Ir para conteúdo

Foto

paginas do IE abrem sozinhas com propaganda


Este tópico foi arquivado. Isto significa que você não pode mais responder ao tópico.
13 respostas neste tópico

#1
nonona

nonona

    Novato

  • Novato
  • Pip
  • 13 posts
Algumas páginas de propaganda abrem sozinha durante a navegação, segue os logs de acordo com o tutorial. Apesar de ter gerado o log no MbrScan, o tamanho dele ficou em 44,8 kb, assim na hora de anexá-lo não foi permitido dizendo que o arquivo é muito grande para fazer upload. porém o log tá gerado aqui, se necessário ou se tiver uma forma alternativa de encaminhá-lo. Desde já agradeço o serviço prestado por este fórum que é feito de maneira gratuita através do empenho de diversos voluntários.

Arquivo(s) anexado(s)



#2
Ciro-Mota

Ciro-Mota

    Assistente Profissional

  • Assistente Profissional
  • 52.955 posts
nonona,

NÃO tente realizar sozinho nenhum procedimento de limpeza. Em especial, não execute por conta própria ferramentas utilizadas no fórum Remoção de Malware. O uso indevido de algumas ferramentas poderá danificar o seu computador ou, no mínimo, remover parcialmente os sinais de uma infecção que serviriam de informação ao analista. A equipe não será responsabilizada por consequências resultantes de uso indevido e/ou não-informado das ferramentas. - Regra nº8 da Remoção de Malwares

Poste um novo log do Hijackthis.

Por favor, observe o seguinte:

  • Não utilize softwares que não foram indicado.
  • Não inicie novo tópico sobre esse problema. Poste suas respostas sempre neste tópico.
  • As análises podem levar algum tempo, portanto seja paciente.
  • As instruções são específicas para o seu computador, e devem ser aplicadas somente nele.
  • Se algo der errado, não importa. Sempre acompanhe seu tópico, informando-me dos resultados, até que seu computador esteja limpo.
  • Aviso: Evite utilizar as tags <QUOTE> ou <CODE> nos logs, isso prejudica a leitura na hora da analise.
  • Por favor, não abandone seu tópico. Para nós é importante saber se a remoção foi bem sucedida.
  • Se você não receber uma resposta minha em até 5 dias. Me envie uma Mensagem Privada (MP)

**Tenha consideração a quem te ajuda, não Abandone seu tópico!**
[Membro da ASAP] // [Junte-se ao ARIS-LD] // [Linha Defensiva no Twitter]
Imagem Postada

Blog do Ciro Mota
Visite em: http://www.ciromota.net/

#3
nonona

nonona

    Novato

  • Novato
  • Pip
  • 13 posts
não consegui anexar o arquivo por isso estou colocando no corpo da mensagem
Logfile of HijackThis v1.99.1
Scan saved at 23:29:10, on 16/04/2013
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Running processes:
C:\ProgramData\Browser Manager\2.6.1125.80\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Windows\PixArt\PAC7302\Monitor.exe
C:\Users\Nona\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65brmon.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbserver.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\CrExtP65.exe
C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\CrExtP65.exe
C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\CrExtP65.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\Nona\Desktop\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incre...om?a=DgW6N6V7AP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft..../?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft..../?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: IncrediMail MediaBar Portugues 2 Toolbar - {140afdc9-061f-4b86-8c58-42994309768f} - C:\Program Files (x86)\IncrediMail_MediaBar_Portugues_2\prxtbInc0.dll
R3 - URLSearchHook: (no name) - {4c60e5ab-5c68-4c59-abaa-885010b24b32} - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65SrcAs.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: IncrediMail MediaBar Portugues 2 - {140afdc9-061f-4b86-8c58-42994309768f} - C:\Program Files (x86)\IncrediMail_MediaBar_Portugues_2\prxtbInc0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: IB Updater Helper - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\IB Updater\Extension32.dll
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll
O2 - BHO: FindLyrics - {44C9CC91-6A4A-4579-B4B5-899ECDC18DC6} - C:\Program Files (x86)\FindLyrics\FindLyrics.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Funmoods Helper Object - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\PROGRA~2\Funmoods\1.5.23.22\bh\escort.dll (file missing)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Auxiliar de Conexão do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Toolbar BHO - {a235e1e3-6296-4710-af39-104a7faa6c7c} - C:\PROGRA~2\FROMDO~2\bar\1.bin\65bar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Program Files (x86)\GbPlugin\gbieh.dll
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Program Files (x86)\GbPlugin\gbiehcef.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: DealPly - {EF7BD87A-8024-11E2-F316-F3E56188709B} - C:\Program Files (x86)\DealPly\DealPlyIE.dll
O2 - BHO: Search Assistant BHO - {f236ca79-3123-4afb-9f74-e98117ad5625} - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65SrcAs.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: IncrediMail MediaBar Portugues 2 Toolbar - {140afdc9-061f-4b86-8c58-42994309768f} - C:\Program Files (x86)\IncrediMail_MediaBar_Portugues_2\prxtbInc0.dll
O3 - Toolbar: Funmoods Toolbar - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\PROGRA~2\Funmoods\1.5.23.22\escorTlbr.dll (file missing)
O3 - Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - (no file)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: FromDocToPDF - {c66a678d-5e6c-4af9-8f57-c6192f42cf74} - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65bar.dll
O3 - Toolbar: PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
O4 - HKLM\..\Run: [Firebird] C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbguard.exe -a
O4 - HKLM\..\Run: [FromDocToPDF Search Scope Monitor] "C:\PROGRA~2\FROMDO~2\bar\1.bin\65srchmn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [FromDocToPDF_65 Browser Plugin Loader] C:\PROGRA~2\FROMDO~2\bar\1.bin\65brmon.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [SDP] C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe /auto
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\Nona\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Nona\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&nviar para o OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: E&nviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Notas Ligadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Notas Ligadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Exibir ou ocultar HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O11 - Options group: [INTERNATIONAL] International
O13 - Gopher Prefix:
O15 - Trusted Zone: imagem.caixa.gov.br
O15 - Trusted Zone: internetbanking.caixa.gov.br
O15 - Trusted Zone: www.caixa.gov.br
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus....ek_sys_ctrl.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.h...pdetect119b.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logme...trl.cab?lmi=972
O17 - HKLM\System\CCS\Services\Tcpip\..\{6485388D-118F-4B51-BC86-7DBA1E566B16}: NameServer = 200.204.0.10 200.204.0.138
O17 - HKLM\System\CS1\Services\Tcpip\..\{6485388D-118F-4B51-BC86-7DBA1E566B16}: NameServer = 200.204.0.10 200.204.0.138
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (file missing)
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - c:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\progra~3\browse~1\261125~1.80\{16cdf~1\browse~1.dll
O20 - Winlogon Notify: GbPluginBb - C:\Program Files (x86)\GbPlugin\gbieh.dll
O20 - Winlogon Notify: GbPluginCef - C:\Program Files (x86)\GbPlugin\gbiehCef.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Browser Manager - Unknown owner - C:\ProgramData\Browser Manager\2.6.1125.80\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FromDocToPDFService (FromDocToPDF_65Service) - COMPANYVERS_NAME - C:\PROGRA~2\FROMDO~2\bar\1.bin\65barsvc.exe
O23 - Service: Gbp Service (GbpSv) - GAS Tecnologia - C:\PROGRA~2\GbPlugin\GbpSv.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc (file missing)
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)
O23 - Service: IB Updater - Unknown owner - C:\Program Files\IB Updater\ExtensionUpdaterService.exe
O23 - Service: Updater Service (IBUpdaterService) - Unknown owner - C:\ProgramData\IBUpdaterService\ibsvc.exe" /SERVICE (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Microsoft SharePoint Workspace Audit Service - Unknown owner - C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" /auditservice (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PDF Architect Helper Service - pdfforge GbR - C:\Program Files (x86)\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GbR - C:\Program Files (x86)\PDF Architect\ConversionService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

#4
Ciro-Mota

Ciro-Mota

    Assistente Profissional

  • Assistente Profissional
  • 52.955 posts
nonona,

1)

Baixe o AdwCleaner e salve no desktop.
http://general-chang...de/2-adwcleaner

Execute o arquivo adwcleaner.exe

*** Usuários do Windows Vista ou Windows 7 clique com o direito sobre o arquivo adwcleaner.exe, depois clique em Imagem Postada.

Clique em Remover.

Abrirá um bloco de notas com o resultado. Selecione, copie e cole o seu conteúdo na próxima resposta.

2)

Desative temporariamente seu antivirus, antispywares e firewall, para não causar conflitos.

Baixe Imagem Postada e salve no desktop.

Dê um duplo-clique para executar o Junkware Removal Tool (JRT).

*** Usuários do Windows Vista ou Windows 7 Clique com o direito sobre o arquivo JRT.exe, depois clique em Imagem Postada.

A ferramenta comecará o exame do seu sistema. Tenha paciência pois pode demorar um pouco dependendo da quantidades de ítens a examinar.

Ao final, um log se abrirá. É salvo no desktop com o nome de JRT.txt.

Selecione, copie e cole o conteúdo deste log na sua próxima resposta.

3)

Baixe o Malwarebytes' Anti-Malware (MBAM)
http://download.cnet...4-10804572.html

Dê um duplo-clique no mbam-setup.exe, escolha a linguagem e na instalação, aceite todas as opções padrão.
  • Verifique se as caixas Atualizar Malwarebytes Anti-Malware e Executar Malwarebytes Anti-Malware estão marcadas e clique então, em Concluir.
  • Se houver atualizações a serem feitas, serão baixadas e instaladas.
  • Ao final da atualização, com o programa aberto, marque Verificação Rápida e clique no botão Verificar.
  • Começará então o exame. Aguarde, pois pode demorar.
  • Ao acabar o exame, clique em OK, depois no botão Mostrar Resultados para ver o relatório.
  • Se houver ítens encontrados, certifique-se de que, estão todos marcados e clique no botão Remover.
  • Ao final da desinfecção, abrirá o Bloco de notas com um log e poderá aparecer um aviso se quer reiniciar o PC. (Ver Nota abaixo)
  • O log é automaticamente salvo pelo MBAM e para vê-lo, clique na aba Logs na janela principal do programa.
  • Selecione, copie e cole todo o conteúdo deste log na sua próxima resposta, juntamente com um novo log do HijackThis.
NOTA: Se o MBAM encontrar arquivos que não consiga remover, poderá ter de reiniciar o PC (talvez mais de uma vez). Faça isso imediatamente, ao ser perguntado se quer reiniciar o PC.

Em caso de dúvidas, leia o tutorial do programa:
http://linhadefensiv...showtopic=75554
**Tenha consideração a quem te ajuda, não Abandone seu tópico!**
[Membro da ASAP] // [Junte-se ao ARIS-LD] // [Linha Defensiva no Twitter]
Imagem Postada

Blog do Ciro Mota
Visite em: http://www.ciromota.net/

#5
nonona

nonona

    Novato

  • Novato
  • Pip
  • 13 posts
# AdwCleaner v2.200 - Relatório criado em 17/04/2013 às 16:22:33
# Atualizado em 02/04/2013 por Xplode
# Sistema Operacional : Windows 7 Ultimate Service Pack 1 (64 bits)
# Usuário : Nona - NONA-PC
# Modo de Boot : Normal
# Executado de : C:\Users\Nona\Desktop\adwcleaner.exe
# Opção [Remover]

***** [Serviços] *****
Encerrado & Removido : Browser Manager
Encerrado & Removido : IB Updater
Encerrado & Removido : IBUpdaterService
***** [Arquivos/Pastas] *****
Arquivo Removido : C:\END
Arquivo Removido : C:\user.js
Arquivo Removido : C:\Users\Nona\AppData\Local\funmoods.crx
Arquivo Removido : C:\Users\Nona\AppData\Local\funmoods-speeddial.crx
Arquivo Removido : C:\Users\Nona\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
Arquivo Removido : C:\Users\Nona\AppData\Roaming\Mozilla\Firefox\Profiles\qfba875t.default\bprotector_extensions.sqlite
Pasta Removido : C:\Program Files (x86)\Conduit
Pasta Removido : C:\Program Files (x86)\DealPly
Pasta Removido : C:\Program Files (x86)\file scout
Pasta Removido : C:\Program Files (x86)\FilesFrog Update Checker
Pasta Removido : C:\Program Files (x86)\IncrediMail_MediaBar_Portugues_2
Pasta Removido : C:\Program Files (x86)\Perion
Pasta Removido : C:\Program Files\IB Updater
Pasta Removido : C:\ProgramData\Ask
Pasta Removido : C:\ProgramData\Babylon
Pasta Removido : C:\ProgramData\IBUpdaterService
Pasta Removido : C:\Users\Nona\AppData\Local\APN
Pasta Removido : C:\Users\Nona\AppData\Local\Conduit
Pasta Removido : C:\Users\Nona\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceinkbgepmlklmaffnhopafmjanmoeid
Pasta Removido : C:\Users\Nona\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg
Pasta Removido : C:\Users\Nona\AppData\Local\PackageAware
Pasta Removido : C:\Users\Nona\AppData\LocalLow\BabylonToolbar
Pasta Removido : C:\Users\Nona\AppData\LocalLow\Conduit
Pasta Removido : C:\Users\Nona\AppData\LocalLow\IncrediMail_MediaBar_Portugues_2
Pasta Removido : C:\Users\Nona\AppData\Roaming\Babylon
Pasta Removido : C:\Users\Nona\AppData\Roaming\DealPly
Pasta Removido : C:\Users\Nona\AppData\Roaming\file scout
Pasta Removido : C:\Users\Nona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
Pasta Removido : C:\Users\Nona\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
Pasta Removido : C:\Users\Nona\AppData\Roaming\Mozilla\Firefox\Profiles\qfba875t.default\extensions\amo@dealplyshopping.com
Pasta Removido : C:\Users\Nona\AppData\Roaming\OpenCandy
Pasta Removido : C:\Users\Nona\AppData\Roaming\pdfforge
Pasta Removido : C:\Users\Nona\AppData\Roaming\PerformerSoft
Pasta Removido : C:\Users\Nona\AppData\Roaming\SpeedanAlysis
Removido Durante o reboot : C:\ProgramData\Browser Manager
***** [Registro] *****
Chave Removida : HKCU\Software\AppDataLow\Software\Conduit
Chave Removida : HKCU\Software\AppDataLow\Software\IncrediMail_MediaBar_Portugues_2
Chave Removida : HKCU\Software\AppDataLow\Software\PriceGong
Chave Removida : HKCU\Software\AppDataLow\Software\SmartBar
Chave Removida : HKCU\Software\AppDataLow\Toolbar
Chave Removida : HKCU\Software\BabylonToolbar
Chave Removida : HKCU\Software\BrowserMngr
Chave Removida : HKCU\Software\Conduit
Chave Removida : HKCU\Software\DataMngr
Chave Removida : HKCU\Software\DataMngr_Toolbar
Chave Removida : HKCU\Software\DealPly
Chave Removida : HKCU\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh
Chave Removida : HKCU\Software\Google\Chrome\Extensions\ceinkbgepmlklmaffnhopafmjanmoeid
Chave Removida : HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Chave Removida : HKCU\Software\IM
Chave Removida : HKCU\Software\Iminent
Chave Removida : HKCU\Software\ImInstaller
Chave Removida : HKCU\Software\InstallCore
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{140AFDC9-061F-4B86-8C58-42994309768F}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1631550F-191D-4826-B069-D9439253D926}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{336D0C35-8A85-403A-B9D2-65C292C39087}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A09AB6EB-31B5-454C-97EC-9B294D92EE2A}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AA74D58F-ACD0-450D-A85E-6C04B171C044}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{140AFDC9-061F-4B86-8C58-42994309768F}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{336D0C35-8A85-403A-B9D2-65C292C39087}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF971472-C32D-44B6-905C-4D93708F3ED1}
Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Chave Removida : HKCU\Software\Somoto
Chave Removida : HKCU\Software\5c55dc8fbc38ea41
Chave Removida : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Chave Removida : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Chave Removida : HKLM\Software\Babylon
Chave Removida : HKLM\Software\BrowserMngr
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Chave Removida : HKLM\SOFTWARE\Classes\Extension.ExtensionhelperObject
Chave Removida : HKLM\SOFTWARE\Classes\Extension.ExtensionhelperObject.1
Chave Removida : HKLM\SOFTWARE\Classes\f
Chave Removida : HKLM\SOFTWARE\Classes\funmoods.dskBnd
Chave Removida : HKLM\SOFTWARE\Classes\funmoods.dskBnd.1
Chave Removida : HKLM\SOFTWARE\Classes\funmoods.funmoodsHlpr
Chave Removida : HKLM\SOFTWARE\Classes\funmoods.funmoodsHlpr.1
Chave Removida : HKLM\SOFTWARE\Classes\funmoodsApp.appCore
Chave Removida : HKLM\SOFTWARE\Classes\funmoodsApp.appCore.1
Chave Removida : HKLM\SOFTWARE\Classes\Prod.cap
Chave Removida : HKLM\SOFTWARE\Classes\Toolbar.CT2727622
Chave Removida : HKLM\SOFTWARE\Classes\TypeLib\{03119103-0854-469D-807A-171568457991}
Chave Removida : HKLM\SOFTWARE\Classes\TypeLib\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3}
Chave Removida : HKLM\SOFTWARE\Classes\TypeLib\{1D5A4199-956E-49BC-B89F-6A35C57C0D13}
Chave Removida : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Chave Removida : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Chave Removida : HKLM\Software\Conduit
Chave Removida : HKLM\Software\DataMngr
Chave Removida : HKLM\Software\DealPly
Chave Removida : HKLM\Software\IB Updater
Chave Removida : HKLM\Software\Iminent
Chave Removida : HKLM\Software\ImInstaller
Chave Removida : HKLM\Software\IncrediMail_MediaBar_Portugues_2
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsLatest_RASAPI32
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\FunmoodsLatest_RASMANCS
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup_RASAPI32
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\IminentSetup_RASMANCS
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF971472-C32D-44B6-905C-4D93708F3ED1}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\5c55dc8fbc38ea41
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{13119113-0854-469D-807A-171568457991}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{140AFDC9-061F-4B86-8C58-42994309768F}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{33119133-0854-469D-807A-171568457991}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{965B9DBE-B104-44AC-950A-8A5F97AFF439}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DF971472-C32D-44B6-905C-4D93708F3ED1}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ceinkbgepmlklmaffnhopafmjanmoeid
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2C52D31A-62BD-4952-829E-AF4D3B45EC3C}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FE6EADE5-0F46-4CAA-A07F-B76152A3E4DF}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{140AFDC9-061F-4B86-8C58-42994309768F}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IncrediMail_MediaBar_Portugues_2 Toolbar
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service
Chave Removida : HKLM\SOFTWARE\Classes\CLSID\{336D0C35-8A85-403A-B9D2-65C292C39087}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{23119123-0854-469D-807A-171568457991}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{23C70BCA-6E23-4A65-AD2E-1389062074F1}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{23D8EEF7-0E13-4000-B9C4-6603C1E912D1}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{295CACB4-51F5-46FD-914E-C72BAAE1B672}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{2CE5C4B9-6DBE-4528-96FA-C9FF38EF1762}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{34C1FDF7-02C1-4F23-B393-F48B16E071D1}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{54291324-7A3D-4F11-B707-3FB6A2C97BD9}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{59C63F11-D4E5-46E7-9B8A-EE158DCA83A8}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{5DA22CBD-0029-4A09-B757-CF0FAFC488ED}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{77A6E7D4-4A83-4A9B-A2A0-EF3B125DC29D}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{C0585B2F-74D7-4734-88DE-6C150C5D4036}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{CA17D76B-F91D-4659-A7FD-A9F7ED375CDD}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{D8242E89-2F81-484A-AE5B-BA8CAD5B7347}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{EF0588D6-1621-4A75-B8BE-F4BC34794136}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Chave Removida : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Chave Removida : HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh
Chave Removida : HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj
Chave Removida : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{336D0C35-8A85-403A-B9D2-65C292C39087}
Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{336D0C35-8A85-403a-B9D2-65C292C39087}_is1
Chave Removida : HKLM\SOFTWARE\Software
Chave Removida : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Chave Removida : HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Chave Removida : HKU\S-1-5-21-277650631-4165597396-2036752673-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Valor Removida : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Valor Removida : HKCU\Software\Microsoft\Internet Explorer\Main [BrowserMngr Start Page]
Valor Removida : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Valor Removida : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [BrowserMngrDefaultScope]
Valor Removida : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{140AFDC9-061F-4B86-8C58-42994309768F}]
Valor Removida : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{140AFDC9-061F-4B86-8C58-42994309768F}]
Valor Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SDP]
Valor Removida : HKCU\Software\Mozilla\Firefox\Extensions [speedanalysis@SpeedAnalysis.com]
Valor Removida : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{140AFDC9-061F-4B86-8C58-42994309768F}]
Valor Removida : HKLM\SOFTWARE\Mozilla\Firefox\extensions [{336D0C35-8A85-403a-B9D2-65C292C39087}]
Valor Removida : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [speedanalysis@SpeedAnalysis.com]
Valor Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{140AFDC9-061F-4B86-8C58-42994309768F}]
Valor Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]
Valor Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}]
***** [Navegadores] *****
-\\ Internet Explorer v10.0.9200.16537
Substituído : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://start.funmoods.com/?f=2&a=ironpub&chnl=ironpub&cd=2XzuyEtN2Y1L1Qzu0FyEyC0DtDyE0C0EtBzytB0DzzyEyCtDtN0D0Tzu0StByDtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=938199261 --> hxxp://www.google.com
Substituído : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - oldTabs] = hxxp://start.funmoods.com/?f=2&a=ironpub&chnl=ironpub&cd=2XzuyEtN2Y1L1Qzu0FyEyC0DtDyE0C0EtBzytB0DzzyEyCtDtN0D0Tzu0StByDtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=938199261 --> hxxp://www.google.com
-\\ Mozilla Firefox v20.0.1 (pt-BR)
Arquivo : C:\Users\Nona\AppData\Roaming\Mozilla\Firefox\Profiles\qfba875t.default\prefs.js
C:\Users\Nona\AppData\Roaming\Mozilla\Firefox\Profiles\qfba875t.default\user.js ... Removido !
[OK] Arquivo está limpo.
-\\ Google Chrome v26.0.1410.64
Arquivo : C:\Users\Nona\AppData\Local\Google\Chrome\User Data\Default\Preferences
Removida [l.2633] : homepage = "hxxp://search.conduit.com/?ctid=CT3201317&SearchSource=48&CUI=UN28908705723642396&UM[...]
*************************
AdwCleaner[S1].txt - [27483 octets] - [17/04/2013 16:22:33]
########## EOF - C:\AdwCleaner[S1].txt - [27544 octets] ##########

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.8.4 (04.16.2013:1)
OS: Windows 7 Ultimate x64
Ran by Nona on 17/04/2013 at 16:34:36,95
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


~~~ Services

~~~ Registry Values
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\windows nt\currentversion\windows\\AppInit_DLLs
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-277650631-4165597396-2036752673-1000\software\microsoft\internet explorer\main\\Start Page
Successfully repaired: [Registry Value] hkey_current_user\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\.default\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-18\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-19\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\s-1-5-20\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_users\S-1-5-21-277650631-4165597396-2036752673-1000\software\microsoft\internet explorer\searchscopes\\DefaultScope
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\DisplayName
Successfully repaired: [Registry Value] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{0633ee93-d776-472f-a0ff-e1416b8b2e3a}\\URL

~~~ Registry Keys
Successfully deleted: [Registry Key] hkey_current_user\software\baidu
Successfully deleted: [Registry Key] hkey_current_user\software\filescout
Successfully deleted: [Registry Key] hkey_current_user\software\im
Successfully deleted: [Registry Key] hkey_current_user\software\performersoft llc
Successfully deleted: [Registry Key] hkey_local_machine\software\systweak
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{cff4db9b-135f-47c0-9269-b4c6572fd61a}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{e627dc4b-8c04-4234-a2d4-1d634ee01c41}
Successfully deleted: [Registry Key] hkey_local_machine\software\microsoft\internet explorer\searchscopes\{e627dc4b-8c04-4234-a2d4-1d634ee01c41}

~~~ Files
Successfully deleted: [File] C:\eula.1028.txt
Successfully deleted: [File] C:\eula.1031.txt
Successfully deleted: [File] C:\eula.1033.txt
Successfully deleted: [File] C:\eula.1036.txt
Successfully deleted: [File] C:\eula.1040.txt
Successfully deleted: [File] C:\eula.1041.txt
Successfully deleted: [File] C:\eula.1042.txt
Successfully deleted: [File] C:\eula.2052.txt
Successfully deleted: [File] C:\install.res.1028.dll
Successfully deleted: [File] C:\install.res.1031.dll
Successfully deleted: [File] C:\install.res.1033.dll
Successfully deleted: [File] C:\install.res.1036.dll
Successfully deleted: [File] C:\install.res.1040.dll
Successfully deleted: [File] C:\install.res.1041.dll
Successfully deleted: [File] C:\install.res.1042.dll
Successfully deleted: [File] C:\install.res.2052.dll
Successfully deleted: [File] C:\install.res.3082.dll

~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\baidu"
Successfully deleted: [Folder] "C:\ProgramData\browser manager"
Successfully deleted: [Folder] "C:\Users\Nona\AppData\Roaming\baidu"
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{0007CD68-FBB3-4568-9EF4-BBDBC6755968}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{0150D803-BD17-496E-A07E-461952ABAF92}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{030A6FF7-AED3-4913-B58C-F74E144B30B1}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{03A9BCB7-CB17-4572-ACC4-C858FBDCC956}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{07DE7E1B-84F1-4444-AB81-62028C7537A0}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{083F80D8-59A7-4B0B-BD90-CF7B004165EB}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{0B7C2558-FC5E-4C2B-BBC8-83306A062169}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{0E2D8B0C-49BA-47DD-AB47-DD5E492DD50E}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{0EBF1BC9-0812-41A7-8ED2-14C71C0A0547}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{12698421-2518-48A4-9581-1105FC170C7C}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{18E393FE-CFCA-4D40-A3B6-7DF5620E84D2}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{19680CD7-07D7-49C7-A7E4-B705DD3FBF6D}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{1AC13674-6D41-4A2A-8AAF-7AC20905CEEA}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{1B952142-FA61-42AA-BAAB-0D1DCB410D61}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{1BC07983-EBDF-40AB-8FDB-28508D12EAB6}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{1BCB023D-BC2D-44A9-8D66-BC52EFD0E041}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{1C661ACF-2E6C-41B2-ACBF-063CF70CFC5C}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{1E92966A-98E5-43BC-97A7-0B4559F66170}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{1F8D87CA-2544-4725-B58F-7A33BE7C5685}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{1F99FE98-F9B6-4F42-B825-D565737DF896}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{2018DFD1-5C77-4AED-AA6B-1DB156054EA7}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{20BF9E3A-EDB3-4909-A8C4-32CC300FA91E}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{21FEC93B-76C5-439D-A6D7-8CCDC6A43088}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{2934E3F4-9553-4F10-B5BD-B490BCE6E075}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{2A469E77-5788-4596-AFED-01A59F23682E}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{2AA18FFC-70E7-42E8-BD62-4C779284B939}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{2BEEF5E7-F6BC-44D1-AF88-0DD90DC67E78}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{2C312A43-0B87-476F-87BE-058909AD6051}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{2D2E743C-CED2-4C74-984D-31A15D41E5C2}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{303546D2-8313-401B-8999-0C3396E087D8}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{30BF2857-43AB-43E5-9043-9A31B962FB5B}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{317307DF-696E-443C-9288-5EC67B5B7D5A}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{31AA18D8-9BA3-4722-AD14-FED089B9B723}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{3209FCCA-8969-40B3-9B05-55207B8BC421}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{338BDE44-1BB7-4341-9CEB-F105B8EC25EB}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{3557F13E-CB85-40EB-AD69-280DC7B0C358}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{362A87AC-B593-406D-BCA9-37A55A7F1ED1}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{36A98FBC-D21E-4C95-8D25-0E0C29F01985}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{387C1856-2F4A-4072-9017-EF87D7E01212}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{398408B2-EED6-46DA-B489-55C45EFD82EB}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{3A473E4A-31E6-4DCC-9725-B911233329E4}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{3AB27702-B90D-431A-B552-8D5F28EFDDB2}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{3B26B3F7-5EE8-420E-9AA9-B214D2F07998}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{3C506655-FA07-4E14-85AA-92EEA5E0A4BD}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{3C865A50-ACFB-4058-BF8C-0B6E9C52AC4D}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{3D19D5A6-419C-4D37-906C-CBD472BB2F8E}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{3E90629E-774B-4DB1-B3A6-19B84604F1AE}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{3ECABC23-B7F4-4A88-98C8-E9F656B3C2E0}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{40520197-F635-47CA-9786-A9FA3663837C}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{41515914-9628-4E6B-949A-B89F58FBABE3}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{42D8DBA9-043A-42CB-9F0D-CE15989ECDD3}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{4402439D-4EE6-4722-B5F1-71F770CF8793}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{4643C487-BBF8-40BD-AD3D-B4437F38701B}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{46F415E0-AFFC-46C1-ABE6-1A1AC8C91DA6}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{479A5125-F982-4CEF-BCCF-2DDFF177BA18}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{47BAA2DF-77A0-4E98-9330-DAF72995B908}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{49C31B3E-42A8-40D5-9BE3-FA77736A1B07}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{4E26BC36-A86D-483F-9B9A-8C7F437743F0}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{4EDFAB44-B15A-4B98-AC95-13BE347DF224}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{4F03D5BE-B63D-4979-9E75-B5F2BC4C73EC}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{50B0D36E-CA30-493E-99B9-3D0EC2BC8629}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{533869DB-C49F-497F-AEEB-F6024F749163}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{54D44F7C-ED72-4294-B474-2B47C65BB87A}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{596C48DE-F71B-4187-AF39-37C8CE65EF76}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{5AC59A02-7F07-4058-9BDD-7580C6D1F431}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{5C2C4CA3-B8DA-4CA3-96C6-8C44F18F2078}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{5E3A4572-885A-4D32-8BD2-B14F849A4B9C}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{600E9E2A-F589-4765-9964-AAB87791A1EB}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{63F63323-2824-4282-B686-9010BCA9BC8E}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{645D12DA-47A6-4B49-9D67-CD0E524C7C57}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{64D4D170-09C5-4F72-A78B-C5933ADC123B}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{67DBE8A7-811E-4295-80E1-54006EE0E847}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{68B8D47A-F883-4443-A8B0-26FB7CB155B2}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{6A0C5A5F-955D-47BA-8302-4E6A8D0B1B88}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{6A5CF0E1-1056-4230-A619-02C3844F8F6F}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{6B8C0F71-9C5F-468A-89EF-E22CDDBC6C09}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{6C04A377-465C-40B2-80F3-5324CA267476}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{6E5E0BCD-BD28-4726-8D50-52F971229F26}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{711D26FC-2A12-4322-96E8-27F70461B16A}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{71C2B001-40EC-4077-BC64-0524095BA952}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{727B91AB-03BD-4D8A-8BE6-0CBB6E4F972F}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{72C91229-B194-42DC-AB0F-C3B5C6F4C3E4}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{73FB017A-564E-4BFD-9AB7-74EDA9AFF883}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{781EDA9E-13B3-4FA9-912A-67E81CDA747A}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{78954587-89AD-4B76-87F6-E112AA594301}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{78C9EF80-B0D2-4F36-96AC-FC88A36FCF1B}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{7A791843-A9E2-45CF-ACF8-973211063D28}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{7B09FE13-AC27-48E8-8B67-62556420DC7C}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{7E13F4E7-3A3A-45B1-9199-FCC254A569BF}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{7ED5C8BE-54C9-4775-BA93-A51138CD68BB}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{7F2E869B-1D22-4D5A-8990-EC05BB6AF1A3}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{80949618-9DC9-4CE7-9A7A-4C52895F0055}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{80E8E64A-A089-4DBA-B16B-F8C8A0D3AD7D}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{83CF971E-5C8B-4C8F-A4E3-1CCFA195B16B}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{85B4CA0E-2337-4043-BCE0-E1B044B0146A}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{86D9DCCC-A9BA-4DB2-8765-E5137AD32342}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{88191476-5EDA-46F3-B6CE-E9611CECF677}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{8A3160D4-6EB0-4092-874B-7FC49C852C11}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{8AE2B206-2367-458C-B0BB-B88E26A3177A}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{8CF78548-C34F-45DC-BFBF-4E4D8F37750A}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{8D2E311A-40FF-4912-A595-30C4A443E776}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{8E1C3F9D-0D76-4487-B604-EA65CCDD9764}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{90D1ED12-9238-4246-836D-3E4E63FA816C}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{9436689D-628B-4011-B992-6D23463F4D49}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{94DC1271-39BD-45D0-ACFA-D8121C16F453}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{95B5786B-680A-42E3-985C-1F30D56ABD1C}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{96A6C431-3C51-4C19-B33A-13F182BEB6DC}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{9838D2DC-9F43-4010-A74B-54423BF2B2C5}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{999541F2-A1DA-4FF8-80D1-B5C60A3FC599}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{99E2F9C6-DF9F-4E17-B648-9503184430C7}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{9BE3BB53-7798-4F28-8585-7B1A580BB6AF}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{9C35BB90-ED09-4B2C-B818-F8E6010D5F34}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{9D227F0D-6ECA-43B8-A1D6-1F3E823BAD64}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{9D2DF242-49E9-491C-B6C1-37D2C81DF3C6}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{9D940439-8395-49F5-8A09-A5B141E3ECE9}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{9E4DD968-E784-43A7-99E0-FBE5A6EE95B1}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{9F8DA542-E3D8-400C-B552-B044F35A7C1B}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{A16F6F5F-3DC0-4D09-BB78-4EDF8EA1F3F1}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{A2A29A13-5AB4-4A32-BC7A-BC3DFB473532}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{A38BDD59-1B6B-4F61-989D-9C409E940343}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{A5DF2843-97EC-4D66-ACAB-D43794FD3208}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{A709BBF3-C40E-42FB-B58B-6A45A4F5194A}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{A74ED8D8-1B75-4102-A30F-62EA497877DC}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{A7F37A5B-9AD0-4A73-BA5C-69173BF08623}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{A8F0B783-2B61-4A4D-BAD9-C1F49094EE35}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{A9877F52-0D38-4560-B11A-A56FCD97FAF7}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{AB1BF2AA-8238-473B-A514-BB6503D826F6}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{AECA4428-0545-4523-AB35-BA2A18021B18}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{AF2BB767-4A84-4D30-A7BB-EA55564C5A0D}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{B0C49FF8-1D74-496E-A1EA-136B86D00763}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{B0C5BBFD-D0B1-43E0-AD43-FA9A0AF8B91D}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{B134CD71-66AF-47FC-A214-424FF73BD50E}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{B2DCCD69-3C42-4109-A5C7-3A3B8ABD9448}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{B2DD0DED-B3B3-4154-8F1C-8F3704545EB4}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{B74D6487-E82A-4E22-97A9-8FC130EE16C1}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{B79901B9-1AD7-46F8-834D-E8A0926658F4}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{B8B0E153-9E74-4A37-9547-0CAE2B5A2B50}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{B8CAF1AE-4D34-4493-B5FD-660377BCDD30}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{B91BDD70-72B7-4E3A-9AC8-A1F17A441FD1}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{BA105699-00A8-430C-9E65-384317FA5D1E}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{BB5D857E-3011-4067-8DDD-BC31782C2C43}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{BCA26BE1-3920-4CEA-942F-AEA232672A3D}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{C28A9E34-1CEE-4468-85FC-B13F25058531}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{C3D226FA-393A-436E-88B2-4C09020B8F3C}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{C559CBDB-1180-403D-9613-CC33BFC3DF84}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{C66713D1-E8B5-48A7-801A-0BC06C4754EF}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{CA571129-9687-4A2A-B1F2-5D130C700E82}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{CAD60D4D-F0BD-4750-A57A-9588E2054509}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{CB1FA60D-83CA-4DEB-B57D-4F759AA9923C}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{CBDD6F37-A8AD-443D-A0F3-5141F5956E34}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{CC476262-0D3F-4493-BC99-B6A4CCD5B461}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{CC505B5B-A367-4B11-90FA-4E7A9CA955AA}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{CFB79E8C-0F74-4032-8197-13024EF7D275}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{D11026D5-E891-4C1E-BDC3-08E14979178A}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{D2BCEEB1-434D-43F5-8853-E1157D867F30}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{D6B2028E-F257-419B-8766-B1902D0B64F3}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{D6E20D90-0A32-4E6C-BF59-01657510DAC0}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{D6E58E75-E418-4890-8A03-25A01DD30AC2}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{D7257C1F-DAEA-43EC-8A2A-49E7CB501C4E}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{D78D1F09-377B-49FD-A2D3-E85B029C90AE}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{D95561E4-FC3B-467E-A799-80563F6A04D7}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{DA6C9F8B-BA37-4388-8081-2F6629F60C13}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{DAD771DB-A5B2-4627-9469-A66E5B51B023}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{DC492F1A-3A61-40A1-881C-B30625DED463}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{DE2D3ECF-7680-457C-A0FC-08A21F7290D6}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{DED8EB10-8712-4C11-AA63-7194312F0C83}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{DF43C5F9-A208-493E-AF8F-38562B544FFE}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{DF8BF171-B8CF-4B0F-8A02-E712665D1F41}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{DFB15D4C-425A-4066-B8F4-93F4474F2781}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{E138C110-C9FB-4A95-9C4B-5B88FE697F26}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{E2A99418-CEEF-4E84-9EF4-D5E733315D76}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{E3441EC3-D9FE-410B-84A3-87ED236842D5}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{E4553E81-12C6-40CA-97CD-CF9986C7774E}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{E57C6B99-6AB3-437E-B22F-3347B101FBA1}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{E5B69A93-F5F5-4491-A1B5-6E9403ED2A1B}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{E5D08EDB-D41D-442F-B8A2-7E125E3720E5}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{E5EBC11B-84C7-491D-90BD-95939FF92CC1}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{E6288F46-50F0-400B-90CE-F5117500A46D}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{E7BD4317-48F3-4EF2-AA09-7FD0FE818319}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{E864D66F-0F67-4337-BE91-C6B45952564C}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{EB013973-AB47-4190-ADB5-6DEBF5844DF2}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{EC3E8019-A881-48DD-8F5F-8A3A77E185DC}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{F1489FF4-EC8C-4964-A606-738B9388821B}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{F2A6EA14-9245-47ED-855A-256A4F5BF78F}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{F2FEE69B-9506-4051-BD4F-3E4BDAAC326B}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{F491C548-99CD-45F1-8756-932E8F6EBE88}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{F7170C71-6DC6-43EA-9902-6F8F23CAFEFC}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{F86DD684-F30E-4AAE-98F9-A341A408DC81}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{F8916394-8719-4F8B-9AD8-51D045E84462}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{F8E9AB4F-D217-47FD-A8AF-7C3F803B8B35}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{FBA0B06A-9B45-4D90-943B-C71EB17215B0}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{FDCBAABD-C365-4945-BEDA-8778A2ED7E34}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{FDD91E3D-4ADA-4FF0-9D9D-ECAB62C37E87}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{FE5CE4D5-9091-4CD3-A4A6-AAE50D099F1D}
Successfully deleted: [Empty Folder] C:\Users\Nona\appdata\local\{FE71B0CE-6B24-4288-A3AB-9A00033D9E48}

~~~ Event Viewer Logs were cleared


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17/04/2013 at 16:41:21,23
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org



Versão da Base de Dados: v2013.04.17.10

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16540
Nona :: NONA-PC [administrador]

Proteção: Permitir
17/04/2013 16:51:15
mbam-log-2013-04-17 (16-51-15).txt

Tipo de Verificação: Verificação Rápida
Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM
Opções de verificação desativadas: P2P
Objetos escaneados: 230063
Tempo decorrido: 5 minuto(s), 44 segundo(s)

Processos de Memória Detectados: 0
(Não foram detectados ítens maliciosos)

Módulos de Memória Detectados: 0
(Não foram detectados ítens maliciosos)

Chaves de Registro Detectadas: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Enviado para a Quarentena e deletado com sucesso.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Enviado para a Quarentena e deletado com sucesso.

Valores de Registro Detectadas: 0
(Não foram detectados ítens maliciosos)

Itens de Dados no Registro Detectadas: 0
(Não foram detectados ítens maliciosos)

Pastas Detectadas: 0
(Não foram detectados ítens maliciosos)

Arquivos Detectados: 0
(Não foram detectados ítens maliciosos)

(fim)

Logfile of HijackThis v1.99.1
Scan saved at 17:00:36, on 17/04/2013
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Running processes:
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Windows\PixArt\PAC7302\Monitor.exe
C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Nona\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65brmon.exe
C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbserver.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
C:\Program Files (x86)\JDownloader\jre\bin\javaw.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\CrExtP65.exe
C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\CrExtP65.exe
C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\CrExtP65.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Users\Nona\Desktop\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft..../?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft..../?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {4c60e5ab-5c68-4c59-abaa-885010b24b32} - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65SrcAs.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll
O2 - BHO: FindLyrics - {44C9CC91-6A4A-4579-B4B5-899ECDC18DC6} - C:\Program Files (x86)\FindLyrics\FindLyrics.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Auxiliar de Conexão do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Toolbar BHO - {a235e1e3-6296-4710-af39-104a7faa6c7c} - C:\PROGRA~2\FROMDO~2\bar\1.bin\65bar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: G-Buster Browser Defense - {C41A1C0E-EA6C-11D4-B1B8-444553540000} - C:\Program Files (x86)\GbPlugin\gbieh.dll
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Program Files (x86)\GbPlugin\gbiehcef.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Search Assistant BHO - {f236ca79-3123-4afb-9f74-e98117ad5625} - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65SrcAs.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: FromDocToPDF - {c66a678d-5e6c-4af9-8f57-c6192f42cf74} - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65bar.dll
O3 - Toolbar: PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AMD AVT] Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
O4 - HKLM\..\Run: [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
O4 - HKLM\..\Run: [Firebird] C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbguard.exe -a
O4 - HKLM\..\Run: [FromDocToPDF Search Scope Monitor] "C:\PROGRA~2\FROMDO~2\bar\1.bin\65srchmn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [FromDocToPDF_65 Browser Plugin Loader] C:\PROGRA~2\FROMDO~2\bar\1.bin\65brmon.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files (x86)\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [SkyDrive] "C:\Users\Nona\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Nona\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&nviar para o OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: E&nviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Notas Ligadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Notas Ligadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Exibir ou ocultar HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O11 - Options group: [INTERNATIONAL] International
O13 - Gopher Prefix:
O15 - Trusted Zone: imagem.caixa.gov.br
O15 - Trusted Zone: internetbanking.caixa.gov.br
O15 - Trusted Zone: www.caixa.gov.br
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus....ek_sys_ctrl.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20614.www2.h...pdetect119b.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logme...trl.cab?lmi=972
O17 - HKLM\System\CCS\Services\Tcpip\..\{6485388D-118F-4B51-BC86-7DBA1E566B16}: NameServer = 200.204.0.10 200.204.0.138
O17 - HKLM\System\CS1\Services\Tcpip\..\{6485388D-118F-4B51-BC86-7DBA1E566B16}: NameServer = 200.204.0.10 200.204.0.138
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (file missing)
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - c:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - Winlogon Notify: GbPluginBb - C:\Program Files (x86)\GbPlugin\gbieh.dll
O20 - Winlogon Notify: GbPluginCef - C:\Program Files (x86)\GbPlugin\gbiehCef.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FromDocToPDFService (FromDocToPDF_65Service) - COMPANYVERS_NAME - C:\PROGRA~2\FROMDO~2\bar\1.bin\65barsvc.exe
O23 - Service: Gbp Service (GbpSv) - GAS Tecnologia - C:\PROGRA~2\GbPlugin\GbpSv.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc (file missing)
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP LaserJet Service - HP - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
O23 - Service: HP SI Service (HPSIService) - Unknown owner - C:\Windows\system32\HPSIsvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Microsoft SharePoint Workspace Audit Service - Unknown owner - C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" /auditservice (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PDF Architect Helper Service - pdfforge GbR - C:\Program Files (x86)\PDF Architect\HelperService.exe
O23 - Service: PDF Architect Service - pdfforge GbR - C:\Program Files (x86)\PDF Architect\ConversionService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

#6
Ciro-Mota

Ciro-Mota

    Assistente Profissional

  • Assistente Profissional
  • 52.955 posts
nonona,

Baixe OTL by OldTimer, e salve na sua área de trabalho.

Clique com o direito sobre o arquivo OTL.exe, depois clique em Imagem Postada.

Onde diz Saída, marque Padrão
Marque também estas opções:
  • Data de Criação -> mude para 90 dias
  • Usar WhiteList para Nomes de Companhias.
  • Ignorar Arquivos Microsoft
  • Verificar Lop
  • Verificar Purity
Selecione estas linhas em vermelho, clique com o direito sobre a seleção, e escolha a opção copiar


CREATERESTOREPOINT
netsvcs
%systemroot%\system32\drivers\*.* /90
%systemdrive%\drivers\*.exe
%SYSTEMDRIVE%\*.*
%LOCALAPPDATA%\*.exe
%LOCALAPPDATA%\*.txt
%LOCALAPPDATA%\*.ini
%LOCALAPPDATA%\*.dll
%LOCALAPPDATA%\*.dat
%USERPROFILE%\*.exe
%USERPROFILE%\*.txt
%USERPROFILE%\*.ini
%USERPROFILE%\*.dll
%USERPROFILE%\*.dat /30
C:\windows\system32\Tasks\*.* /s
C:\windows\system32\Tasks\*.* /s /64
%windir%\tasks\*.* /s
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.com
%systemroot%\*.scr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run /s
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMP
HKCU\Software\Microsoft\Internet Explorer\Downloads
/md5start
services.*
/md5stop
%systemdrive%\$Recycle.Bin|@;true;true;true /fp


Volte ao programa, clique com o direito em qualquer parte branca da sessão Exames Personalizados/Correções e escolha colar

Clique no botão Imagem Postada

O OTL começará a examinar seu computador. Não interrompa o processo e nem use outras janelas até que ele termine.

Não modifique nenhuma outra configuração, a menos que tenha sido orientado (a) a fazer isso.

O exame demora um pouco, tenha paciência.

Quando terminar, dois blocos de notas serão exibidos: OTL.txt e Extras.txt
Ambos ficarão salvos dentro do mesmo diretório onde está o OTL.exe, ou seja, na sua área de trabalho.

Copie todo o conteúdo do OTL.txt e cole na sua resposta.
Anexe o arquivo Extras.txt

OBS: Caso os logs fiquem muito grandes e exceda o limite do forum, envie-os para um arquivo .zip ou .rar e anexe-os à sua resposta.
**Tenha consideração a quem te ajuda, não Abandone seu tópico!**
[Membro da ASAP] // [Junte-se ao ARIS-LD] // [Linha Defensiva no Twitter]
Imagem Postada

Blog do Ciro Mota
Visite em: http://www.ciromota.net/

#7
nonona

nonona

    Novato

  • Novato
  • Pip
  • 13 posts
Anexo os logs, conforme instruções

Arquivo(s) anexado(s)



#8
Ciro-Mota

Ciro-Mota

    Assistente Profissional

  • Assistente Profissional
  • 52.955 posts
nonona,

Selecione e copie o texto dentro do CODE, clique com o direito sobre a seleção e escolha a opção copiar:

OBS: Certifique-se de copiar começando pela letra e sinal de dois pontos ": O" de OTL.

:OTL
PRC - [2013/02/22 17:35:34 | 001,292,432 | ---- | M] () -- C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\CrExtP65.exe
PRC - [2013/02/22 17:35:34 | 000,042,504 | ---- | M] (COMPANYVERS_NAME) -- C:\PROGRA~2\FROMDO~2\bar\1.bin\65barsvc.exe
PRC - [2013/02/22 17:35:34 | 000,030,096 | ---- | M] (VER_COMPANY_NAME) -- C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65brmon.exe
MOD - [2013/02/22 17:35:34 | 001,292,432 | ---- | M] () -- C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\CrExtP65.exe
MOD - [2013/02/22 17:35:34 | 001,187,472 | ---- | M] () -- C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\CrExt.dll
MOD - [2013/02/22 17:35:34 | 000,080,536 | ---- | M] () -- C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\t8ExtPEx.dll
MOD - [2013/02/22 17:35:34 | 000,071,952 | ---- | M] () -- C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\t8ExtEx.dll
SRV - [2013/02/22 17:35:34 | 000,042,504 | ---- | M] (COMPANYVERS_NAME) [Auto | Running] -- C:\PROGRA~2\FROMDO~2\bar\1.bin\65barsvc.exe -- (FromDocToPDF_65Service)
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=ironpub&chnl=ironpub&cd=2XzuyEtN2Y1L1Qzu0FyEyC0DtDyE0C0EtBzytB0DzzyEyCtDtN0D0Tzu0StByEtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=235934517
IE - HKLM\..\SearchScopes\{9a216821-0ec5-49a3-85ac-fb72ae79a1e8}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^Y6^xdm041^YY^br&si=swissconverter&ptb=4B69E0A7-8303-4A5E-813D-52E1E2DFF1B3&ind=2013022215&n=77fc4807&psa=&st=sb&searchfor={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://mystart.incredimail.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com?a=DgW6N6V7AP
IE - HKCU\..\URLSearchHook: {4c60e5ab-5c68-4c59-abaa-885010b24b32} - No CLSID value found
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
IE - HKCU\..\SearchScopes,DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
IE - HKCU\..\SearchScopes\{4984F4A6-B5ED-9439-1288-50F62804D331}: "URL" = http://mystart.incredimail.com//?search={searchTerms}&loc=search_box&a=DgW6N6V7AP
IE - HKCU\..\SearchScopes\{9a216821-0ec5-49a3-85ac-fb72ae79a1e8}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^Y6^xdm041^YY^br&si=swissconverter&ptb=4B69E0A7-8303-4A5E-813D-52E1E2DFF1B3&ind=2013022215&n=77fc4807&psa=&st=sb&searchfor={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com/portuguese/?search={searchTerms}&loc=search_box
FF - prefs.js..extensions.enabledAddons: findlyrics%40findlyrics.co:1.110
FF - HKLM\Software\MozillaPlugins\@FromDocToPDF_65.com/Plugin: C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\NP65Stub.dll (MindSpark)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\65ffxtbr@FromDocToPDF_65.com: C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin [2013/02/22 17:35:44 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\findlyrics@findlyrics.co: C:\Program Files (x86)\FindLyrics\FF\ [2013/04/15 14:48:49 | 000,000,000 | ---D | M]
[2013/04/15 14:48:49 | 000,000,000 | ---D | M] ("FindLyrics") -- C:\PROGRAM FILES (X86)\FINDLYRICS\FF
CHR - homepage: http://search.conduit.com/?ctid=CT3201317&SearchSource=48&CUI=UN28908705723642396&UM=1
O2 - BHO: (FindLyrics) - {44C9CC91-6A4A-4579-B4B5-899ECDC18DC6} - C:\Program Files (x86)\FindLyrics\FindLyrics.dll (FindLyrics)
O2 - BHO: (Toolbar BHO) - {a235e1e3-6296-4710-af39-104a7faa6c7c} - C:\PROGRA~2\FROMDO~2\bar\1.bin\65bar.dll (MindSpark)
O2 - BHO: (Search Assistant BHO) - {f236ca79-3123-4afb-9f74-e98117ad5625} - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65SrcAs.dll (MindSpark)
O3 - HKLM\..\Toolbar: (FromDocToPDF) - {c66a678d-5e6c-4af9-8f57-c6192f42cf74} - C:\Program Files (x86)\FromDocToPDF_65\bar\1.bin\65bar.dll (MindSpark)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [FromDocToPDF Search Scope Monitor] "C:\PROGRA~2\FROMDO~2\bar\1.bin\65srchmn.exe" /m=2 /w /h File not found
O4 - HKLM..\Run: [FromDocToPDF_65 Browser Plugin Loader] C:\PROGRA~2\FROMDO~2\bar\1.bin\65brmon.exe (VER_COMPANY_NAME)
[2013/04/15 14:48:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FindLyrics
[2013/02/22 17:36:25 | 000,000,000 | ---D | C] -- C:\Users\Nona\AppData\Local\FromDocToPDF_65
[2013/02/22 17:35:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FromDocToPDF_65
[2013/02/23 19:35:04 | 000,000,022 | ---- | M] () -- C:\Windows\SysWow64\SysGroloads.dll
[2013/04/17 09:06:10 | 000,003,436 | ---- | M] () -- C:\Windows\SysNative\Tasks\Browser Manager
[2013/04/15 14:49:00 | 000,003,364 | ---- | M] () -- C:\Windows\SysNative\Tasks\DealPlyUpdate
[2013/04/15 14:48:52 | 000,003,022 | ---- | M] () -- C:\Windows\SysNative\Tasks\FindLyrics Update
@Alternate Data Stream - 116 bytes -> C:\ProgramData\Temp:C33E37F9

:Commands
[createrestorepoint]
[purity]
[emptytemp]

Clique com o direito sobre o arquivo OTL.exe, depois clique em Imagem Postada.

Clique com o direito em qualquer parte branca, da sessão Exames Personalizados/Correções e escolha a opção colar

Feche TODAS as janelas (exceto o próprio OTL).

Clique no botão Imagem Postada

O programa executará o script e reiniciará o seu computador.
Quando o Windows for carregado, o OTL será executado automaticamente. Permita a sua execução.
Um bloco de notas será aberto, contendo algumas informações.
Copie TODO o conteúdo deste bloco de notas e cole na sua resposta.

Uma cópia deste log ficará armazenado na pasta C:\_OTL\MovedFiles com o nome no seguinte formato data_hora.log.

Exemplo: 03142010_145545.log

Poste também um novo log do Hijackthis.
**Tenha consideração a quem te ajuda, não Abandone seu tópico!**
[Membro da ASAP] // [Junte-se ao ARIS-LD] // [Linha Defensiva no Twitter]
Imagem Postada

Blog do Ciro Mota
Visite em: http://www.ciromota.net/

#9
nonona

nonona

    Novato

  • Novato
  • Pip
  • 13 posts
segue anexo

Arquivo(s) anexado(s)



#10
Ciro-Mota

Ciro-Mota

    Assistente Profissional

  • Assistente Profissional
  • 52.955 posts
nonona,

Desative temporiariamente seu AntiVirus
  • Utilize o Navegador Internet Explorer para utilizar o serviço!
  • Acesse o site AQUI
  • Faça o scan de acordo com a imagem abaixo:

    Imagem Postada
  • Ao final da verificação clique em List of found threats, clique em Export to text file... e marque a caixa "Delete Quarantined files", clique em [FINISH]
    Será gerado um relatório, que estará em:
C:\Program Files (x86)\ESET\ESET Online Scanner\log.txt

Poste esse log.
**Tenha consideração a quem te ajuda, não Abandone seu tópico!**
[Membro da ASAP] // [Junte-se ao ARIS-LD] // [Linha Defensiva no Twitter]
Imagem Postada

Blog do Ciro Mota
Visite em: http://www.ciromota.net/

#11
nonona

nonona

    Novato

  • Novato
  • Pip
  • 13 posts

segue anexo log

Arquivo(s) anexado(s)



#12
Ciro-Mota

Ciro-Mota

    Assistente Profissional

  • Assistente Profissional
  • 52.955 posts

nonona,

 

Para finalizar:

  • Execute o OTL.exe
    Clique no botão Botao_Limpeza_OTL.png.

    Permita que seu computador seja reiniciado.


  • iconjava.png Atualize o Java. Versões antigas têm vunerabilidades que alguns malwares podem usar para infectar seu sistema.
    • Faça download da última versão do Java SE 7u21.
    • Clique em JRE Download
    • Marque a caixa Accept License Agreement..
    • Clique no link para download Windows x86 Offline 30.2 MB jre-7u21-windows-i586.exe e salve no seu desktop.
    • Feche qualquer programa que esteja executando, especialmente navegadores.
    • Vá em Iniciar > Painel de Controle duplo clique em Adicionar ou Remover Programas e remova todas as versões antigas do Java.
      Exemplos de versões antigas
      Java 2 Runtime Environment, SE v1.4.2
      J2SE Runtime Environment 5.0
      J2SE Runtime Environment 5.0 Update 6
    • Selecione qualquer item com nome Java Runtime Environment (JRE ou J2SE).
    • Clique no botão Remover ou Alterar/Remover.
    • Repita quantas vezes for necessária para remover cada versão do Java.
    • Reincie seu computador uma vez que todas as versões do Java tenham sido removidas.
    • Agora vá no seu desktop, clique duas vezes em jre-7u21-windows-i586.exe para instalar a mais nova versão.
    • ATENÇÃO: Desmarque a caixa de instalação da ASK Toolbar.


  • iconadobe.png  Atualize o Adobe Reader. Versões antigas têm vulnerabilidades que são exploradas por malwares.

    Clique aqui e instale a mais nova versão.

  • iconflash.png Mantenha o Flash Player atualizado. Versões antigas também têm vulnerabilidades que são exploradas por malwares. Clique nos dois links abaixo e baixe a versão mais atual:
    http://download.macr...11_active_x.exe
    http://download.macr...r_11_plugin.exe

  • worm.png Worms USB (vírus de pendrive) podem infectar qualquer tipo de dispositivo de armazenamento removível (pendrives, mp3, mp4, celulares, cartões de memória, câmeras fotográficas). Este tipo de malware explora um recurso nativo do Windows chamado Autorun, ou Autoplay (é aquele assistente que aparece quando você insere um cd ou pendrive, perguntando com qual programa você deseja abri-lo). O Autoplay precisa de um arquivo chamado autorun.inf para funcionar.

    Mantenha um cópia limpa e protegida do arquivo autorun.inf em todos os dispositivos removíveis e em todas as unidades do sistema. Deste modo, se acaso você plugar o seu pendrive em algum pc infectado, o malware não vai conseguir sobreescrever o arquivo pré-existente. Mas ainda assim ele poderá copiar seus executáveis maliciosos para o pendrive, tais como .EXE, .SCR, .CMD, .PIF, .BAT, .COM.
    Se você plugar este pendrive em uma máquina limpa e executar algum desses arquivos maliciosos, esse sistema será infectado da mesma forma. Portanto, tenha cuidado e use o bom senso.

    Para criar um arquivo autorun.inf protegido no Windows XP:

    Faça o download do Flash_Disinfector.exe e salve na sua área de trabalho.
    • Conecte todos os dispositivos de armazenamento removível nas portas USBs. Salve o que achar necessário, EXCETO arquivos executáveis, depois formate as mídias, indo em Meu Computador e clicando com o direito sobre a unidade da mídia, escolhendo a opção "Formatar"
    • Execute o Flash_Disinfector.exe.
    • Vá seguindo os prompts que poderão aparecer.
    • Espere até que o programa conclua a busca e depois saia do programa.


    Para Windows Vista e 7: Panda USB Vaccine

  • TFC_icon.pngPara manutenção de sistema, remoção de arquivos temporários e inválidos, baixe TFC, by OldTimer.

    Feche TODOS os programas e execute o TFC. Clique no botão Start e aguarde. Sua área de trabalho irá desaparecer, não se preocupe, isso faz parte do processo.

    Tenha paciência, conforme a quantidade de dados a serem excluídos, o processo pode demorar mais de 2 minutos.

    Quando terminar, você será solicitado a reiniciar seu computador. REINICIE.

    Caso não lhe seja solicitado, reinicie manualmente.

  • iconwu.pngVisite o Windows Update regularmente e verifique por atualizações.
    Novas brechas de segurança são descobertas com freqüência. Muitos malwares exploram essas brechas, infectando sistemas sem depender de nenhuma ação do usuário. A Microsoft corrige essas brechas através das atualizações.
    Por isso é fundamental manter o seu sistema atualizado.


  • Aprenda alguns cuidados e dicas para manter seu computador limpo. Leia o artigo Proteja seu pc:
    http://linhadefensiv...proteja-seu-pc/

  • Se não há mais nenhum problema relacionado a malwares, clique no botão denunld.png e peça para fecharem seu tópico.


Se você tiver alguma dúvida relacionada a informática e tecnologia, sinta-se à vontade para postar em qualquer área do forum Linha Defensiva.


**Tenha consideração a quem te ajuda, não Abandone seu tópico!**
[Membro da ASAP] // [Junte-se ao ARIS-LD] // [Linha Defensiva no Twitter]
Imagem Postada

Blog do Ciro Mota
Visite em: http://www.ciromota.net/

#13
nonona

nonona

    Novato

  • Novato
  • Pip
  • 13 posts

Gostaria de agradecer o Fórum, pois trabalha com muita dedicação e é de muita valia, devendo aqueles que utilizarem dele não abandonar jamais o seu tópico e reconhecer o empenho do fórum. Parabéns ao Linha defensiva e seus voluntários!!!!!



#14
netcriptus

netcriptus

    Coordenador de Moderação

  • Coordenador
  • 1.839 posts
PROBLEMA RESOLVIDO
 
Caso queira solicitar a reabertura do tópico, utilize o botão Denunciar para entrar em contato com a moderação.

Nota: Somente o autor pode realizar essa solicitação na área Remoção de Malware.
Linha Defensiva no Twitter!
Imagem Postada
Sorria, você está sendo Googlado.