Fórum SecSecurity

Gostaria de reagir a esta mensagem? Crie uma conta em poucos cliques ou inicie sessão para continuar.
Fórum SecSecurity

Implementando Limpeza e Seguranca em seu computador!

Palavras-chaves

Últimos assuntos

» OpenTip (...by Kaspersky.com)
Possível KeyLogger nessa maquina! EmptySáb Mar 23, 2024 10:28 am por joram

» KpRm ( ... by Kernel-panik )
Possível KeyLogger nessa maquina! EmptyTer Ago 11, 2020 9:47 pm por joram

» ESET Rogue Applications Remover ( ... by Eset.com )
Possível KeyLogger nessa maquina! EmptySáb Ago 01, 2020 7:49 am por joram

» PW Clean 2.7 ( ... by Doutor PW )
Possível KeyLogger nessa maquina! EmptyTer maio 15, 2018 9:27 am por joram

» CKScanner ( ... by askey127 )
Possível KeyLogger nessa maquina! EmptySáb maio 05, 2018 1:12 pm por joram

» AdwCleaner ( ... by XPlode )
Possível KeyLogger nessa maquina! EmptySeg Abr 16, 2018 8:47 am por joram

» ZHPDiag ( ... de Nicolas Coolman )
Possível KeyLogger nessa maquina! EmptySáb Abr 14, 2018 8:56 am por joram

» Argente - Registry Cleaner ( ... by Argente Software )
Possível KeyLogger nessa maquina! EmptyDom Nov 19, 2017 4:36 pm por joram

» ListChkdskResult ( ... by SleepyDude )
Possível KeyLogger nessa maquina! EmptyDom Set 24, 2017 1:39 pm por joram

outubro 2024

SegTerQuaQuiSexSábDom
 123456
78910111213
14151617181920
21222324252627
28293031   

Calendário Calendário

Parceiros

Fórum grátis

Os membros mais mencionados

Nenhum usuário

2 participantes

    Possível KeyLogger nessa maquina!

    Edvan
    Edvan
    Membro
    Membro


    Mensagens : 428
    Data de inscrição : 14/02/2013
    Idade : 44
    Localização : Natal/RN

    Possível KeyLogger nessa maquina! Empty Possível KeyLogger nessa maquina!

    Mensagem por Edvan Ter Dez 10, 2013 12:49 pm

    Log para analise [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

    Possível KeyLogger nessa maquina!

    Ao pressionar Ctrl+Alt R aparece opção para login pedindo senha, rodei algumas ferramentas, passei o Avast em modo de segurança pegou 49 pragas.

    OBS: Agora ao pressionar Ctrl+Alt R nao aparece mais nada, porem gostaria de saber se tem algum vestígios de Keyloggers nesse pc.

    # AdwCleaner v3.014 - Relatório criado 10/12/2013 às 09:30:45
    # Atualizado 01/12/2013 por Xplode
    # Sistema Operacional : Windows 7 Home Basic Service Pack 1 (64 bits)
    # Usuário : João Paulo - FABIO
    # Executando de : C:\Users\FábioRafael\Downloads\adwcleaner.exe
    # Opção : Limpar

    ***** [ Serviços ] *****

    Serviço Deletada : BackupStack

    ***** [ Arquivos / Pastas ] *****

    Pasta Deletada : C:\ProgramData\Babylon
    Pasta Deletada : C:\ProgramData\BonanzaDealsLive
    Pasta Deletada : C:\ProgramData\boost_interprocess
    Pasta Deletada : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly
    Pasta Deletada : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eSupport.com
    Pasta Deletada : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
    Pasta Deletada : C:\Program Files (x86)\BonanzaDeals
    Pasta Deletada : C:\Program Files (x86)\BonanzaDealsLive
    Pasta Deletada : C:\Program Files (x86)\BrowserCompanion
    Pasta Deletada : C:\Program Files (x86)\DAEMON Tools Toolbar
    Pasta Deletada : C:\Program Files (x86)\eSupport.com
    Pasta Deletada : C:\Program Files (x86)\Iminent
    Pasta Deletada : C:\Program Files (x86)\myfree codec
    Pasta Deletada : C:\Program Files (x86)\MyPC Backup
    Pasta Deletada : C:\Program Files (x86)\Searchqu Toolbar
    Pasta Deletada : C:\Users\João Paulo\AppData\Local\BonanzaDealsLive
    Pasta Deletada : C:\Users\João Paulo\AppData\Local\Ilivid Player
    Pasta Deletada : C:\Users\JOOPAU~1\AppData\Local\Temp\incredibar.com
    Pasta Deletada : C:\Users\João Paulo\AppData\LocalLow\BabylonToolbar
    Pasta Deletada : C:\Users\João Paulo\AppData\LocalLow\bbrs_002.tb
    Pasta Deletada : C:\Users\João Paulo\AppData\LocalLow\incredibar.com
    Pasta Deletada : C:\Users\João Paulo\AppData\LocalLow\searchquband
    Pasta Deletada : C:\Users\João Paulo\AppData\LocalLow\Searchqutoolbar
    Pasta Deletada : C:\Users\João Paulo\AppData\Roaming\Babylon
    Pasta Deletada : C:\Users\João Paulo\AppData\Roaming\baidu
    Pasta Deletada : C:\Users\João Paulo\AppData\Roaming\Funmoods
    Pasta Deletada : C:\Users\João Paulo\AppData\Roaming\OpenCandy
    Pasta Deletada : C:\Users\João Paulo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
    Pasta Deletada : C:\Users\João Paulo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Video downloader
    Pasta Deletada : C:\Users\João Paulo\AppData\Roaming\Mozilla\Firefox\Profiles\qpbrsbaq.default\Searchqutoolbar
    Arquivo Deletada : C:\Users\JOOPAU~1\AppData\Local\Temp\Searchqu.ini
    Arquivo Deletada : C:\Users\JOOPAU~1\AppData\Local\Temp\searchqutoolbar-manifest.xml
    Arquivo Deletada : C:\Users\JOOPAU~1\AppData\Local\Temp\SetupDataMngr_Searchqu.exe
    Arquivo Deletada : C:\Users\João Paulo\AppData\Roaming\Mozilla\Firefox\Profiles\qpbrsbaq.default\user.js
    Arquivo Deletada : C:\Windows\System32\Tasks\Dealply
    Arquivo Deletada : C:\Windows\System32\Tasks\Funmoods

    ***** [ Atalhos ] *****


    ***** [ Registro ] *****

    Chave Deletedo : HKLM\SOFTWARE\Google\Chrome\Extensions\kolgnaidildmdbfgdnoapjdianbpajne
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\DNSBHO.dll
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\tdataprotocol.DLL
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\updatebho.DLL
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\wit4ie.DLL
    Chave Deletedo : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
    Chave Deletedo : HKLM\SOFTWARE\Classes\BrowserConnection.Loader
    Chave Deletedo : HKLM\SOFTWARE\Classes\BrowserConnection.Loader.1
    Chave Deletedo : HKLM\SOFTWARE\Classes\DnsBHO.BHO
    Chave Deletedo : HKLM\SOFTWARE\Classes\DnsBHO.BHO.1
    Chave Deletedo : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr
    Chave Deletedo : HKLM\SOFTWARE\Classes\Incredibar.IncredibarHlpr.1
    Chave Deletedo : HKLM\SOFTWARE\Classes\Prod.cap
    Chave Deletedo : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\base64
    Chave Deletedo : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\chrome
    Chave Deletedo : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\prox
    Chave Deletedo : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard
    Chave Deletedo : HKLM\SOFTWARE\Classes\SearchQUIEHelper.DNSGuard.1
    Chave Deletedo : HKLM\SOFTWARE\Classes\tdataprotocol.CTData
    Chave Deletedo : HKLM\SOFTWARE\Classes\tdataprotocol.CTData.1
    Chave Deletedo : HKLM\SOFTWARE\Classes\updatebho.TimerBHO
    Chave Deletedo : HKLM\SOFTWARE\Classes\updatebho.TimerBHO.1
    Chave Deletedo : HKLM\SOFTWARE\Classes\wit4ie.WitBHO
    Chave Deletedo : HKLM\SOFTWARE\Classes\wit4ie.WitBHO.2
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\I Want This_RASAPI32
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\I Want This_RASMANCS
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BonanzaDealsLive.exe
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F}
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C}
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\{AC662AF2-4601-4A68-84DF-A3FE83F1A5F9}
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
    Chave Deletedo : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{00000001-4FEF-40D3-B3FA-E0531B897F98}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{5ACE96C0-C70A-4A4D-AF14-2E7B869345E1}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{64697678-0000-0010-8000-00AA00389B71}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{67C71B35-A416-4A54-BD1D-15965A4FE41C}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{FD501041-8EBE-11CE-8183-00AA00577DA2}
    Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
    Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
    Chave Deletedo : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
    Chave Deletedo : HKLM\SOFTWARE\Classes\TypeLib\{5B4144E1-B61D-495A-9A50-CD1A95D86D15}
    Chave Deletedo : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
    Chave Deletedo : HKLM\SOFTWARE\Classes\TypeLib\{830B56CB-FD22-44AA-9887-7898F4F4158D}
    Chave Deletedo : HKLM\SOFTWARE\Classes\TypeLib\{841D5A49-E48D-413C-9C28-EB3D9081D705}
    Chave Deletedo : HKLM\SOFTWARE\Classes\TypeLib\{8830DDF0-3042-404D-A62C-384A85E34833}
    Chave Deletedo : HKLM\SOFTWARE\Classes\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A}
    Chave Deletedo : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531}
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063412-BEA4-4D76-8ED3-183BE6220D17}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00CBB66B-1D3B-46D3-9577-323A336ACB50}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6E13DDE1-2B6E-46CE-8B66-DC8BF36F6B99}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448}
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063412-BEA4-4D76-8ED3-183BE6220D17}
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65BCD620-07DD-012F-819F-073CF1B8F7C6}
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
    Chave Deletedo : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
    Chave Deletedo : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
    Valor Deletedo : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{99079A25-328F-4BD4-BE04-00955ACAA0A7}]
    Valor Deletedo : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\CLSID\{9D717F81-9148-4F12-8568-69135F087DB0}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4CA8-A185-8FF989AF1115}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\CLSID\{FEFD3AF5-A346-4451-AA23-A3AD54915515}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{44B619BC-3D2B-4990-AA4F-9AA366921792}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{BFE569F7-646C-4512-969B-9BE3E580D393}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
    Chave Deletedo : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D717F81-9148-4F12-8568-69135F087DB0}
    Valor Deletedo : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
    Chave Deletedo : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Chave Deletedo : HKCU\Software\Blabbers       
    Chave Deletedo : HKCU\Software\Blabbers
    Chave Deletedo : HKCU\Software\BonanzaDealsLive
    Chave Deletedo : HKCU\Software\BrowserCompanion
    Chave Deletedo : HKCU\Software\DataMngr
    Chave Deletedo : HKCU\Software\DataMngr_Toolbar
    Chave Deletedo : HKCU\Software\Funmoods
    Chave Deletedo : HKCU\Software\IM
    Chave Deletedo : HKCU\Software\Iminent
    Chave Deletedo : HKCU\Software\ImInstaller
    Chave Deletedo : HKCU\Software\InstallCore
    Chave Deletedo : HKCU\Software\Myfree Codec
    Chave Deletedo : HKCU\Software\SmartBar
    Chave Deletedo : HKCU\Software\AppDataLow\Software\Crossrider
    Chave Deletedo : HKCU\Software\AppDataLow\Software\PriceGong
    Chave Deletedo : HKCU\Software\AppDataLow\Software\searchqutoolbar
    Chave Deletedo : HKLM\Software\Babylon
    Chave Deletedo : HKLM\Software\BonanzaDealsLive
    Chave Deletedo : HKLM\Software\BrowserCompanion
    Chave Deletedo : HKLM\Software\DataMngr
    Chave Deletedo : HKLM\Software\Iminent
    Chave Deletedo : HKLM\Software\InstallCore
    Chave Deletedo : HKLM\Software\Myfree Codec
    Chave Deletedo : HKLM\Software\SearchquMediabarTb
    Chave Deletedo : HKLM\Software\Vittalia
    Chave Deletedo : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BrowserCompanion
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchqu Toolbar
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
    Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Video downloader
    Chave Deletedo : [x64] HKLM\SOFTWARE\DataMngr
    Chave Deletedo : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
    Dados Deletedo : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SEARCH~1\Datamngr\datamngr.dll
    Dados Deletedo : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SEARCH~1\Datamngr\IEBHO.dll
    Dados Deletedo : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SEARCH~1\Datamngr\x64\datamngr.dll
    Dados Deletedo : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SEARCH~1\Datamngr\x64\IEBHO.dll

    ***** [ Navegadores ] *****

    -\\ Internet Explorer v11.0.9600.16428

    Configurações Restauradas : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
    Configurações Restauradas : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
    Configurações Restauradas : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
    Configurações Restauradas : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
    Configurações Restauradas : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
    Configurações Restauradas : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
    Configurações Restauradas : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]

    -\\ Mozilla Firefox v25.0.1 (pt-BR)

    [ Arquivo : C:\Users\João Paulo\AppData\Roaming\Mozilla\Firefox\Profiles\qpbrsbaq.default\prefs.js ]

    Linha deletada : user_pref("browser.search.order.1", "Search Results");
    Linha deletada : user_pref("extensions.BabylonToolbar.admin", false);
    Linha deletada : user_pref("extensions.BabylonToolbar.aflt", "babsst");
    Linha deletada : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");
    Linha deletada : user_pref("extensions.BabylonToolbar.babExt", "");
    Linha deletada : user_pref("extensions.BabylonToolbar.babTrack", "affID=109540");
    Linha deletada : user_pref("extensions.BabylonToolbar.babext", "babExt");
    Linha deletada : user_pref("extensions.BabylonToolbar.babtrack", "babTrack");
    Linha deletada : user_pref("extensions.BabylonToolbar.bbDpng", "29");
    Linha deletada : user_pref("extensions.BabylonToolbar.cntry", "BR");
    Linha deletada : user_pref("extensions.BabylonToolbar.dfltLng", "en");
    Linha deletada : user_pref("extensions.BabylonToolbar.dfltlng", "en");
    Linha deletada : user_pref("extensions.BabylonToolbar.dfltsrch", "false");
    Linha deletada : user_pref("extensions.BabylonToolbar.dpkLst", "");
    Linha deletada : user_pref("extensions.BabylonToolbar.envrmnt", "production");
    Linha deletada : user_pref("extensions.BabylonToolbar.excTlbr", false);
    Linha deletada : user_pref("extensions.BabylonToolbar.firstrun", false);
    Linha deletada : user_pref("extensions.BabylonToolbar.hdrMd5", "6E4A7EB839F13618F962D950FEB6EF34");
    Linha deletada : user_pref("extensions.BabylonToolbar.hmpg", false);
    Linha deletada : user_pref("extensions.BabylonToolbar.hrdid", "e45ff02e00000000000068a3c422eac8");
    Linha deletada : user_pref("extensions.BabylonToolbar.id", "e45ff02e00000000000068a3c422eac8");
    Linha deletada : user_pref("extensions.BabylonToolbar.instlDay", "15614");
    Linha deletada : user_pref("extensions.BabylonToolbar.instlRef", "sst");
    Linha deletada : user_pref("extensions.BabylonToolbar.instlday", "15614");
    Linha deletada : user_pref("extensions.BabylonToolbar.instlref", "sst");
    Linha deletada : user_pref("extensions.BabylonToolbar.isdcmntcmplt", "false");
    Linha deletada : user_pref("extensions.BabylonToolbar.keywordurl", "");
    Linha deletada : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.8.0.716:14:14");
    Linha deletada : user_pref("extensions.BabylonToolbar.lastdp", 4);
    Linha deletada : user_pref("extensions.BabylonToolbar.mntrvrsn", "1.3.1");
    Linha deletada : user_pref("extensions.BabylonToolbar.newTab", false);
    Linha deletada : user_pref("extensions.BabylonToolbar.newtab", "false");
    Linha deletada : user_pref("extensions.BabylonToolbar.newtaburl", "");
    Linha deletada : user_pref("extensions.BabylonToolbar.pnu_base", "{\"newVrsn\":\"59\",\"lastVrsn\":\"59\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"true\",\"msgTs\":0,\"lstMsgTs\":0}");
    Linha deletada : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
    Linha deletada : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
    Linha deletada : user_pref("extensions.BabylonToolbar.prtnrid", "babylon");
    Linha deletada : user_pref("extensions.BabylonToolbar.savedVrsnTs", "1");
    Linha deletada : user_pref("extensions.BabylonToolbar.sg", "czb");
    Linha deletada : user_pref("extensions.BabylonToolbar.smplGrp", "czb");
    Linha deletada : user_pref("extensions.BabylonToolbar.smplgrp", "czb");
    Linha deletada : user_pref("extensions.BabylonToolbar.srcExt", "ss");
    Linha deletada : user_pref("extensions.BabylonToolbar.srcext", "ss");
    Linha deletada : user_pref("extensions.BabylonToolbar.srch", "");
    Linha deletada : user_pref("extensions.BabylonToolbar.srchprvdr", "");
    Linha deletada : user_pref("extensions.BabylonToolbar.tlbrId", "base");
    Linha deletada : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=e45ff02e00000000000068a3c422eac8&q=");
    Linha deletada : user_pref("extensions.BabylonToolbar.tlbrid", "base");
    Linha deletada : user_pref("extensions.BabylonToolbar.tlbrsrchurl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=e45ff02e00000000000068a3c422eac8&q=");
    Linha deletada : user_pref("extensions.BabylonToolbar.vrsn", "1.8.0.7");
    Linha deletada : user_pref("extensions.BabylonToolbar.vrsnTs", "1.8.0.716:14:14");
    Linha deletada : user_pref("extensions.BabylonToolbar.vrsni", "1.8.0.7");
    Linha deletada : user_pref("extensions.BabylonToolbar.vrsnts", "1.8.0.716:14:14");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.babExt", "");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=109540");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.hardId", "e45ff02e00000000000068a3c422eac8");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.id", "e45ff02e00000000000068a3c422eac8");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.instlDay", "15408");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.8.0.716:14:14");
    Linha deletada : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
    Linha deletada : user_pref("extensions.crossrider.bic", "135fcf102837fe475c16fa3a7bdc0e0d");
    Linha deletada : user_pref("extensions.helperbar.DockingPositionDown", false);
    Linha deletada : user_pref("extensions.helperbar.SmartbarDisabled", false);
    Linha deletada : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
    Linha deletada : user_pref("extensions.helperbar.Visibility", false);
    Linha deletada : user_pref("extensions.incredibar_i.aflt", "orgnl");
    Linha deletada : user_pref("extensions.incredibar_i.dfltLng", "");
    Linha deletada : user_pref("extensions.incredibar_i.did", "10595");
    Linha deletada : user_pref("extensions.incredibar_i.excTlbr", "false");
    Linha deletada : user_pref("extensions.incredibar_i.hardId", "e45ff02e00000000000068a3c422eac8");
    Linha deletada : user_pref("extensions.incredibar_i.id", "e45ff02e00000000000068a3c422eac8");
    Linha deletada : user_pref("extensions.incredibar_i.installerproductid", "26");
    Linha deletada : user_pref("extensions.incredibar_i.instlDay", "15409");
    Linha deletada : user_pref("extensions.incredibar_i.instlRef", "");
    Linha deletada : user_pref("extensions.incredibar_i.ms_url_id", "");
    Linha deletada : user_pref("extensions.incredibar_i.newTab", false);
    Linha deletada : user_pref("extensions.incredibar_i.ppd", "");
    Linha deletada : user_pref("extensions.incredibar_i.prdct", "incredibar");
    Linha deletada : user_pref("extensions.incredibar_i.productid", "26");
    Linha deletada : user_pref("extensions.incredibar_i.prtnrId", "Incredibar");
    Linha deletada : user_pref("extensions.incredibar_i.smplGrp", "none");
    Linha deletada : user_pref("extensions.incredibar_i.tlbrId", "base");
    Linha deletada : user_pref("extensions.incredibar_i.tlbrSrchUrl", "hxxp://mystart.Incredibar.com/?a=6OyviGUjP5&loc=IB_TB&i=26&search=");
    Linha deletada : user_pref("extensions.incredibar_i.upn2", "6OyviGUjP5");
    Linha deletada : user_pref("extensions.incredibar_i.upn2n", "92261037385159947");
    Linha deletada : user_pref("extensions.incredibar_i.vrsn", "1.5.3.27");
    Linha deletada : user_pref("extensions.incredibar_i.vrsnTs", "1.5.3.2721:50:13");
    Linha deletada : user_pref("extensions.incredibar_i.vrsni", "1.5.3.27");
    Linha deletada : user_pref("iminent.ShowThankyouPixel", "0");
    Linha deletada : user_pref("iminent.displayFavLinks", "0");
    Linha deletada : user_pref("iminent.registerToolbarEvent100", "1377651437335");
    Linha deletada : user_pref("iminent.registerToolbarEvent101", "1377574547005");
    Linha deletada : user_pref("iminent.registerToolbarEvent102", "1377569139577");
    Linha deletada : user_pref("iminent.registerToolbarEvent109", "1377569005262");
    Linha deletada : user_pref("iminent.registerToolbarEvent110", "1377569044470");
    Linha deletada : user_pref("iminent.registerToolbarEvent111", "1377569005272");
    Linha deletada : user_pref("iminent.registerToolbarEvent112", "1377569005368");
    Linha deletada : user_pref("iminent.registerToolbarEvent122", "1377569005282");
    Linha deletada : user_pref("iminent.version", "7.33.3.1");
    Linha deletada : user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.33.3.1\",\"InstallEventCTime\":1377137079593,\"InstallEvent\":\"True\"}");
    Linha deletada : user_pref("iminent.webbooster.scripts.minibar.LayoutId", "1");
    Linha deletada : user_pref("iminent.webbooster.scripts.minibar.ROOTEXTENSION", "chrome://iminentwebbooster/content/minibar");
    Linha deletada : user_pref("iminent.webbooster.scripts.minibar.SOFTONICREFRESHRATE", "140000");
    Linha deletada : user_pref("iminent.webbooster.scripts.minibar.Services.BHPCode", "01");
    Linha deletada : user_pref("iminent.webbooster.scripts.minibar.Services.DefaultEvent", "000");
    Linha deletada : user_pref("iminent.webbooster.scripts.minibar.Services.DefaultWebSite", "000");
    Linha deletada : user_pref("iminent.webbooster.scripts.minibar.Services.IminentClientCode", "11");
    Linha deletada : user_pref("iminent.webbooster.scripts.minibar.Services.SmartFavCode", "02");
    Linha deletada : user_pref("iminent.webbooster.scripts.minibar.ShowThankyouPixel", "0");
    Linha deletada : user_pref("iminent.webbooster.scripts.minibar.displayFavLinks", "0");
    Linha deletada : user_pref("iminent.webbooster.scripts.minibar.registerToolbarEvent102", "1376197583109");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.LayoutId", "1");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.ROOTEXTENSION", "chrome://iminentwebbooster/content/minibar");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.SOFTONICREFRESHRATE", "140000");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.Services.BHPCode", "01");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.Services.DefaultEvent", "000");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.Services.DefaultWebSite", "000");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.Services.IminentClientCode", "11");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.Services.SmartFavCode", "02");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.ShowThankyouPixel", "0");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.displayFavLinks", "0");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent102", "1376197569317");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent109", "1377136361451");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent110", "1376077344324");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent111", "1377136361470");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent112", "1377136425569");
    Linha deletada : user_pref("iminent.webbooster.scripts.sslminibar.registerToolbarEvent122", "1377136361488");
    Linha deletada : user_pref("keyword.URL", "hxxp://feed.snap.do/?publisher=Bundlore&dpid=Bundlore&co=BR&userid=53efc0c7-f5b1-4f2a-a819-adc3f666b11d&searchtype=ds&installDate=05/05/2013&q=");

    -\\ Google Chrome v

    [ Arquivo : C:\Users\João Paulo\AppData\Local\Google\Chrome\User Data\Default\preferences ]

    Deletedo : urls_to_restore_on_startup

    *************************

    AdwCleaner[R0].txt - [40983 octets] - [10/12/2013 09:28:28]
    AdwCleaner[S0].txt - [37842 octets] - [10/12/2013 09:30:45]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [37903 octets] ##########
    joram
    joram
    Administrador Fundador
    Administrador Fundador


    Mensagens : 626
    Data de inscrição : 14/08/2012
    Idade : 71
    Localização : Rio de Janeiro

    Possível KeyLogger nessa maquina! Empty Re: Possível KeyLogger nessa maquina!

    Mensagem por joram Qui Dez 12, 2013 6:56 am

    Bom Dia! Edvan

    |- Execute este script na ferramenta ZHPFix.

    script zhpfix
    [MD5.00000000000000000000000000000000] [APT] [{9BD4437C-4088-4B91-A6BF-F2B772A982C1}] (...) -- H:\Programas 4gb\SetupVirtualCloneDrive5423.exe (.not file.) 
    [MD5.4B4F478A9C377EC6C44FF59C4D0873F0] [SPRF][20/04/2013] (.DealPly Technologies Ltd - DealPly.) -- C:\Users\João Paulo\AppData\Local\Temp\100413_y.exe   [1279744]  =>PUP.DealPly
    O3 - Toolbar: (no name) [64Bits] - [HKLM]{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} Chave orfã
    O3 - Toolbar\WebBrowser: (no name) [64Bits] - [HKCU]{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} Chave orfã
    O4 - GS\Desktop [Public]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.)  -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] =>Hijacker.Browsers
    O4 - GS\TaskBar [João Paulo]: Mozilla Firefox.lnk . (.Mozilla Corporation - Firefox.)  -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] =>Hijacker.Browsers
    G2 - GCE: Preference [User Data\Default] [bkomkajifikmkfnjgphkjcfeepbnojok] PriceGong v.5.6.8 (Désactivé) =>Adware.PriceGong
    G2 - GCE: Preference [User Data\Default] [fpknlgclcjbgepbagcobhdainldkgggl] PSafe ClikSeguro v.1.0.7, (Désactivé)
    G2 - GCE: Preference [User Data\Default] [igdhbblpcellaljokkpfhcjlagemhgjl] Iminent v.6.32.3.1, (Désactivé) =>Adware.IMBooster
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: Modified
    [HKLM\Software\Google\Chrome\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok]   =>Adware.PriceGong^
    [HKLM\Software\Google\Chrome\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl]   =>Adware.IMBooster^
    [HKLM\SYSTEM\CurrentControlSet\Services\KMService]   =>Hijacker.Office^
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375]   =>PUP.Tarma
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5]   =>PUP.Tarma
    [HKLM\Software\Wow6432Node\360Safe]   =>Trojan.Lozavita
    C:\Users\João Paulo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkomkajifikmkfnjgphkjcfeepbnojok   =>Adware.PriceGong^
    C:\Users\João Paulo\AppData\Local\Google\Chrome\User Data\Default\Extensions\igdhbblpcellaljokkpfhcjlagemhgjl   =>Adware.IMBooster^
    C:\Program Files (x86)\vGrabber-software   =>PUP.vGrabber
    C:\Users\João Paulo\AppData\Local\Temp\100413_y.exe   =>PUP.DealPly^
    C:\Users\João Paulo\AppData\Local\Temp\dealply.exe   =>PUP.DealPly^
    C:\Users\João Paulo\AppData\Local\Temp\tbbabylonv3.exe   =>PUP.Babylon^
    C:\Users\João Paulo\AppData\Local\Temp\square_babylonv2.bmp  =>PUP.SweetIM
    C:\Users\João Paulo\AppData\Local\Temp\square_babylonv3.bmp  =>PUP.SweetIM
    C:\Users\João Paulo\AppData\Local\Temp\blabbers-ff-le.xpi  =>PUP.Blabbers
    C:\Users\João Paulo\AppData\Local\Temp\datamngrUI.exe.10847576  =>Adware.Bandoo
    firewallraz
    emptytemp
    emptyclsid

    |- Poste o relatório!

    ///////////

    |- Como não houve resposta para o presente,o mesmo será fechado!

    Abs!

      Data/hora atual: Sex Out 18, 2024 3:38 am