11 - 00000871 _____ C:\Users\Alfredo\Desktop\ZHPDiag.lnk
2016-01-01 17:10 - 2016-01-01 17:11 - 02054656 _____ C:\Users\Alfredo\Desktop\ZHPDiag3.exe
2016-01-01 14:57 - 2016-01-01 14:58 - 01599336 _____ (Malwarebytes) C:\Users\Alfredo\Desktop\JRT.exe
2015-12-31 00:32 - 2015-12-31 03:12 - 00004712 _____ C:\WINDOWS\SysWOW64\Nydpauyjo.ini
2015-12-31 00:32 - 2015-12-31 03:12 - 00002424 _____ C:\WINDOWS\SysWOW64\NydpauyjoOff.ini
2015-12-31 00:32 - 2015-12-31 00:32 - 00034712 _____ () C:\WINDOWS\system32\Drivers\bsdriver.sys
2015-12-31 00:32 - 2015-12-31 00:32 - 00000000 ____D C:\Users\Alfredo\AppData\Local\Tempfolder
2015-12-31 00:32 - 2015-12-30 23:34 - 00768360 _____ C:\WINDOWS\system32\Nydpauyjo64.dll
2015-12-31 00:32 - 2015-12-30 23:34 - 00289128 _____ C:\WINDOWS\SysWOW64\Nydpauyjo.dll
2015-12-30 10:16 - 2015-12-31 00:32 - 00056728 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\cherimoya.sys
CustomCLSID: HKU\S-1-5-21-2447171046-917324971-2953145129-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Alfredo\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-2447171046-917324971-2953145129-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Alfredo\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-2447171046-917324971-2953145129-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Alfredo\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-2447171046-917324971-2953145129-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Alfredo\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-2447171046-917324971-2953145129-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Alfredo\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2447171046-917324971-2953145129-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Alfredo\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => Nenhum Arquivo
CustomCLSID: HKU\S-1-5-21-2447171046-917324971-2953145129-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Alfredo\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2447171046-917324971-2953145129-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Alfredo\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => Nenhum Arquivo
Task: {0E464B7D-5555-4247-9779-A83394D0F064} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {14CDB34E-553E-4191-B188-5535A86F14E1} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2447171046-917324971-2953145129-1000Core => C:\Users\Alfredo\AppData\Local\Google\Update\GoogleUpdate.exe [2015-12-04] (Google Inc.)
Task: {3DD67D8E-BFB8-4C03-8825-236E1FE426D1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {A88597EB-886E-4BC7-9CE8-1E222B439BC4} - \{1A0CBE13-75AE-4300-82B2-D763359C2602} -> Nenhum Arquivo <==== ATENÇÃO
Task: {BF9D04FA-DEDF-4124-B19D-0ED544F11D09} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2447171046-917324971-2953145129-1000UA => C:\Users\Alfredo\AppData\Local\Google\Update\GoogleUpdate.exe [2015-12-04] (Google Inc.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2447171046-917324971-2953145129-1000Core.job => C:\Users\Alfredo\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2447171046-917324971-2953145129-1000UA.job => C:\Users\Alfredo\AppData\Local\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\WINDOWS\system32\Drivers\gbpddfac64.sys:X5ZN8aGvT4
AlternateDataStreams: C:\WINDOWS\system32\Drivers\wsddfac.sys:X5ZN8aGXs4
C:\WINDOWS\system32\Drivers\bsdriver.sys
C:\Users\Alfredo\ZHPCleaner.exe
C:\Users\Alfredo\AppData\Local\Temp\sqlite3.dll
Folder: C:\Program Files\shopperz301220151513
DeleteKey: HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Nydpauyjo
CreateRestorePoint:
EmptyTemp:
Reboot:
end
> Execute FRST/FRST64 >> Clique "Corrigir" << Aguarde!
> Na mensagem,clique Executar.
> Poste o relatório! (Fixlog.txt)
< Peço aos visitantes que não utilizem este script em outros computadores,sob risco de danos aos mesmos! >
A+