Fórum SecSecurity

Gostaria de reagir a esta mensagem? Crie uma conta em poucos cliques ou inicie sessão para continuar.
Fórum SecSecurity

Implementando Limpeza e Seguranca em seu computador!

Palavras-chaves

Últimos assuntos

» OpenTip (...by Kaspersky.com)
PC lento, log para analise. EmptySáb Mar 23, 2024 10:28 am por joram

» KpRm ( ... by Kernel-panik )
PC lento, log para analise. EmptyTer Ago 11, 2020 9:47 pm por joram

» ESET Rogue Applications Remover ( ... by Eset.com )
PC lento, log para analise. EmptySáb Ago 01, 2020 7:49 am por joram

» PW Clean 2.7 ( ... by Doutor PW )
PC lento, log para analise. EmptyTer maio 15, 2018 9:27 am por joram

» CKScanner ( ... by askey127 )
PC lento, log para analise. EmptySáb maio 05, 2018 1:12 pm por joram

» AdwCleaner ( ... by XPlode )
PC lento, log para analise. EmptySeg Abr 16, 2018 8:47 am por joram

» ZHPDiag ( ... de Nicolas Coolman )
PC lento, log para analise. EmptySáb Abr 14, 2018 8:56 am por joram

» Argente - Registry Cleaner ( ... by Argente Software )
PC lento, log para analise. EmptyDom Nov 19, 2017 4:36 pm por joram

» ListChkdskResult ( ... by SleepyDude )
PC lento, log para analise. EmptyDom Set 24, 2017 1:39 pm por joram

novembro 2024

SegTerQuaQuiSexSábDom
    123
45678910
11121314151617
18192021222324
252627282930 

Calendário Calendário

Parceiros

Fórum grátis

Os membros mais mencionados

Nenhum usuário

2 participantes

    PC lento, log para analise.

    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 44
    Localização : Natal/RN

    PC lento, log para analise. Empty PC lento, log para analise.

    Mensagem por Edvan Qua Ago 14, 2013 3:56 pm

    A versão nova do ZHPDiag está linda.
     O AdwCleaner Também.

    Log para analise [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

    # AdwCleaner v3.000 - Report created14/08/2013at16:15:44
    # Updated 13/08/2013 by Xplode
    # Operating System : Microsoft Windows XP Service Pack 3 (32 bits)
    # Username : f002902 - FUN0004
    # Running from : C:\Documents and Settings\f002902\Desktop\adwcleaner.exe

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****


    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****


    ***** [ Browsers ] *****

    -\\ Internet Explorer v8.0.6001.18702

    Setting Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch] - [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    Setting Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant] - [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

    -\\ Mozilla Firefox v3.6.24 (pt-BR)

    File Deleted : C:\Documents and Settings\f002519\Dados de aplicativos\Mozilla\Firefox\Profiles\t2hdf4cf.default\.autoreg
    File Deleted : C:\Arquivos de programas\Mozilla Firefox\.autoreg

    [ File : C:\Documents and Settings\f002519\Dados de aplicativos\Mozilla\Firefox\Profiles\t2hdf4cf.default\prefs.js ]

    [OK] No bad entry found.

    [ File : C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\prefs.js ]

    Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.style", ".WRCN {display:none} #yui-main .tsrc_vnru .ti[...]
    Line Deleted : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\:\\/\\/(.+\\.)?ask\\.com\\/.*");
    Line Deleted : user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .search-results .titl[...]

    -\\ Google Chrome v28.0.1500.95


    [ File : C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\preferences ]

    [OK] No bad entry found.

    [ File : C:\Documents and Settings\f002902\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\preferences ]

    [OK] No bad entry found.

    *************************

    AdwCleaner[0].txt - [2015 octets] - [14/08/2013 16:15:44]

    ########## EOF - C:\AdwCleaner\AdwCleaner[0].txt - [2074 octets] ##########



    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 5.4.5 (08.13.2013:1)
    OS: Microsoft Windows XP x86
    Ran by f002902 on 14/08/2013 at 16:24:46,84
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Registry Values

    Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
    Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



    ~~~ Registry Keys

    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}



    ~~~ Files



    ~~~ Folders



    ~~~ FireFox

    Emptied folder: C:\Documents and Settings\f002902\Dados de aplicativos\mozilla\firefox\profiles\bchmt8c8.default\minidumps [1 files]





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 14/08/2013 at 16:28:57,59
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    joram
    joram
    Administrador Fundador
    Administrador Fundador


    Mensagens : 626
    Data de inscrição : 14/08/2012
    Idade : 71
    Localização : Rio de Janeiro

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por joram Qua Ago 14, 2013 4:39 pm

    Boa Tarde! Edvan

    O3 - Toolbar\WebBrowser: (no name) - [HKCU]{EF99BD32-C1FB-11D2-892F-0090271D4F88} Chave órfão    => Yahoo Companion!
    O3 - Toolbar\WebBrowser: (no name) - [HKCU]{0E5CBF21-D15F-11D0-8301-00AA005B4383} Chave órfão    => Infection BT (Cram Toolbar.Adw)
    O20 - Winlogon Notify: DkWLNP . (.SafeNet, Inc. - SafeNet Virtual Driver for Citrix..) -- C:\WINDOWS\system32\DkWLNP.dll    => Infection Vundo
    O20 - Winlogon Notify:  GbPluginCef . (...) -- C:\Arquivos de programas\GbPlugin\gbiehCef.dll (.not file.)
    O45 - LFCP:[MD5.D24D224DEE14122605C9D95DA1F2AC58] - 06/08/2013 - 18:30:41 ---A- - C:\WINDOWS\Prefetch\SWAP.EXE-3B3C2F3B.pf
    O45 - LFCP:[MD5.6F6D8DB7ECEDEA5FB2ECC7E977660218] - 13/08/2013 - 17:05:20 ---A- - C:\WINDOWS\Prefetch\HPPSCAN0.EXE-0D67BAEC.pf
    O45 - LFCP:[MD5.0EC752BF52D5271295CD078290000B79] - 14/08/2013 - 08:20:29 ---A- - C:\WINDOWS\Prefetch\FUNPEC.EXE-0C5E44B0.pf
    O45 - LFCP:[MD5.918FD2F3C4335D34AA56CA4D60E9ADF8] - 14/08/2013 - 13:50:35 ---A- - C:\WINDOWS\Prefetch\THUNDERBIRDPORTABLE.EXE-2013993C.pf
    O45 - LFCP:[MD5.8828616558BC324EE54494594885450E] - 14/08/2013 - 15:48:38 ---A- - C:\WINDOWS\Prefetch\NFECOMM.EXE-1C2E844C.pf
    O45 - LFCP:[MD5.F446D58F4A2C5970E1B016B0C8C859D8] - 14/08/2013 - 16:07:45 ---A- - C:\WINDOWS\Prefetch\AXMONITOR.EXE-31F7ADF3.pf
    O45 - LFCP:[MD5.67EFA8398ADB619F8F0E8D25A4092C92] - 14/08/2013 - 16:07:48 ---A- - C:\WINDOWS\Prefetch\DKAUTOREG.EXE-1948992B.pf
    O45 - LFCP:[MD5.F1A3599A738A92216E94EC2B2902F354] - 14/08/2013 - 16:07:49 ---A- - C:\WINDOWS\Prefetch\DANFEMON.EXE-0695F483.pf
    O45 - LFCP:[MD5.EFC942FFB34E8E573585D8545308DFEC] - 14/08/2013 - 16:07:56 ---A- - C:\WINDOWS\Prefetch\DANFEV.EXE-0540CC3F.pf
    O45 - LFCP:[MD5.C8218954050B7B9D6E13F79BF35BF730] - 14/08/2013 - 16:07:56 ---A- - C:\WINDOWS\Prefetch\UNIDANFE.EXE-377DC2B9.pf
    O45 - LFCP:[MD5.B2BE6681FAB733ABF671634722D04781] - 14/08/2013 - 16:08:03 ---A- - C:\WINDOWS\Prefetch\DANFEMON.EXE-0DAD2C6D.pf
    O45 - LFCP:[MD5.AAB6BB048F80A876575282B630994E83] - 14/08/2013 - 16:24:49 ---A- - C:\WINDOWS\Prefetch\JRT.EXE-1D158E9B.pf
    O45 - LFCP:[MD5.0C11AE9C9D39E96311C800798F1D1097] - 14/08/2013 - 16:28:57 ---A- - C:\WINDOWS\Prefetch\NIRCMD.DAT-2F897858.pf
    O51 - MPSK:{2bcd4003-dfe9-11e2-b81b-001a4d78d5e2}\AutoRun\command. (...) -- E:\SISetup.exe (.not file.)
    O51 - MPSK:{34c891d0-d0e9-11dd-b2ae-001a4d78d5e2}\AutoRun\command. (...) -- C:\WINDOWS\system32\Start.exe (.not file.)

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}]    => Yahoo Companion!
    [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{EF99BD32-C1FB-11D2-892F-0090271D4F88}    => Yahoo Companion!
    [HKLM\Software\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]    
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]    
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]    
    [HKLM\Software\Classes\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]    
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]    
    [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}]    

    [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{EF99BD32-C1FB-11D2-892F-0090271D4F88}    

    C:\Arquivos de programas\Yahoo!
    C:\Arquivos de programas\Mozilla FireFox\searchplugins\yahoo-br.xml

    [HKCU\Software\Yahoo]    
    [HKCU\Software\yahooinstall]    
    [HKLM\Software\Yahoo]

    emptytemp
        
    |- Cole este script em ZHPFix.
    |- Poste o log!

    A+


    Última edição por joram em Qui Ago 15, 2013 9:15 am, editado 1 vez(es)
    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 44
    Localização : Natal/RN

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por Edvan Qua Ago 14, 2013 4:42 pm

    Rapport de ZHPFix 2013.7.20.5 par Nicolas Coolman, Update du 20/07/2013
    Fichier d'export Registre : 
    Run by f002902 at 14/08/2013 17:41:48
    High Elevated Privileges : OK
    Windows XP Professional Service Pack 3 (Build 2600)

    Recycle Files Deleted

    ========== Registry Key ==========
    DELETED  Key: CLSID: [HKLM\SOFTWARE\Classes\CLSID\{0E5CBF21-D15F-11D0-8301-00AA005B4383}]
    DELETED Key: Winlogon Notify: DkWLNP
    DELETED Key: Winlogon Notify:  GbPluginCef
    DELETED CLSID MPSK: {2bcd4003-dfe9-11e2-b81b-001a4d78d5e2}
    DELETED CLSID MPSK: {34c891d0-d0e9-11dd-b2ae-001a4d78d5e2}
    DELETED Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    DELETED Key: HKLM\Software\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    DELETED Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
    DELETED Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
    DELETED Key: HKLM\Software\Classes\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
    DELETED Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}
    NOT FOUND Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    DELETED Key: HKCU\Software\Yahoo
    DELETED Key: HKCU\Software\yahooinstall
    DELETED Key: HKLM\Software\Yahoo

    ========== Registry Value ==========
    DELETED Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88}
    DELETED Toolbar: {0E5CBF21-D15F-11D0-8301-00AA005B4383}
    NOT FOUND [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{EF99BD32-C1FB-11D2-892F-0090271D4F88}

    ========== Repertory ==========
    DELETED Folder: c:\arquivos de programas\yahoo!
    DELETED Window Temporary

    ========== File ==========
    DELETE on Reboot c:\windows\system32\dkwlnp.dll
    NOT FOUND File: c:\arquivos de programas\gbplugin\gbiehcef.dll
    DELETED File: c:\windows\prefetch\swap.exe-3b3c2f3b.pf 
    DELETED File: c:\windows\prefetch\hppscan0.exe-0d67baec.pf 
    DELETED File: c:\windows\prefetch\funpec.exe-0c5e44b0.pf 
    DELETED File: c:\windows\prefetch\thunderbirdportable.exe-2013993c.pf 
    DELETED File: c:\windows\prefetch\nfecomm.exe-1c2e844c.pf 
    DELETED File: c:\windows\prefetch\axmonitor.exe-31f7adf3.pf 
    DELETED File: c:\windows\prefetch\dkautoreg.exe-1948992b.pf 
    DELETED File: c:\windows\prefetch\danfemon.exe-0695f483.pf 
    DELETED File: c:\windows\prefetch\danfev.exe-0540cc3f.pf 
    DELETED File: c:\windows\prefetch\unidanfe.exe-377dc2b9.pf 
    DELETED File: c:\windows\prefetch\danfemon.exe-0dad2c6d.pf 
    DELETED File: c:\windows\prefetch\jrt.exe-1d158e9b.pf 
    DELETED File: c:\windows\prefetch\nircmd.dat-2f897858.pf 
    DELETED File: C:\Arquivos de programas\Mozilla FireFox\searchplugins\yahoo-br.xml
    DELETED File***: c:\arquivos de programas\mozilla firefox\searchplugins\yahoo-br.xml
    DELETED Window Temporary


    ========== Summary ==========
    15 : Registry Key
    3 : Registry Value
    2 : Repertory
    18 : File


    End of clean in 01mn 11s

    ========== Report File ==========
    C:\ZHP\ZHPFix[R1].txt - 14/08/2013 17:42:03 [3102]
    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 44
    Localização : Natal/RN

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por Edvan Qui Ago 15, 2013 7:00 am

    ComboFix 13-08-14.02 - f002902 14/08/2013  18:01:00.2.2 - x86
    Microsoft Windows XP Professional  5.1.2600.3.1252.55.1046.18.1983.1467 [GMT -3:00]
    Executando de: c:\documents and settings\f002902\Desktop\ComboFix.exe
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .
    ADS - drivers: deleted 8 bytes in 1 streams.
    .
    (((((((((((((((((((((((((((((((((((((   Outras Exclusões   )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\documents and settings\All Users\5uk2HCmq.ico
    c:\documents and settings\All Users\Dados de aplicativos\TEMP
    c:\documents and settings\All Users\Dados de aplicativos\TEMP\gbplugin_ie_bb_setup.exe
    c:\documents and settings\f002902\Meus documentos\Readiris.DUS
    c:\windows\IsUn0416.exe
    c:\windows\system\chron32.dll
    c:\windows\system32\bios_setup110.txt
    .
    .
    ((((((((((((((((   Arquivos/Ficheiros criados de 2013-07-14 to 2013-08-14  ))))))))))))))))))))))))))))
    .
    .
    2013-08-14 19:34 . 2013-08-14 19:34 512 ----a-w- C:\PhysicalDisk0_MBR.bin
    2013-08-14 19:29 . 2013-08-14 20:42 -------- d-----w- C:\ZHP
    2013-08-14 19:29 . 2013-08-14 19:34 -------- d-----w- c:\arquivos de programas\ZHPDiag
    2013-08-14 19:24 . 2013-08-14 19:24 -------- d-----w- c:\windows\ERUNT
    2013-08-14 19:15 . 2013-08-14 19:21 -------- d-----w- C:\AdwCleaner
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((   Relatório Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2013-06-28 12:12 . 2013-06-28 12:12 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
    2013-06-28 12:12 . 2008-07-17 13:15 144896 ----a-w- c:\windows\system32\javacpl.cpl
    2013-06-28 12:12 . 2013-06-28 12:12 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
    2013-06-28 12:12 . 2010-12-09 17:37 789416 ----a-w- c:\windows\system32\deployJava1.dll
    2013-06-27 21:03 . 2013-03-04 15:01 175176 ----a-w- c:\windows\system32\drivers\aswVmm.sys
    2013-06-27 21:03 . 2011-05-19 19:20 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2013-06-27 21:03 . 2008-12-30 17:38 369584 ----a-w- c:\windows\system32\drivers\aswSP.sys
    .
    .
    ((((((((((((((((((((((((((   Pontos de Carregamento do Registro   )))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* entradas vazias e legítimas por padrão não são apresentadas. 
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
    @="{472083B0-C522-11CF-8763-00608CC02F24}"
    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
    2013-05-09 08:58 121968 ----a-w- c:\arquivos de programas\Alwil Software\Avast5\ashShell.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DkStartup"="c:\arquivos de programas\SafeNet\BSecClient\dkstartup.exe" [2008-07-29 49152]
    "AxMonitor"="c:\arquivos de programas\SafeNet\BSecClient\axmonitor.exe" [2008-07-29 450560]
    "DkAutoReg"="c:\arquivos de programas\SafeNet\BSecClient\DkAutoReg.exe" [2008-07-29 253952]
    "Adobe Reader Speed Launcher"="c:\arquivos de programas\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
    "DANFEmon"="c:\arquivos de programas\danfeview\danfemon.exe" [2011-07-27 3449856]
    "avast"="c:\arquivos de programas\Alwil Software\Avast5\avastUI.exe" [2013-05-09 4858968]
    "Adobe ARM"="c:\arquivos de programas\Arquivos comuns\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
    "HPUsageTrackingLEDM"="c:\arquivos de programas\HP\HP UT LEDM\bin\hppusg.exe" [2009-10-15 30264]
    "SunJavaUpdateSched"="c:\arquivos de programas\Arquivos comuns\Java\Java Update\jusched.exe" [2013-03-12 253816]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
    2005-05-03 10:43 69632 -c--a-r- c:\windows\ALCMTR.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
    2006-05-04 08:26 2808832 -c--a-r- c:\windows\ALCWZRD.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    2007-06-01 13:21 153136 ----a-w- c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
    2006-10-27 03:47 31016 ----a-w- c:\arquivos de programas\Microsoft Office\Office12\GrooveMonitor.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDAudDeck]
    2007-05-11 07:47 790528 ----a-r- c:\arquivos de programas\VIA\VIAudioi\HDADeck\HDeck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    2007-03-01 18:57 153136 ----a-w- c:\arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
    2007-07-05 08:08 16380416 -c--a-r- c:\windows\RTHDCPL.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
    2007-06-15 08:45 1826816 -c--a-r- c:\windows\SkyTel.exe
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
    2006-07-21 08:14 86016 -c--a-r- c:\windows\SOUNDMAN.EXE
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
    2006-09-21 08:36 53248 ----a-r- c:\windows\system32\VTTimer.exe
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Arquivos de programas\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Arquivos de programas\\Microsoft Office\\Office12\\GROOVE.EXE"=
    "c:\\Arquivos de programas\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Arquivos de programas\\Microsoft Silverlight\\4.1.10329.0\\Silverlight.Configuration.exe"=
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
    .
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
    "AllowInboundEchoRequest"= 1 (0x1)
    .
    R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [04/03/2013 12:01 49376]
    R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [04/03/2013 12:01 175176]
    R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [22/02/2010 17:16 46888]
    R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [13/01/2009 15:25 16896]
    R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [13/01/2009 15:25 52224]
    R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [19/05/2011 16:20 770344]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [30/12/2008 14:38 369584]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/12/2008 14:38 29816]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [04/03/2013 12:01 66336]
    R2 DkVcm;SafeNet Virtual Channel Monitor;c:\windows\system32\dkvcm.exe [29/07/2008 07:01 122880]
    R2 HPSIService;HP SI Service;c:\windows\system32\HPSIsvc.exe [28/06/2013 08:53 100232]
    R3 iKeyEnum;Rainbow iKey Enumerator;c:\windows\system32\drivers\IKEYENUM.SYS [10/11/2009 15:40 12240]
    R3 iKeyIFD;Rainbow iKey Virtual Reader;c:\windows\system32\drivers\IKEYIFD.SYS [10/11/2009 15:40 18704]
    R3 NdisrdMP;NdisrdMP;c:\windows\system32\drivers\GbpNdisrd.sys [28/12/2011 07:48 29432]
    S2 GbpSv;Gbp Service;c:\arquiv~1\GbPlugin\GbpSv.exe --> c:\arquiv~1\GbPlugin\GbpSv.exe [?]
    S2 gupdate;Serviço do Google Update (gupdate);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [27/02/2012 07:45 136176]
    S3 gupdatem;Serviço do Google Update (gupdatem);c:\arquivos de programas\Google\Update\GoogleUpdate.exe [27/02/2012 07:45 136176]
    S3 mvusbews;USB EWS Device;c:\windows\system32\drivers\mvusbews.sys [28/06/2013 08:54 16896]
    S3 Ndisrd;GAS Tecnologia Service;c:\windows\system32\drivers\GbpNdisrd.sys [28/12/2011 07:48 29432]
    S3 RnbToken;Rainbow iKey Token Service;c:\windows\system32\drivers\RNBTOKEN.SYS [10/11/2009 15:40 22096]
    S4 vision;bosrtibha;c:\program files\8u6N4r\3M7K3s.exe --> c:\program files\8u6N4r\3M7K3s.exe [?]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2013-07-31 16:31 1173456 ----a-w- c:\arquivos de programas\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe
    .
    Conteúdo da pasta 'Tarefas Agendadas'
    .
    2013-08-14 c:\windows\Tasks\avast! Emergency Update.job
    - c:\arquivos de programas\Alwil Software\Avast5\AvastEmUpdate.exe [2012-07-02 08:58]
    .
    2013-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2012-02-27 10:44]
    .
    2013-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\arquivos de programas\Google\Update\GoogleUpdate.exe [2012-02-27 10:44]
    .
    2013-08-14 c:\windows\Tasks\User_Feed_Synchronization-{B62FD68D-8CB9-46BA-AFD2-0B9F96BEA28B}.job
    - c:\windows\system32\msfeedssync.exe [2009-03-08 07:31]
    .
    .
    ------- Scan Suplementar -------
    .
    uStart Page = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    IE: E&xportar para o Microsoft Excel - c:\arquiv~1\MICROS~2\Office12\EXCEL.EXE/3000
    Trusted Zone: bancobrasil.com.br\www
    Trusted Zone: bancobrasil.com.br\www14
    Trusted Zone: bancobrasil.com.br\www2
    Trusted Zone: bb.com.br\www
    Trusted Zone: com.br\[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    Trusted Zone: com.br\[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    Trusted Zone: com.br\www14.bancobrasil
    Trusted Zone: com.br\www2.bancobrasil
    TCP: DhcpNameServer = 10.4.65.16
    DPF: Microsoft XML Parser for Java - [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    FF - ProfilePath - c:\documents and settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\
    FF - prefs.js: browser.startup.homepage - [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\arquivos de programas\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    FF - Ext: avast! Online Security: [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] - c:\arquivos de programas\Alwil Software\Avast5\WebRep\FF
    FF - Ext: SmartPrintButton: [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] - c:\arquivos de programas\Hewlett-Packard\SmartPrint\QPExtension
    FF - Ext: Modulo de Protecao - Banco do Brasil: {87F8774F-B485-47E2-A755-A40A8A5E886C} - %profile%\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}
    .
    - - - - ORFÃOS REMOVIDOS - - - -
    .
    HKLM-Run-HPUsageTracking - c:\arquivos de programas\HP\HP UT\bin\hppusg.exe
    Notify- GbPluginBb - c:\arquivos de programas\GbPlugin\gbieh.dll
    AddRemove-Mozilla Thunderbird (2.0.0.24) - c:\thunderbird padrão\App\thunderbird\uninstall\helper.exe
    .
    .
    .
    **************************************************************************
    .
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    Rootkit scan 2013-08-14 18:08
    Windows 5.1.2600 Service Pack 3 NTFS
    .
    Procurando processos ocultos ... 
    .
    Procurando entradas auto inicializáveis ocultas ... 
    .
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      HPUsageTracking = c:\arquivos de programas\HP\HP UT\bin\hppusg.exe "c:\arquivos de programas\HP\HP UT\"???? ??????????????????????????????????????? 
    .
    Procurando ficheiros/arquivos ocultos ... 
    .
    Varredura completada com sucesso
    arquivos/ficheiros ocultos: 0
    .
    **************************************************************************
    .
    Tempo para conclusão: 2013-08-14  18:09:57
    ComboFix-quarantined-files.txt  2013-08-14 21:09
    .
    Pré-execução: 11 pasta(s) 129.106.247.680 bytes disponíveis
    Pós execução: 15 pasta(s) 129.139.826.688 bytes disponíveis
    .
    - - End Of File - - 8FAFBA3906E5602545AA926A2E2F2542
    239FC8B1C26D5286165A956F5A98D8D7
    joram
    joram
    Administrador Fundador
    Administrador Fundador


    Mensagens : 626
    Data de inscrição : 14/08/2012
    Idade : 71
    Localização : Rio de Janeiro

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por joram Qui Ago 15, 2013 9:14 am

    Bom Dia! Edvan

    < c:\program files\8u6N4r\3M7K3s.exe >

    |- Conhece este arquivo Edvan?

    -/-

    |- Baixe: < [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] > ( ... by Smeenk )

    |- Ou aqui! < [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem][Tens de ter uma conta e sessão iniciada para poderes visualizar este link] >

    |- Salve-o no desktop!
    |- Desabilite seu antivírus!
    |- Para Windows 7,execute zoek.exe como administrador.

    resethosts;
    autoclean;
    emptyalltemp;


    |- Copie e cole estas informações,em vermelho,no campo da ferramenta.
    |- Clique "Run Script".

    Zoek.exe is running now.
    Do not start any browser windows, they will be closed automatically.
    Please wait! This window will close when finished.
    A logfile will open afterwards and can also be found on your systemdrive as zoek-results.log
    |- Surgirão estas informações,pedindo-lhe que aguarde o relatório.

    [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]

    |- Aceite e/ou confirme o reboot!

    zoek.hta failed by unknown error.
    Restart computer, and try again.
    |- Ps: Ao obter algum erro,reinicie o PC e execute,novamente,a ferramenta.
    |- Poste o relatório,que estará em C:\zoek-results.txt <<
    |- Poste,à seguir,um novo log do HijackThis.

    A+
    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 44
    Localização : Natal/RN

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por Edvan Qui Ago 15, 2013 9:16 am

     Bom Dia! [b style="margin: 0px; padding: 0px; color: rgb(97, 97, 97); font-family: Arial, Verdana, Tahoma, sans-serif; font-size: 12px; line-height: 16px; background-color: rgb(255, 255, 255);"]Edvan[/b]

    < c:\program files\8u6N4r\3M7K3s.exe >

    |- Conhece este arquivo [b style="margin: 0px; padding: 0px; color: rgb(97, 97, 97); font-family: Arial, Verdana, Tahoma, sans-serif; font-size: 12px; line-height: 16px; background-color: rgb(255, 255, 255);"]Edvan[/b]?
    Nao conheço amigo, abri a pasta nao tinha nada, deletei as pastas..agora vou passar a ferramenta zoek.exe.

     Toda vez que o pc é ligado, aparece essa mensagem no desktop!.
    [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]


    Última edição por Edvan em Qui Ago 15, 2013 9:44 am, editado 1 vez(es)
    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 44
    Localização : Natal/RN

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por Edvan Qui Ago 15, 2013 9:41 am

    pronto amigo..


    Zoek.exe Version 4.0.0.4 Updated 10-August-2013
    Tool run by f002902 on 15/08/2013 at 10:24:53,67.
    Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86
    Running in: Normal Mode Internet Access Detected
    Launched: C:\Documents and Settings\f002902\Desktop\zoek.exe [Script inserted] 

    ==== System Restore Info ======================

    15/08/2013 10:25:43 Zoek.exe System Restore Point Created Succesfully.

    ==== Reset Hosts File ======================

    # Copyright (c) 1993-2006 Microsoft Corp. 

    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows. 

    # This file contains the mappings of IP addresses to host names. Each 
    # entry should be kept on an individual line. The IP address should 
    # be placed in the first column followed by the corresponding host name. 
    # The IP address and the host name should be separated by at least one 
    # space. 

    # Additionally, comments (such as these) may be inserted on individual 
    # lines or following the machine name denoted by a '#' symbol. 

    # For example: 

    #      102.54.94.97     rhino.acme.com          # source server 
    #       38.25.63.10     x.acme.com              # x client host 
     
    127.0.0.1       localhost 

    ==== Suspicious Entries Found ======================

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "3389:TCP"="3389:TCP:*:Disabled:@xpsp2res.dll,-22009"
    "139:TCP"="139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004"
    "445:TCP"="445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005"
    "137:UDP"="137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001"
    "138:UDP"="138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002"
    "1900:UDP"="1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007"
    "2869:TCP"="2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008"

    ==== Deleting CLSID Registry Keys ======================

    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21252\Software\Microsoft\Internet Explorer\SearchScopes\{8C57A8CD-AA78-42BB-A7E9-2C2D588C4C02} deleted successfully

    ==== Deleting CLSID Registry Values ======================


    ==== Deleting Services ======================


    ==== FireFox Fix ======================

    ProfilePath: C:\Documents and Settings\f002519\Dados de aplicativos\Mozilla\Firefox\Profiles\t2hdf4cf.default

    user.js not found
    ---- Lines yahoo removed from prefs.js ----


    ---- Lines yahoo modified from prefs.js ----


    ---- FireFox user.js and prefs.js backups ---- 

    prefs_082013_1029_.backup

    ProfilePath: C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default

    user.js not found
    ---- Lines yahoo removed from prefs.js ----

    user_pref("extensions.wrc.SearchRules.yahoo.com.style", ".WRCN {display:none} .sm-hd .WRCN, .sm-links .WRCN, .res h3 > .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
    user_pref("extensions.wrc.SearchRules.yahoo.com.url", "^http(s)?\\:\\/\\/((.)+\\.)?search\\.yahoo\\.com\\/(.)*");

    ---- Lines yahoo modified from prefs.js ----


    ---- FireFox user.js and prefs.js backups ---- 

    prefs_082013_1029_.backup

    ==== Deleting Files \ Folders ======================

    "C:\WINDOWS\002695_.tmp" deleted
    "C:\WINDOWS\SET3.tmp" deleted
    "C:\WINDOWS\SET4.tmp" deleted
    "C:\WINDOWS\SET8.tmp" deleted
    "C:\found.000" deleted

    ==== Firefox Extensions ======================

    ProfilePath: C:\Documents and Settings\f002519\Dados de aplicativos\Mozilla\Firefox\Profiles\t2hdf4cf.default
    - Java Console - C:\Arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    - Java Console - C:\Arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    - Java Quick Starter - C:\Arquivos de programas\Java\jre6\lib\deploy\jqs\ff
    - Modulo de Protecao - Banco do Brasil - %ProfilePath%\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}

    ProfilePath: C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default
    - Java Console - C:\Arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    - Java Console - C:\Arquivos de programas\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    - avast Online Security - C:\Arquivos de programas\Alwil Software\Avast5\WebRep\FF
    - SmartPrintButton - C:\Arquivos de programas\Hewlett-Packard\SmartPrint\QPExtension
    - Modulo de Protecao - Banco do Brasil - %ProfilePath%\extensions\{87F8774F-B485-47E2-A755-A40A8A5E886C}

    ==== Firefox Plugins ======================

    Profilepath: C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default
    CF4ABE599858E10EEB911E16FBCFD87D - C:\Arquivos de programas\Windows Media Player\npdrmv2.dll - Microsoft® DRM
    02A4A41FAC9BF96155B3E8068D1DF4B6 - C:\Arquivos de programas\Windows Media Player\npwmsdrm.dll - Microsoft® DRM
    76E34EA1089E92709C5725407B565DA1 - C:\Arquivos de programas\Windows Media Player\npdsplay.dll - Windows Media Player Plug-in Dynamic Link Library
    87B41E7975298577BC56B6E82F0E6B34 - C:\Arquivos de programas\Java\jre7\bin\npjpi170_25.dll - Java(TM) Platform SE 7 U25
    101700E93EB905992B518256CB441829 - C:\Arquivos de programas\Google\Update\1.3.21.153\npGoogleUpdate3.dll - Google Update
    711A2E6A55EC7BFD59B5F649D58B704B - c:\Arquivos de programas\Microsoft Silverlight\4.1.10329.0\npctrl.dll - Silverlight Plug-In
    ABCB4A6EAB701C629378255ABCB308E5 - C:\Arquivos de programas\Java\jre7\bin\plugin2\npjp2.dll - Java(TM) Platform SE 7 U25
    D7324EB1EDCB8990F8522DE0311359E9 - C:\WINDOWS\system32\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17
    FE0D220C82B38ACA3D1C21F6E842661F - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll - Shockwave Flash
    D8B6E3361E06B43FCC0E8CBD9C088579 - C:\Arquivos de programas\Mozilla Firefox\plugins\npnul32.dll - Mozilla Default Plug-in
    9681C555F1B28E6A717772B420A9AEDF - C:\Arquivos de programas\Adobe\Reader 8.0\Reader\browser\nppdf32.dll - Adobe Acrobat


    ==== Chrome Look ======================


    ==== Set IE to Default ======================

    Old Values:
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    "Start Page"="http://www.funpec.br/ponto_online/"
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
    No DefaultScope Set For HKCU

    New Values:
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    "Start Page"="http://www.funpec.br/ponto_online/"
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

    ==== All HKCU SearchScopes ======================

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
    {0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
    {6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

    ==== Deleting CLSID Registry Keys ======================

    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21252\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E37CB5F0-51F5-4395-A808-5FA49E399F83} deleted successfully
    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21252\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E37CB5F0-51F5-4395-A808-5FA49E399F83} deleted successfully
    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21252\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E37CB5F0-51F5-4395-A808-5FA49E399003} deleted successfully
    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21252\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E37CB5F0-51F5-4395-A808-5FA49E399003} deleted successfully
    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21252\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21252\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21252\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C41A1C0E-EA6C-11D4-B1B8-444553540000} deleted successfully
    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21252\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C41A1C0E-EA6C-11D4-B1B8-444553540000} deleted successfully
    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21252\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C41A1C0E-EA6C-11D4-B1B8-444553540003} deleted successfully
    HKEY_USERS\S-1-5-21-2586132527-314635491-3328972525-21252\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C41A1C0E-EA6C-11D4-B1B8-444553540003} deleted successfully
    HKEY_CLASSES_ROOT\CLSID\{B5A7F190-DDA6-4420-B3BA-52453494E6CD} deleted successfully
    HKEY_CLASSES_ROOT\CLSID\{E37CB5F0-51F5-4395-A808-5FA49E399F83} deleted successfully
    HKEY_CLASSES_ROOT\CLSID\{E37CB5F0-51F5-4395-A808-5FA49E399003} deleted successfully
    HKEY_CLASSES_ROOT\CLSID\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully
    HKEY_CLASSES_ROOT\CLSID\{C41A1C0E-EA6C-11D4-B1B8-444553540000} deleted successfully
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540000} deleted successfully
    HKEY_CLASSES_ROOT\CLSID\{C41A1C0E-EA6C-11D4-B1B8-444553540003} deleted successfully
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C41A1C0E-EA6C-11D4-B1B8-444553540003} deleted successfully

    ==== Deleting CLSID Registry Values ======================

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B5A7F190-DDA6-4420-B3BA-52453494E6CD} deleted successfully
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{B5A7F190-DDA6-4420-B3BA-52453494E6CD} deleted successfully
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E37CB5F0-51F5-4395-A808-5FA49E399F83} deleted successfully
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{E37CB5F0-51F5-4395-A808-5FA49E399F83} deleted successfully
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E37CB5F0-51F5-4395-A808-5FA49E399003} deleted successfully
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{E37CB5F0-51F5-4395-A808-5FA49E399003} deleted successfully
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{72853161-30C5-4D22-B7F9-0BBC1D38A37E} deleted successfully

    ==== Empty IE Cache ======================

    C:\Documents and Settings\NetworkService\Configurações locais\Temporary Internet Files\Content.IE5 emptied successfully
    C:\WINDOWS\system32\config\systemprofile\Configurações locais\Temporary Internet Files\Content.IE5 emptied successfully
    C:\Documents and Settings\f002902\Configurações locais\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
    C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

    ==== Empty FireFox Cache ======================

    C:\Documents and Settings\f002519\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\t2hdf4cf.default\Cache emptied successfully
    C:\Documents and Settings\f002902\Configurações locais\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\Cache emptied successfully

    ==== Empty Chrome Cache ======================

    C:\Documents and Settings\f002902\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Cache emptied successfully
    C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Google\Chrome\User Data\Default\Cache emptied successfully

    ==== Empty All Flash Cache ======================

    Flash Cache Emptied Successfully

    ==== Empty All Java Cache ======================

    Java Cache cleared successfully

    ==== After Reboot ======================

    ==== Empty Temp Folders ======================

    C:\WINDOWS\Temp successfully emptied
    C:\DOCUME~1\f002902\CONFIG~1\Temp successfully emptied

    ==== Deleting Files / Folders ======================

    "C:\Documents and Settings\f002902\Configurações locais\Temporary Internet Files\Content.IE5\index.dat" not deleted
    "C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\index.dat" not deleted

    ==== EOF on 15/08/2013 at 10:33:44,26 ======================
    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 44
    Localização : Natal/RN

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por Edvan Qui Ago 15, 2013 9:54 am

    Antes de rodar o zoek.exe passei o avast em modo de segurança.

    [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]
    joram
    joram
    Administrador Fundador
    Administrador Fundador


    Mensagens : 626
    Data de inscrição : 14/08/2012
    Idade : 71
    Localização : Rio de Janeiro

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por joram Qui Ago 15, 2013 10:02 am

    Bom Dia! Edvan

    |- Utilize o HitmanPro em Modo de Segurança.
    |- Ao concluir,poste o relatório e desinstale-o.

    -/-

    |- Baixe: < [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] > ( Antimalware! )
    |- Salve-o em Arquivos de programas ou Program Files.
    |- Clique direito em "HitmanPro.exe" e execute-o como administrador.
    |- Clique "Próximo" -> Aceite o Acordo de licença.
    |- Clique "Próximo" e aguarde a finalização do escaneamento.
    |- Ao concluir,clique "Próximo" e ative a licença gratuita.

    [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

    |- Clique,novamente,em "Próximo" para que ocorra a remoção dos objetos detectados.
    |- Ao concluir,clique "Guardar relatório" e escolha seu desktop!
    |- Poste o relatório!

    Abs!
    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 44
    Localização : Natal/RN

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por Edvan Qui Ago 15, 2013 10:18 am

    Código:

    HitmanPro 3.7.3.193
    www.hitmanpro.com

       Computer name . . . . : FUN0004
       Windows . . . . . . . : 5.1.3.2600.X86/2
       Safe Mode Boot  . . . : MINIMAL
       User name . . . . . . : FUN0004\Administrador
       License . . . . . . . : Free

       Scan date . . . . . . : 2013-08-15 11:03:07
       Scan mode . . . . . . : Normal
       Scan duration . . . . : 4m 16s
       Disk access mode  . . : Direct disk access (SRB)
       Cloud . . . . . . . . : No connection
       Reboot  . . . . . . . : No

       Threats . . . . . . . : 0
       Traces  . . . . . . . : 8

       Objects scanned . . . : 506.116
       Files scanned . . . . : 14.978
       Remnants scanned  . . : 85.218 files / 405.920 keys

    Suspicious files ____________________________________________________________

       C:\Documents and Settings\f002902\Backup_HD_Tiago\Arquivos_Dados\Requisições\real\MP10Setup.exe
          Size . . . . . . . : 12.794.881 bytes
          Age  . . . . . . . : 783.1 days (2011-06-24 09:16:11)
          Entropy  . . . . . : 8.0
          SHA-256  . . . . . : 86ED2F0998759E27B1190104D88402293595A5B55A06577B252CB08CC45B4F84
          Product  . . . . . : Windows Media Component Setup Application
          Publisher  . . . . : Microsoft Corporation
          Description  . . . : Windows Media Component Setup Application
          Version  . . . . . : 10.00.00.3802
          Copyright  . . . . : (C) Microsoft Corporation. All rights reserved.
          RSA Key Size . . . : 2048
          Authenticode . . . : Invalid
          Fuzzy  . . . . . . : 23.0
             Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
             Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.

       C:\WINDOWS\PEV.exe
          Size . . . . . . . : 256.000 bytes
          Age  . . . . . . . : 0.7 days (2013-08-14 17:46:58)
          Entropy  . . . . . : 8.0
          SHA-256  . . . . . : AE0F5CC54E4B133DF66A54572A7CE52FAFF11F8FD0CAEAB088AAD3699D6EC924
          Fuzzy  . . . . . . : 22.0
             Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
             The .rsrc (resources) section in this program is set to executable. This is an indication of malware infection.
             Authors name is missing in version info. This is not common to most programs.
             Version control is missing. This file is probably created by an individual. This is not typical for most programs.
             Time indicates that the file appeared recently on this computer.
             The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
             Program contains PE structure anomalies. This is not typical for most programs.
          Forensic Cluster
             -10.9s C:\Documents and Settings\f002902\Menu Iniciar\Programas\Ferramentas administrativas\
             -10.8s C:\Documents and Settings\f002902\Menu Iniciar\Programas\Ferramentas administrativas\desktop.ini
             -8.0s C:\Qoobox\
             -8.0s C:\Qoobox\Quarantine\
             -8.0s C:\Qoobox\Quarantine\Registry_backups\
             -3.2s C:\Qoobox\BackEnv\
             -3.0s C:\Qoobox\Quarantine\catchme.log
             -0.0s C:\WINDOWS\grep.exe
             -0.0s C:\WINDOWS\sed.exe
             -0.0s C:\WINDOWS\SWSC.exe
             -0.0s C:\WINDOWS\SWXCACLS.exe
              0.0s C:\WINDOWS\PEV.exe
              0.0s C:\WINDOWS\SWREG.exe
              0.0s C:\WINDOWS\zip.exe
              0.0s C:\WINDOWS\MBR.exe
              0.0s C:\WINDOWS\NIRCMD.exe


    Cookies _____________________________________________________________________

       C:\Documents and Settings\Administrador\Cookies\administrador@adinterax[2].txt
       C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\cookies.sqlite:ad.yieldmanager.com
       C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\cookies.sqlite:atdmt.com
       C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\cookies.sqlite:doubleclick.net
       C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\cookies.sqlite:oracle.112.2o7.net
       C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\cookies.sqlite:statse.webtrendslive.com





    =========================xx========================


    Código:

    HitmanPro 3.7.3.193
    www.hitmanpro.com

       Computer name . . . . : FUN0004
       Windows . . . . . . . : 5.1.3.2600.X86/2
       Safe Mode Boot  . . . : MINIMAL
       User name . . . . . . : FUN0004\Administrador
       License . . . . . . . : Free

       Scan date . . . . . . : 2013-08-15 11:03:07
       Scan mode . . . . . . : Normal
       Scan duration . . . . : 4m 16s
       Disk access mode  . . : Direct disk access (SRB)
       Cloud . . . . . . . . : No connection
       Reboot  . . . . . . . : No

       Threats . . . . . . . : 0
       Traces  . . . . . . . : 8

       Objects scanned . . . : 506.116
       Files scanned . . . . : 14.978
       Remnants scanned  . . : 85.218 files / 405.920 keys

    Suspicious files ____________________________________________________________

       C:\Documents and Settings\f002902\Backup_HD_Tiago\Arquivos_Dados\Requisições\real\MP10Setup.exe
          Size . . . . . . . : 12.794.881 bytes
          Age  . . . . . . . : 783.1 days (2011-06-24 09:16:11)
          Entropy  . . . . . : 8.0
          SHA-256  . . . . . : 86ED2F0998759E27B1190104D88402293595A5B55A06577B252CB08CC45B4F84
          Product  . . . . . : Windows Media Component Setup Application
          Publisher  . . . . : Microsoft Corporation
          Description  . . . : Windows Media Component Setup Application
          Version  . . . . . : 10.00.00.3802
          Copyright  . . . . : (C) Microsoft Corporation. All rights reserved.
          RSA Key Size . . . : 2048
          Authenticode . . . : Invalid
          Fuzzy  . . . . . . : 23.0
             Program is altered or corrupted since it was code signed by its author. This is typical for malware and pirated software.
             Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.

       C:\WINDOWS\PEV.exe
          Size . . . . . . . : 256.000 bytes
          Age  . . . . . . . : 0.7 days (2013-08-14 17:46:58)
          Entropy  . . . . . : 8.0
          SHA-256  . . . . . : AE0F5CC54E4B133DF66A54572A7CE52FAFF11F8FD0CAEAB088AAD3699D6EC924
          Fuzzy  . . . . . . : 22.0
             Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
             The .rsrc (resources) section in this program is set to executable. This is an indication of malware infection.
             Authors name is missing in version info. This is not common to most programs.
             Version control is missing. This file is probably created by an individual. This is not typical for most programs.
             Time indicates that the file appeared recently on this computer.
             The file is located in a folder that contains core operating system files from Windows. This is not typical for most programs and is only common to system tools, drivers and hacking utilities.
             Program contains PE structure anomalies. This is not typical for most programs.
          Forensic Cluster
             -10.9s C:\Documents and Settings\f002902\Menu Iniciar\Programas\Ferramentas administrativas\
             -10.8s C:\Documents and Settings\f002902\Menu Iniciar\Programas\Ferramentas administrativas\desktop.ini
             -8.0s C:\Qoobox\
             -8.0s C:\Qoobox\Quarantine\
             -8.0s C:\Qoobox\Quarantine\Registry_backups\
             -3.2s C:\Qoobox\BackEnv\
             -3.0s C:\Qoobox\Quarantine\catchme.log
             -0.0s C:\WINDOWS\grep.exe
             -0.0s C:\WINDOWS\sed.exe
             -0.0s C:\WINDOWS\SWSC.exe
             -0.0s C:\WINDOWS\SWXCACLS.exe
              0.0s C:\WINDOWS\PEV.exe
              0.0s C:\WINDOWS\SWREG.exe
              0.0s C:\WINDOWS\zip.exe
              0.0s C:\WINDOWS\MBR.exe
              0.0s C:\WINDOWS\NIRCMD.exe


    Cookies _____________________________________________________________________

       C:\Documents and Settings\Administrador\Cookies\administrador@adinterax[2].txt
       C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\cookies.sqlite:ad.yieldmanager.com
       C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\cookies.sqlite:atdmt.com
       C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\cookies.sqlite:doubleclick.net
       C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\cookies.sqlite:oracle.112.2o7.net
       C:\Documents and Settings\f002902\Dados de aplicativos\Mozilla\Firefox\Profiles\bchmt8c8.default\cookies.sqlite:statse.webtrendslive.com


     

    Pode RODAR O [b class="bbc" style="color: rgb(15, 114, 218); font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 14px; line-height: 22px; background-color: rgba(123, 166, 13, 0.0980392);"][Tens de ter uma conta e sessão iniciada para poderes visualizar este link]?[/b]
    joram
    joram
    Administrador Fundador
    Administrador Fundador


    Mensagens : 626
    Data de inscrição : 14/08/2012
    Idade : 71
    Localização : Rio de Janeiro

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por joram Qui Ago 15, 2013 10:37 am

    Olá! Edvan

    Edvan escreveu:Toda vez que o pc é ligado, aparece essa mensagem no desktop!.
    |- Este informe permanece?
    |- Sim! Execute o DelFix.
    A+
    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 44
    Localização : Natal/RN

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por Edvan Qui Ago 15, 2013 10:39 am

    Hurum, isso é referente ao net framework, vem acontecendo faz um tempinho.
    vou reiniciar novamente para ver!

    Pode rodar o Delfix?

     
    # DelFix v10.4 - Logfile created 15/08/2013 at 11:41:08
    # Updated 19/07/2013 by Xplode
    # Username : f002902 - FUN0004
    # Operating System : Microsoft Windows XP Service Pack 3 (32 bits)

    ~ Removing disinfection tools ...

    Deleted : C:\Qoobox
    Deleted : C:\ZHP
    Deleted : C:\Arquivos de programas\ZHPDiag
    Deleted : C:\ComboFix.txt
    Deleted : C:\PhysicalDisk0_MBR.bin
    Deleted : C:\zoek-results.log
    Deleted : C:\Documents and Settings\f002902\Desktop\adwcleaner.exe
    Deleted : C:\Documents and Settings\f002902\Desktop\AdwCleaner[0].txt
    Deleted : C:\Documents and Settings\f002902\Desktop\ComboFix.exe
    Deleted : C:\Documents and Settings\f002902\Desktop\JRT.exe
    Deleted : C:\Documents and Settings\f002902\Desktop\JRT.txt
    Deleted : C:\Documents and Settings\f002902\Desktop\ZHPDiag.txt
    Deleted : C:\Documents and Settings\f002902\Desktop\ZHPDiag2.exe
    Deleted : C:\Documents and Settings\f002902\Desktop\ZHPFixReport.txt
    Deleted : C:\Documents and Settings\f002902\Desktop\zoek.exe
    Deleted : C:\Documents and Settings\All Users\Desktop\MBRCheck.lnk
    Deleted : C:\Documents and Settings\All Users\Desktop\ZHPDiag.lnk
    Deleted : C:\Documents and Settings\All Users\Desktop\ZHPFix.lnk
    Deleted : C:\WINDOWS\grep.exe
    Deleted : C:\WINDOWS\PEV.exe
    Deleted : C:\WINDOWS\NIRCMD.exe
    Deleted : C:\WINDOWS\MBR.exe
    Deleted : C:\WINDOWS\SED.exe
    Deleted : C:\WINDOWS\SWREG.exe
    Deleted : C:\WINDOWS\SWSC.exe
    Deleted : C:\WINDOWS\SWXCACLS.exe
    Deleted : C:\WINDOWS\Zip.exe
    Deleted : HKLM\SOFTWARE\AdwCleaner
    Deleted : HKLM\SOFTWARE\Swearware
    Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1
    Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

    ~ Cleaning system restore ...

    Deleted : RP #1044 [Ponto de verificação do sistema | 05/17/2013 15:30:13]
    Deleted : RP #1045 [Ponto de verificação do sistema | 05/20/2013 11:41:55]
    Deleted : RP #1046 [Ponto de verificação do sistema | 05/21/2013 15:15:16]
    Deleted : RP #1047 [Ponto de verificação do sistema | 05/22/2013 15:40:06]
    Deleted : RP #1048 [Ponto de verificação do sistema | 05/23/2013 15:57:29]
    Deleted : RP #1049 [Ponto de verificação do sistema | 05/24/2013 16:43:58]
    Deleted : RP #1050 [Ponto de verificação do sistema | 05/27/2013 12:47:29]
    Deleted : RP #1051 [Ponto de verificação do sistema | 05/28/2013 13:53:37]
    Deleted : RP #1052 [Ponto de verificação do sistema | 05/29/2013 14:18:38]
    Deleted : RP #1053 [Ponto de verificação do sistema | 05/31/2013 10:09:24]
    Deleted : RP #1054 [Ponto de verificação do sistema | 06/03/2013 10:35:33]
    Deleted : RP #1055 [Ponto de verificação do sistema | 06/04/2013 15:15:14]
    Deleted : RP #1056 [Ponto de verificação do sistema | 06/05/2013 15:20:02]
    Deleted : RP #1057 [Ponto de verificação do sistema | 06/06/2013 15:33:20]
    Deleted : RP #1058 [Ponto de verificação do sistema | 06/07/2013 15:35:10]
    Deleted : RP #1059 [Ponto de verificação do sistema | 06/10/2013 15:17:19]
    Deleted : RP #1060 [Ponto de verificação do sistema | 06/11/2013 15:17:33]
    Deleted : RP #1061 [Ponto de verificação do sistema | 06/12/2013 15:37:14]
    Deleted : RP #1062 [Ponto de verificação do sistema | 06/13/2013 15:50:22]
    Deleted : RP #1063 [Ponto de verificação do sistema | 06/14/2013 16:08:49]
    Deleted : RP #1064 [Ponto de verificação do sistema | 06/17/2013 11:53:54]
    Deleted : RP #1065 [Ponto de verificação do sistema | 06/18/2013 13:46:59]
    Deleted : RP #1066 [Ponto de verificação do sistema | 06/19/2013 13:56:50]
    Deleted : RP #1067 [Ponto de verificação do sistema | 06/20/2013 15:21:48]
    Deleted : RP #1068 [Ponto de verificação do sistema | 06/21/2013 15:32:25]
    Deleted : RP #1069 [Ponto de verificação do sistema | 06/25/2013 11:19:20]
    Deleted : RP #1070 [Ponto de verificação do sistema | 06/26/2013 13:01:51]
    Deleted : RP #1071 [Ponto de verificação do sistema | 06/27/2013 15:14:48]
    Deleted : RP #1072 [Installed Windows XP Wdf01009. | 06/28/2013 11:54:16]
    Deleted : RP #1073 [Driver de impressão HP LaserJet Professional M1132 MF instalado | 06/28/2013 11:54:56]
    Deleted : RP #1074 [Instalado Java 7 Update 25 | 06/28/2013 12:12:00]
    Deleted : RP #1075 [Instalado Readiris Pro 12 | 06/28/2013 12:34:47]
    Deleted : RP #1076 [Ponto de verificação do sistema | 07/01/2013 11:59:29]
    Deleted : RP #1077 [Ponto de verificação do sistema | 07/02/2013 13:28:46]
    Deleted : RP #1078 [Ponto de verificação do sistema | 07/03/2013 15:17:13]
    Deleted : RP #1079 [Ponto de verificação do sistema | 07/04/2013 16:17:50]
    Deleted : RP #1080 [Ponto de verificação do sistema | 07/05/2013 21:15:07]
    Deleted : RP #1081 [Ponto de verificação do sistema | 07/08/2013 13:31:17]
    Deleted : RP #1082 [Ponto de verificação do sistema | 07/09/2013 15:16:23]
    Deleted : RP #1083 [Ponto de verificação do sistema | 07/10/2013 15:26:16]
    Deleted : RP #1084 [Ponto de verificação do sistema | 07/12/2013 11:28:29]
    Deleted : RP #1085 [Ponto de verificação do sistema | 07/13/2013 15:31:59]
    Deleted : RP #1086 [Ponto de verificação do sistema | 07/15/2013 11:40:10]
    Deleted : RP #1087 [Ponto de verificação do sistema | 07/16/2013 12:31:25]
    Deleted : RP #1088 [Ponto de verificação do sistema | 07/17/2013 12:41:37]
    Deleted : RP #1089 [Ponto de verificação do sistema | 07/18/2013 13:17:50]
    Deleted : RP #1090 [Ponto de verificação do sistema | 07/19/2013 15:22:37]
    Deleted : RP #1091 [Ponto de verificação do sistema | 07/22/2013 12:00:51]
    Deleted : RP #1092 [Ponto de verificação do sistema | 07/23/2013 12:22:58]
    Deleted : RP #1093 [Ponto de verificação do sistema | 07/24/2013 12:29:16]
    Deleted : RP #1094 [Ponto de verificação do sistema | 07/25/2013 13:58:18]
    Deleted : RP #1095 [Ponto de verificação do sistema | 07/26/2013 15:19:27]
    Deleted : RP #1096 [Ponto de verificação do sistema | 07/29/2013 14:29:46]
    Deleted : RP #1097 [Ponto de verificação do sistema | 07/30/2013 15:15:13]
    Deleted : RP #1098 [Ponto de verificação do sistema | 07/31/2013 15:42:39]
    Deleted : RP #1099 [Ponto de verificação do sistema | 08/01/2013 16:17:03]
    Deleted : RP #1100 [Ponto de verificação do sistema | 08/02/2013 18:26:57]
    Deleted : RP #1101 [Ponto de verificação do sistema | 08/05/2013 13:25:33]
    Deleted : RP #1102 [Ponto de verificação do sistema | 08/06/2013 13:57:20]
    Deleted : RP #1103 [Ponto de verificação do sistema | 08/07/2013 15:17:10]
    Deleted : RP #1104 [Ponto de verificação do sistema | 08/08/2013 15:46:12]
    Deleted : RP #1105 [Ponto de verificação do sistema | 08/09/2013 16:29:37]
    Deleted : RP #1106 [Ponto de verificação do sistema | 08/12/2013 14:01:16]
    Deleted : RP #1107 [Ponto de verificação do sistema | 08/13/2013 15:10:19]
    Deleted : RP #1108 [Ponto de verificação do sistema | 08/14/2013 15:18:00]
    Deleted : RP #1109 [zoek.exe restore point | 08/15/2013 13:25:43]

    New restore point created !

    ~ Resetting system settings ... OK

    ########## - EOF - ##########
    joram
    joram
    Administrador Fundador
    Administrador Fundador


    Mensagens : 626
    Data de inscrição : 14/08/2012
    Idade : 71
    Localização : Rio de Janeiro

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por joram Qui Ago 15, 2013 10:46 am

    Olá Edvan!

    |- Já tentou desinstalar o .Net Framework e re-instalar buscando  versão atualizada?

    A+
    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 44
    Localização : Natal/RN

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por Edvan Qui Ago 15, 2013 10:46 am

    Nao está mais aparecendo amigo, desde já lhe agradeço pela pronta ajuda.

    Pode fechar o tópico!
    joram
    joram
    Administrador Fundador
    Administrador Fundador


    Mensagens : 626
    Data de inscrição : 14/08/2012
    Idade : 71
    Localização : Rio de Janeiro

    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por joram Qui Ago 15, 2013 10:50 am

    CASO RESOLVIDO!

    Necessitando novo auxílio para este computador,basta abrir "Novo Tópico" e relatar o problema.

    Conteúdo patrocinado


    PC lento, log para analise. Empty Re: PC lento, log para analise.

    Mensagem por Conteúdo patrocinado


      Data/hora atual: Qui Nov 21, 2024 1:30 pm