osousa

Membro
  • Total de itens

    75
  • Registro em

  • Última visita

Reputação

0 Neutral

Sobre osousa

  • Rank
    Membro

Contact Methods

  • ICQ
    0
  1. Bom dia!. fiz os procedimentos como solicitado. att Osni Sousa
  2. Boa tarde, reportando o que aconteceu, 1) A maquina nao queria abrir relatou que " Não é possível entrar em sua conta" este problema persistiu em 3 tentativas, ai deu tela azul e depois de reiniciar ela voltou. 2) baixei o programa e passei demorou uns minutos, não muitos até que foi rápido. 3) resultado "zero" em tudo, found threats = 0, neutralizaed 0 threats e quarentena 0 objetos. 4) estou anexando o relatorio. Osni TDSSKiller.3.1.0.12_18.03.2017_15.21.21_log.txt
  3. Boa Noite, aconteceu o seguinte ele desligou sozinho duas vezes enquanto fazia o scan do rogue killer, mas consegui fazer hoje, duas horas e uns quebrados de analise. segue abaixo. RogueKiller V12.9.9.0 [Feb 27 2017] (Free) por Adlice Software mail : http://www.adlice.com/contact/ Feedback : http://forum.adlice.com Site : http://www.adlice.com/download/roguekiller/ Blog : http://www.adlice.com Sistema Operacional : Windows 10 (10.0.14393) 32 bits version Iniciou : Modo normal Usuário : Osni [Administrador] Started from : C:\Users\Osni\Desktop\RogueKiller.exe Modo : Escanear -- Data : 03/12/2017 17:51:00 (Duration : 02:24:35) ¤¤¤ Processos : 0 ¤¤¤ ¤¤¤ Registro : 1 ¤¤¤ [PUM.StartMenu] HKEY_USERS\S-1-5-21-3695658054-273983158-1288157723-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Encontrado ¤¤¤ Tarefas : 0 ¤¤¤ ¤¤¤ Arquivos : 1 ¤¤¤ [Hidden.ADS][Stream] C:\Windows\System32\drivers:GbpKmAp.lst -> Encontrado ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Arquivos de hosts : 0 ¤¤¤ ¤¤¤ Antirootkit : 1 (Driver: Carregado) ¤¤¤ [SSDT:Inl(Hook.SSDT)] ZwFlushWriteBuffer[295] : C:\Windows\System32\halmacpi.dll @ 0xffffffff8202fc80 (call dword [0x822b10a0]) ¤¤¤ Navegadores : 2 ¤¤¤ [PUM.SearchEngine][Firefox:Config] xnk8gk76.default : user_pref("browser.search.selectedEngine", ""); -> Encontrado [PUM.SearchEngine][Firefox:Config] xnk8gk76.default : user_pref("browser.search.defaultenginename", ""); -> Encontrado ¤¤¤ Verificação da MBR : ¤¤¤ +++++ PhysicalDrive0: WDC WD1200BEVS-00UST0 ATA Device +++++ --- User --- [MBR] 61539773dfeca52e733cf7b0005c00ad [BSP] 72ba4cac66d56825eac783d8c062663e : Windows Vista/7/8 MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 114020 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 1 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 233517056 | Size: 450 MB User = LL1 ... OK User = LL2 ... OK aguardo instruções Osni rogue_killer_1203.txt
  4. Boa Noite, segue conforme solicitado, 1) etapa 1 anexado arquivo fiz, ontem estava tarde desliguei depois que fiz. 2) etapa 2, segue abaixo # AdwCleaner v6.044 - Relatório criado 02/03/2017 às 19:46:36 # Atualizado em 28/02/2017 por Malwarebytes # Banco de dados : 2017-03-02.1 [Servidor] # Sistema operacional : Windows 10 Pro (X86) # Usuário : Osni - OSNI-NOTE01 # Executando de : C:\Users\Osni\Desktop\adwcleaner_6.044.exe # Modo: Limpo # Apoio : https://www.malwarebytes.com/support ***** [ Serviços ] ***** ***** [ Pastas ] ***** [-] Pasta excluída:C:\Program Files\77zip [-] Pasta excluída:C:\Program Files\Zula Games ***** [ Arquivos ] ***** [-] Arquivo excluído:C:\Users\Osni\AppData\Roaming\Mozilla\Firefox\Profiles\xnk8gk76.default\extensions\zulagames@ZulaGames.com.xpi ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Atalhos ] ***** ***** [ Atividades agendadas ] ***** ***** [ Registro ] ***** [-] Valor apagado:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{58124A0B-DC32-4180-9BFF-E0E21AE34026}] [-] Valor apagado:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}] [-] Valor apagado:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}] [-] Chave excluída:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5 [-] Chave excluída:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375 [-] Chave excluída:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18C9E3869A16248439FE3FF9EB02207A [-] Chave excluída:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D8011310B2622942868A458964FFDC5 [-] Chave excluída:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C63F7979DCC2154CB9591969A5CB89D [-] Chave excluída:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6DD31E6C1A73B334383DF186676F4D20 [-] Chave excluída:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB3204F747B20694B8D49EF92D8DC94B [-] Chave excluída:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C81E33A400B6F814E90C7A3354E2A3A5 [-] Chave excluída:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDBF68C5F16790341B7C6FD7C7F8E4FC [-] Chave excluída:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFA531D0F3A71504DA7AC6A11CE33739 ***** [ Verificando navegadores ... ] ***** [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.minibar.LayoutId" - "1" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.minibar.ROOTEXTENSION" - "chrome://iminentwebbooster/content/minibar" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.minibar.Services.BHPCode" - "01" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.minibar.Services.DefaultEvent" - "000" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.minibar.Services.DefaultWebSite" - "000" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.minibar.Services.IminentClientCode" - "11" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.minibar.Services.SmartFavCode" - "02" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.minibar.registerToolbarEvent102" - "1378682429843" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.sslminibar.LayoutId" - "1" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.sslminibar.ROOTEXTENSION" - "chrome://iminentwebbooster/content/minibar" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.sslminibar.Services.BHPCode" - "01" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.sslminibar.Services.DefaultEvent" - "000" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.sslminibar.Services.DefaultWebSite" - "000" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.sslminibar.Services.IminentClientCode" - "11" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.sslminibar.Services.SmartFavCode" - "02" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.sslminibar.ShowThankyouPixel" - "0" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.sslminibar.displayFavLinks" - "1" [-] Preferências do Firefox limpas:"iminent.webbooster.scripts.sslminibar.registerToolbarEvent105" - "1378682463185" ************************* :: Chaves "Tracing" excluídas :: Configurações Winsock restauradas ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [4769 Bytes] - [02/03/2017 19:46:36] C:\AdwCleaner\AdwCleaner[R0].txt - [18112 Bytes] - [29/09/2013 16:28:26] C:\AdwCleaner\AdwCleaner[S0].txt - [17730 Bytes] - [29/09/2013 16:29:58] C:\AdwCleaner\AdwCleaner[S1].txt - [6539 Bytes] - [02/03/2017 19:44:12] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [5063 Bytes] ########## 3) etapa 3, segue abaixo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.1 (02.11.2017) Operating System: Windows 10 Pro x86 Ran by Osni (Administrator) on 02/03/2017 at 20:50:31,91 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 1 Successfully deleted: C:\Program Files\GUT718F.tmp (File) Registry: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 02/03/2017 at 20:56:10,59 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 4) foi um sacrificio para fazer a etapa 3, o avira bloqueou, mas depois de desativar o firewal e o avira consegui fazer 5) - aguardo instruções Osni Sousa malwarebytes.txt
  5. Boa Noite, meu notebook esta com um comportamento suspeito, não abre alguns sites, desliga sozinho, e ja chegou a mostrar tela azul, Nao sei dizer se foi depois que meu filho pequeno usou ou depois de alguma atualização do windows 10. Se voces puderem me ajudar agradeço. segue postagem dos relatorios FSS.txt MbrScan.log ZA-Scan.txt
  6. Sim, ficou ate mais facil o banco criou um tipo um aplicativo que abre direto, antes eu não conseguia instalar ele, agora depois que você me instruiu e limpamos a maquina esta funcionando certinho. obrigado pela ajuda, abs Osni.
  7. Boa Noite, eu tentei, mas nao consegui. entao procurando no site do itau, encontrei uma versão que voce instala direto na maquina. instalei esta versão. att Osni
  8. Oi boa noite, então, meu banco é o itau, eu não consigo instalar o programa de segurança no chrome, já desisntalou o antigo e não instala o novo, dá umas mensagens de erro, que vou anexar para você e quem sabe você já viu e pode me dar uma idéia de como corrigir. obrigado. Osni.
  9. OI boa noite, Então fiz os testes, embora nao tenha conseguido colocar aquela regra percebi que a maquinha nao abre mais a pagina falsa, pelo internet explorer ela abre com o programa de segurança instalado, no chrome diz que o programa nao esta instalado, mas tem o "S" no https:/, e no edge nem tentei foi de lá que arrumei toda essa dor de cabeça. Se pelas suas analises me disser que a maquina esta limpa podemos dar por finalizado. obrigado por tudo, fico no aguardo Osni.
  10. Oi, boa noite, desculpa não sei fazer isso não, pode me explicar Osni.
  11. Boa Noite, depois que voce começou a me orientar, nunca mais tentei acessar a pagina do banco. hoje eu tentei abrir o site, pelo chrome abriu mas nao instala o programa de segurança. Pelo internet explorer tambem abriu e instalou o programa de segurança. O edge nem abre mais para qualquer coisa abre uma pagina azul e depois fecha sozinho, sem dar tempo de digitar qualquer coisa. Amanhã vou ligar no banco e pedir para liberar o acesso, informando que a maquina ta limpa. Ah percebi que o AVIRA da uma mensagem toda vez que entro no banco de bloqueio, apareceu com o chrome e como internet explorer. vou anexar, o que voce me diz a maquina ta limpa? Osni
  12. Boa Noite, foi necessário, desativar o avira e o windows defender, ambos acusaram o programa como vírus e removeram para a lixeira. segue log SecurityCheck by glax24 & Severnyj v.1.4.0.34 [18.01.16] WebSite: www.safezone.cc DateLog: 18.01.2016 19:40:53 Path starting: C:\Users\OSNI\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe Log directory: C:\SecurityCheck\ IsAdmin: True User: OSNI VersionXML: 2.30i-18.01.2016 ___________________________________________________________________________ Windows 10(6.3.10586) (x86) Professional Lang: Portuguese(0416) Installation date OS: 15.12.2015 06:35:06 LicenseStatus: Windows®, Professional edition The machine is permanently activated. Boot Mode: Normal Default Browser: C:\WINDOWS\system32\LaunchWinApp.exe SystemDrive: C: FS: [NTFS] Capacity: [74 Gb] Used: [38.2 Gb] Free: [35.8 Gb] ------------------------------- [ Windows ] ------------------------------- Internet Explorer 11.63.10586.0 [+] User Account Control enabled Automatic download and scheduled installation Windows Update (wuauserv) - The service is running Central de Segurança (wscsvc) - The service is running Registro remoto (RemoteRegistry) - The service has stopped ---------------------------- [ Antivirus_WMI ] ---------------------------- Avira Antivirus (disabled and up to date) Windows Defender (disabled) --------------------------- [ FirewallWindows ] --------------------------- Firewall do Windows (MpsSvc) - The service is running --------------------------- [ AntiSpyware_WMI ] --------------------------- Avira Antivirus (disabled and up to date) Windows Defender (disabled) ---------------------- [ AntiVirusFirewallInstall ] ----------------------- Avira Antivirus v.15.0.15.129 ESET Online Scanner v3 Avira Launcher v.1.1.53.13962 -------------------------- [ SecurityUtilities ] -------------------------- Malwarebytes Anti-Malware versão 2.2.0.1024 v.2.2.0.1024 --------------------------- [ OtherUtilities ] ---------------------------- Arquivo do WinRAR Microsoft Silverlight v.5.1.41212.0 --------------------------------- [ P2P ] --------------------------------- µTorrent v.3.4.5.41372 Warning! P2P-client. -------------------------------- [ Java ] --------------------------------- Java 8 Update 66 v.8.0.660.18 ------------------------------- [ Browser ] ------------------------------- Google Chrome v.47.0.2526.111 --------------------------- [ RunningProcess ] ---------------------------- C:\Users\OSNI\AppData\Local\Google\Chrome\Application\chrome.exe v.47.0.2526.111 sched.exe avguard.exe avshadow.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe v.15.0.15.106 C:\Program Files\Malwarebytes Anti-Malware\mbam.exe v.2.3.125.0 mbamscheduler.exe mbamservice.exe MsMpEng.exe MpCmdRun.exe C:\Program Files\Windows Defender\MSASCui.exe v.4.9.10586.0 ----------------------------- [ End of Log ] ------------------------------ Tenho uma pergunta, uma versão que tinha instalado do photoshop parou de funcionar, é normal. aguardo instruções. Osni
  13. Boa Noite, 1) o Button Manager, é um programa que veio com o scaner, eu uso toda vez que vou escanear alguma folha. 2) - segue o texto do fixlog. Resultado da Correção pela Farbar Recovery Scan Tool (x86) Versão:10-01-2015 01 Executado por OSNI (2016-01-17 19:16:23) Run:1 Executando a partir de C:\Users\OSNI\Desktop Perfis Carregados: OSNI (Perfis Disponíveis: OSNI) Modo da Inicialização: Normal ============================================== fixlist Conteúdo: ***************** start CreateRestorePoint: Task: {03393D14-3EE8-48AE-83D5-30331CA928B9} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> Nenhum Arquivo <==== ATENÇÃO Task: {11AA6B9D-ED49-4A66-9E7F-C3FB6D7F5C25} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> Nenhum Arquivo <==== ATENÇÃO Task: {55A2B2D6-78CB-4A22-9CF0-9E470914C162} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> Nenhum Arquivo <==== ATENÇÃO Task: {59DE7A9A-BD47-4FFB-95D0-DFC8DC2AD0AD} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> Nenhum Arquivo <==== ATENÇÃO Task: {712D0D0D-EC32-4394-8545-6E23F2C30E26} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> Nenhum Arquivo <==== ATENÇÃO Task: {71574D20-2F63-492B-9E9B-81D9B5216344} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> Nenhum Arquivo <==== ATENÇÃO Task: {7B423833-DC28-4B90-B8C9-C00D32385D8D} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> Nenhum Arquivo <==== ATENÇÃO Task: {7F5354D5-00FC-45C1-B211-CD0C54931CDB} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> Nenhum Arquivo <==== ATENÇÃO Task: {8A987C26-6CBD-4D31-8880-213AD4487602} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> Nenhum Arquivo <==== ATENÇÃO Task: {B5DB1ADE-D3FC-480E-981F-8F7B1FA15C04} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> Nenhum Arquivo <==== ATENÇÃO Task: {BD2EC824-B3A9-44CD-929B-236E5778F1B6} - \Run_Bobby_Browser -> Nenhum Arquivo <==== ATENÇÃO Task: {F6FB1665-9A14-4FB3-B181-28F600AFF565} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> Nenhum Arquivo <==== ATENÇÃO FirewallRules: [{15E0DBEB-5389-4F4F-A855-1872150CA325}] => (Allow) C:\Program Files\YourFileDownloader\YourFileDownloader.exe FirewallRules: [{A40EBE13-EBC7-4144-8311-6B6CFAE2AD24}] => (Allow) C:\Program Files\YourFileDownloader\YourFileDownloader.exe FirewallRules: [{46B8FA5C-61CD-47F8-B177-713A134020AC}] => (Allow) C:\Program Files\YourFileDownloader\Downloader.exe FirewallRules: [{D082D5CC-4AA2-4261-B8A5-739E09191931}] => (Allow) C:\Program Files\YourFileDownloader\Downloader.exe C:\Program Files\YourFileDownloader cmd: ipconfig /flushdns EmptyTemp: end ***************** Ponto de Restauração criado com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{03393D14-3EE8-48AE-83D5-30331CA928B9}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03393D14-3EE8-48AE-83D5-30331CA928B9}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{11AA6B9D-ED49-4A66-9E7F-C3FB6D7F5C25}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11AA6B9D-ED49-4A66-9E7F-C3FB6D7F5C25}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{55A2B2D6-78CB-4A22-9CF0-9E470914C162}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55A2B2D6-78CB-4A22-9CF0-9E470914C162}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{59DE7A9A-BD47-4FFB-95D0-DFC8DC2AD0AD}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{59DE7A9A-BD47-4FFB-95D0-DFC8DC2AD0AD}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{712D0D0D-EC32-4394-8545-6E23F2C30E26}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{712D0D0D-EC32-4394-8545-6E23F2C30E26}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{71574D20-2F63-492B-9E9B-81D9B5216344}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{71574D20-2F63-492B-9E9B-81D9B5216344}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7B423833-DC28-4B90-B8C9-C00D32385D8D}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7B423833-DC28-4B90-B8C9-C00D32385D8D}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7F5354D5-00FC-45C1-B211-CD0C54931CDB}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7F5354D5-00FC-45C1-B211-CD0C54931CDB}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8A987C26-6CBD-4D31-8880-213AD4487602}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A987C26-6CBD-4D31-8880-213AD4487602}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B5DB1ADE-D3FC-480E-981F-8F7B1FA15C04}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5DB1ADE-D3FC-480E-981F-8F7B1FA15C04}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD2EC824-B3A9-44CD-929B-236E5778F1B6}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD2EC824-B3A9-44CD-929B-236E5778F1B6}" => chave removido (a) com sucesso. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Run_Bobby_Browser => chave não encontrado (a). "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F6FB1665-9A14-4FB3-B181-28F600AFF565}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F6FB1665-9A14-4FB3-B181-28F600AFF565}" => chave removido (a) com sucesso. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => chave removido (a) com sucesso. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{15E0DBEB-5389-4F4F-A855-1872150CA325} => valor removido (a) com sucesso. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A40EBE13-EBC7-4144-8311-6B6CFAE2AD24} => valor removido (a) com sucesso. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{46B8FA5C-61CD-47F8-B177-713A134020AC} => valor removido (a) com sucesso. HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D082D5CC-4AA2-4261-B8A5-739E09191931} => valor removido (a) com sucesso. "C:\Program Files\YourFileDownloader" => não encontrado (a). ========= ipconfig /flushdns ========= Configura��o de IP do Windows Libera��o do Cache do DNS Resolver bem-sucedida. ========= Fim de CMD: ========= EmptyTemp: => 711 MB de dados temporários Removidos. O sistema precisou ser reiniciado. ==== Fim de Fixlog 19:19:45 ==== obrigado, aguardo instruções Osni.
  14. Boa Noite, fiz 3 tentativas e ele não aceitou colar o texto. segue anexado obrigado Osni ps.; aguardo novas instruções FRST.txt Addition.txt
  15. boa noite, segue conforme solicitado. ZA-Scan V1.0.0.5 Updated 31-December-2015 Tool run by OSNI on 14/01/2016 at 20:57:43,07. Microsoft Windows 10 Pro 10.0.10586 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Users\OSNI\Downloads\ZaScan\ZA-Scan.exe Script used: C:\Users\OSNI\Downloads\ZaScan\zascript.txt ==== System Restore Info ====================== ==== Empty Folders Check ====================== C:\Program Files\uTorrent deleted successfully C:\PROGRA~2\boost_interprocess deleted successfully C:\PROGRA~2\Comms deleted successfully C:\PROGRA~2\ISIS Drivers deleted successfully C:\PROGRA~2\SoftwareDistribution deleted successfully C:\Users\OSNI\AppData\Local\ActiveSync deleted successfully C:\Users\OSNI\AppData\Local\EmieBrowserModeList deleted successfully C:\Users\OSNI\AppData\Local\EmieSiteList deleted successfully C:\Users\OSNI\AppData\Local\EmieUserList deleted successfully C:\Users\OSNI\AppData\Local\Opera Software deleted successfully C:\Users\OSNI\AppData\Local\PeerDistRepub deleted successfully C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Maps deleted successfully C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\PeerDistPub deleted successfully C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\PeerDistRepub deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== FireFox Fix ====================== Deleted from C:\Users\OSNI\AppData\Roaming\Mozilla\Firefox\Profiles\mLoC7IxE.default\prefs.js: Added to C:\Users\OSNI\AppData\Roaming\Mozilla\Firefox\Profiles\mLoC7IxE.default\prefs.js: user_pref("browser.startup.homepage", "about:home"); user_pref("browser.newtab.url", "about:newtab"); ==== Deleting Files \ Folders ====================== C:\Program Files\uTorrent not found C:\Program Files\Arquivos Comuns deleted C:\Users\OSNI\AppData\Local\Aplicativo Itau deleted C:\PROGRA~2\Package Cache deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted C:\WINDOWS\system32\GroupPolicy\Machine deleted C:\WINDOWS\system32\GroupPolicy\User deleted C:\WINDOWS\system32\GroupPolicy\gpt.ini deleted C:\Users\OSNI\AppData\Roaming\Mozilla\Firefox\Profiles\mLoC7IxE.default\extensions\abs@avira.com deleted ==== Firefox Start and Search pages ====================== ProfilePath: C:\Users\OSNI\AppData\Roaming\Mozilla\Firefox\Profiles\mLoC7IxE.default user_pref("browser.startup.homepage", "about:home"); user_pref("browser.newtab.url", "about:newtab"); ==== Firefox Extensions Registry ====================== [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "web2pdfextension@web2pdf.adobedotcom"="C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn" [15/04/2015 22:04] ==== Firefox Extensions ====================== ==== Firefox Plugins ====================== ==== Chromium Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions efaidnbmnnnibpcajpcglclefindmkaj - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx[03/12/2014 04:31] flliilndjeohchalpbbcdekjklbdgfkk - No path found[] ==== Chromium Fix ====================== C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_shopping.uol.com.br_0.localstorage deleted successfully C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_shopping.uol.com.br_0.localstorage-journal deleted successfully C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ads1.msads.net_0.localstorage deleted successfully C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_ads1.msads.net_0.localstorage-journal deleted successfully C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage deleted successfully C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_c.betrad.com_0.localstorage-journal deleted successfully C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage deleted successfully C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal deleted successfully ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04 ==== Reset Google Chrome ====================== C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully ==== shortcuts on Users Desktops ====================== C:\Users\OSNI\Desktop\audacity.exe - Atalho.lnk - C:\Program Files\Audacity\audacity.exe C:\Users\OSNI\Desktop\Button Manager.lnk - C:\Program Files\Avision\Button Manager\ButtonManager.exe /gogoscan C:\Users\OSNI\Desktop\Dropbox.lnk - C:\Users\OSNI\AppData\Roaming\Dropbox\bin\Dropbox.exe /home C:\Users\OSNI\Desktop\Google Chrome.lnk - C:\Users\OSNI\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\OSNI\Desktop\IRPF2015 - Declaração de Ajuste Anual, Final de Espólio e Saída Definitiva do País.lnk - C:\Users\OSNI\Desktop\Itaú.lnk - C:\Users\OSNI\Desktop\Microsoft Office Access 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe C:\Users\OSNI\Desktop\Microsoft Office Excel 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe C:\Users\OSNI\Desktop\Nero Burning ROM.lnk - C:\Windows\Installer\{B3756FCF-13D3-460B-88D5-33CB88CE6CFA}\ARPPRODUCTICON.exe C:\Users\OSNI\Desktop\Samsung Drive Manager.lnk - C:\Program Files\Clarus\Samsung Drive Manager\Drive Manager.exe C:\Users\OSNI\Desktop\Samsung Link Osni.sousa@hotmail.com.lnk - C:\Users\OSNI\Samsung Link\Osni.sousa@hotmail.com C:\Users\OSNI\Desktop\Voobys.lnk - C:\Users\OSNI\Desktop\µTorrent.lnk - ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk - C:\Program Files\Adobe\Acrobat 11.0\Acrobat\Acrobat.exe C:\Users\Public\Desktop\Adobe Application Manager.lnk - C:\Program Files\Common Files\Adobe\OOBE\PDApp\core\PDapp.exe --appletID=CCM_UI --appletVersion=1.0 --workflow=CCM_workflow_launch C:\Users\Public\Desktop\Adobe FormsCentral.lnk - C:\Program Files\Adobe\Acrobat 11.0\FormsCentral\FormsCentralForAcrobat.exe C:\Users\Public\Desktop\Avira Launcher.lnk - C:\Program Files\Avira\Launcher\Avira.Systray.exe /showMiniGui C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk - C:\Program Files\Malwarebytes Anti-Malware\mbam.exe C:\Users\Public\Desktop\Nero 2015.lnk - C:\Windows\Installer\{9D780839-6E97-4E2A-A5F7-711AF221B609}\NeroLauncher.ex_06255901E67449719980557FAA5EC1C6.exe C:\Users\Public\Desktop\Presto PageManager 7.16.lnk - C:\Users\Public\Desktop\Readiris Pro 11.lnk - C:\Program Files\Readiris Pro 11 HP\readiris.exe C:\Users\Public\Desktop\µTorrent.lnk - ==== shortcuts in Users Start Menu ====================== C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk - C:\WINDOWS\system32\magnify.exe C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk - C:\WINDOWS\system32\narrator.exe C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk - C:\WINDOWS\system32\osk.exe C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk - C:\WINDOWS\system32\notepad.exe C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk - C:\WINDOWS\system32\cmd.exe C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk - page=SettingsPageAppsDefaults C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk - page=SettingsPagePCSystemDevices C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk - C:\WINDOWS\system32\magnify.exe C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk - C:\WINDOWS\system32\narrator.exe C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk - C:\WINDOWS\system32\osk.exe C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk - C:\WINDOWS\system32\notepad.exe C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk - C:\WINDOWS\system32\cmd.exe C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk - page=SettingsPageAppsDefaults C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk - page=SettingsPagePCSystemDevices C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk - C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk - C:\Users\OSNI\AppData\Local\Microsoft\OneDrive\OneDrive.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk - C:\WINDOWS\system32\magnify.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk - C:\WINDOWS\system32\narrator.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk - C:\WINDOWS\system32\osk.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk - C:\WINDOWS\system32\notepad.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicativo Itaú\Desinstalador.lnk - C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicativo Itaú\Itaú.lnk - C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox.lnk - C:\Users\OSNI\AppData\Roaming\Dropbox\bin\Dropbox.exe /home C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Users\OSNI\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk - C:\Users\OSNI\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk - C:\WINDOWS\system32\cmd.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk - C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk - C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk - page=SettingsPageAppsDefaults C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk - page=SettingsPagePCSystemDevices C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk - C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk - C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell ISE.lnk - C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell_ISE.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe C:\Users\USURIO~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk - C:\WINDOWS\system32\magnify.exe C:\Users\USURIO~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk - C:\WINDOWS\system32\narrator.exe C:\Users\USURIO~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\On-Screen Keyboard.lnk - C:\WINDOWS\system32\osk.exe C:\Users\USURIO~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk - C:\WINDOWS\system32\notepad.exe C:\Users\USURIO~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Command Prompt.lnk - C:\WINDOWS\system32\cmd.exe C:\Users\USURIO~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\computer.lnk - C:\Users\USURIO~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk - C:\Users\USURIO~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Default Apps.lnk - page=SettingsPageAppsDefaults C:\Users\USURIO~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Devices.lnk - page=SettingsPagePCSystemDevices C:\Users\USURIO~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\File Explorer.lnk - C:\Users\USURIO~1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Run.lnk - ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk - C:\Program Files\Common Files\Adobe\OOBE\PDApp\core\PDapp.exe --appletID=CCM_UI --appletVersion=1.0 --workflow=CCM_workflow_launch C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk - C:\Program Files\Adobe\Adobe Bridge CS6\Bridge.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk - C:\Program Files\Adobe\Adobe Utilities - CS6\ExtendScript Toolkit CS6\ExtendScript Toolkit.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk - C:\Program Files\Adobe\Adobe Extension Manager CS6\Adobe Extension Manager CS6.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS6.lnk - C:\Program Files\Adobe\Adobe Photoshop CS6\Photoshop.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devices Flow.lnk - C:\WINDOWS\DevicesFlow\DevicesFlow.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk - C:\WINDOWS\System32\Control.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk - C:\WINDOWS\MiracastView\MiracastView.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk - C:\WINDOWS\PrintDialog\PrintDialog.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk - C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility\Speech Recognition.lnk - C:\WINDOWS\Speech\Common\sapisvr.exe -SpeechUX C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk - C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk - C:\WINDOWS\system32\mspaint.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk - C:\WINDOWS\system32\mstsc.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk - C:\WINDOWS\system32\SnippingTool.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Steps Recorder.lnk - C:\WINDOWS\system32\psr.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk - C:\WINDOWS\system32\StikyNot.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Fax and Scan.lnk - C:\WINDOWS\system32\WFS.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Media Player.lnk - C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk - C:\Program Files\Windows NT\Accessories\wordpad.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\XPS Viewer.lnk - C:\WINDOWS\system32\xpsrchvw.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk - C:\WINDOWS\system32\charmap.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Windows Journal.lnk - C:\Program Files\Windows Journal\Journal.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk - C:\WINDOWS\system32\comexp.msc C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk - C:\WINDOWS\system32\compmgmt.msc /s C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\dfrgui.lnk - C:\WINDOWS\system32\dfrgui.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Disk Cleanup.lnk - C:\WINDOWS\system32\cleanmgr.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk - C:\WINDOWS\system32\eventvwr.msc /s C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk - C:\WINDOWS\system32\iscsicpl.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk - C:\WINDOWS\system32\MdSched.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\ODBC Data Sources.lnk - C:\WINDOWS\system32\odbcad32.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk - C:\WINDOWS\system32\perfmon.msc /s C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk - C:\WINDOWS\system32\printmanagement.msc C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Resource Monitor.lnk - C:\WINDOWS\system32\perfmon.exe /res C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk - C:\WINDOWS\system32\secpol.msc /s C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk - C:\WINDOWS\system32\services.msc C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk - C:\WINDOWS\system32\msconfig.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Information.lnk - C:\WINDOWS\system32\msinfo32.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk - C:\WINDOWS\system32\taskschd.msc /s C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk - C:\WINDOWS\system32\WF.msc C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Avira Launcher.lnk - C:\Program Files\Avira\Launcher\Avira.Systray.exe /showMiniGui C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Antivirus\Ajuda do Avira Antivirus.lnk - C:\Program Files\Avira\AntiVir Desktop\57\avwin.chm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Antivirus\Avira na Internet.lnk - C:\Program Files\Avira\AntiVir Desktop\weblink.url C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira\Antivirus\Iniciar Avira Antivirus.lnk - C:\Program Files\Avira\AntiVir Desktop\avcenter.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configurar Java.lnk - C:\Program Files\Java\jre1.8.0_66\bin\javacpl.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Obter Ajuda.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Sobre o Java.lnk - C:\Program Files\Java\jre1.8.0_66\bin\javacpl.exe -tab about C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Verificar Atualizações.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visite Java.com.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Desinstalar Malwarebytes Anti-Malware.lnk - C:\Program Files\Malwarebytes Anti-Malware\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware Notifications.lnk - C:\Program Files\Malwarebytes Anti-Malware\mbam.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Program Files\Malwarebytes Anti-Malware\mbam.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Application Compatibility Toolkit\Application Compatibility Manager.lnk - C:\Program Files\Microsoft Application Compatibility Toolkit\Application Compatibility Manager\ACM.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Application Compatibility Toolkit\Compatibility Administrator (32-bit).lnk - C:\WINDOWS\Installer\{0F5AEBB0-43F3-4571-ACE7-A7942E8AA179}\Compatadmin.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Application Compatibility Toolkit\Demo Application\Stock Viewer.lnk - C:\Program Files\Microsoft Application Compatibility Toolkit\Compatibility Administrator (32-bit)\Demo Application\StockViewer\StockViewer.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Application Compatibility Toolkit\Developer and Tester Tools\Internet Explorer Compatibility Test Tool.lnk - C:\WINDOWS\Installer\{0F5AEBB0-43F3-4571-ACE7-A7942E8AA179}\testtool.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Application Compatibility Toolkit\Developer and Tester Tools\Standard User Analyzer Wizard.lnk - C:\WINDOWS\Installer\{0F5AEBB0-43F3-4571-ACE7-A7942E8AA179}\SUAnalyzerIcon.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Application Compatibility Toolkit\Developer and Tester Tools\Standard User Analyzer.lnk - C:\WINDOWS\Installer\{0F5AEBB0-43F3-4571-ACE7-A7942E8AA179}\SUAnalyzerIcon.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk - C:\Program Files\Microsoft Silverlight\5.1.41212.0\Silverlight.Configuration.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Default Programs.lnk - C:\WINDOWS\system32\control.exe /name Microsoft.DefaultPrograms C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Task Manager.lnk - C:\WINDOWS\system32\taskmgr.exe /7 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools\Windows Defender.lnk - C:\Program Files\Windows Defender\MSASCui.exe ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\OSNI\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Aimersoft Video Converter Ultimate.lnk - C:\Program Files\Aimersoft\Video Converter Ultimate\VideoConverterUltimate.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Users\OSNI\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files\Internet Explorer\iexplore.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk - C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE /recycle C:\Users\OSNI\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\OSNI\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\OSNI\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft Office Word 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk - C:\Users\OSNI\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Users\OSNI\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Office Outlook 2007.lnk - C:\Windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe C:\Users\OSNI\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files\Windows Media Player\wmplayer.exe /prefetch:1 C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - ==== Empty IE Cache ====================== C:\Users\Default\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\OSNI\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\OSNI\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\OSNI\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\OSNI\AppData\Local\Microsoft\Windows\INetCache\IE\XXDJ1MVV will be deleted at reboot ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\OSNI\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== Java Cache cleared successfully ==== Empty Temp Folders ====================== C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\OSNI\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== Deleting Files / Folders ====================== "C:\Users\OSNI\AppData\Local\Microsoft\Windows\INetCache\IE\XXDJ1MVV" deleted ==== EOF on 14/01/2016 at 21:33:54,63 ====================== aguardo instruçoes Osni