Ir para conteúdo

DigRam

Moderadores
  • Total de itens

    7066
  • Registro em

  • Última visita

  • Dias vencidos

    13

DigRam venceu o dia em Janeiro 6

Teve o conteúdo mais curtido

Reputação

144 Muito Bom

Sobre DigRam

  • Classificação
    Equipe iMasters
  • Data de Nascimento 07/15/1953

Informações Pessoais

  • Sexo
    Masculino
  • Localização
    RIO DE JANEIRO
  • Interesses
    Especialidade em Eletrônica
    Matemática
    Segurança da Informação ( Remoção de Malwares )

Contato

  • Site Pessoal
    http://secsecurity.forumbrasil.net/

Últimos Visitantes

9808725 visualizações
  1. DigRam

    Análise de log hijackthis

    /_ Bom Dia! William Bruno _\ Não vi malwares nos relatórios! Seu computador é limpo. > Baixe: < ZHPCleaner > < ... de Nicolas Coolman > > Ou |Aqui!| << Mirror! > Caso tenha algum impedimento ao download,assista este tutorial que foi postado no YouTube,para desativar o Windows SmartScreen. > Estando na página,clique > Salve-a ao desktop! ( ZHPCleaner.exe ) > Desabilite seu antivírus e execute ZHPCleaner.exe << > Ao abrir esta tela,evite clicar em Update ou Atualização,para não ser direcionado ao ZHPBrowser. > Ps: Feche a mensagem ao clicar no ["X"]. > Com a ferramenta aberta,clique em Scanner. > Aguarde a conclusão! > Ao concluir,clique Repair. > Ps: Ignore possíveis alertas quanto à sua configuração de rede. (DNS) > Clique Sim >> Sim! > Surgirão guias que estarão em vermelho,indicando problemas a serem reparados. > Clique Repair. > Ao concluir,clique Report. > Poste o log de reparo: ~ Type : Reparo Este será seu relatório direto,obtido ao modificar na barra de endereços,de (.html) para (.txt). Basta selecionar (ctrl + A),copiar (ctrl + C) e colar ao seu Post ou Bloco de Notas. (ctrl + V) Disponibilize o relatório em Cjoint.com ou utilize spoiler,cuja instrução está ao final daquela página. Outra opção,é hospedar o relatório em Hébergement de fichiers, Security-x.fr. [Abs]
  2. DigRam

    Infecção por Malware Desconhecido

    /_ Boa Noite! Silas Pedro Alcantara _\ > Baixe: < ZHPCleaner > < ... de Nicolas Coolman > > Ou |Aqui!| << Mirror! > Caso tenha algum impedimento ao download,assista este tutorial que foi postado no YouTube,para desativar o Windows SmartScreen. > Estando na página,clique > Salve-a ao desktop! ( ZHPCleaner.exe ) > Desabilite seu antivírus e execute ZHPCleaner.exe << > Ao abrir esta tela,evite clicar em Update ou Atualização,para não ser direcionado ao ZHPBrowser. > Ps: Feche a mensagem ao clicar no ["X"]. > Com a ferramenta aberta,clique em Scanner. > Aguarde a conclusão! > Ao concluir,clique Repair. > Ps: Ignore possíveis alertas quanto à sua configuração de rede. (DNS) > Clique Sim >> Sim! > Surgirão guias que estarão em vermelho,indicando problemas a serem reparados. > Clique Repair. > Ao concluir,clique Report. > Poste o log de reparo: ~ Type : Reparo Este será seu relatório direto,obtido ao modificar na barra de endereços,de (.html) para (.txt). Basta selecionar (ctrl + A),copiar (ctrl + C) e colar ao seu Post ou Bloco de Notas. (ctrl + V) Disponibilize o relatório em Cjoint.com ou utilize spoiler,cuja instrução está ao final daquela página. Outra opção,é hospedar o relatório em Hébergement de fichiers, Security-x.fr. [Abs]
  3. DigRam

    Infecção por Malware Desconhecido

    /_ Boa Noite! Silas Pedro Alcantara _\ > Desinstale: App Explorer (HKU\S-1-5-21-2181840671-3561481943-960450070-1002\...\Host App Service) (Version: 0.273.2.800 - SweetLabs) <==== ATENÇÃO > Copie estas informações que estão em vermelho,para o Bloco de Notas. > Salve-as com o nome fixlist. << Texto ou Unicode,caso solicite! > Salve-as ao desktop! ( Área de trabalho ... ) start:: CloseProcesses: HKU\S-1-5-21-2181840671-3561481943-960450070-1002\...\RunOnce: [Application Restart #1] => C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe [2360000 2016-10-25] (Adobe Systems Incorporated) <==== ATENÇÃO SearchScopes: HKU\S-1-5-21-2181840671-3561481943-960450070-1002 -> DefaultScope {AE4FB2CA-A28B-4E30-93DD-ABE54FA25491} URL = SearchScopes: HKU\S-1-5-21-2181840671-3561481943-960450070-1002 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10440__180323__yaie&p={searchTerms} 2018-07-13 15:43 - 2018-07-13 15:43 - 000004903 _____ C:\Users\Todos os Usuários\vfiakfjk.zeu 2018-07-13 15:43 - 2018-07-13 15:43 - 000004903 _____ C:\ProgramData\vfiakfjk.zeu 2018-07-13 15:43 - 2018-07-13 15:43 - 000000016 _____ C:\Users\Todos os Usuários\mntemp 2018-07-13 15:43 - 2018-07-13 15:43 - 000000016 _____ C:\ProgramData\mntemp 2018-07-13 13:32 - 2018-07-13 13:32 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignff9a8ba6bfb5bc79 2018-07-13 13:32 - 2018-07-13 13:32 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign3d47ed339d5984fe 2018-07-13 13:31 - 2018-07-13 13:31 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign65def44e5c41ac15 2018-07-13 13:31 - 2018-07-13 13:31 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign57409dd5f99438ff 2018-07-13 01:44 - 2018-07-13 01:44 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign544694a68d453cbd 2018-07-13 00:46 - 2018-07-13 00:46 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb20e71656fd0aacd 2018-07-13 00:46 - 2018-07-13 00:46 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign5f0b2a22c51bf9ff 2018-07-13 00:46 - 2018-07-13 00:46 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign27e3402fd7d112da 2018-07-12 17:10 - 2018-07-12 17:10 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign6cbe3fbcd50ec0db 2018-07-12 17:09 - 2018-07-12 17:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign4ce41e1cfeda3164 2018-07-12 17:09 - 2018-07-12 17:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign1344ef86030bf77b 2018-07-12 17:09 - 2018-07-12 17:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign0007524559306f5c 2018-07-11 17:13 - 2018-07-11 17:13 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign4758d4b3d646c5c2 2018-07-11 17:07 - 2018-07-11 17:07 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign09f93dee8426df4f 2018-07-11 17:05 - 2018-07-11 17:05 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign29fcc88c5549127d 2018-07-11 17:04 - 2018-07-11 17:04 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb95d0f6976667442 2018-07-11 17:01 - 2018-07-11 17:01 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb237a646ea1550a0 2018-07-11 16:48 - 2018-07-11 16:48 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign6a01045f03f316a4 2018-07-11 16:46 - 2018-07-11 16:46 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignf92a6bff93fabd43 2018-07-11 14:50 - 2018-07-11 14:50 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignca55d6ef149fb846 2018-07-11 14:47 - 2018-07-11 14:47 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb902b9c3c0fbdfd4 2018-07-11 14:47 - 2018-07-11 14:47 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign8f7befb2a1a795b8 2018-07-11 14:47 - 2018-07-11 14:47 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign59a22667dff22361 2018-07-08 21:13 - 2018-07-09 19:13 - 000000000 _____ () C:\Users\silas\AppData\Local\Temp\00e481b5e22dbe1f649fcddd505d3eb7.dll 2018-07-08 21:13 - 2018-07-09 19:13 - 000000017 _____ () C:\Users\silas\AppData\Local\Temp\3796d1d61e088f2bf8ee07b0bf214b63.dll 2018-07-10 17:19 - 2018-07-10 17:21 - 048805832 _____ (SweetLabs,Inc.) C:\Users\silas\AppData\Local\Temp\octF978.tmp.exe 2018-06-30 23:09 - 2018-06-30 23:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign831e829d7dc962fe 2018-06-30 23:09 - 2018-06-30 23:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign5bf0e62f5743e769 2018-06-30 23:09 - 2018-06-30 23:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign2aea907d0b91fb69 2018-06-30 22:58 - 2018-06-30 22:58 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign620aca81bc1e77e5 2018-06-30 22:57 - 2018-06-30 22:57 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignff1b0dbd5743e707 2018-06-30 22:57 - 2018-06-30 22:57 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignda3b542a9747951c 2018-06-29 02:44 - 2018-06-29 02:44 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignabbdcddf06f82d54 2018-06-29 02:43 - 2018-06-29 02:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignc09015c9194c55b3 2018-06-29 02:39 - 2018-06-29 02:39 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignca726ff0eafe266a 2018-06-29 02:39 - 2018-06-29 02:39 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign82e9d0857f6a8282 2018-06-29 02:15 - 2018-06-29 02:15 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign9ebec1e59dfc771d 2018-06-29 02:14 - 2018-06-29 02:14 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign573c9fdeddb7dfab 2018-06-29 02:12 - 2018-06-29 02:12 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign68a2adaedfe40dcf 2018-06-29 02:11 - 2018-06-29 02:11 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigna8ca52316a055e32 2018-06-29 02:11 - 2018-06-29 02:11 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign326488dcbff9700f 2018-06-11 21:02 - 2018-06-11 21:02 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignedc41c712dace101 2018-06-11 19:43 - 2018-06-11 19:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign759aa1a616ba8c81 2018-06-11 19:42 - 2018-06-11 19:42 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigndae9c7c14d579e5d 2018-06-11 19:42 - 2018-06-11 19:42 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignc59cf9710821fab5 2018-06-10 21:35 - 2018-06-10 21:35 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign5d8f9e96178bb501 2018-06-10 18:47 - 2018-06-10 18:47 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign3ea79d616f77cf1b 2018-06-10 18:28 - 2018-06-10 18:28 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign69e24871a7488253 2018-06-10 18:18 - 2018-06-10 18:18 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignd4b957bb0e04f00c 2018-06-10 18:18 - 2018-06-10 18:18 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign2b16d86ccafd0ca0 2018-06-10 18:13 - 2018-06-10 18:13 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign23178ca322e5bdda 2018-06-10 17:16 - 2018-06-10 17:16 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign511b92524bb85d45 2018-06-10 17:01 - 2018-06-10 17:01 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignc817ed500f5765bc 2018-06-10 17:01 - 2018-06-10 17:01 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign4072662919650b5c 2018-06-10 17:01 - 2018-06-10 17:01 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign3b84eac62fc2dbc6 2018-06-10 16:59 - 2018-06-10 16:59 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign876b9ada238e3561 2018-06-10 16:59 - 2018-06-10 16:59 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign0108018dde07f09d 2018-06-10 15:52 - 2018-06-10 15:52 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign7474f2bd374f438d 2018-06-10 15:52 - 2018-06-10 15:52 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign7439ec641a8bda9f 2018-06-10 15:51 - 2018-06-10 15:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigndc4b9d506e9b37c3 2018-06-10 15:51 - 2018-06-10 15:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigna4846771b52a9264 2018-06-10 15:51 - 2018-06-10 15:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign2080a60e91b9ea87 2018-06-10 15:48 - 2018-06-10 15:48 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignf1ef3f521abd1ee4 2018-06-10 15:48 - 2018-06-10 15:48 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignc5580fd42fea8bb4 2018-05-30 16:43 - 2018-05-30 16:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign059eadc6d5c569c4 2018-05-30 16:42 - 2018-05-30 16:42 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb8c81fd548742c40 2018-05-30 16:42 - 2018-05-30 16:42 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign937bf32edb6987ea 2018-05-27 18:56 - 2018-05-27 18:56 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigna4beec2754652c10 2018-05-27 17:22 - 2018-05-27 17:22 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign9679863cc59c3ea1 2018-05-27 17:22 - 2018-05-27 17:22 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign7a44f599ae412bc1 2018-05-27 17:22 - 2018-05-27 17:22 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign2e0dcb163bdceea7 2018-05-25 14:38 - 2018-05-25 14:38 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignf5a2c26fd23ed1cc 2018-05-25 14:37 - 2018-05-25 14:37 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignac1365d93273fe2c 2018-05-25 14:37 - 2018-05-25 14:37 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign298e3bca8bc41d83 2018-05-25 14:35 - 2018-05-25 14:35 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign1c32be1c9746329d 2018-05-25 14:34 - 2018-05-25 14:34 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign8a086087d54ed2b4 2018-05-25 14:34 - 2018-05-25 14:34 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign6c7b4b0d67622011 2018-05-25 14:34 - 2018-05-25 14:34 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign4298681c259285ee 2018-05-25 14:34 - 2018-05-25 14:34 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign287c83ff54eadff7 2018-05-25 14:34 - 2018-05-25 14:34 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign00b856c5c62e0b81 2018-05-25 14:32 - 2018-05-25 14:32 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign0aa461bcc5f4bb58 2018-05-25 14:31 - 2018-05-25 14:31 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb505bb05acc5479c 2018-05-25 14:31 - 2018-05-25 14:31 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign347728321424309a 2018-05-25 14:30 - 2018-05-25 14:30 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignec5b00cfae754db3 2018-05-25 14:27 - 2018-05-25 14:27 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign9ff1a5305a40abb9 2018-05-25 14:27 - 2018-05-25 14:27 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign090832c6bb0c674e 2018-05-25 14:21 - 2018-05-25 14:21 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign97346c64df7da121 2018-05-25 14:20 - 2018-05-25 14:20 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignc08fdc3b52959e89 2018-05-25 14:20 - 2018-05-25 14:20 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign06601199333d30ed 2018-05-24 21:43 - 2018-05-24 22:18 - 023775142 _____ C:\Users\silas\OneDrive\Documentos\para o drive.pptx 2018-05-22 16:39 - 2018-05-22 16:39 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigned71f73b694caf36 2018-05-22 16:38 - 2018-05-22 16:38 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb3d8c755c070995e 2018-05-22 16:38 - 2018-05-22 16:38 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign47fe57e413e489c6 2018-05-22 16:38 - 2018-05-22 16:38 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign440b61788ce4d27d 2018-05-22 16:38 - 2018-05-22 16:38 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign19ae1490e3e6f2ea 2018-05-21 21:31 - 2018-05-21 21:31 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignf93570183a01b1e7 2018-05-21 21:29 - 2018-05-21 21:29 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign2e0ed7e23a3d3624 2018-05-21 21:27 - 2018-05-21 21:27 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignafbb7012adef277e 2018-05-21 21:27 - 2018-05-21 21:27 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign34d644577cf3aaac 2018-05-21 20:43 - 2018-05-21 20:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb5851bc9434deb72 2018-05-21 20:43 - 2018-05-21 20:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign93b91ce16a7c41f0 2018-05-21 20:43 - 2018-05-21 20:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign8e6ec7f1548a6952 2018-05-21 20:43 - 2018-05-21 20:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign83baee0f646c145f 2018-05-21 20:43 - 2018-05-21 20:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign0e96be787d4dc451 2018-05-18 17:43 - 2018-05-18 17:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign434a9702adf41858 2018-05-18 17:38 - 2018-05-18 17:38 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign8ebf3ea0af79beff 2018-05-18 17:37 - 2018-05-18 17:37 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignff0bd4203ed14694 2018-05-18 17:37 - 2018-05-18 17:37 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign4b8e42d605652154 2018-05-18 17:36 - 2018-05-18 17:36 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb8f79ff335240ba4 2018-05-18 17:00 - 2018-05-18 17:00 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigna4323ad9dfb16e73 2018-05-18 16:54 - 2018-05-18 16:54 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign45041e2c084a22f5 2018-05-18 16:54 - 2018-05-18 16:54 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign245b8c43d8813022 2018-05-18 16:30 - 2018-05-18 16:30 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign08976d1ce88b087c 2018-05-18 16:25 - 2018-05-18 16:25 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign865b1ed90c5cbccb 2018-05-18 16:25 - 2018-05-18 16:25 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign5ce80a150fd6cbfd 2018-05-18 16:24 - 2018-05-18 16:24 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign6e9262139036a408 2018-05-18 16:24 - 2018-05-18 16:24 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign021ba21d79b56bee 2018-05-18 16:16 - 2018-05-18 16:16 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign474e0f01638e0517 2018-05-18 16:09 - 2018-05-18 16:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign2dddcf8ad9846bf8 2018-05-18 16:09 - 2018-05-18 16:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign2c6bb436d3c0a596 2018-05-18 16:08 - 2018-05-18 16:08 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign9b559c66461dc96a 2018-05-18 16:08 - 2018-05-18 16:08 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign41a9729b3589504d 2018-05-18 16:08 - 2018-05-18 16:08 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign041f0eddf8b50344 2018-05-14 18:54 - 2018-05-14 18:54 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign5edf23a98dc38797 2018-05-14 18:51 - 2018-05-14 18:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign922c4268b4a94a47 2018-05-14 18:51 - 2018-05-14 18:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign5e9a97dd778191b8 2018-05-14 16:55 - 2018-05-14 16:55 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigna35bec9ce70e78f6 2018-05-14 16:55 - 2018-05-14 16:55 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign3e737623833d7635 2018-05-14 16:55 - 2018-05-14 16:55 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign023393a727ce7ef5 2018-05-12 21:11 - 2018-05-12 21:11 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignd2b9fcba1cecb972 2018-05-12 21:08 - 2018-05-12 21:08 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignf9db8cd8f1a90943 2018-05-12 21:06 - 2018-05-12 21:06 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign3eea38f38725b0f5 2018-05-12 20:47 - 2018-05-12 20:47 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignf8cab033793f071e 2018-05-12 20:47 - 2018-05-12 20:47 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign6f9905e4b73569e7 2018-05-12 20:47 - 2018-05-12 20:47 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign1a591ecf0a65dde2 2018-05-12 19:07 - 2018-05-12 19:07 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign4d5f854cf569932c 2018-05-12 18:49 - 2018-05-12 18:49 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign25d33fbfe1c1c9f9 2018-05-12 18:40 - 2018-05-12 18:40 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign6815d18e23f84f14 2018-05-12 18:37 - 2018-05-12 18:37 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignc226c9c0415c7bd7 2018-05-12 18:36 - 2018-05-12 18:36 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign8880e17c2ea27c77 2018-05-12 18:25 - 2018-05-12 18:25 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign3c0eae36a4a306e0 2018-05-12 18:25 - 2018-05-12 18:25 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign1d183386c457d66c 2018-05-12 18:24 - 2018-05-12 18:24 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign9a42b37c9dc6a12a 2018-05-12 18:24 - 2018-05-12 18:24 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign821b6e7a3f99522b 2018-05-12 18:24 - 2018-05-12 18:24 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign31a922baf0debd00 2018-05-12 18:24 - 2018-05-12 18:24 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign14ddd3bbd4b870ec 2018-05-12 18:00 - 2018-05-12 18:00 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign65de205bc85f8a44 2018-05-12 18:00 - 2018-05-12 18:00 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign4181a3e59f786a19 2018-05-12 17:59 - 2018-05-12 17:59 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign802d672c68d34ac5 2018-05-12 17:59 - 2018-05-12 17:59 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign79fac9e0a956e80e 2018-05-09 09:31 - 2018-05-09 09:31 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign776e108498bdd5a9 2018-05-09 09:01 - 2018-05-09 09:01 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign482b514c121a84a8 2018-05-09 09:01 - 2018-05-09 09:01 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign28d6dfeb4fe8e1c1 2018-05-09 09:00 - 2018-05-09 09:00 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignee67d92bd6642797 2018-05-09 09:00 - 2018-05-09 09:00 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign42872e53d15ac62f 2018-05-09 08:51 - 2018-05-09 08:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign8d2f13fbd77199e8 2018-05-09 08:51 - 2018-05-09 08:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign3d995f480fe6f805 2018-05-09 08:51 - 2018-05-09 08:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign2c6038b03bc3f5c6 2018-05-08 14:43 - 2018-05-08 14:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignedb17506343e6310 2018-05-08 14:43 - 2018-05-08 14:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignd1526ed6d0c082a7 2018-05-08 14:43 - 2018-05-08 14:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign71dcc9d045ae7633 2018-05-07 15:56 - 2018-05-07 15:56 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign83ac6d6e71c330ac 2018-05-07 15:32 - 2018-05-07 15:32 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign5d278c2bf6f502bf 2018-05-07 14:43 - 2018-05-07 14:43 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigna104e29c04831121 2018-05-07 14:03 - 2018-05-07 14:03 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign6de5668cf835860a 2018-05-07 14:02 - 2018-05-07 14:02 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigna48c15e77e4240ea 2018-05-07 14:02 - 2018-05-07 14:02 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign50edab3b3a5ff999 2018-05-07 14:02 - 2018-05-07 14:02 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign4e25ce80051b1a9e 2018-05-07 13:38 - 2018-05-07 13:38 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignd1b11ef4752e3c80 2018-05-07 13:38 - 2018-05-07 13:38 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign52bb43339371ecb5 2018-05-07 13:36 - 2018-05-07 13:36 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignda3fb57b2f04c9db 2018-05-07 13:36 - 2018-05-07 13:36 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb98a1c37d7acf23e 2018-05-02 15:50 - 2018-05-02 15:50 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigne837e61190be25f9 2018-05-02 15:49 - 2018-05-02 15:49 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign6fdf8090c279d6e4 2018-05-02 15:49 - 2018-05-02 15:49 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign3d6cf4e5c1902959 2018-05-01 17:09 - 2018-05-01 17:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign9fefd2c12a047e18 2018-05-01 17:09 - 2018-05-01 17:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign6b4994063ecdbde5 2018-05-01 16:23 - 2018-05-01 16:23 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign114a29c3bee4a1e3 2018-05-01 16:22 - 2018-05-01 16:22 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign6f489fe5dd5860df 2018-05-01 16:21 - 2018-05-01 16:21 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignedc47e4edd7fd3bc 2018-05-01 16:21 - 2018-05-01 16:21 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign83c45d4c60c2618c 2018-05-01 16:21 - 2018-05-01 16:21 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign5205ea53e78e55ab 2018-05-01 16:21 - 2018-05-01 16:21 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign1e3e9545ccf986e5 2018-04-30 16:07 - 2018-04-30 16:07 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignbf17e90c563fd00d 2018-04-30 16:07 - 2018-04-30 16:07 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb4494643ffc8d848 2018-04-30 16:07 - 2018-04-30 16:07 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign1bef4c5208c95e39 2018-04-29 00:57 - 2018-04-29 00:57 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignf43e4437896d864a 2018-04-29 00:34 - 2018-04-29 00:34 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignf13e3dd89020b567 2018-04-29 00:34 - 2018-04-29 00:34 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignecb187205e4c1122 2018-04-29 00:34 - 2018-04-29 00:34 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigna74d8cfba60d66be 2018-04-29 00:34 - 2018-04-29 00:34 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign58cbfa45b84e9f40 2018-04-29 00:20 - 2018-04-29 00:20 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigndce55bc429800a90 2018-04-28 23:51 - 2018-04-28 23:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsigncaa5936025f51134 2018-04-28 23:51 - 2018-04-28 23:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign50b1046b5391d181 2018-04-28 22:02 - 2018-04-28 22:02 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign3166bb1335334bd4 2018-04-28 22:01 - 2018-04-28 22:01 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignd7da2b08165b5a1b 2018-04-28 22:01 - 2018-04-28 22:01 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign26bd39e1d395ebc4 2018-04-28 22:01 - 2018-04-28 22:01 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign01a6a238c43a187c 2018-04-28 21:24 - 2018-04-28 21:24 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignc2f768f879647944 2018-04-28 21:17 - 2018-04-28 21:17 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign2d548a686f6fb723 2018-04-28 20:45 - 2018-04-28 20:45 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign5d56bf76a3abf269 2018-04-28 20:40 - 2018-04-28 20:40 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign8aad0f5786ccfc74 2018-04-28 19:34 - 2018-04-28 19:34 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign8532048e26f5d96e 2018-04-28 19:29 - 2018-04-28 19:29 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign678c11f39df365de 2018-04-28 19:27 - 2018-04-28 19:27 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign4410106f9ee3ad6d 2018-04-28 19:27 - 2018-04-28 19:27 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign39d7add0085312ac 2018-04-28 19:26 - 2018-04-28 19:26 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb41fb3d713f1fc18 2018-04-28 19:24 - 2018-04-28 19:24 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign46c20164423ce8b6 2018-04-28 19:21 - 2018-04-28 19:21 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign15b0298448c9f6e3 2018-04-28 19:20 - 2018-04-28 19:20 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignf132d478545bf36a 2018-04-28 19:20 - 2018-04-28 19:20 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignc615e48ba2c4fb0a 2018-04-28 19:20 - 2018-04-28 19:20 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignaff539228f7ade2c 2018-04-28 19:20 - 2018-04-28 19:20 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign2aee68fc3dd174d3 2018-04-28 19:19 - 2018-04-28 19:19 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign84c7693396456be7 2018-04-28 19:19 - 2018-04-28 19:19 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign0ba8184d8b61303e 2018-04-28 15:51 - 2018-04-28 15:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignc48acc68ae1095e0 2018-04-28 15:51 - 2018-04-28 15:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign3e0d4325a5efa098 2018-04-28 15:51 - 2018-04-28 15:51 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign0bd278107fbb58e5 2018-04-28 15:22 - 2018-04-28 15:22 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignb1b0211bfc93ff9a 2018-04-28 15:22 - 2018-04-28 15:22 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignaffb405540d42341 2018-04-28 15:21 - 2018-04-28 15:21 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign9981e8d9b99a41ae 2018-04-28 15:21 - 2018-04-28 15:21 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign97fa59145285b103 2018-04-28 15:21 - 2018-04-28 15:21 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign2e22f7c06bfdebb1 2018-04-28 15:21 - 2018-04-28 15:21 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign1627d59c336b8b8d 2018-04-28 15:19 - 2018-04-28 15:19 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignf620dcd65ec8ff20 2018-04-28 15:19 - 2018-04-28 15:19 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign69a880459bb6ad3f 2018-04-28 15:13 - 2018-04-28 15:13 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign648a15b76206f057 2018-04-28 15:12 - 2018-04-28 15:12 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignca48d1790c0f47de 2018-04-28 15:12 - 2018-04-28 15:12 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign558489fcbfca737b 2018-04-28 15:12 - 2018-04-28 15:12 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign4585bb949735b572 2018-04-28 15:10 - 2018-04-28 15:10 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignfd6c77f343688346 2018-04-28 15:10 - 2018-04-28 15:10 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignd6d0dd04fe98c6ad 2018-04-28 15:10 - 2018-04-28 15:10 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign5fb63ff09453bc33 2018-04-28 15:09 - 2018-04-28 15:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignf39e32571c97ed66 2018-04-28 15:09 - 2018-04-28 15:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignbead328b28f273d1 2018-04-28 15:09 - 2018-04-28 15:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsignba937efac2b923ab 2018-04-28 15:09 - 2018-04-28 15:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign928134f999f64763 2018-04-28 15:09 - 2018-04-28 15:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign5a0b459d876501f2 2018-04-28 15:09 - 2018-04-28 15:09 - 000000000 ____D C:\Users\silas\AppData\Local\Tempzxpsign4fb41dd886a6a5ed Task: {3C3770E6-C9D2-4140-99A3-A010B5A2C0FA} - System32\Tasks\App Explorer => C:\Users\silas\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [2018-06-19] (SweetLabs, Inc) <==== ATENÇÃO Task: {BD41CA40-06CB-46DA-9F3D-5A15D51FF1D1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-03-21] (Adobe Systems Incorporated) AlternateDataStreams: C:\Users\silas\OneDrive\Documentos\Adobe:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194] AlternateDataStreams: C:\Users\silas\OneDrive\Documentos\Any Video Converter:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194] AlternateDataStreams: C:\Users\silas\OneDrive\Documentos\App:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194] AlternateDataStreams: C:\Users\silas\OneDrive\Documentos\Corel:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194] AlternateDataStreams: C:\Users\silas\OneDrive\Documentos\Data:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194] C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe CreateRestorePoint: Emptytemp: Hosts: end:: > Execute FRST/FRST64 >> Clique "Corrigir" << Aguarde! > Poste o relatório "Resultado da Correção pela Farbar Recovery Scan Tool" (Fixlog.txt) > Este e outros relatórios,podem ser encontrados na pasta: Disco Local (C) > FRST > Logs []s
  4. DigRam

    Análise de log hijackthis

    /_ Boa Noite! William Bruno _\ > Desinstale: <2> CPUID CPU-Z 1.82.1 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.82.1 - ) <==== ATENÇÃO Malwarebytes versão 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes) > Copie estas informações que estão em vermelho,para o Bloco de Notas. > Salve-as com o nome fixlist. << Texto ou Unicode,caso solicite! > Salve-as ao desktop! ( Área de trabalho ... ) start:: CloseProcesses: 2018-04-18 08:28 - 2018-04-18 08:29 - 000000000 ____D C:\AdwCleaner 2018-04-18 08:28 - 2018-04-18 08:28 - 007256272 _____ (Malwarebytes) C:\Users\rocha\Downloads\AdwCleaner.exe 2018-04-18 08:25 - 2018-04-18 08:25 - 001790024 _____ (Malwarebytes) C:\Users\rocha\Downloads\JRT.exe ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Nenhum Arquivo ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Nenhum Arquivo ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> Nenhum Arquivo ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => -> Nenhum Arquivo ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes) Task: {CB6465DC-304B-4ADF-B283-8B20E661EF77} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-04-12] (Piriform Ltd) ShortcutWithArgument: C:\Users\rocha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicativos do Google Chrome\Postman.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=fhbjgbiflinjbdggehcddcbncdddomop AlternateDataStreams: C:\Users\rocha\OneDrive\Documentos\Modelos Personalizados do Office:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.Metadata [194] HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" Emptytemp: end:: > Execute FRST/FRST64 >> Clique "Corrigir" << Aguarde! > Poste o relatório "Resultado da Correção pela Farbar Recovery Scan Tool" (Fixlog.txt) > Este e outros relatórios,podem ser encontrados na pasta: Disco Local (C) > FRST > Logs []s
  5. DigRam

    Análise de log hijackthis

    /_ Boa Noite! William Bruno _\ > Baixe: < Farbar Recovery Scan Tool > > No link àcima,temos a ferramenta para sistemas 32bits! > No link àcima,temos o download para sistemas 64bits! (FRST64.exe) > Salve-a ao desktop! (Área de trabalho ...) > Execute a ferramenta! > Clique "Sim" >> "Examinar". > Antes de clicar "Examinar",verifique se as caixinhas em "Whitelist" estão assinaladas. > Em "Exame Opcional",deixe marcada as checkbox "Addition.txt" e "Arquivos 90 Dias". > Ps: Será gerado,também,o relatório "Addition.txt". > Poste os relatórios! (FRST.txt + Addition.txt) > Como os logs serão extensos,envie-os à cjoint.com. > Clique no botão Parcourir... > Busque o relatório e clique no botão Abrir. > Clique no botão "Créer le lien Cjoint". > Copie o link que está ao lado de "Le lien a été créé" e poste-o em sua resposta. > Ou clique "Copier le lien (*)" e cole o link ao seu Post. > Outra opção,é hospedar os relatórios em Hébergement de fichiers, Security-x.fr. > Ou ainda,em dl.free.fr. > Fique atento,pois teremos 2 links a serem postados! A+
  6. DigRam

    Programinha Paint se despede

    < Motta > Já não era sem tempo! Já estava morto mesmo.... []s
  7. /_ Fabinho Silveira _\ Resta-lhe, para finalizar,a execução com a ZHPCleaner que é específica ao KMSpico,removendo algumas de suas entradas. > Baixe: < ZHPCleaner > < ... de Nicolas Coolman > > Ou |Aqui!| << Mirror! > Caso tenha algum impedimento ao download,assista este tutorial que foi postado no YouTube,para desativar o Windows SmartScreen. > Estando na página,clique > Salve-a ao desktop! ( ZHPCleaner.exe ) > Desabilite seu antivírus e execute ZHPCleaner.exe << > Ao abrir esta tela,evite clicar em Update ou Atualização,para não ser direcionado ao ZHPBrowser. > Ps: Feche a mensagem ao clicar no [X]. > Com a ferramenta aberta,clique em Scanner. > Aguarde a conclusão! > Ao concluir,clique Repair. > Ps: Ignore possíveis alertas quanto à sua configuração de rede. (DNS) > Clique Sim >> Sim! > Surgirão guias que estarão em vermelho,indicando problemas a serem reparados. > Clique Repair. > Ao concluir,clique Report. > Poste o log de reparo: ~ Type : Reparo Este será seu relatório direto,obtido ao modificar na barra de endereços,de (.html) para (.txt). Basta selecionar (ctrl + A),copiar (ctrl + C) e colar ao seu Post ou Bloco de Notas. (ctrl + V) Disponibilize o relatório em Cjoint.com << Outra opção,é hospedar o relatório em Hébergement de fichiers, Security-x.fr. [Abs]
  8. /_ Bom Dia! Fabinho Silveira _\ Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76 Tcpip\..\Interfaces\{611cc63b-d6d9-4ccc-89b0-c1069879542d}: [DhcpNameServer] 75.75.75.75 75.75.76.76 Tcpip\..\Interfaces\{81e3ccd4-97a4-44a4-b2be-09e85f1dfe4f}: [DhcpNameServer] 75.75.75.75 75.75.76.76 -- -- > Foi sua escolha esta configuração de rede? Running from C:\Users\valeu\Downloads << > Mova a ferramenta FRST ao desktop,pois a mesma encontra-se em diretório incorreto! > Copie estas informações que estão em vermelho,para o Bloco de Notas. > Salve-as com o nome fixlist. << Texto ou Unicode,caso solicite! > Salve-as ao desktop! ( Área de trabalho ... ) start:: CloseProcesses: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION HKU\S-1-5-21-2911689879-524526275-566669397-1001\...\Run: [windows] => C:\windows\windows.vbs [89 2017-05-06] () <==== ATTENTION ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File FirewallRules: [TCP Query User{687D7EC9-0893-433F-B1E4-1BBAB5F74AFC}C:\windows\window.exe] => (Allow) C:\windows\window.exe FirewallRules: [UDP Query User{EEDD7129-C7A1-46A6-B70E-A9A8DD1A3FA6}C:\windows\window.exe] => (Allow) C:\windows\window.exe 2018-02-03 20:20 - 2018-02-03 20:31 - 000000000 ____D C:\ProgramData\AVAST Software 2018-04-23 14:50 - 2018-04-23 14:58 - 000000000 ____D C:\WINDOWS\AutoKMS 2018-04-23 14:48 - 2018-04-23 14:48 - 000004608 _____ C:\WINDOWS\SECOH-QAD.exe 2018-01-30 09:05 - 2018-01-30 06:08 - 000006137 _____ C:\WINDOWS\151931647_log -.txt 2018-01-30 09:05 - 2018-01-30 06:08 - 000006137 _____ C:\WINDOWS\151731647_log - Copia.txt 2018-01-30 09:05 - 2018-01-30 06:03 - 000006137 _____ C:\WINDOWS\151733647_log -.txt 2018-01-30 06:44 - 2018-01-30 06:09 - 000008414 _____ C:\WINDOWS\1517316477_log- -.txt 2018-01-30 06:44 - 2018-01-30 06:08 - 000008419 _____ C:\WINDOWS\1517316477_log --.txt 2018-01-30 06:44 - 2018-01-30 06:08 - 000008419 _____ C:\WINDOWS\1517316477_log -.txt 2018-01-30 06:44 - 2018-01-30 06:08 - 000006137 _____ C:\WINDOWS\151731647_log-.txt 2018-01-30 06:44 - 2018-01-30 06:03 - 000006137 _____ C:\WINDOWS\151731647_log -.txt 2018-01-30 06:44 - 2018-01-30 06:02 - 000006136 _____ C:\WINDOWS\- 154731541_log -.txt 2018-01-30 06:44 - 2018-01-30 06:02 - 000006136 _____ C:\WINDOWS\- 152731541_log -.txt 2018-01-30 05:37 - 2017-12-25 02:48 - 000157713 ____H C:\WINDOWS\windows.bat 2018-01-30 05:37 - 2017-12-10 09:14 - 004890112 _____ () C:\WINDOWS\Window.exe 2018-01-30 05:37 - 2017-12-10 09:14 - 004890112 _____ C:\WINDOWS\Window.exe 2018-01-30 05:37 - 2017-06-22 15:57 - 000000162 ____H C:\WINDOWS\system32.vbs 2018-01-30 05:37 - 2017-05-06 14:20 - 000000089 _____ C:\WINDOWS\windows.vbs C:\ProgramData\AVAST Software C:\Windows\Window.exe C:\WINDOWS\windows.bat C:\windows\windows.vbs CreateRestorePoint: RemoveProxy: EmptyTemp: Reboot: Hosts: end:: > Execute FRST/FRST64 >> Clique "Corrigir" << Aguarde! > Poste o relatório "Resultado da Correção pela Farbar Recovery Scan Tool" (Fixlog.txt) > Este e outros relatórios,podem ser encontrados na pasta: Disco Local (C) > FRST > Logs < Peço aos visitantes que não utilizem este script em outros computadores,sob risco de danos aos mesmos! > [Abs]
  9. /_ Bom Dia! Fabinho Silveira _\ > Baixe: < Farbar Recovery Scan Tool > > No link àcima,temos a ferramenta para sistemas 32bits! > No link àcima,temos o download para sistemas 64bits! (FRST64.exe) > Salve-a ao desktop! (Área de trabalho ...) > Execute a ferramenta! > Clique "Sim" >> "Examinar". > Antes de clicar "Examinar",verifique se as caixinhas em "Whitelist" estão assinaladas. > Em "Exame Opcional",deixe marcada as checkbox "Addition.txt" e "Arquivos 90 Dias". > Ps: Será gerado,também,o relatório "Addition.txt". > Poste os relatórios! (FRST.txt + Addition.txt) > Como os logs serão extensos,envie-os à cjoint.com. > Clique no botão Parcourir... > Busque o relatório e clique no botão Abrir. > Clique no botão "Créer le lien Cjoint". > Copie o link que está ao lado de "Le lien a été créé" e poste-o em sua resposta. > Ou clique "Copier le lien (*)" e cole o link ao seu Post. > Outra opção,é hospedar os relatórios em Hébergement de fichiers, Security-x.fr. > Ou ainda,em dl.free.fr. > Fique atento,pois teremos 2 links a serem postados! A+
  10. Caso Resolvido! Para sua Segurança! Leia as dicas ou orientações contidas na Cartilha de Segurança para Internet. Caso Resolvido!
  11. /_ Boa Noite! cgf95 _\ ---\\ Explorer ( File, Folder) (4) MOVED file: C:\Windows\AutoKMS\AutoKMS.exe [CODYQX4 - AutoKMS] =>HackTool.AutoKMS MOVED file: C:\Windows\AutoKMS\AutoKMS.log =>HackTool.AutoKMS MOVED folder*: C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS MOVED folder*: C:\Windows\AutoKMS =>HackTool.AutoKMS -- -- > A ZHPCleaner removeu as sobras do validador KMSpico. > Seu computador está limpo! > Ps: Durante o scan da ZHPCleaner,surge esta janela. > Ps: Ignore possíveis alertas quanto à sua configuração de rede. (DNS) > Clique Sim >> Sim! > Tudo Ok? []s
  12. /_ cgf95 _\ Baixe e execute a ZHPCleaner! Poste o relatório! []s
  13. < Atualização canned da ZHPCleaner;de Nicolas Coolman > > Baixe: < ZHPCleaner > < ... de Nicolas Coolman > > Ou |Aqui!| << Mirror! > Caso tenha algum impedimento ao download,assista este tutorial que foi postado no YouTube,para desativar o Windows SmartScreen. > Estando na página,clique > Salve-a ao desktop! ( ZHPCleaner.exe ) > Desabilite seu antivírus e execute ZHPCleaner.exe << > Ao abrir esta tela,evite clicar em Update ou Atualização,para não ser direcionado ao ZHPBrowser. > Ps: Feche a mensagem ao clicar no "X". > Com a ferramenta aberta,clique em Scanner. > Aguarde a conclusão! > Ao concluir,clique Repair. > Ps: Ignore possíveis alertas quanto à sua configuração de rede. (DNS) > Clique Sim >> Sim! > Surgirão guias que estarão em vermelho,indicando problemas a serem reparados. > Clique Repair. > Ao concluir,clique Report. > Poste o log de reparo: ~ Type : Reparo Este será seu relatório direto,obtido ao modificar na barra de endereços,de (.html) para (.txt). Basta selecionar (ctrl + A),copiar (ctrl + C) e colar ao seu Post ou Bloco de Notas. (ctrl + V) Disponibilize o relatório em Cjoint.com. Outra opção,é hospedar o relatório em Hébergement de fichiers, Security-x.fr. [Abs]
  14. Saudações! A adwcleaner sofreu muitas modificações,quando a trouxe da França aos nossos rincões. (Setembro 2011) Agora pertence a Malwarebytes,bem como sua irmã de época,a JunkWare Removal Tool. (JRT) > Baixe: < > ( ... par Xplode ) > Ou daqui: < AdwCleaner > << Link! > Ao acessar,clique em "Download Now". > Salve-o ao desktop! > Desabilite seu antivírus! < > > Clique direito em adwcleaner.exe,e escolha sua execução como administrador. > Clique "Definições". > Estando em "Definições",deixe as configurações conforme este banner. > Ps: Dê início ao scan,clicando em "Verificar Agora". > Ao concluir,clique "Limpar e Reparar". > Na mensagem,clique "Limpar e Reiniciar". > Ao concluir,clique "Ver Ficheiro de Registos". > Copie e poste o relatório! (Mode: Clean) []s
  15. Tópico Arquivado Como o autor não respondeu por mais de 10 dias, o tópico foi arquivado. Caso você seja o autor do tópico e quer reabrir, envie uma mensagem privada para um moderador da área juntamente com o link para este tópico e explique o motivo da reabertura.
×

Informação importante

Ao usar o fórum, você concorda com nossos Termos e condições.