Usamos cookies para medir audiência e melhorar sua experiência. Você pode aceitar ou recusar a qualquer momento. Veja sobre o iMasters.
Instalei um programa que mascaradamente também instalou essa porcaria de Ask toolbar, a pesquisa Ask e consegui tirar , mas a toolbar não sai , aparece o seguinte quando vou nas extensões :
/applications/core/interface/imageproxy/imageproxy.php?img=http://img651.imageshack.us/img651/3340/capturarhk.png&key=9bb2adbfb70d56fe77bcc3885af67c039cfb0480e61507c5d42e2b2653363a87" alt="capturarhk.png" />
O botão ''Ativada'' não pode ser desmarcado . Peço ajuda para remover , segue um log do hijackthis :
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:50:53, on 12/02/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Auxiliar de Conexão do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGetBHO - {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - C:\Users\Alemão\AppData\Roaming\FlashGetBHO\FlashGetBHO.dll
O2 - BHO: Free Download Manager - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: Baixar com o Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dllink.htm
O8 - Extra context menu item: Baixar tudo com o Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlall.htm
O8 - Extra context menu item: Baixar vídeo com o Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download all links by FlashGet3 - C:\Program Files (x86)\FlashGet Network\FlashGet 3\BHO\fdgetallurl.htm
O8 - Extra context menu item: Download by FlashGet3 - C:\Program Files (x86)\FlashGet Network\FlashGet 3\BHO\fdgeturl.htm
O8 - Extra context menu item: Download selecionado pelo Free Download Manager - file://C:\Program Files (x86)\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Fazer o download de todos os links usando o IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Fazer o download usando o IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeO23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe--
End of file - 9160 bytes
Olá wings , obrigado pela sua rapidez , mas não , esta barra não é do Avira , foi o FormatFactory que eu instalei , e que instalou secretamente o Ask. Pode ter certeza que eu quero removê-la !!
:seta: Baixe o AdwCleaner (...de Xplode) e salve-o no Desktop (Área de Trabalho)
*Execute-o. Usuários do Windows Vista ou do Windows 7 devem clicar com o botão direito do mouse no arquivo e selecionar Executar como administrador
*Clique [Remover]. Em alguns casos, o PC será reiniciado para a completa remoção. Clique [OK] para reiniciar.
/applications/core/interface/imageproxy/imageproxy.php?img=http://t.imgbox.com/adp5cC2y.jpg&key=fd291e0a2654af5f4e675157a38b294f5609577ca677d3e79623ae9e39213ffa" alt="adp5cC2y.jpg" />
*Cole o relatório apresentado
Feito wings , mas não removeu nada ..
*** [serviços] ***
*** [Arquivos/Pastas] ***
Pasta Removido : C:\ProgramData\Ask
Pasta Removido : C:\Users\Alemão\AppData\Local\APN
Pasta Removido : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
*** [Registro] ***
Chave Removida : HKCU\Software\APN
Chave Removida : HKCU\Software\AppDataLow\Software\AskToolbar
Chave Removida : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Chave Removida : HKLM\Software\APN
Chave Removida : HKLM\Software\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Chave Removida : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
*** [Navegadores] ***
-\\ Internet Explorer v9.0.8112.16457
[OK] Registro está limpo.
-\\ Mozilla Firefox v19.0 (pt-BR)
Arquivo : C:\Users\Alemão\AppData\Roaming\Mozilla\Firefox\Profiles\gngtu53k.default\prefs.js
C:\Users\Alemão\AppData\Roaming\Mozilla\Firefox\Profiles\gngtu53k.default\user.js ... Removido !
Removida : user_pref("browser.search.defaultengine", "Ask.com");
Removida : user_pref("browser.search.defaultenginename", "Ask.com");
Removida : user_pref("browser.search.order.1", "Ask.com");
Removida : user_pref("browser.search.selectedEngine", "Ask.com");
Removida : user_pref("extensions.asktb.ff-original-keyword-url", "");
-\\ Google Chrome v24.0.1312.60
Arquivo : C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Arquivo está limpo.
*************************
AdwCleaner[s2].txt - [2206 octets] - [12/02/2013 17:13:53]
########## EOF - C:\AdwCleaner[s2].txt - [2266 octets] ##########
:seta: Baixe o Junkware Removal Tool (...de Thisisu) e salve-o no Desktop (Área de Trabalho)
*Feche o Google Chrome
*Execute-o. Usuários do Windows Vista ou do Windows 7 devem clicar com o botão direito do mouse no arquivo e selecionar Executar como administrador
*Tecle [ENTER]
/applications/core/interface/imageproxy/imageproxy.php?img=http://t.imgbox.com/abf606zR.jpg&key=e1d4dade8d80839edfccb487759becd47f6a586a1635f0744141b6dc141d766e" alt="abf606zR.jpg" />
*Será feito um backup do registro e, em seguida, o programa será executado automaticamente
/applications/core/interface/imageproxy/imageproxy.php?img=http://t.imgbox.com/adq2T7iE.jpg&key=7d179812a36b9b10b93f02a6e41d6adc6b6d2d8e82e34b5b81fb0569a83ef290" alt="adq2T7iE.jpg" />
*Aguarde...pode demorar.
*Cole o relatório apresentado
wings , o programa retorna a seguinte mensagem , na parte de '' Checking Registry - Quick Scan ''
Utilitário de localização de cadeia de caracteres (QGREP) parou de funcionar.
OK...
:seta: Execute o AdwCleaner, clique [Desinstalar] > [sim]
http://imgbox.com/abyzbgH4'>/applications/core/interface/imageproxy/imageproxy.php?img=http://t.imgbox.com/abyzbgH4.jpg&key=1cd68a22183c9c57870153931569517377fed52000aa5b8e57435a13b972642d" alt="abyzbgH4.jpg" />
:seta: Delete o JRT, seu relatório e a pasta C:\JRT
:seta: Baixe o http://www.infospyware.com/Software/click.php?id=25'>AT-Destroyer (...de InfoSpyware) e salve-o no Desktop (Área de Trabalho)
*Execute-o. Usuários do Windows Vista ou do Windows 7 devem clicar com o botão direito do mouse no arquivo e selecionar Executar como administrador
*Clique [buscar]
http://imgbox.com/adfz6ix0'>/applications/core/interface/imageproxy/imageproxy.php?img=http://t.imgbox.com/adfz6ix0.jpg&key=8548b532d25545c8e0a7f1266b7699ffbed4c473b2d8307ae2041e80520d741d" alt="adfz6ix0.jpg" />
*Cole o relatório apresentado
Aqui está :
######################## AT-Destroyer By Infospyware.
Hora/Día/Mes/Año: 18:00:35 \\\ 12/02/2013
AT-Destroyer 2.1 By Infospyware ---> www.infospyware.com
Última actualización: 30/11/2012
Opción escogida: 1 :Buscar
Versión Internet Explorer:9.0.8112.16421
Mozilla Firefox:19.0.0.4785
Google Chrome:24.0.1312.60
Privilegios: Alemão - Administrador
Modo Actual: Modo Normal.
Nombre del pc: PC
Información del sistema operativo:X64-WIN_7-Service Pack 1
nombre del usuario:Alemão
Lenguaje del sistema: Portugués
>>>>>> Servicios <<<<<<
>>>>>> Carpetas <<<<<<
>>>>>> Archivos <<<<<<
>>>>>> Registro <<<<<<
>>>>>> Heurística <<<<<<
>>>>>> Internet Explorer <<<<<<
Start Page==http://go.microsoft.com/fwlink/?LinkId=69157
Local Page==C:\Windows\SysWOW64\blank.htm
Search Page==http://go.microsoft.com/fwlink/?LinkId=54896
Default_search_url==http://go.microsoft.com/fwlink/?LinkId=54896
Default_Page_URL==http://go.microsoft.com/fwlink/?LinkId=69157
''HKCU\Software\Microsoft\Internet Explorer\Main''
Start Page==http://www.google.com.br/
Local Page==C:\Windows\system32\blank.htm
Search Page==http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Default_search_url==
Default_Page_URL==
HKEY_USERS\S-1-5-21-11842420-550085179-1162059400-1000\Software\Microsoft\Internet Explorer\Main''
Start Page==http://www.google.com.br/
Local Page==C:\Windows\system32\blank.htm
Search Page==http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Default_search_url==
Default_Page_URL==
>>>>>> Firefox <<<<<<
user_pref("browser.startup.homepage", "[http://www.google.com/](http://www.google.com/)");
user_pref("browser.startup.homepage_override.buildID", "20130206083616");
user_pref("browser.startup.homepage_override.mstone", "19.0");
user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
user_pref("pref.browser.homepage.disable_button.current_page", false);
user_pref("pref.browser.homepage.disable_button.restore_default", false);
>>>>>> Extensiones Firefox <<<<<<
C:\Program Files (x86)\{972ce4c6-7e08-4474-a285-3208198ce6fd}
>>>>>> Plugins Firefox <<<<<<
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.13.2
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@raidcall.kr/RCplugin
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9
>>>>>> Google Chrome <<<<<<
"homepage": "http://www.google.com.br/",
"homepage_url": "http://www.internetdownloadmanager.com/",
"homepage": "http://www.google.com.br/",
>>>>>> Extensiones Google Chrome <<<<<<
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\7
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaapoldfpilohhfkhihnhdckpackghi
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmolcgpienlcieaajfkkdamlngancncm
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
======== Listado ===========
C:\Users\Alemão\AppData\Roaming\Ashampoo [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Auslogics [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Avira [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\BITS [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\BreakPoint Software [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\DAEMON Tools Lite [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\DMCache [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Easeware [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\FlashGet [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\FlashGetBHO [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\FlashgetSetup [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Free Download Manager [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\GetRightToGo [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\GlarySoft [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\GrabPro [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Identities [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\IDM [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\IObit [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Macromedia [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Malwarebytes [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Media Center Programs [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Media Player Classic [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Microsoft [sDI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Mipony [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\mIRC [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Mozilla [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Orbit [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\PointBlank [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Process Hacker 2 [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\ProgSense [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\RCKR [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\SecuROM [RHD] 0 ( )
C:\Users\Alemão\AppData\Roaming\Skype [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Spyware Terminator [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\System Monitor II_CPU0_Settings.ini [AI] 1,76 KB ( )
C:\Users\Alemão\AppData\Roaming\TeamViewer [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\TechSmith [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Theta [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\TS3Client [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Unity [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\uTorrent [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Winamp [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Windows Live Writer [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\WinRAR [DI] 0 ( )
C:\Program Files (x86)\Adobe [D] 0( 0)
C:\Program Files (x86)\AmIcoSingLun [D] 0( 0)
C:\Program Files (x86)\ApecSoft [D] 0( 0)
C:\Program Files (x86)\Ashampoo [D] 0( 0)
C:\Program Files (x86)\Auslogics [D] 0( 0)
C:\Program Files (x86)\Avira [D] 0( 0)
C:\Program Files (x86)\Borland [D] 0( 0)
C:\Program Files (x86)\Cheat Engine 6.1 [D] 0( 0)
C:\Program Files (x86)\Cheat Engine 6.2 [D] 0( 0)
C:\Program Files (x86)\Common Files [D] 0( 0)
C:\Program Files (x86)\DAEMON Tools Lite [D] 0( 0)
C:\Program Files (x86)\Dead Space 3 [D] 0( 0)
C:\Program Files (x86)\desktop.ini [HSA] 174 bytes( 0)
C:\Program Files (x86)\DsNET Corp [D] 0( 0)
C:\Program Files (x86)\Electronic Arts [D] 0( 0)
C:\Program Files (x86)\ESET [D] 0( 0)
C:\Program Files (x86)\Everything [D] 0( 0)
C:\Program Files (x86)\FlashGet Network [D] 0( 0)
C:\Program Files (x86)\Free Download Manager [D] 0( 0)
C:\Program Files (x86)\FreeTime [D] 0( 0)
C:\Program Files (x86)\GameVicio [D] 0( 0)
C:\Program Files (x86)\Google [D] 0( 0)
C:\Program Files (x86)\Hitman Absolution [D] 0( 0)
C:\Program Files (x86)\HWiNFO32 [D] 0( 0)
C:\Program Files (x86)\InstallShield Installation Information [HD] 0( 0)
C:\Program Files (x86)\Intel [D] 0( 0)
C:\Program Files (x86)\Internet Download Manager [D] 0( 0)
C:\Program Files (x86)\Internet Explorer [D] 0( 0)
C:\Program Files (x86)\IObit [D] 0( 0)
C:\Program Files (x86)\Java [D] 0( 0)
C:\Program Files (x86)\K-Lite Codec Pack [D] 0( 0)
C:\Program Files (x86)\KONAMI [D] 0( 0)
C:\Program Files (x86)\Malwarebytes' Anti-Malware [D] 0( 0)
C:\Program Files (x86)\Microsoft SDKs [D] 0( 0)
C:\Program Files (x86)\Microsoft Silverlight [D] 0( 0)
C:\Program Files (x86)\Microsoft SQL Server [D] 0( 0)
C:\Program Files (x86)\Microsoft SQL Server Compact Edition [D] 0( 0)
C:\Program Files (x86)\Microsoft Synchronization Services [D] 0( 0)
C:\Program Files (x86)\Microsoft Visual Studio 10.0 [D] 0( 0)
C:\Program Files (x86)\Microsoft.NET [D] 0( 0)
C:\Program Files (x86)\mIRC [D] 0( 0)
C:\Program Files (x86)\Mozilla Firefox [D] 0( 0)
C:\Program Files (x86)\Mozilla Maintenance Service [D] 0( 0)
C:\Program Files (x86)\MSBuild [D] 0( 0)
C:\Program Files (x86)\PremiumSoft [D] 0( 0)
C:\Program Files (x86)\QuickTime [D] 0( 0)
C:\Program Files (x86)\RaidCall [D] 0( 0)
C:\Program Files (x86)\Razer [D] 0( 0)
C:\Program Files (x86)\Reference Assemblies [D] 0( 0)
C:\Program Files (x86)\RocketDock [D] 0( 0)
C:\Program Files (x86)\Skype [RD] 0( 0)
C:\Program Files (x86)\Spyware Terminator [D] 0( 0)
C:\Program Files (x86)\Steam [D] 0( 0)
C:\Program Files (x86)\TaskExplorer [D] 0( 0)
C:\Program Files (x86)\TeamSpeak 3 Client [D] 0( 0)
C:\Program Files (x86)\TeamViewer [D] 0( 0)
C:\Program Files (x86)\TechSmith [D] 0( 0)
C:\Program Files (x86)\trend micro [D] 0( 0)
C:\Program Files (x86)\Uninstall Information [HD] 0( 0)
C:\Program Files (x86)\uTorrent [D] 0( 0)
C:\Program Files (x86)\VIA [D] 0( 0)
C:\Program Files (x86)\VS Revo Group [D] 0( 0)
C:\Program Files (x86)\Winamp [D] 0( 0)
C:\Program Files (x86)\Winamp Detect [D] 0( 0)
C:\Program Files (x86)\Windows Defender [D] 0( 0)
C:\Program Files (x86)\Windows Live [D] 0( 0)
C:\Program Files (x86)\Windows Mail [D] 0( 0)
C:\Program Files (x86)\Windows Media Player [D] 0( 0)
C:\Program Files (x86)\Windows NT [D] 0( 0)
C:\Program Files (x86)\Windows Photo Viewer [D] 0( 0)
C:\Program Files (x86)\Windows Portable Devices [D] 0( 0)
C:\Program Files (x86)\Windows Sidebar [D] 0( 0)
C:\ProgramData\AmUStor [DI] 0 0
C:\ProgramData\Application Data [HSDLI] 0 0
C:\ProgramData\ashampoo [DI] 0 0
C:\ProgramData\Avira [DI] 0 0
C:\ProgramData\Comodo [DI] 0 0
C:\ProgramData\Comodo Downloader [DI] 0 0
C:\ProgramData\Dados de aplicativos [HSDLI] 0 0
C:\ProgramData\DAEMON Tools Lite [DI] 0 0
C:\ProgramData\Desktop [HSDLI] 0 0
C:\ProgramData\Documentos [HSDLI] 0 0
C:\ProgramData\Documents [HSDLI] 0 0
C:\ProgramData\EA Core [DI] 0 0
C:\ProgramData\Electronic Arts [DI] 0 0
C:\ProgramData\Favorites [HSDLI] 0 0
C:\ProgramData\Favoritos [HSDLI] 0 0
C:\ProgramData\Free Download Manager [DI] 0 0
C:\ProgramData\HitmanPro [DI] 0 0
C:\ProgramData\IDM [DI] 0 0
C:\ProgramData\IObit [DI] 0 0
C:\ProgramData\KONAMI [DI] 0 0
C:\ProgramData\Malwarebytes [DI] 0 0
C:\ProgramData\Menu Iniciar [HSDLI] 0 0
C:\ProgramData\Microsoft [sDI] 0 0
C:\ProgramData\Modelos [HSDLI] 0 0
C:\ProgramData\Mozilla [DI] 0 0
C:\ProgramData\MySQL [DI] 0 0
C:\ProgramData\Razer [DI] 0 0
C:\ProgramData\Skype [DI] 0 0
C:\ProgramData\Solidshield [DI] 0 0
C:\ProgramData\Spyware Terminator [DI] 0 0
C:\ProgramData\Start Menu [HSDLI] 0 0
C:\ProgramData\Sun [DI] 0 0
C:\ProgramData\TechSmith [DI] 0 0
C:\ProgramData\TEMP [DAI] 0 0
C:\ProgramData\Templates [HSDLI] 0 0
C:\ProgramData\VS [DI] 0 0
======================EOF=======================
A extensão foi detectada pelo programa.
Vamos ver se remove.
:seta: Feche o Google Chrome
*Execute o AT-Destroyer. Usuários do Windows Vista ou do Windows 7 devem clicar com o botão direito do mouse no arquivo e selecionar Executar como administrador
*Clique [buscar y Destruir]
http://imgbox.com/adxd8Vlh'>/applications/core/interface/imageproxy/imageproxy.php?img=http://t.imgbox.com/adxd8Vlh.jpg&key=be78bfe5415ff8d18d10eec37a81e1dccfeaeef718601e5cc0b87254fd60ab3f" alt="adxd8Vlh.jpg" />
*Caso seja necessário, o programa solicitará a reinicialização do PC
*Cole o relatório apresentado
Removido com sucesso wings , muito obrigado pela sua ajuda !
######################## AT-Destroyer [2.1] By Infospyware.
Hora/Día/Mes/Año: 18:12:04 \\\ 12/02/2013
AT-Destroyer 2.1 By Infospyware ---> www.infospyware.com
Última actualización: 30/11/2012
Opción escogida: 2 :Buscar y Destruir
Versión Internet Explorer:9.0.8112.16421
Mozilla Firefox:19.0.0.4785
Google Chrome:24.0.1312.60
Privilegios: Alemão - Administrador
Modo Actual: Modo Normal.
Nombre del pc: PC
Información del sistema operativo:X64-WIN_7-Service Pack 1
nombre del usuario:Alemão
Lenguaje del sistema: Portugués
>>>>>>> Servicios <<<<<<<
>>>>>> Carpetas <<<<<<
>>>>>> Archivos <<<<<<
>>>>>> Registro <<<<<<
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
>>>>>> Heurística <<<<<<
>>>>>> Internet Explorer <<<<<<
Start Page==www.google.com
Local Page==C:\Windows\SysWOW64\blank.htm
Search Page==http://go.microsoft.com/fwlink/?LinkId=54896
Default_search_url==http://go.microsoft.com/fwlink/?LinkId=54896
Default_Page_URL==http://go.microsoft.com/fwlink/?LinkId=69157
''HKCU\Software\Microsoft\Internet Explorer\Main''
Start Page==www.google.com
Local Page==C:\Windows\system32\blank.htm
Search Page==http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Default_search_url==
Default_Page_URL==
HKEY_USERS\S-1-5-21-11842420-550085179-1162059400-1000\Software\Microsoft\Internet Explorer\Main''
Start Page==www.google.com
Local Page==C:\Windows\system32\blank.htm
Search Page==http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Default_search_url==
Default_Page_URL==
>>>>>> Firefox <<<<<<
user_pref("browser.startup.homepage", "[http://www.google.com/](http://www.google.com/)");
user_pref("browser.startup.homepage_override.buildID", "20130206083616");
user_pref("browser.startup.homepage_override.mstone", "19.0");
user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
user_pref("pref.browser.homepage.disable_button.current_page", false);
user_pref("pref.browser.homepage.disable_button.restore_default", false);
>>>>>> Extensiones Firefox <<<<<<
C:\Program Files (x86)\{972ce4c6-7e08-4474-a285-3208198ce6fd}
>>>>>> Plugins Firefox <<<<<<
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.13.2
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.13.2
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@raidcall.kr/RCplugin
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9
>>>>>> Google Chrome <<<<<<
"homepage": "http://www.google.com/",
"homepage_changed": true,
"homepage_is_newtabpage": false,
>>>>>> Extensiones Google Chrome <<<<<<
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\7
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaapoldfpilohhfkhihnhdckpackghi
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmolcgpienlcieaajfkkdamlngancncm
C:\Users\Alemão\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
======== Listado ===========
C:\Users\Alemão\AppData\Roaming\Ashampoo [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Auslogics [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Avira [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\BITS [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\BreakPoint Software [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\DAEMON Tools Lite [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\DMCache [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Easeware [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\FlashGet [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\FlashGetBHO [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\FlashgetSetup [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Free Download Manager [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\GetRightToGo [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\GlarySoft [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\GrabPro [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Identities [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\IDM [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\IObit [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Macromedia [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Malwarebytes [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Media Center Programs [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Media Player Classic [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Microsoft [sDI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Mipony [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\mIRC [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Mozilla [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Orbit [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\PointBlank [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Process Hacker 2 [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\ProgSense [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\RCKR [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\SecuROM [RHD] 0 ( )
C:\Users\Alemão\AppData\Roaming\Skype [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Spyware Terminator [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\System Monitor II_CPU0_Settings.ini [AI] 1,76 KB ( )
C:\Users\Alemão\AppData\Roaming\TeamViewer [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\TechSmith [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Theta [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\TS3Client [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Unity [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\uTorrent [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Winamp [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\Windows Live Writer [DI] 0 ( )
C:\Users\Alemão\AppData\Roaming\WinRAR [DI] 0 ( )
C:\Program Files (x86)\Add Remove Pro [D] 0( 0)
C:\Program Files (x86)\Adobe [D] 0( 0)
C:\Program Files (x86)\AmIcoSingLun [D] 0( 0)
C:\Program Files (x86)\ApecSoft [D] 0( 0)
C:\Program Files (x86)\Ashampoo [D] 0( 0)
C:\Program Files (x86)\Auslogics [D] 0( 0)
C:\Program Files (x86)\Avira [D] 0( 0)
C:\Program Files (x86)\Borland [D] 0( 0)
C:\Program Files (x86)\Cheat Engine 6.1 [D] 0( 0)
C:\Program Files (x86)\Cheat Engine 6.2 [D] 0( 0)
C:\Program Files (x86)\Common Files [D] 0( 0)
C:\Program Files (x86)\DAEMON Tools Lite [D] 0( 0)
C:\Program Files (x86)\Dead Space 3 [D] 0( 0)
C:\Program Files (x86)\desktop.ini [HSA] 174 bytes( 0)
C:\Program Files (x86)\DsNET Corp [D] 0( 0)
C:\Program Files (x86)\Electronic Arts [D] 0( 0)
C:\Program Files (x86)\ESET [D] 0( 0)
C:\Program Files (x86)\Everything [D] 0( 0)
C:\Program Files (x86)\FlashGet Network [D] 0( 0)
C:\Program Files (x86)\Free Download Manager [D] 0( 0)
C:\Program Files (x86)\FreeTime [D] 0( 0)
C:\Program Files (x86)\GameVicio [D] 0( 0)
C:\Program Files (x86)\Google [D] 0( 0)
C:\Program Files (x86)\Hitman Absolution [D] 0( 0)
C:\Program Files (x86)\HWiNFO32 [D] 0( 0)
C:\Program Files (x86)\InstallShield Installation Information [HD] 0( 0)
C:\Program Files (x86)\Intel [D] 0( 0)
C:\Program Files (x86)\Internet Download Manager [D] 0( 0)
C:\Program Files (x86)\Internet Explorer [D] 0( 0)
C:\Program Files (x86)\IObit [D] 0( 0)
C:\Program Files (x86)\Java [D] 0( 0)
C:\Program Files (x86)\K-Lite Codec Pack [D] 0( 0)
C:\Program Files (x86)\KONAMI [D] 0( 0)
C:\Program Files (x86)\Malwarebytes' Anti-Malware [D] 0( 0)
C:\Program Files (x86)\Microsoft SDKs [D] 0( 0)
C:\Program Files (x86)\Microsoft Silverlight [D] 0( 0)
C:\Program Files (x86)\Microsoft SQL Server [D] 0( 0)
C:\Program Files (x86)\Microsoft SQL Server Compact Edition [D] 0( 0)
C:\Program Files (x86)\Microsoft Synchronization Services [D] 0( 0)
C:\Program Files (x86)\Microsoft Visual Studio 10.0 [D] 0( 0)
C:\Program Files (x86)\Microsoft.NET [D] 0( 0)
C:\Program Files (x86)\mIRC [D] 0( 0)
C:\Program Files (x86)\Mozilla Firefox [D] 0( 0)
C:\Program Files (x86)\Mozilla Maintenance Service [D] 0( 0)
C:\Program Files (x86)\MSBuild [D] 0( 0)
C:\Program Files (x86)\PremiumSoft [D] 0( 0)
C:\Program Files (x86)\QuickTime [D] 0( 0)
C:\Program Files (x86)\RaidCall [D] 0( 0)
C:\Program Files (x86)\Razer [D] 0( 0)
C:\Program Files (x86)\Reference Assemblies [D] 0( 0)
C:\Program Files (x86)\RocketDock [D] 0( 0)
C:\Program Files (x86)\Skype [RD] 0( 0)
C:\Program Files (x86)\Spyware Terminator [D] 0( 0)
C:\Program Files (x86)\Steam [D] 0( 0)
C:\Program Files (x86)\TaskExplorer [D] 0( 0)
C:\Program Files (x86)\TeamSpeak 3 Client [D] 0( 0)
C:\Program Files (x86)\TeamViewer [D] 0( 0)
C:\Program Files (x86)\TechSmith [D] 0( 0)
C:\Program Files (x86)\trend micro [D] 0( 0)
C:\Program Files (x86)\Uninstall Information [HD] 0( 0)
C:\Program Files (x86)\uTorrent [D] 0( 0)
C:\Program Files (x86)\VIA [D] 0( 0)
C:\Program Files (x86)\VS Revo Group [D] 0( 0)
C:\Program Files (x86)\Winamp [D] 0( 0)
C:\Program Files (x86)\Winamp Detect [D] 0( 0)
C:\Program Files (x86)\Windows Defender [D] 0( 0)
C:\Program Files (x86)\Windows Live [D] 0( 0)
C:\Program Files (x86)\Windows Mail [D] 0( 0)
C:\Program Files (x86)\Windows Media Player [D] 0( 0)
C:\Program Files (x86)\Windows NT [D] 0( 0)
C:\Program Files (x86)\Windows Photo Viewer [D] 0( 0)
C:\Program Files (x86)\Windows Portable Devices [D] 0( 0)
C:\Program Files (x86)\Windows Sidebar [D] 0( 0)
C:\ProgramData\AmUStor [DI] 0 0
C:\ProgramData\Application Data [HSDLI] 0 0
C:\ProgramData\ashampoo [DI] 0 0
C:\ProgramData\Avira [DI] 0 0
C:\ProgramData\Comodo [DI] 0 0
C:\ProgramData\Comodo Downloader [DI] 0 0
C:\ProgramData\Dados de aplicativos [HSDLI] 0 0
C:\ProgramData\DAEMON Tools Lite [DI] 0 0
C:\ProgramData\Desktop [HSDLI] 0 0
C:\ProgramData\Documentos [HSDLI] 0 0
C:\ProgramData\Documents [HSDLI] 0 0
C:\ProgramData\EA Core [DI] 0 0
C:\ProgramData\Electronic Arts [DI] 0 0
C:\ProgramData\Favorites [HSDLI] 0 0
C:\ProgramData\Favoritos [HSDLI] 0 0
C:\ProgramData\Free Download Manager [DI] 0 0
C:\ProgramData\HitmanPro [DI] 0 0
C:\ProgramData\IDM [DI] 0 0
C:\ProgramData\IObit [DI] 0 0
C:\ProgramData\KONAMI [DI] 0 0
C:\ProgramData\Malwarebytes [DI] 0 0
C:\ProgramData\Menu Iniciar [HSDLI] 0 0
C:\ProgramData\Microsoft [sDI] 0 0
C:\ProgramData\Modelos [HSDLI] 0 0
C:\ProgramData\Mozilla [DI] 0 0
C:\ProgramData\MySQL [DI] 0 0
C:\ProgramData\Razer [DI] 0 0
C:\ProgramData\Skype [DI] 0 0
C:\ProgramData\Solidshield [DI] 0 0
C:\ProgramData\Spyware Terminator [DI] 0 0
C:\ProgramData\Start Menu [HSDLI] 0 0
C:\ProgramData\Sun [DI] 0 0
C:\ProgramData\TechSmith [DI] 0 0
C:\ProgramData\TEMP [DAI] 0 0
C:\ProgramData\Templates [HSDLI] 0 0
C:\ProgramData\VS [DI] 0 0
==================== EOF ==================
:seta: Execute o AT-Destroyer, clique [Desinstalar] > [OK] e o PC será reiniciado
Um abraço.....:bye:
PROBLEMA RESOLVIDO
Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico.
Olá GaloFrito
Geralmente esta barra está relacionada ao Avira Web Protection.
Tem certeza que deseja removê-la?