Fórum SecSecurity

Implementando Limpeza e Seguranca em seu computador!

Palavras chave

Últimos assuntos

» ResetBrowser ( ... de Nicolas Coolman )
Ter Maio 31, 2016 5:58 am por joram

» herdProtectScan ( ... by herdprotect.com )
Seg Mar 07, 2016 10:58 pm por joram

» Emsisoft Emergency Kit ( ... by Emsisoft.com )
Dom Fev 28, 2016 5:40 am por joram

» Dr.WEB Link Checker ( ... by Doctor Web.Ltd )
Qui Fev 11, 2016 9:51 am por joram

» Computador com erros no navegador
Sab Ago 29, 2015 8:04 pm por joram

» Justiça determina que PSafe retire alertas desleais
Qua Ago 19, 2015 6:58 am por joram

» Google vai fazer buscas offline internas no desktop do seu PC
Ter Ago 18, 2015 8:19 am por joram

» Baidu lança buscador no Brasil!
Seg Ago 17, 2015 12:25 pm por joram

» Kaspersky é acusada de inventar vírus!
Sex Ago 14, 2015 3:32 pm por joram

Dezembro 2016

SegTerQuaQuiSexSabDom
   1234
567891011
12131415161718
19202122232425
262728293031 

Calendário Calendário

Parceiros

Fórum grátis

Os membros mais marcados


    suspeita de virus log para analise.

    Compartilhe

    Edvan
    Membro
    Membro

    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 36
    Localização : Natal/RN

    suspeita de virus log para analise.

    Mensagem por Edvan em Qua Abr 03, 2013 2:48 pm

    Essa maquina reiniciou 2 vezes, suspeita de virus, log para analise.

    Link [Você precisa estar registrado e conectado para ver este link.]

    joram
    Administrador Fundador
    Administrador Fundador

    Mensagens : 608
    Data de inscrição : 14/08/2012
    Idade : 63
    Localização : Rio de Janeiro

    Re: suspeita de virus log para analise.

    Mensagem por joram em Qua Abr 03, 2013 3:24 pm

    Edvan escreveu:Essa maquina reiniciou 2 vezes, suspeita de virus, log para analise.

    Link [Você precisa estar registrado e conectado para ver este link.]
    Olá! Edvan

    proxyfix
    emptytemp
    emptyflash
    emptyclsid
    firewallraz


    |- Execute este script,como de praxe,em ZHPFix.
    |- Poste o relatório!

    Abs!

    Edvan
    Membro
    Membro

    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 36
    Localização : Natal/RN

    Re: suspeita de virus log para analise.

    Mensagem por Edvan em Qui Abr 04, 2013 3:20 pm

    Mais algum procedimento amigo.?

    .Rapport de ZHPFix 2013.3.9.1 par Nicolas Coolman, Update du 9/03/2013
    Fichier d'export Registre :
    Run by f002282 at 04/04/2013 16:16:31
    High Elevated Privileges : OK
    Windows XP Professional Service Pack 3 (Build 2600)

    Recycle Files Deleted

    ========== Registry Value ==========
    ProxyFix : Proxy killed successfully
    DELETED ProxyServer Value
    DELETED ProxyEnable Value
    DELETED EnableHttp1_1 Value
    DELETED ProxyHttp1.1 Value
    DELETED ProxyOverride Value
    DELETED FirewallRaz (SP) : C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe
    DELETED FirewallRaz (SP) : C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
    DELETED FirewallRaz (DP) : C:\Arquivos de programas\Windows Live\Messenger\wlcsdk.exe
    DELETED FirewallRaz (DP) : C:\Arquivos de programas\Windows Live\Messenger\msnmsgr.exe
    No Value in Firewall Exception Register Key (FirewallRaz)

    ========== Repertory ==========
    No Empty CLSID Directories

    ========== File ==========
    DELETED Window Temporary
    DELETED Flash Cookies


    ========== Summary ==========
    11 : Registry Value
    1 : Repertory
    2 : File


    End of clean in 00mn 05s

    ========== Report File ==========
    C:\ZHP\ZHPFix[R1].txt - 04/04/2013 16:16:32 [1166]

    joram
    Administrador Fundador
    Administrador Fundador

    Mensagens : 608
    Data de inscrição : 14/08/2012
    Idade : 63
    Localização : Rio de Janeiro

    Re: suspeita de virus log para analise.

    Mensagem por joram em Sex Abr 05, 2013 8:23 am

    Bom Dia! Edvan

    [HKLM\Software\Classes\Installer\Features\758F5690DAAD39F40845E0E23C8C5C0B] =>PUP.SweetIM
    [HKLM\Software\Classes\Installer\Products\758F5690DAAD39F40845E0E23C8C5C0B] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\758F5690DAAD39F40845E0E23C8C5C0B] =>PUP.SweetIM
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] =>Toolbar.Yahoo
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] =>Toolbar.Yahoo
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] =>Toolbar.Yahoo
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4318DF19719275242801CBE292063A4C] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75D5168E5E176C24981B4E5DBD991078] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8724E58E6C7D00C48A0D4F3345EB2C26] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB676B0E1B9EFA049B9F7DDDA9645734] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31BBB0B825EDEF45AB0FE7099C68C81] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B471D8D7319336B4CA89374ED0D7B806] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC30043663AA2CA4DA1DAA9CA5FDCC75] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDC83385E6C239F4C876A77A37DF581D] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432] =>PUP.SweetIM
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E] =>PUP.SweetIM
    [HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =>Toolbar.Bing
    [HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] =>Toolbar.Bing
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636] =>PUP.SweetIM^
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094] =>PUP.SweetIM^
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536] =>PUP.SweetIM^
    |- Faça o mesmo com estes,em ZHPFix.
    |- Poste o relatório!

    -/-

    |- Baixe: < [Você precisa estar registrado e conectado para ver este link.] > ( ... par Xplode )

    |- Ao acessar,clique na imagem: < [Você precisa estar registrado e conectado para ver esta imagem.] >

    |- Salve-o no desktop!
    |- Ps: Se utilizar o navegador IE9 para o download,desabilite o filtro "SmartScreen".
    |- Execute-o e clique direito em adwcleaner.exe,e escolha sua execução como "administrador",caso utilize Windows Vista ou 7.

    [Você precisa estar registrado e conectado para ver este link.]

    |- Ps: Dê início ao scan,clicando em "Remover".
    |- Ao concluir,poste o relatório: C:\AdwCleaner [S1].txt

    A+

    Edvan
    Membro
    Membro

    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 36
    Localização : Natal/RN

    Re: suspeita de virus log para analise.

    Mensagem por Edvan em Sex Abr 05, 2013 3:36 pm

    Rapport de ZHPFix 2013.3.9.1 par Nicolas Coolman, Update du 9/03/2013
    Fichier d'export Registre :
    Run by f002282 at 05/04/2013 16:22:38
    High Elevated Privileges : OK
    Windows XP Professional Service Pack 3 (Build 2600)

    Recycle Files Deleted

    ========== Registry Key ==========
    DELETED Key: HKLM\Software\Classes\Installer\Features\758F5690DAAD39F40845E0E23C8C5C0B
    ERROR Key****: HKLM\Software\Classes\Installer\Products\758F5690DAAD39F40845E0E23C8C5C0B
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\758F5690DAAD39F40845E0E23C8C5C0B
    DELETED Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    DELETED Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\789034A89BAC50E4782F0A7BDBF75632
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75D5168E5E176C24981B4E5DBD991078
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8724E58E6C7D00C48A0D4F3345EB2C26
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB676B0E1B9EFA049B9F7DDDA9645734
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B31BBB0B825EDEF45AB0FE7099C68C81
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B471D8D7319336B4CA89374ED0D7B806
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC30043663AA2CA4DA1DAA9CA5FDCC75
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDC83385E6C239F4C876A77A37DF581D
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F754C503375A13344B22388E18DFE87E
    DELETED Key: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    DELETED Key: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536


    ========== Summary ==========
    51 : Registry Key


    End of clean in 00mn 07s

    ========== Report File ==========
    C:\ZHP\ZHPFix[R1].txt - 04/04/2013 16:16:32 [1218]
    C:\ZHP\ZHPFix[R2].txt - 05/04/2013 16:22:38 [7027]



    ----------------------------xx------------------------------------


    # AdwCleaner v2.200 - Relatório criado em 05/04/2013 às 16:25:07
    # Atualizado em 02/04/2013 por Xplode
    # Sistema Operacional : Microsoft Windows XP Service Pack 3 (32 bits)
    # Usuário : f002282 - FUN0123
    # Modo de Boot : Normal
    # Executado de : C:\Documents and Settings\f002282\Meus documentos\Downloads\adwcleaner.exe
    # Opção [Remover]


    ***** [Serviços] *****


    ***** [Arquivos/Pastas] *****

    Arquivo Removido : C:\Documents and Settings\f002282\Dados de aplicativos\Mozilla\Firefox\Profiles\tu81cpd1.default\searchplugins\Askcom.xml
    Arquivo Removido : C:\Documents and Settings\f002282\Dados de aplicativos\Mozilla\Firefox\Profiles\tu81cpd1.default\searchplugins\Conduit.xml
    Arquivo Removido : C:\Documents and Settings\f002282\Dados de aplicativos\Mozilla\Firefox\Profiles\tu81cpd1.default\searchplugins\funmoods.xml
    Arquivo Removido : C:\Documents and Settings\f002282\Dados de aplicativos\Mozilla\Firefox\Profiles\tu81cpd1.default\searchplugins\SweetIm.xml
    Pasta Removido : C:\Documents and Settings\All Users\Dados de aplicativos\boost_interprocess
    Pasta Removido : C:\Documents and Settings\f002282\Dados de aplicativos\Mozilla\Firefox\Profiles\tu81cpd1.default\Conduit
    Pasta Removido : C:\Documents and Settings\f002282\Dados de aplicativos\Mozilla\Firefox\Profiles\tu81cpd1.default\ConduitEngine
    Pasta Removido : C:\Documents and Settings\f002282\Dados de aplicativos\Mozilla\Firefox\Profiles\tu81cpd1.default\CT2233703
    Pasta Removido : C:\Documents and Settings\f002282\Dados de aplicativos\Mozilla\Firefox\Profiles\tu81cpd1.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}
    Pasta Removido : C:\Documents and Settings\f002282\Dados de aplicativos\Mozilla\Firefox\Profiles\tu81cpd1.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
    Pasta Removido : C:\Documents and Settings\f002282\Dados de aplicativos\Mozilla\Firefox\Profiles\tu81cpd1.default\SweetIMToolbarData
    Pasta Removido : C:\Documents and Settings\f003314\Dados de aplicativos\Mozilla\Firefox\Profiles\83qyyhjc.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}

    ***** [Registro] *****

    Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Chave Removida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Chave Removida : HKLM\Software\Classes\Installer\Products\758F5690DAAD39F40845E0E23C8C5C0B
    Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{0965F857-DAAD-4F93-8054-0E2EC3C8C5B0}
    Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Chave Removida : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
    Chave Removida : HKLM\SOFTWARE\Software

    ***** [Navegadores] *****

    -\\ Internet Explorer v8.0.6001.18702

    [OK] Registro está limpo.

    -\\ Mozilla Firefox v3.6.28 (pt-BR)

    Arquivo : C:\Documents and Settings\f003314\Dados de aplicativos\Mozilla\Firefox\Profiles\83qyyhjc.default\prefs.js

    [OK] Arquivo está limpo.

    Arquivo : C:\Documents and Settings\f002282\Dados de aplicativos\Mozilla\Firefox\Profiles\tu81cpd1.default\prefs.js

    C:\Documents and Settings\f002282\Dados de aplicativos\Mozilla\Firefox\Profiles\tu81cpd1.default\user.js ... Removido !

    Removida : user_pref("CT2233703..clientLogIsEnabled", true);
    Removida : user_pref("CT2233703..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
    Removida : user_pref("CT2233703..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
    Removida : user_pref("CT2233703.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
    Removida : user_pref("CT2233703.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
    Removida : user_pref("CT2233703.BrowserCompStateIsOpen_129690223998609054", true);
    Removida : user_pref("CT2233703.BrowserCompStateIsOpen_129914005525627596", true);
    Removida : user_pref("CT2233703.BrowserCompStateIsOpen_130074650688786960", true);
    Removida : user_pref("CT2233703.BrowserCompStateIsOpen_1359634297000", true);
    Removida : user_pref("CT2233703.CTID", "CT2233703");
    Removida : user_pref("CT2233703.CurrentServerDate", "5-4-2013");
    Removida : user_pref("CT2233703.DialogsAlignMode", "LTR");
    Removida : user_pref("CT2233703.DialogsGetterLastCheckTime", "Mon Apr 01 2013 08:37:27 GMT-0300 (Hora oficial d[...]
    Removida : user_pref("CT2233703.DownloadReferralCookieData", "");
    Removida : user_pref("CT2233703.EMailNotifierPollDate", "Thu May 24 2012 10:07:04 GMT-0300 (Hora oficial do Bra[...]
    Removida : user_pref("CT2233703.FirstServerDate", "17-5-2011");
    Removida : user_pref("CT2233703.FirstTime", true);
    Removida : user_pref("CT2233703.FirstTimeFF3", true);
    Removida : user_pref("CT2233703.FixPageNotFoundErrors", true);
    Removida : user_pref("CT2233703.GroupingServerCheckInterval", 1440);
    Removida : user_pref("CT2233703.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
    Removida : user_pref("CT2233703.HasUserGlobalKeys", true);
    Removida : user_pref("CT2233703.Initialize", true);
    Removida : user_pref("CT2233703.InitializeCommonPrefs", true);
    Removida : user_pref("CT2233703.InstallationAndCookieDataSentCount", 3);
    Removida : user_pref("CT2233703.InstallationType", "UnknownIntegration");
    Removida : user_pref("CT2233703.InstalledDate", "Tue May 17 2011 12:06:23 GMT-0300 (Hora oficial do Brasil)");
    Removida : user_pref("CT2233703.InvalidateCache", false);
    Removida : user_pref("CT2233703.IsGrouping", false);
    Removida : user_pref("CT2233703.IsMulticommunity", false);
    Removida : user_pref("CT2233703.IsOpenThankYouPage", false);
    Removida : user_pref("CT2233703.IsOpenUninstallPage", false);
    Removida : user_pref("CT2233703.LanguagePackLastCheckTime", "Fri Apr 05 2013 15:38:32 GMT-0300 (Hora oficial do[...]
    Removida : user_pref("CT2233703.LanguagePackReloadIntervalMM", 1440);
    Removida : user_pref("CT2233703.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
    Removida : user_pref("CT2233703.LastLogin_3.15.1.0", "Fri Apr 05 2013 14:11:01 GMT-0300 (Hora oficial do Brasil[...]
    Removida : user_pref("CT2233703.LastLogin_3.2.4.0", "Thu May 24 2012 09:54:22 GMT-0300 (Hora oficial do Brasil)[...]
    Removida : user_pref("CT2233703.LatestVersion", "3.15.1.0");
    Removida : user_pref("CT2233703.Locale", "en");
    Removida : user_pref("CT2233703.MCDetectTooltipHeight", "83");
    Removida : user_pref("CT2233703.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
    Removida : user_pref("CT2233703.MCDetectTooltipWidth", "295");
    Removida : user_pref("CT2233703.MyStuffEnabledAtInstallation", true);
    Removida : user_pref("CT2233703.RadioIsPodcast", false);
    Removida : user_pref("CT2233703.RadioLastCheckTime", "Thu May 24 2012 09:54:21 GMT-0300 (Hora oficial do Brasil[...]
    Removida : user_pref("CT2233703.RadioLastUpdateIPServer", "3");
    Removida : user_pref("CT2233703.RadioLastUpdateServer", "129141247792900000");
    Removida : user_pref("CT2233703.RadioMediaID", "11027882");
    Removida : user_pref("CT2233703.RadioMediaType", "Media Player");
    Removida : user_pref("CT2233703.RadioMenuSelectedID", "EBRadioMenu_CT223370311027882");
    Removida : user_pref("CT2233703.RadioStationName", "DANCE%20radio");
    Removida : user_pref("CT2233703.RadioStationURL", "hxxp://www.abradio.cz/asx/danceradio32.asx");
    Removida : user_pref("CT2233703.SavedHomepage", "hxxp://go.microsoft.com/fwlink/?LinkId=69157");
    Removida : user_pref("CT2233703.SearchFromAddressBarIsInit", true);
    Removida : user_pref("CT2233703.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT223[...]
    Removida : user_pref("CT2233703.SearchInNewTabEnabled", true);
    Removida : user_pref("CT2233703.SearchInNewTabIntervalMM", 1440);
    Removida : user_pref("CT2233703.SearchInNewTabLastCheckTime", "Fri Apr 05 2013 15:38:27 GMT-0300 (Hora oficial [...]
    Removida : user_pref("CT2233703.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
    Removida : user_pref("CT2233703.SearchInNewTabUsageUrl", "hxxp://usage.hosting.toolbar.conduit-services.com/usa[...]
    Removida : user_pref("CT2233703.ServiceMapLastCheckTime", "Fri Apr 05 2013 15:38:29 GMT-0300 (Hora oficial do B[...]
    Removida : user_pref("CT2233703.SettingsLastCheckTime", "Fri Apr 05 2013 14:10:57 GMT-0300 (Hora oficial do Bra[...]
    Removida : user_pref("CT2233703.SettingsLastUpdate", "1365093283");
    Removida : user_pref("CT2233703.ThirdPartyComponentsInterval", 504);
    Removida : user_pref("CT2233703.ThirdPartyComponentsLastCheck", "Thu May 24 2012 09:54:19 GMT-0300 (Hora oficia[...]
    Removida : user_pref("CT2233703.ThirdPartyComponentsLastUpdate", "1331805997");
    Removida : user_pref("CT2233703.ToolbarShrinkedFromSetup", false);
    Removida : user_pref("CT2233703.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2233703");
    Removida : user_pref("CT2233703.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
    Removida : user_pref("CT2233703.UserID", "UN36114776092940193");
    Removida : user_pref("CT2233703.WeatherNetwork", "");
    Removida : user_pref("CT2233703.WeatherPollDate", "Thu May 24 2012 09:54:22 GMT-0300 (Hora oficial do Brasil)")[...]
    Removida : user_pref("CT2233703.WeatherUnit", "C");
    Removida : user_pref("CT2233703.alertChannelId", "631527");
    Removida : user_pref("CT2233703.backendstorage./9b+7e,x305", "2423");
    Removida : user_pref("CT2233703.backendstorage./9b+7e06cg5el;8i:k", "247E2D2F226A7473747171747875787D242F4B4947[...]
    Removida : user_pref("CT2233703.backendstorage./9b+7e3x305", "2423");
    Removida : user_pref("CT2233703.backendstorage./9b+7e6x305", "2423");
    Removida : user_pref("CT2233703.backendstorage./9b+7e7x305", "2423");
    Removida : user_pref("CT2233703.backendstorage./9b+7e<x305", "2423");
    Removida : user_pref("CT2233703.backendstorage./9b+7eax305", "2423");
    Removida : user_pref("CT2233703.backendstorage./9b+7ebe3g=;d9n9=d", "372C2D326975762E3A3C7B3A39434A494841434B26[...]
    Removida : user_pref("CT2233703.backendstorage./9b+7etx305", "2423");
    Removida : user_pref("CT2233703.backendstorage./9b-0?3g>d", "6A693B6F6B6C6D6D7A76474479207B4C7C77257D514F242A22[...]
    Removida : user_pref("CT2233703.backendstorage./9b-0?3g@6:5;", "");
    Removida : user_pref("CT2233703.backendstorage./9b-3=3eccja=f>", "247E333D2C452F4135276F297B7E7D21202F26313E424[...]
    Removida : user_pref("CT2233703.backendstorage./9b/>01=9a6k6<im;krie@pdawm", "6E6A68707374757677");
    Removida : user_pref("CT2233703.backendstorage./9b3=>@44i48?", "372C2D326975763342363341484779213F3E484F4E4D464[...]
    Removida : user_pref("CT2233703.backendstorage./9b5ba==9cjag", "673A716B6B7371757A7643794777797E787C7B507C");
    Removida : user_pref("CT2233703.backendstorage./9b6b11g4c56b>f;p;anr@p", "6E6D6E6B6B6E71767076767473");
    Removida : user_pref("CT2233703.backendstorage./9b9643g3/9e", "6A");
    Removida : user_pref("CT2233703.backendstorage./9b<:222h64<", "393F352F3E");
    Removida : user_pref("CT2233703.backendstorage./9b=+03eh8h8j?:", "4443");
    Removida : user_pref("CT2233703.backendstorage./9b?+e2a52d8", "372C2D326975762E3A3C7B3A39434A494841434B26514649[...]
    Removida : user_pref("CT2233703.backendstorage./9b?b0d:8aj62<h", "6D");
    Removida : user_pref("CT2233703.backendstorage./9ba@0<0bi6a7gn:6@l?", "6E6B");
    Removida : user_pref("CT2233703.backendstorage.shoppingapp.gk.exipres", "547565204D617920323920323031322030393A[...]
    Removida : user_pref("CT2233703.backendstorage.shoppingapp.gk.geolocation", "6272617A696C");
    Removida : user_pref("CT2233703.generalConfigFromLogin", "{"ApiMaxAlerts":"12","SocialDomains":"social.c[...]
    Removida : user_pref("CT2233703.homepageProtectorEnableByLogin", true);
    Removida : user_pref("CT2233703.initDone", true);
    Removida : user_pref("CT2233703.myStuffEnabled", true);
    Removida : user_pref("CT2233703.myStuffPublihserMinWidth", 400);
    Removida : user_pref("CT2233703.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
    Removida : user_pref("CT2233703.myStuffServiceIntervalMM", 1440);
    Removida : user_pref("CT2233703.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
    Removida : user_pref("CT2233703.revertSettingsEnabled", true);
    Removida : user_pref("CT2233703.searchProtectorDialogDelayInSec", 10);
    Removida : user_pref("CT2233703.searchProtectorEnableByLogin", true);
    Removida : user_pref("CT2233703.testingCtid", "");
    Removida : user_pref("CT2233703.toolbarAppMetaDataLastCheckTime", "Fri Apr 05 2013 15:38:31 GMT-0300 (Hora ofic[...]
    Removida : user_pref("CT2233703.toolbarContextMenuLastCheckTime", "Tue May 17 2011 12:06:26 GMT-0300 (Hora ofic[...]
    Removida : user_pref("CT2233703.usagesFlag", 2);
    Removida : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2233703/CT2233703[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/631527/627389/BR", ""0"")[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2233703", [...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2233703",[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", ""d76323372b05c3[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2233703&octid=[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2233703/CT2233703[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/equalizer[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/minimize.[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/play.gif"[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/stop.gif"[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/BankImages/RadioSkins/Bluenote/vol.gif",[...]
    Removida : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", ""70f[...]
    Removida : user_pref("CommunityToolbar.EngineOwner", "CT2233703");
    Removida : user_pref("CommunityToolbar.EngineOwnerGuid", "{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}");
    Removida : user_pref("CommunityToolbar.EngineOwnerToolbarId", "4shared.com");
    Removida : user_pref("CommunityToolbar.OriginalEngineOwner", "CT2233703");
    Removida : user_pref("CommunityToolbar.OriginalEngineOwnerGuid", "{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}");
    Removida : user_pref("CommunityToolbar.OriginalEngineOwnerToolbarId", "4shared.com");
    Removida : user_pref("CommunityToolbar.SearchFromAddressBarSavedUrl", "hxxp://www.bing.com/search?FORM=IEFM1&q=[...]
    Removida : user_pref("CommunityToolbar.ToolbarsList", "CT2233703");
    Removida : user_pref("CommunityToolbar.ToolbarsList2", "CT2233703");
    Removida : user_pref("CommunityToolbar.alert.alertInfoInterval", 1440);
    Removida : user_pref("CommunityToolbar.alert.alertInfoLastCheckTime", "Thu May 24 2012 09:54:19 GMT-0300 (Hora [...]
    Removida : user_pref("CommunityToolbar.alert.clientsServerUrl", "hxxp://alert.client.conduit.com");
    Removida : user_pref("CommunityToolbar.alert.locale", "en");
    Removida : user_pref("CommunityToolbar.alert.loginIntervalMin", 1440);
    Removida : user_pref("CommunityToolbar.alert.loginLastCheckTime", "Thu May 24 2012 09:54:19 GMT-0300 (Hora ofic[...]
    Removida : user_pref("CommunityToolbar.alert.loginLastUpdateTime", "1313487611");
    Removida : user_pref("CommunityToolbar.alert.messageShowTimeSec", 20);
    Removida : user_pref("CommunityToolbar.alert.servicesServerUrl", "hxxp://alert.services.conduit.com");
    Removida : user_pref("CommunityToolbar.alert.showTrayIcon", false);
    Removida : user_pref("CommunityToolbar.alert.userCloseIntervalMin", 300);
    Removida : user_pref("CommunityToolbar.alert.userId", "989c69c0-b541-4256-ab01-d5eea37c8736");
    Removida : user_pref("CommunityToolbar.globalUserId", "1ecc0800-ae2b-4758-bf78-c4fede869c09");
    Removida : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2233703");
    Removida : user_pref("browser.search.defaultengine", "Ask.com");
    Removida : user_pref("browser.search.defaultthis.engineName", "4shared Web Search");
    Removida : user_pref("browser.search.order.1", "Ask.com");
    Removida : user_pref("browser.search.selectedEngine", "SweetIM Search");
    Removida : user_pref("extensions.funmoods.admin", false);
    Removida : user_pref("extensions.funmoods.aflt", "pcmega1");
    Removida : user_pref("extensions.funmoods.cntry", "BR");
    Removida : user_pref("extensions.funmoods.cv", "cv5");
    Removida : user_pref("extensions.funmoods.dfltLng", "");
    Removida : user_pref("extensions.funmoods.dfltSrch", true);
    Removida : user_pref("extensions.funmoods.excTlbr", false);
    Removida : user_pref("extensions.funmoods.hdrMd5", "444B621203D992D37E50BE4FDEFD3725");
    Removida : user_pref("extensions.funmoods.hmpg", true);
    Removida : user_pref("extensions.funmoods.id", "585cbe860000000000006cf049fae4ac");
    Removida : user_pref("extensions.funmoods.instlDay", "15427");
    Removida : user_pref("extensions.funmoods.instlRef", "");
    Removida : user_pref("extensions.funmoods.lastVrsnTs", "1.5.12.28:48:02");
    Removida : user_pref("extensions.funmoods.newTab", true);
    Removida : user_pref("extensions.funmoods.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=pcmega1");
    Removida : user_pref("extensions.funmoods.noFFXTlbr", false);
    Removida : user_pref("extensions.funmoods.prdct", "funmoods");
    Removida : user_pref("extensions.funmoods.prtnrId", "funmoods");
    Removida : user_pref("extensions.funmoods.sg", "none");
    Removida : user_pref("extensions.funmoods.smplGrp", "none");
    Removida : user_pref("extensions.funmoods.srchPrvdr", "Search");
    Removida : user_pref("extensions.funmoods.tlbrId", "base");
    Removida : user_pref("extensions.funmoods.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=pcmega1&q=[...]
    Removida : user_pref("extensions.funmoods.vrsn", "1.5.12.2");
    Removida : user_pref("extensions.funmoods.vrsnTs", "1.5.12.28:48:02");
    Removida : user_pref("extensions.funmoods.vrsni", "1.5.12.2");
    Removida : user_pref("extensions.funmoods_i.aflt", "pcmega1");
    Removida : user_pref("extensions.funmoods_i.dfltLng", "");
    Removida : user_pref("extensions.funmoods_i.dfltSrch", true);
    Removida : user_pref("extensions.funmoods_i.dnsErr", true);
    Removida : user_pref("extensions.funmoods_i.excTlbr", false);
    Removida : user_pref("extensions.funmoods_i.hmpg", true);
    Removida : user_pref("extensions.funmoods_i.hmpgUrl", "hxxp://start.funmoods.com/?f=1&a=pcmega1");
    Removida : user_pref("extensions.funmoods_i.id", "585cbe860000000000006cf049fae4ac");
    Removida : user_pref("extensions.funmoods_i.instlDay", "15427");
    Removida : user_pref("extensions.funmoods_i.instlRef", "");
    Removida : user_pref("extensions.funmoods_i.newTab", true);
    Removida : user_pref("extensions.funmoods_i.newTabUrl", "hxxp://start.funmoods.com/?f=2&a=pcmega1");
    Removida : user_pref("extensions.funmoods_i.prdct", "funmoods");
    Removida : user_pref("extensions.funmoods_i.prtnrId", "funmoods");
    Removida : user_pref("extensions.funmoods_i.smplGrp", "none");
    Removida : user_pref("extensions.funmoods_i.srchPrvdr", "Search");
    Removida : user_pref("extensions.funmoods_i.tlbrId", "base");
    Removida : user_pref("extensions.funmoods_i.tlbrSrchUrl", "hxxp://start.funmoods.com/results.php?f=3&a=pcmega1&[...]
    Removida : user_pref("extensions.funmoods_i.vrsn", "1.5.12.2");
    Removida : user_pref("extensions.funmoods_i.vrsnTs", "1.5.12.28:48:02");
    Removida : user_pref("extensions.funmoods_i.vrsni", "1.5.12.2");
    Removida : user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2233703&q=");
    Removida : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
    Removida : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
    Removida : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
    Removida : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
    Removida : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
    Removida : user_pref("sweetim.toolbar.mode.debug", "false");
    Removida : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "Ask.com");
    Removida : user_pref("sweetim.toolbar.previous.browser.search.defaulturl", "hxxp://search.conduit.com/ResultsEx[...]
    Removida : user_pref("sweetim.toolbar.previous.browser.search.selectedEngine", "Search");
    Removida : user_pref("sweetim.toolbar.previous.browser.startup.homepage", "hxxp://start.funmoods.com/?f=1&a=pcm[...]
    Removida : user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://www.bing.com/search?FORM=IEFM1&q=");
    Removida : user_pref("sweetim.toolbar.search.external", "<?xml version="1.0"?><TOOLBAR><EXTERNAL_SEARCH engin[...]
    Removida : user_pref("sweetim.toolbar.search.history.capacity", "10");
    Removida : user_pref("sweetim.toolbar.searchguard.enable", "true");
    Removida : user_pref("sweetim.toolbar.simapp_id", "{C0FBB7B6-FCAB-4DFE-AEE0-C13846BA7864}");
    Removida : user_pref("sweetim.toolbar.urls.homepage", "hxxp://home.sweetim.com/?barid={C0FBB7B6-FCAB-4DFE-AEE0-[...]
    Removida : user_pref("sweetim.toolbar.version", "1.4.0.0");

    Arquivo : C:\Documents and Settings\f001770\Dados de aplicativos\Mozilla\Firefox\Profiles\1cjfwumb.default\prefs.js

    Removida : user_pref("browser.startup.homepage", "hxxp://br.ask.com/?l=dis&o=14597");

    Arquivo : C:\Documents and Settings\f002000\Dados de aplicativos\Mozilla\Firefox\Profiles\qvup0wvw.default\prefs.js

    Removida : user_pref("browser.startup.homepage", "hxxp://br.ask.com/?l=dis&o=14597");

    -\\ Google Chrome v26.0.1410.43

    Arquivo : C:\Documents and Settings\f002282\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Preferences

    Removida [l.1742] : homepage = "hxxp://start.funmoods.com/?f=1&a=pcmega1",
    Removida [l.2036] : urls_to_restore_on_startup = [ "hxxp://start.funmoods.com/?f=1&a=pcmega1" ]

    Arquivo : C:\Documents and Settings\f002488\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Preferences

    [OK] Arquivo está limpo.

    Arquivo : C:\Documents and Settings\f001770\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Preferences

    [OK] Arquivo está limpo.

    *************************

    AdwCleaner[S1].txt - [23283 octets] - [05/04/2013 16:25:07]

    ########## EOF - C:\AdwCleaner[S1].txt - [23344 octets] ##########

    joram
    Administrador Fundador
    Administrador Fundador

    Mensagens : 608
    Data de inscrição : 14/08/2012
    Idade : 63
    Localização : Rio de Janeiro

    Re: suspeita de virus log para analise.

    Mensagem por joram em Sex Abr 05, 2013 3:55 pm

    Boa Tarde! Edvan

    |- Instale o MBAM: < [Você precisa estar registrado e conectado para ver este link.] >

    |- Atualize o programa!

    [Você precisa estar registrado e conectado para ver este link.]

    |- Desmarque a caixa: "Ativar trial gratuito do Malwarebytes Anti-Malware PRO"
    |- Clique "Concluir".
    |- Escolha o escaneamento Rápido! >> Verificar!
    |- Desabilite programas de proteção,ao executar o malwarebytes.
    |- Para Windows Vista ou 7,clique direito no arquivo e execute-o como administrador.
    |- Ps: Para determinadas infecções,a ferramenta pedirá reboot. << Confirme!

    [Você precisa estar registrado e conectado para ver esta imagem.]

    |- Ao concluir,clique em "Ok" >> "Ver Resultados" >> "Remover Selecionados".
    |- Poste,o relatório: mbam-log-2013-xx-xx (00-00-00).txt
    |- Indo à janela principal do MBAM,clique na aba Logs para obter o relatório.

    A+

    Edvan
    Membro
    Membro

    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 36
    Localização : Natal/RN

    Re: suspeita de virus log para analise.

    Mensagem por Edvan em Sex Abr 05, 2013 4:12 pm

    Malwarebytes Anti-Malware 1.70.0.1100
    [Você precisa estar registrado e conectado para ver este link.]

    Versão da Base de Dados: v2013.04.05.09

    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 8.0.6001.18702
    f002282 :: FUN0123 [administrador]

    05/04/2013 16:58:36
    mbam-log-2013-04-05 (16-58-36).txt

    Tipo de Verificação: Verificação Rápida
    Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM
    Opções de verificação desativadas: P2P
    Objetos escaneados: 457813
    Tempo decorrido: 8 minuto(s), 27 segundo(s)

    Processos de Memória Detectados: 0
    (Não foram detectados ítens maliciosos)

    Módulos de Memória Detectados: 0
    (Não foram detectados ítens maliciosos)

    Chaves de Registro Detectadas: 0
    (Não foram detectados ítens maliciosos)

    Valores de Registro Detectadas: 0
    (Não foram detectados ítens maliciosos)

    Itens de Dados no Registro Detectadas: 0
    (Não foram detectados ítens maliciosos)

    Pastas Detectadas: 0
    (Não foram detectados ítens maliciosos)

    Arquivos Detectados: 0
    (Não foram detectados ítens maliciosos)

    (fim)

    joram
    Administrador Fundador
    Administrador Fundador

    Mensagens : 608
    Data de inscrição : 14/08/2012
    Idade : 63
    Localização : Rio de Janeiro

    Re: suspeita de virus log para analise.

    Mensagem por joram em Sex Abr 05, 2013 4:17 pm

    Olá! Edvan

    |- Baixe: |[Você precisa estar registrado e conectado para ver este link.]| ( ... de Xplode )

    [Você precisa estar registrado e conectado para ver esta imagem.]

    |- Estando na página,clique na seta verde para o download.
    |- Salve-a em um local conveniente! ( desktop! )
    |- Feche aplicativos que estejam abertos.

    [Você precisa estar registrado e conectado para ver este link.]

    |- Execute-a!
    |- Com as duas checkbox marcadas!
    |- Clique "Run".
    |- Tudo Ok?

    Abs!

    Edvan
    Membro
    Membro

    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 36
    Localização : Natal/RN

    Re: suspeita de virus log para analise.

    Mensagem por Edvan em Sex Abr 05, 2013 4:27 pm

    Tudo Ok amigo.

    # DelFix v10.2 - Logfile created 05/04/2013 at 17:24:03
    # Updated 02/04/2013 by Xplode
    # Username : f002282 - FUN0123

    ~ Removing disinfection tools ...


    ~ Cleaning system restore ...

    Deleted : RP #734 [Ponto de verificação do sistema | 01/22/2013 09:57:36]
    Deleted : RP #735 [Ponto de verificação do sistema | 01/23/2013 10:29:56]
    Deleted : RP #736 [Ponto de verificação do sistema | 01/24/2013 11:28:20]
    Deleted : RP #737 [Ponto de verificação do sistema | 01/29/2013 09:47:31]
    Deleted : RP #738 [Ponto de verificação do sistema | 01/31/2013 09:47:09]
    Deleted : RP #739 [Ponto de verificação do sistema | 02/01/2013 09:48:32]
    Deleted : RP #740 [Ponto de verificação do sistema | 02/04/2013 09:48:44]
    Deleted : RP #741 [Ponto de verificação do sistema | 02/05/2013 10:24:48]
    Deleted : RP #742 [Ponto de verificação do sistema | 02/06/2013 10:31:38]
    Deleted : RP #743 [Ponto de verificação do sistema | 02/07/2013 11:19:20]
    Deleted : RP #744 [Ponto de verificação do sistema | 02/08/2013 12:17:49]
    Deleted : RP #745 [Ponto de verificação do sistema | 02/14/2013 09:42:04]
    Deleted : RP #746 [Ponto de verificação do sistema | 02/15/2013 10:30:21]
    Deleted : RP #747 [Ponto de verificação do sistema | 02/18/2013 09:57:54]
    Deleted : RP #748 [Ponto de verificação do sistema | 02/19/2013 12:36:52]
    Deleted : RP #749 [Ponto de verificação do sistema | 02/20/2013 14:03:13]
    Deleted : RP #750 [Ponto de verificação do sistema | 02/21/2013 14:36:30]
    Deleted : RP #751 [Ponto de verificação do sistema | 02/22/2013 15:15:07]
    Deleted : RP #752 [Ponto de verificação do sistema | 02/25/2013 09:44:38]
    Deleted : RP #753 [Ponto de verificação do sistema | 02/26/2013 09:47:13]
    Deleted : RP #754 [Ponto de verificação do sistema | 02/27/2013 10:26:17]
    Deleted : RP #755 [Ponto de verificação do sistema | 02/28/2013 10:28:02]
    Deleted : RP #756 [Ponto de verificação do sistema | 03/01/2013 11:11:39]
    Deleted : RP #757 [Ponto de verificação do sistema | 03/04/2013 09:36:07]
    Deleted : RP #758 [Ponto de verificação do sistema | 03/05/2013 10:19:52]
    Deleted : RP #759 [Ponto de verificação do sistema | 03/06/2013 11:57:15]
    Deleted : RP #760 [Ponto de verificação do sistema | 03/07/2013 12:26:46]
    Deleted : RP #761 [Ponto de verificação do sistema | 03/08/2013 13:17:04]
    Deleted : RP #762 [Ponto de verificação do sistema | 03/11/2013 09:42:07]
    Deleted : RP #763 [Ponto de verificação do sistema | 03/12/2013 10:26:10]
    Deleted : RP #764 [Ponto de verificação do sistema | 03/13/2013 10:29:52]
    Deleted : RP #765 [Ponto de verificação do sistema | 03/14/2013 12:45:59]
    Deleted : RP #766 [Ponto de verificação do sistema | 03/15/2013 13:16:01]
    Deleted : RP #767 [Ponto de verificação do sistema | 03/18/2013 09:41:17]
    Deleted : RP #768 [Ponto de verificação do sistema | 03/19/2013 10:23:31]
    Deleted : RP #769 [Ponto de verificação do sistema | 03/20/2013 10:28:36]
    Deleted : RP #770 [Ponto de verificação do sistema | 03/21/2013 11:22:36]
    Deleted : RP #771 [Ponto de verificação do sistema | 03/22/2013 13:18:51]
    Deleted : RP #772 [Ponto de verificação do sistema | 03/25/2013 09:47:00]
    Deleted : RP #773 [Ponto de verificação do sistema | 03/26/2013 10:29:34]
    Deleted : RP #774 [Ponto de verificação do sistema | 03/27/2013 10:52:48]
    Deleted : RP #775 [Ponto de verificação do sistema | 04/01/2013 09:48:40]
    Deleted : RP #776 [Ponto de verificação do sistema | 04/02/2013 09:53:02]
    Deleted : RP #777 [Ponto de verificação do sistema | 04/03/2013 10:24:25]
    Deleted : RP #778 [Ponto de verificação do sistema | 04/04/2013 10:36:57]
    Deleted : RP #779 [Installed Franson GpsGate 2.6 | 04/04/2013 13:11:30]
    Deleted : RP #780 [Removed Franson GpsGate 2.6 | 04/04/2013 13:32:21]
    Deleted : RP #781 [Ponto de verificação do sistema | 04/05/2013 15:07:58]

    New restore point created !

    ########## - EOF - ##########

    joram
    Administrador Fundador
    Administrador Fundador

    Mensagens : 608
    Data de inscrição : 14/08/2012
    Idade : 63
    Localização : Rio de Janeiro

    Re: suspeita de virus log para analise.

    Mensagem por joram em Sex Abr 05, 2013 4:39 pm

    CASO RESOLVIDO!

    Necessitando novo auxílio para este computador,basta abrir "Novo Tópico" e relatar o problema.

    Conteúdo patrocinado

    Re: suspeita de virus log para analise.

    Mensagem por Conteúdo patrocinado Hoje à(s) 12:58 pm


      Data/hora atual: Sex Dez 02, 2016 12:58 pm