Oi joram
Meu computador apresenta alguma lentidão.
Será que é vírus?
Agradecida!
Meu computador apresenta alguma lentidão.
Será que é vírus?
Agradecida!
Nenhum usuário |
|- Estando com o Bloco de Notas aberto,acione os atalhos: "Ctrl+A" -> "Ctrl+C"[MD5.2096B76B1A5D4E5CE2BCB19C0FADA911] - (...) -- E:\Documents and Settings\All Users\Dados de aplicativos\OptimizerPro1\OptimizerPro1.exe [210944] [PID.]
[MD5.00000000000000000000000000000000] [APT] [OptimizerPro1UpdaterTask{89B1254A-DE9D-4ED4-8A5D-619833295552}] (...) -- E:\Documents and Settings\Matheus\Dados de aplicativos\OptimizerPro1\OptimizerPro1.exe (.not file.)
[MD5.00000000000000000000000000000000] [APT] [SymInstallStub] (...) -- E:\DOCUME~1\Matheus\CONFIG~1\Temp\Adobe\Shockwave 11\SymInstallStub.exe (.not file.)
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
O2 - BHO: V9-Helper Loader - {4DE0953E-490E-4D6F-BDDA-0516C372F3AF} . (.Beijing Elex Technology Co., Ltd - TODO: <File description>.) -- E:\WINDOWS\system32\v9loader.dll
O3 - Toolbar: V9-ToolBar - [HKLM]{742E70CF-7770-412d-86CB-230B322E807C} . (.FOF_SILENT Beijing Elex Technology Co., Lt - V9-ToolBar.) -- E:\WINDOWS\system32\v9-toolbar.dll
O3 - Toolbar: (no name) - [HKLM]{98889811-442D-49dd-99D7-DC866BE87DBC} . (...) -- (.not file.) => Infection BT (Toolbar.Babylon)
O2 - BHO: Funmoods Helper Object - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} Orphean Key
O3 - Toolbar: (no name) - [HKLM]{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} . (...) -- (.not file.)
O4 - Global Startup: E:\Documents And Settings\Matheus\Desktop\Continue SweetIM Installation.lnk . (...) -- E:\Documents and Settings\Matheus\Configurações locais\Temp\Shortcut_SweetImSetup.exe (.not file.)
O4 - Global Startup: E:\Documents And Settings\Matheus\Desktop\Continue SweetIM Installation.lnk . (...) -- E:\Documents and Settings\Matheus\Configurações locais\Temp\Shortcut_SweetImSetup.exe (.not file.)
O42 - Logiciel: OptimizerPro1 Updater - (.Unknown owner.) [HKLM] -- OptimizerPro1
O42 - Logiciel: V9 HomeTool - (.ELEX Technology.) [HKLM] -- V9Software
O43 - CFD: 16/8/2012 - 15:38:43 - [1,425] ----D E:\Arquivos de programas\v9Soft
O43 - CFD: 4/12/2011 - 13:12:21 - [6,311] ----D E:\Documents and Settings\Matheus\Configurações locais\Dados de aplicativos\Babylon
O43 - CFD: 7/4/2012 - 11:09:45 - [0,063] ----D E:\Documents and Settings\Matheus\Configurações locais\Dados de aplicativos\Conduit
O47 - AAKE:Key Export SP - "E:\Documents and Settings\Matheus\Meus documentos\Downloads\Facemoods (1).exe" [Enabled] .(...) -- E:\Documents and Settings\Matheus\Meus documentos\Downloads\Facemoods (1).exe (.not file.)
O47 - AAKE:Key Export SP - "E:\Level Up! Games\Combat Arms\CombatArms.exe" [Enabled] .(...) -- E:\Level Up! Games\Combat Arms\CombatArms.exe (.not file.)
O47 - AAKE:Key Export SP - "E:\Level Up! Games\Combat Arms\Engine.exe" [Enabled] .(...) -- E:\Level Up! Games\Combat Arms\Engine.exe (.not file.)
O47 - AAKE:Key Export DP - "E:\Level Up! Games\Combat Arms\CombatArms.exe" [Enabled] .(...) -- E:\Level Up! Games\Combat Arms\CombatArms.exe (.not file.)
O47 - AAKE:Key Export DP - "E:\Level Up! Games\Combat Arms\Engine.exe" [Enabled] .(...) -- E:\Level Up! Games\Combat Arms\Engine.exe (.not file.)
O69 - SBI: SearchScopes [HKCU] {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} - (Search the web (Babylon)) - [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] => Toolbar.Babylon
[HKLM\Software\360Safe] => Infection Diverse (Lozavita.Troj)
[HKLM\Software\Classes\escort.escortIEPane]
[HKLM\Software\Classes\escort.escortIEPane.1]
[HKLM\Software\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}] => Infection BT (Adware.Agent)
[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ecdf796-c2dc-4d79-a620-cce0c0a66cc9}] => Infection BT (Adware.MyWebSearch)
[HKLM\Software\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] => Infection BT (Toolbar.Babylon)
[HKLM\Software\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}] => Infection BT (Toolbar.Babylon)
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49dd-99D7-DC866BE87DBC}] => Infection BT (Toolbar.Babylon)
[HKLM\Software\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}] => Infection BT (Toolbar.Babylon)
[HKLM\Software\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] => Infection BT (Toolbar.Babylon)
[HKLM\Software\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}] => Infection BT (Toolbar.Babylon)
E:\Documents and Settings\Matheus\Configurações locais\Dados de aplicativos\Conduit => Toolbar.Conduit
E:\Documents and Settings\Matheus\Configurações locais\Dados de aplicativos\Babylon
proxyfix
emptytemp
emptyflash
firewallraz
sysrestore
|- Ok! Entendi.Fui eu que postei esse pedido de ajuda,mas é o meu filho que executa as ferramentas que você indica.
[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]*crack* /s
*keygen* /s
*serial* /s
*AutoKMS* /s
*loader* /s
%APPDATA%\Local\*.
%APPDATA%\*.exe /s
%APPDATA%\*.
%USERPROFILE%\AppData\Local\*.*
%USERPROFILE%\AppData\Roaming\*.*
%systemroot%\assembly\tmp\*.* /S /MD5
%systemroot%\assembly\temp\*.* /S /MD5
%systemroot%\assembly\GAC\*.* /S /MD5
%systemroot%\assembly\GAC_32\*.* /S /MD5
%systemroot%\system32\config\systemprofile\AppData\Local\*.*
%windir%\ServiceProfiles\LocalService\AppData\Local\Temp\*.*
%windir%\ServiceProfiles\NetworkService\AppData\Local\Temp\*.*
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes
/md5start
services.exe
/md5stop
regedit /e c:\registrybackup.reg /c
type c:\boot.ini >> test.txt /c
%systemroot%\system32\Tasks\*.* /s
%windir%\tasks\*.* /s
|- Clique no botão Consertar -> Aguarde a conclusão!:OTL
IE - HKU\S-1-5-21-329068152-1004336348-1417001333-1003\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-329068152-1004336348-1417001333-1003\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: URL = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] [TXT_PAYS US - 65.60.5.200]
FF - prefs.js..browser.search.defaultthis.enginename: 4shared.com customized web search
FF - prefs.js..extensions.enabledAddons: [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]:1.5.0
FF - prefs.js..keyword.url: [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] [TXT_PAYS US - 198.143.128.244]
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O8 - Extra context menu item: &Download All using 4shared Desktop - [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] de programas\4shared Desktop\Desktop.32/D_ALL_LINK File not found
O8 - Extra context menu item: &Download using 4shared Desktop - [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] de programas\4shared Desktop\Desktop.32/D_ONE_LINK File not found
O18 - Protocol\Handler\livecall - No CLSID value found
O18 - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\wlmailhtml - No CLSID value found
O20 - AppInit_DLLs: (protector.dll) - E:\WINDOWS\System32\protector.dll ()
[2012/08/15 13:14:48 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users\Dados de aplicativos\OptimizerPro1
[2012/03/02 14:24:49 | 000,790,520 | ---- | C] () -- E:\WINDOWS\System32\protector.dll
[2012/06/12 12:38:36 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Dados de aplicativos\bProtector
[2012/08/16 17:54:00 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Dados de aplicativos\OptimizerPro1
[2011/05/29 10:07:57 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users\Dados de aplicativos\{A2A58654-12AA-408A-B411-58A76959BE7F}
[2012/04/07 11:10:16 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Matheus\Dados de aplicativos\4shared Desktop
[2011/11/15 19:48:47 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Matheus\Dados de aplicativos\Registry Mechanic
[2012/01/18 10:31:24 | 000,010,144 | ---- | M] () -- \Documents and Settings\Matheus\Dados de aplicativos\Mozilla\Firefox\Profiles\z7m80cxu.default\conduitCommon\modules\3.9.0.3\ExternalLibraryLoader.jsm
[2012/06/18 10:27:22 | 000,003,681 | ---- | M] () -- \Documents and Settings\Matheus\Dados de aplicativos\Mozilla\Firefox\Profiles\z7m80cxu.default\extensions\ffxtlbr@funmoods.com\content\loader.xul
[2012/08/23 09:31:41 | 000,016,896 | ---- | M] () -- \WINDOWS\Prefetch\DESKMEDIA_DOWNLOADER_1.0.EXE-2D42FC76.pf
@Alternate Data Stream - 113 bytes -> E:\Documents and Settings\All Users\Dados de aplicativos\TEMP:D1B5B4F1
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
"bProtectorDefaultScope" = -
:Files
E:\Documents and Settings\Matheus\Dados de aplicativos\Registry Mechanic
E:\Documents and Settings\All Users\Dados de aplicativos\bProtector
E:\Documents and Settings\All Users\Dados de aplicativos\OptimizerPro1
E:\Documents and Settings\Matheus\Dados de aplicativos\4shared Desktop
:Commands
[CREATERESTOREPOINT]
[purity]
[emptytemp]
[Reboot]
[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > ->
YN -> HKEY_LOCAL_MACHINE\: Main\"Default_Page_URL" -> www.v9.com/sof/sof_1345142322_653562
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-329068152-1004336348-1417001333-1003\] > ->
YN -> HKEY_USERS\S-1-5-21-329068152-1004336348-1417001333-1003\: Main\"Start Page" -> http://google.atcomet.com/m/
< FireFox Settings [Prefs.js] > -> E:\Documents and Settings\Matheus\Dados de aplicativos\Mozilla\FireFox\Profiles\z7m80cxu.default\prefs.js
YN -> browser.search.defaultthis.enginename -> """"
YN -> browser.search.selectedEngine -> "Search"
YN -> keyword.url -> "http://search.babylon.com/?af=110393&babsrc=adbartrp&mntrid=1044da26000000000000001d60032d43&q="
YN -> browser.search.defaultenginename -> "Search"
YN -> browser.search.selectedEngine -> "Search"
YN -> browser.startup.homepage -> "http://google.atcomet.com/m/"
YN -> browser.startup.homepage -> "www.v9.com/sof/sof_1333804600_752716"
YN -> backup.old.browser.search.selectedEngine -> "search"
< FireFox Extensions [User Folders] > ->
YN -> 4shared.com Community Toolbar -> E:\Documents and Settings\Matheus\Dados de aplicativos\Mozilla\Firefox\Profiles\z7m80cxu.default\extensions\{09ec805c-cb2e-4d53-b0d3-a75a428b81c7}
YN -> ~EmptyValue -> E:\Documents and Settings\Matheus\Dados de aplicativos\Mozilla\Firefox\Profiles\z7m80cxu.default\extensions\ffxtlbr@funmoods.com
YN -> ~EmptyValue -> E:\Documents and Settings\Matheus\Dados de aplicativos\Mozilla\Firefox\Profiles\z7m80cxu.default\extensions\staged
NY -> No name found -> E:\Documents and Settings\Matheus\Dados de aplicativos\Mozilla\Firefox\Profiles\z7m80cxu.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\Setup\bin\PandaSecurityTb_2.0.0.9\$[56]\extensions
< FireFox SearchPlugins [User Folders] > ->
YN -> funmoods.xml -> E:\Documents and Settings\Matheus\Dados de aplicativos\Mozilla\FireFox\Profiles\z7m80cxu.default\searchplugins\funmoods.xml
< FireFox Extensions [Program Folders] > ->
YN -> No name found -> E:\DOCUMENTS AND SETTINGS\MATHEUS\DADOS DE APLICATIVOS\MOZILLA\FIREFOX\PROFILES\Z7M80CXU.DEFAULT\EXTENSIONS\4SHAREDCOPYLINKS.XPI
YN -> Funmoods.com -> E:\DOCUMENTS AND SETTINGS\MATHEUS\DADOS DE APLICATIVOS\MOZILLA\FIREFOX\PROFILES\Z7M80CXU.DEFAULT\EXTENSIONS\FFXTLBR@FUNMOODS.COM
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {4DE0953E-490E-4D6F-BDDA-0516C372F3AF} [HKLM] -> E:\WINDOWS\system32\v9loader.dll [V9BHOLoader]
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
YN -> "{742E70CF-7770-412d-86CB-230B322E807C}" [HKLM] -> E:\WINDOWS\system32\v9-toolbar.dll [V9-ToolBar]
YN -> Beijing Elex Technology Co., Ltd) ->
YN -> "{98889811-442D-49dd-99D7-DC866BE87DBC}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-329068152-1004336348-1417001333-1003\] > -> HKEY_USERS\S-1-5-21-329068152-1004336348-1417001333-1003\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\"{21FA44EF-376D-4D53-9B0F-8A89D3229068}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
YN -> WebBrowser\"{724D43A0-0D85-11D4-9908-00400523E39A}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls
YN -> protector.dll ->
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
[Registry - Additional Scans - Safe List]
< Windows DomainProfile GloballyOpenPorts Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
YN -> \"57650:TCP" -> [57650:TCP:*:Enabled:Pando Media Booster]
YN -> \"57650:UDP" -> [57650:UDP:*:Enabled:Pando Media Booster]
< Windows StandardProfile GloballyOpenPorts Settings > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
YN -> \"57650:TCP" -> [57650:TCP:*:Enabled:Pando Media Booster]
YN -> \"57650:UDP" -> [57650:UDP:*:Enabled:Pando Media Booster]
< Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
YN -> Toolbar Cleaner -> Toolbar Cleaner 1.0
YN -> Usbfix -> UsbFix By El Desaparecido
YN -> V9Software -> V9 HomeTool
< Uninstall List [HKEY_USERS\S-1-5-21-329068152-1004336348-1417001333-1003\] > -> HKEY_USERS\S-1-5-21-329068152-1004336348-1417001333-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
YN -> FoxTab FLV Player -> FoxTab FLV Player
[Files/Folders - Created Within 30 Days]
NY -> v9-toolbar.dll -> E:\WINDOWS\System32\v9-toolbar.dll
[Files/Folders - Modified Within 30 Days]
NY -> funmoods.crx -> E:\Documents and Settings\Matheus\Configurações locais\Dados de aplicativos\funmoods.crx
[Files - No Company Name]
NY -> funmoods.crx -> E:\Documents and Settings\Matheus\Configurações locais\Dados de aplicativos\funmoods.crx
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
|- Rode este script.:COMMANDS
[CLEARALLRESTOREPOINTS]
[reboot]
Sáb Mar 23, 2024 10:28 am por joram
» KpRm ( ... by Kernel-panik )
Ter Ago 11, 2020 9:47 pm por joram
» ESET Rogue Applications Remover ( ... by Eset.com )
Sáb Ago 01, 2020 7:49 am por joram
» PW Clean 2.7 ( ... by Doutor PW )
Ter maio 15, 2018 9:27 am por joram
» CKScanner ( ... by askey127 )
Sáb maio 05, 2018 1:12 pm por joram
» AdwCleaner ( ... by XPlode )
Seg Abr 16, 2018 8:47 am por joram
» ZHPDiag ( ... de Nicolas Coolman )
Sáb Abr 14, 2018 8:56 am por joram
» Argente - Registry Cleaner ( ... by Argente Software )
Dom Nov 19, 2017 4:36 pm por joram
» ListChkdskResult ( ... by SleepyDude )
Dom Set 24, 2017 1:39 pm por joram