Ionara 2 Denunciar post Postado Agosto 7, 2015 Note lento, segue log... Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 21:53:53, on 06/08/2015 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v11.0 (11.00.9600.17840) Boot mode: Normal Running processes: C:\PROGRA~2\GbPlugin\GbpSv.exe C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avpui.exe C:\Program Files (x86)\OEM\iBrightness 1.0.1\iBrightness.exe C:\Program Files (x86)\OEM\IPM 1.9.4\IPM.exe C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\EpmNews.exe C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo13.msn.com/?pc=LCJB R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com.br/?gws_rd=ssl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: VirtualKeyboardBrowserHelperObject - {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~3\Office14\GROOVEEX.DLL O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll O2 - BHO: ContentBlockerBrowserHelperObject - {93BC2EA7-2F17-4729-948A-D2E03FFB2412} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll O2 - BHO: AVG Web TuneUp - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Web TuneUp\4.1.5.143\AVG Web TuneUp.dll O2 - BHO: Safe Money Plugin - {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Program Files (x86)\GbPlugin\gbiehcef.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll O4 - HKLM\..\Run: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60 O4 - HKLM\..\Run: [EaseUS EPM tray] C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.1\bin\EpmNews.exe O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG Web TuneUp\vprot.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" O4 - Global Startup: iBrightness.lnk = ? O4 - Global Startup: IPM.lnk = ? O8 - Extra context menu item: E&nviar para o OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000 O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: E&nviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: Teclado Virtual - {5547CE1F-74E9-41E5-9CBF-5211ECC37341} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\IEExt\ie_plugin.dll O9 - Extra button: &Notas Ligadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Notas Ligadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: imagem.caixa.gov.br O15 - Trusted Zone: internetbanking.caixa.gov.br O15 - Trusted Zone: internetbankingpf.caixa.gov.br O15 - Trusted Zone: www.caixa.gov.br O15 - Trusted Zone: http://www.caixa.gov.br O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O20 - Winlogon Notify: GbPluginCef - C:\Program Files (x86)\GbPlugin\gbiehCef.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: Serviço do Kaspersky Anti-Virus 15.0.2 (AVP15.0.2) - Kaspersky Lab ZAO - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 15.0.2\avp.exe O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\WINDOWS\system32\EasyAntiCheat.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: Gbp Service (GbpSv) - GAS Tecnologia - C:\PROGRA~2\GbPlugin\GbpSv.exe O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Tecnologia de armazenamento Intel® Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel® HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing) O23 - Service: Intel® Capability Licensing Service Interface - Intel® Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel® ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe O23 - Service: Intel® Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: vToolbarUpdater18.8.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.8.0\ToolbarUpdater.exe O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: WtuSystemSupport - Unknown owner - C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe -- End of file - 11127 bytes Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 9, 2015 /!\ Bom Dia! Ionara /!\ > Baixe: < > ( ... by Farbar ) > No banner àcima,é para sistemas 32bits! < Farbar Recovery Scan Tool 64-Bit > > No link àcima,é para sistemas 64bits! > Salve-o no desktop! (Área de trabalho ...) > Execute a ferramenta! Clique "Yes" >> "Scan". > Antes de clicar "Scan",verifique se as caixinhas em "Whitelist" estão assinaladas. > Em "Optional Scan",deixe marcada a checkbox "Addition.txt". > Ps: Será gerado,também,o relatório "Addition.txt" que estará disponibilizado na 1ª execução da ferramenta. > Poste os relatórios! (FRST.txt + Addition.txt) > Como o log será extenso,envie-o à > > Clique no botão Parcourir... > Busque o relatório e clique no botão Abrir. > Clique no botão "Créer le lien Cjoint". > Copie o link que está ao lado de "Le lien a été créé" e poste-o em sua resposta. > O link ao relatório,que é este assinalado,deverá ser colado em sua resposta. > Ou clique "Copier le lien (*)" e cole o link ao seu Post. A+ Compartilhar este post Link para o post Compartilhar em outros sites
Ionara 2 Denunciar post Postado Agosto 10, 2015 Boa noite, seguem logs... http://www.cjoint.com/c/EHkw7lOdlSg http://www.cjoint.com/c/EHkxanfMMLg Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 10, 2015 /!\ Boa Noite! Ionara /!\ > Copie estas informações que estão em vermelho,para o Bloco de Notas. > Salve-as com o nome fixlist. << Texto! > Salve-as no desktop! ( Área de trabalho ... ) -/- C:\Users\Valmor\Desktop << start CloseProcesses: emptytemp: () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.8.0\ToolbarUpdater.exe () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.8.0\loggingserver.exe HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [3175312 2015-07-22] () CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.1.5.143\AVG Web TuneUp.dll [2015-07-22] (AVG) BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.1.5.143\AVG Web TuneUp.dll [2015-07-22] (AVG) FF SelectedSearchEngine: AVG Secure Search FF Extension: AVG Web TuneUp - C:\Users\Valmor\AppData\Roaming\Mozilla\Firefox\Profiles\37lmntv0.default\Extensions\avg@toolbar [2015-05-06] R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1195920 2015-07-22] () S4 McAPExe; "C:\Program Files\McAfee\MSC\McAPExe.exe" [X] S3 EasyAntiCheatSys; \??\C:\WINDOWS\system32\EasyAntiCheat.sys [X] S3 ew_usbenumfilter; \SystemRoot\System32\drivers\ew_usbenumfilter.sys [X] S3 huawei_cdcacm; \SystemRoot\system32\DRIVERS\ew_jucdcacm.sys [X] S3 huawei_enumerator; \SystemRoot\System32\drivers\ew_jubusenum.sys [X] U4 klkbdflt2; \SystemRoot\system32\DRIVERS\klkbdflt2.sys [X] 2015-08-06 21:53 - 2015-08-06 21:53 - 00011129 _____ C:\Users\Valmor\Desktop\hijackthis.log 2015-08-06 21:50 - 2015-08-06 21:50 - 00003013 _____ C:\Users\Valmor\Desktop\HiJackThis.lnk 2015-08-06 21:50 - 2015-08-06 21:50 - 00000000 ____D C:\Users\Valmor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis 2015-08-06 21:50 - 2015-08-06 21:50 - 00000000 ____D C:\Program Files (x86)\Trend Micro 2015-08-06 21:47 - 2015-08-06 21:47 - 01402880 _____ C:\Users\Valmor\Desktop\HijackThis.msi 2015-07-22 18:19 - 2015-05-06 10:28 - 00000000 ____D C:\Program Files\AVG Web TuneUp 2015-07-22 18:19 - 2015-05-06 10:28 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp 2014-02-19 16:13 - 2014-02-19 16:13 - 0510976 _____ () C:\ProgramData\DRV10.tmp 2014-02-19 16:13 - 2014-02-19 16:20 - 9891328 _____ (OEM) C:\ProgramData\E1010.tmp 2015-05-06 10:28 - 2015-07-22 18:19 - 01195920 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe 2015-07-22 18:19 - 2015-07-22 18:19 - 00168336 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.8.0\loggingserver.exe Task: {BDFC3145-819C-41D8-9805-21E924B1D55F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) C:\Users\Valmor\AppData\Local\Temp\SkypeSetup.exe CreateRestorePoint: Reboot: end > Execute FRST/FRST64 >> Clique "Fix" << Aguarde! > Na mensagem,clique Executar. > Poste o relatório! (Fixlog.txt) < Peço aos visitantes que não utilizem este script em outros computadores,sob risco de danos aos mesmos! > A+ Compartilhar este post Link para o post Compartilhar em outros sites
Ionara 2 Denunciar post Postado Agosto 11, 2015 Boa noite, segue fixlog... Fix result of Farbar Recovery Scan Tool (x64) Version:11-08-2015 02 Ran by Ionara (2015-08-11 20:20:58) Run:1 Running from C:\Users\Valmor\Desktop Loaded Profiles: Ionara & Administrador (Available Profiles: Ionara & Administrador & Convidado) Boot Mode: Normal ============================================== fixlist content: ***************** start CloseProcesses: emptytemp: () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe (AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.8.0\ToolbarUpdater.exe () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.8.0\loggingserver.exe HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [3175312 2015-07-22] () CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.1.5.143\AVG Web TuneUp.dll [2015-07-22] (AVG) BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.1.5.143\AVG Web TuneUp.dll [2015-07-22] (AVG) FF SelectedSearchEngine: AVG Secure Search FF Extension: AVG Web TuneUp - C:\Users\Valmor\AppData\Roaming\Mozilla\Firefox\Profiles\37lmntv0.default\Extensions\avg@toolbar [2015-05-06] R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [1195920 2015-07-22] () S4 McAPExe; "C:\Program Files\McAfee\MSC\McAPExe.exe" [X] S3 EasyAntiCheatSys; \??\C:\WINDOWS\system32\EasyAntiCheat.sys [X] S3 ew_usbenumfilter; \SystemRoot\System32\drivers\ew_usbenumfilter.sys [X] S3 huawei_cdcacm; \SystemRoot\system32\DRIVERS\ew_jucdcacm.sys [X] S3 huawei_enumerator; \SystemRoot\System32\drivers\ew_jubusenum.sys [X] U4 klkbdflt2; \SystemRoot\system32\DRIVERS\klkbdflt2.sys [X] 2015-08-06 21:53 - 2015-08-06 21:53 - 00011129 _____ C:\Users\Valmor\Desktop\hijackthis.log 2015-08-06 21:50 - 2015-08-06 21:50 - 00003013 _____ C:\Users\Valmor\Desktop\HiJackThis.lnk 2015-08-06 21:50 - 2015-08-06 21:50 - 00000000 ____D C:\Users\Valmor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis 2015-08-06 21:50 - 2015-08-06 21:50 - 00000000 ____D C:\Program Files (x86)\Trend Micro 2015-08-06 21:47 - 2015-08-06 21:47 - 01402880 _____ C:\Users\Valmor\Desktop\HijackThis.msi 2015-07-22 18:19 - 2015-05-06 10:28 - 00000000 ____D C:\Program Files\AVG Web TuneUp 2015-07-22 18:19 - 2015-05-06 10:28 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp 2014-02-19 16:13 - 2014-02-19 16:13 - 0510976 _____ () C:\ProgramData\DRV10.tmp 2014-02-19 16:13 - 2014-02-19 16:20 - 9891328 _____ (OEM) C:\ProgramData\E1010.tmp 2015-05-06 10:28 - 2015-07-22 18:19 - 01195920 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe 2015-07-22 18:19 - 2015-07-22 18:19 - 00168336 _____ () C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.8.0\loggingserver.exe Task: {BDFC3145-819C-41D8-9805-21E924B1D55F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated) C:\Users\Valmor\AppData\Local\Temp\SkypeSetup.exe CreateRestorePoint: Reboot: end ***************** Processes closed successfully. C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe => No running process found C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.8.0\ToolbarUpdater.exe => No running process found C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.8.0\loggingserver.exe => No running process found HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\vProt => value removed successfully "HKLM\SOFTWARE\Policies\Google" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}" => key removed successfully "HKCR\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => key removed successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}" => key removed successfully "HKCR\Wow6432Node\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}" => key removed successfully Firefox SelectedSearchEngine removed successfully C:\Users\Valmor\AppData\Roaming\Mozilla\Firefox\Profiles\37lmntv0.default\Extensions\avg@toolbar => moved successfully. WtuSystemSupport => service removed successfully McAPExe => service removed successfully EasyAntiCheatSys => service removed successfully ew_usbenumfilter => service removed successfully huawei_cdcacm => service removed successfully huawei_enumerator => service removed successfully klkbdflt2 => service could not remove C:\Users\Valmor\Desktop\hijackthis.log => moved successfully. C:\Users\Valmor\Desktop\HiJackThis.lnk => moved successfully. C:\Users\Valmor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis => moved successfully. C:\Program Files (x86)\Trend Micro => moved successfully. C:\Users\Valmor\Desktop\HijackThis.msi => moved successfully. C:\Program Files\AVG Web TuneUp => moved successfully. C:\Program Files (x86)\AVG Web TuneUp => moved successfully. C:\ProgramData\DRV10.tmp => moved successfully. C:\ProgramData\E1010.tmp => moved successfully. "C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe" => File/Folder not found. C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.8.0\loggingserver.exe => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BDFC3145-819C-41D8-9805-21E924B1D55F}" => key removed successfully "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BDFC3145-819C-41D8-9805-21E924B1D55F}" => key removed successfully C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task => moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Acrobat Update Task" => key removed successfully C:\Users\Valmor\AppData\Local\Temp\SkypeSetup.exe => moved successfully. Restore point was successfully created. EmptyTemp: => 862.6 MB temporary data Removed. The system needed a reboot.. ==== End of Fixlog 20:22:33 ==== Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 12, 2015 /!\ Boa Noite! Ionara /!\ > Baixe: < > ( ... by Malwarebytes.org ) > Salve-o no desktop! > Desabilite seu antivírus! > Para Windows 7,clique direito em JRT.exe e execute-o ... > Aguarde a conclusão e poste o relatório. ( JRT.txt ) > Baixe: < SFTGC > ( ... de Pierre13 ) > Tendo dificuldades no download,utilize o navegador Internet Explorer. > Salve-o no desktop! > Para Windows Vista e 7,execute "SFTGC.exe" como administrador! > Execute-o e clique "Go". > Aguarde seu término,que é rápido. > Poste o relatório! ( SFT.txt ) > Ps: De acordo com o tamanho do relatório,não poste-o diretamente! > Acesse,para esta tarefa! < > A+ Compartilhar este post Link para o post Compartilhar em outros sites
Ionara 2 Denunciar post Postado Agosto 12, 2015 Bom dia, seguem logs... ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 7.5.6 (08.10.2015:1) OS: Windows 8.1 Single Language x64 Ran by Ionara on 12/08/2015 at 6:18:30,29 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services Successfully deleted: [service] vToolbarUpdater18.8.0 [Reboot required] ~~~ Tasks ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} ~~~ Files ~~~ Folders Failed to delete: [Folder] C:\Program Files (x86)\gbplugin Successfully deleted: [Folder] C:\ProgramData\avg security toolbar Successfully deleted: [Folder] C:\ProgramData\gbplugin ~~~ FireFox Successfully deleted: [File] C:\Users\Valmor\AppData\Roaming\mozilla\firefox\profiles\37lmntv0.default\user.js Successfully deleted: [File] C:\Users\Valmor\AppData\Roaming\mozilla\firefox\profiles\37lmntv0.default\searchplugins\avg-secure-search.xml Successfully deleted the following from C:\Users\Valmor\AppData\Roaming\mozilla\firefox\profiles\37lmntv0.default\prefs.js user_pref(browser.search.hiddenOneOffs, Yahoo,Bing,AVG Secure Search,BuscaPé,DuckDuckGo,MercadoLivre,Twitter,Wikipedia (pt)); ~~~ Chrome [C:\Users\Valmor\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset [C:\Users\Valmor\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted: [C:\Users\Valmor\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset [C:\Users\Valmor\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted: [] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12/08/2015 at 6:22:35,21 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ------------------------------------------------------------------------- SFTGC relatório (Pierre13) de quarta-feira 12 agosto 2015 à 06:39:26 version : 2.2.0.1 Atualizado 25/11/2014 Ferramenta lançada em modo Normal e Como um administrador Windows 8.1 Single Language 64 bits Tool start in C:\Users\Valmor\Desktop 390 Itens Excluídos => 28 Mo liberado. (59 s) C:\Users\Valmor\AppData\Local\Temp\.challenge_plain C:\Users\Valmor\AppData\Local\Temp\acrord32_sbx C:\Users\Valmor\AppData\Local\Temp\AdobeARM.log C:\Users\Valmor\AppData\Local\Temp\au-descriptor-1.8.0_51-b16.xml C:\Users\Valmor\AppData\Local\Temp\Convidado.bmp C:\Users\Valmor\AppData\Local\Temp\hsperfdata_Ionara C:\Users\Valmor\AppData\Local\Temp\Ionara.bmp C:\Users\Valmor\AppData\Local\Temp\JavaDeployReg.log C:\Users\Valmor\AppData\Local\Temp\jrt C:\Users\Valmor\AppData\Local\Temp\JRT.txt C:\Users\Valmor\AppData\Local\Temp\jusched.log C:\Users\Valmor\AppData\Local\Temp\Low C:\Users\Valmor\AppData\Local\Temp\odt711E.tmp C:\Users\Valmor\AppData\Local\Temp\qtsingleapp-EAABFC-151a-1-lockfile C:\Users\Valmor\AppData\Local\Temp\qtsingleapp-EAABFC-151a-2-lockfile C:\Users\Valmor\AppData\Local\Temp\Low\Cef C:\Users\Valmor\AppData\Local\Temp\Low\Cef\gbieh.gmd.7303E7EA C:\Users\Valmor\AppData\Local\Temp\Low\Cef\gbiehcef.dll.upd.7303E7EA C:\Users\Valmor\AppData\Local\Temp\jrt\appinit64_null.reg C:\Users\Valmor\AppData\Local\Temp\jrt\appinit_null.reg C:\Users\Valmor\AppData\Local\Temp\jrt\ask.bat C:\Users\Valmor\AppData\Local\Temp\jrt\askCLSID.dat C:\Users\Valmor\AppData\Local\Temp\jrt\askregkey_x64.dat C:\Users\Valmor\AppData\Local\Temp\jrt\askregkey_x86.dat C:\Users\Valmor\AppData\Local\Temp\jrt\askregvalue_x64.dat C:\Users\Valmor\AppData\Local\Temp\jrt\askregvalue_x86.dat C:\Users\Valmor\AppData\Local\Temp\jrt\badAPPINIT.dat C:\Users\Valmor\AppData\Local\Temp\jrt\badFOLDERS.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\badFOLDERScom.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\badFOLDERSstart.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\badLNK.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\badLNK2.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\badTASKS.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\badvalues.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\browsermngr_keys.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\browsermngr_values.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\chrome.bat C:\Users\Valmor\AppData\Local\Temp\jrt\chrome_pref.bat C:\Users\Valmor\AppData\Local\Temp\jrt\CHRregkey_x64.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\CHRregkey_x86.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\CHR_extensions.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\CHR_open_x64.reg C:\Users\Valmor\AppData\Local\Temp\jrt\CHR_open_x86.reg C:\Users\Valmor\AppData\Local\Temp\jrt\CHR_storage.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\clean_shortcut.vbs C:\Users\Valmor\AppData\Local\Temp\jrt\CreateRestorePoint.exe C:\Users\Valmor\AppData\Local\Temp\jrt\CUT.DAT C:\Users\Valmor\AppData\Local\Temp\jrt\datamngr_del.reg C:\Users\Valmor\AppData\Local\Temp\jrt\defaultscope.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\delfolders.bat C:\Users\Valmor\AppData\Local\Temp\jrt\ev_clear.bat C:\Users\Valmor\AppData\Local\Temp\jrt\FFbrowsermngr.dat C:\Users\Valmor\AppData\Local\Temp\jrt\FFextensions.dat C:\Users\Valmor\AppData\Local\Temp\jrt\FFpluginREG.dat C:\Users\Valmor\AppData\Local\Temp\jrt\FFplugins.dat C:\Users\Valmor\AppData\Local\Temp\jrt\FFprefs.dat C:\Users\Valmor\AppData\Local\Temp\jrt\FFregkey_x64.dat C:\Users\Valmor\AppData\Local\Temp\jrt\FFregkey_x86.dat C:\Users\Valmor\AppData\Local\Temp\jrt\FFwhtlist.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\FFXML.dat C:\Users\Valmor\AppData\Local\Temp\jrt\FFXPI.dat C:\Users\Valmor\AppData\Local\Temp\jrt\FF_open_x64.reg C:\Users\Valmor\AppData\Local\Temp\jrt\FF_open_x86.reg C:\Users\Valmor\AppData\Local\Temp\jrt\firefox.bat C:\Users\Valmor\AppData\Local\Temp\jrt\get.bat C:\Users\Valmor\AppData\Local\Temp\jrt\GREP.DAT C:\Users\Valmor\AppData\Local\Temp\jrt\IEwhtlst.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\iexplore.bat C:\Users\Valmor\AppData\Local\Temp\jrt\IE_open_x64.reg C:\Users\Valmor\AppData\Local\Temp\jrt\IE_open_x86.reg C:\Users\Valmor\AppData\Local\Temp\jrt\IFEO.dat C:\Users\Valmor\AppData\Local\Temp\jrt\JQ.DAT C:\Users\Valmor\AppData\Local\Temp\jrt\jrtcurrentmd5 C:\Users\Valmor\AppData\Local\Temp\jrt\jrtnewmd5 C:\Users\Valmor\AppData\Local\Temp\jrt\libiconv2.dll C:\Users\Valmor\AppData\Local\Temp\jrt\libintl3.dll C:\Users\Valmor\AppData\Local\Temp\jrt\medfos.bat C:\Users\Valmor\AppData\Local\Temp\jrt\misc.bat C:\Users\Valmor\AppData\Local\Temp\jrt\Mozilla.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\mws.bat C:\Users\Valmor\AppData\Local\Temp\jrt\nfo C:\Users\Valmor\AppData\Local\Temp\jrt\NIRCMD.DAT C:\Users\Valmor\AppData\Local\Temp\jrt\pcre3.dll C:\Users\Valmor\AppData\Local\Temp\jrt\prelim.bat C:\Users\Valmor\AppData\Local\Temp\jrt\ProgramW6432F.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\regex2.dll C:\Users\Valmor\AppData\Local\Temp\jrt\runvalues.bat C:\Users\Valmor\AppData\Local\Temp\jrt\runvalues_x64.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\runvalues_x86.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\searchlnk.bat C:\Users\Valmor\AppData\Local\Temp\jrt\SED.DAT C:\Users\Valmor\AppData\Local\Temp\jrt\services.dat C:\Users\Valmor\AppData\Local\Temp\jrt\serviceseventlog.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\SHORTCUT.DAT C:\Users\Valmor\AppData\Local\Temp\jrt\surfvox.bat C:\Users\Valmor\AppData\Local\Temp\jrt\TDL4.bat C:\Users\Valmor\AppData\Local\Temp\jrt\temp C:\Users\Valmor\AppData\Local\Temp\jrt\WGET.DAT C:\Users\Valmor\AppData\Local\Temp\jrt\winlogon.reg C:\Users\Valmor\AppData\Local\Temp\jrt\wl_bhoclsid.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\wl_processes.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\wl_services.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\wl_tasks.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\wl_toolbars.cfg C:\Users\Valmor\AppData\Local\Temp\jrt\temp\null.txt C:\Users\Valmor\AppData\Local\Temp\jrt\nfo\GNU utilities for Win32.url C:\Users\Valmor\AppData\Local\Temp\jrt\nfo\grep-2.5.4-GnuWin32.README C:\Users\Valmor\AppData\Local\Temp\jrt\nfo\NirCmd.chm C:\Users\Valmor\AppData\Local\Temp\jrt\nfo\nircmdc.exe C:\Users\Valmor\AppData\Local\Temp\jrt\nfo\sed-4.2.1-GnuWin32.README C:\Users\Valmor\AppData\Local\Temp\jrt\nfo\sed.txt C:\Users\Valmor\AppData\Local\Temp\jrt\nfo\shortcut.txt C:\Users\Valmor\AppData\Local\Temp\jrt\nfo\wget-1.11.4-1-GnuWin32.README C:\Users\Valmor\AppData\Local\Temp\jrt\nfo\wget.txt C:\WINDOWS\TEMP\toolbar_log.txt C:\WINDOWS\Prefetch\ACRORD32.EXE-41B0A0C7.pf C:\WINDOWS\Prefetch\ACRORD32.EXE-41B0A0C8.pf C:\WINDOWS\Prefetch\ADOBEARM.EXE-813E932C.pf C:\WINDOWS\Prefetch\AgAppLaunch.db C:\WINDOWS\Prefetch\AgCx_SC1.db C:\WINDOWS\Prefetch\AgCx_SC1.db.trx C:\WINDOWS\Prefetch\AgCx_SC2.db C:\WINDOWS\Prefetch\AgCx_SC4.db C:\WINDOWS\Prefetch\AgCx_SC5.db C:\WINDOWS\Prefetch\AgGlFaultHistory.db C:\WINDOWS\Prefetch\AgGlFgAppHistory.db C:\WINDOWS\Prefetch\AgGlGlobalHistory.db C:\WINDOWS\Prefetch\AgGlUAD_P_S-1-5-21-4289557062-2233464397-3948540844-1001.db C:\WINDOWS\Prefetch\AgGlUAD_P_S-1-5-21-4289557062-2233464397-3948540844-501.db C:\WINDOWS\Prefetch\AgGlUAD_S-1-5-21-4289557062-2233464397-3948540844-1001.db C:\WINDOWS\Prefetch\AgGlUAD_S-1-5-21-4289557062-2233464397-3948540844-501.db C:\WINDOWS\Prefetch\AgRobust.db C:\WINDOWS\Prefetch\AOMX.EXE-1A9FFD45.pf C:\WINDOWS\Prefetch\ATBROKER.EXE-8B8F7F7C.pf C:\WINDOWS\Prefetch\AUDIODG.EXE-9848A323.pf C:\WINDOWS\Prefetch\AUTHHOST.EXE-2D7C3758.pf C:\WINDOWS\Prefetch\AU_.EXE-06226644.pf C:\WINDOWS\Prefetch\AVG-SECURE-SEARCH-UPDATE_0615-3A22144E.pf C:\WINDOWS\Prefetch\AVG-SECURE-SEARCH-UPDATE_0715-6E96E918.pf C:\WINDOWS\Prefetch\AVGMFAPX.EXE-49B259A5.pf C:\WINDOWS\Prefetch\AVGUI.EXE-D7AAB41F.pf C:\WINDOWS\Prefetch\AVP.EXE-704D44EF.pf C:\WINDOWS\Prefetch\AVPUI.EXE-91DB812D.pf C:\WINDOWS\Prefetch\BCDEDIT.EXE-EB47CDA5.pf C:\WINDOWS\Prefetch\BCSSYNC.EXE-FC0882AC.pf C:\WINDOWS\Prefetch\CALC.EXE-0FE8F3A9.pf C:\WINDOWS\Prefetch\CHROME.EXE-9812FE60.pf C:\WINDOWS\Prefetch\CHROME.EXE-CCF9F3F4.pf C:\WINDOWS\Prefetch\CMD.EXE-2EB3E6E2.pf C:\WINDOWS\Prefetch\CMD.EXE-CD245F9E.pf C:\WINDOWS\Prefetch\COLORCPL.EXE-E82188C0.pf C:\WINDOWS\Prefetch\CONHOST.EXE-F98A1078.pf C:\WINDOWS\Prefetch\CONSENT.EXE-2D674CE4.pf C:\WINDOWS\Prefetch\CREATERESTOREPOINT.EXE-0C8FB16E.pf C:\WINDOWS\Prefetch\CREDENTIALUIBROKER.EXE-E9F92FD0.pf C:\WINDOWS\Prefetch\CSRSS.EXE-A7A2B218.pf C:\WINDOWS\Prefetch\CTTUNE.EXE-0FF879A9.pf C:\WINDOWS\Prefetch\CUT.DAT-9C5FE473.pf C:\WINDOWS\Prefetch\DASHOST.EXE-38AAABF0.pf C:\WINDOWS\Prefetch\DCCW.EXE-DA397BBF.pf C:\WINDOWS\Prefetch\DEFRAG.EXE-22AD8A37.pf C:\WINDOWS\Prefetch\DELEGATE_EXECUTE.EXE-BC0CD1AE.pf C:\WINDOWS\Prefetch\DLLHOST.EXE-5B6442A9.pf C:\WINDOWS\Prefetch\DLLHOST.EXE-6A829A47.pf C:\WINDOWS\Prefetch\DLLHOST.EXE-6E31253B.pf C:\WINDOWS\Prefetch\DLLHOST.EXE-78073FE4.pf C:\WINDOWS\Prefetch\DLLHOST.EXE-7C096765.pf C:\WINDOWS\Prefetch\DLLHOST.EXE-829F390C.pf C:\WINDOWS\Prefetch\DLLHOST.EXE-82CF0F0F.pf C:\WINDOWS\Prefetch\DLLHOST.EXE-B51A0D95.pf C:\WINDOWS\Prefetch\DLLHOST.EXE-BF26B840.pf C:\WINDOWS\Prefetch\DLLHOST.EXE-F3B31CFE.pf C:\WINDOWS\Prefetch\DLLHOST.EXE-F8F2B7B0.pf C:\WINDOWS\Prefetch\DON LAUNCHER.EXE-1FDF6887.pf C:\WINDOWS\Prefetch\DON.EXE-0BDFC79D.pf C:\WINDOWS\Prefetch\DSMUSERTASK.EXE-D4A83970.pf C:\WINDOWS\Prefetch\DWM.EXE-F29FE9E2.pf C:\WINDOWS\Prefetch\dynreservedpri.db C:\WINDOWS\Prefetch\EASEOFACCESSDIALOG.EXE-E54B6BCB.pf C:\WINDOWS\Prefetch\EPMNEWS.EXE-19A9DEFD.pf C:\WINDOWS\Prefetch\EXCEL.EXE-19F992F0.pf C:\WINDOWS\Prefetch\EXPENDABROS.EXE-CCD7D95A.pf C:\WINDOWS\Prefetch\EXPLORER.EXE-03C49D11.pf C:\WINDOWS\Prefetch\FC.EXE-A601B343.pf C:\WINDOWS\Prefetch\FILEMANAGER.EXE-D7E24B17.pf C:\WINDOWS\Prefetch\FIND.EXE-3298DC3B.pf C:\WINDOWS\Prefetch\FINDSTR.EXE-46AC8DA0.pf C:\WINDOWS\Prefetch\FIREFOX.EXE-528BC649.pf C:\WINDOWS\Prefetch\FIXCFG.EXE-4E6CE366.pf C:\WINDOWS\Prefetch\FLASHUTIL_ACTIVEX.EXE-4E6AE223.pf C:\WINDOWS\Prefetch\FRST64.EXE-98805D0B.pf C:\WINDOWS\Prefetch\GBPSV.EXE-BC64CBF2.pf C:\WINDOWS\Prefetch\GFXUIEX.EXE-9CA5FF42.pf C:\WINDOWS\Prefetch\GLCND.EXE-CA2C9DC6.pf C:\WINDOWS\Prefetch\GOOGLEEARTH.EXE-5942F2E9.pf C:\WINDOWS\Prefetch\GOOGLEUPDATE.EXE-0D7FFA90.pf C:\WINDOWS\Prefetch\GOOGLEUPDATE.EXE-0DC756DC.pf C:\WINDOWS\Prefetch\GOOGLEUPDATE.EXE-1B8CD3F4.pf C:\WINDOWS\Prefetch\GOOGLEUPDATE.EXE-24F786D3.pf C:\WINDOWS\Prefetch\GOOGLEUPDATE.EXE-62E5E10F.pf C:\WINDOWS\Prefetch\GOOGLEUPDATE.EXE-667D3C7D.pf C:\WINDOWS\Prefetch\GREP.DAT-7C065845.pf C:\WINDOWS\Prefetch\GWXUX.EXE-96BF65E3.pf C:\WINDOWS\Prefetch\HECISERVER.EXE-AD396A6A.pf C:\WINDOWS\Prefetch\HELPPANE.EXE-5A92E3D5.pf C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-232A1D6E.pf C:\WINDOWS\Prefetch\IASTORDATAMGRSVC.EXE-D1EA3411.pf C:\WINDOWS\Prefetch\IASTORICON.EXE-36ADCADA.pf C:\WINDOWS\Prefetch\IASTORICONLAUNCH.EXE-E6568871.pf C:\WINDOWS\Prefetch\IBRIGHTNESS.EXE-BDD19C96.pf C:\WINDOWS\Prefetch\IEXPLORE.EXE-7A9337F2.pf C:\WINDOWS\Prefetch\IEXPLORE.EXE-F4FB5D2F.pf C:\WINDOWS\Prefetch\IGFXTRAY.EXE-21BDFE68.pf C:\WINDOWS\Prefetch\INTELMEFWSERVICE.EXE-265333D9.pf C:\WINDOWS\Prefetch\IPM.EXE-ABB8304A.pf C:\WINDOWS\Prefetch\IRPF2015WIN32V1.2 (1).EXE-BFE5634C.pf C:\WINDOWS\Prefetch\IRPF2015WIN32V1.2.EXE-BAA8BAAA.pf C:\WINDOWS\Prefetch\JAVA.EXE-8F72B01A.pf C:\WINDOWS\Prefetch\JAVAW.EXE-413DCDED.pf C:\WINDOWS\Prefetch\JAVAW.EXE-87CF19BD.pf C:\WINDOWS\Prefetch\JAVAWS.EXE-01AAAD04.pf C:\WINDOWS\Prefetch\JP2LAUNCHER.EXE-F0B670FE.pf C:\WINDOWS\Prefetch\JQ.DAT-CBCF2C06.pf C:\WINDOWS\Prefetch\JRT.EXE-7DB987F6.pf C:\WINDOWS\Prefetch\JUCHECK.EXE-3F4853CB.pf C:\WINDOWS\Prefetch\JUSCHED.EXE-4B303C70.pf C:\WINDOWS\Prefetch\JXPIINSTALL.EXE-112166E5.pf C:\WINDOWS\Prefetch\KTS15.0.2.361PT_7387.EXE-FAEAAA8D.pf C:\WINDOWS\Prefetch\Layout.ini C:\WINDOWS\Prefetch\LEAGUE OF LEGENDS.EXE-62979394.pf C:\WINDOWS\Prefetch\LEAGUE OF LEGENDS.EXE-884C209A.pf C:\WINDOWS\Prefetch\LEAGUE OF LEGENDS.EXE-9B26671D.pf C:\WINDOWS\Prefetch\LMS.EXE-409EDB07.pf C:\WINDOWS\Prefetch\LOGONUI.EXE-E35F76FB.pf C:\WINDOWS\Prefetch\LOLCLIENT.EXE-07DE81D6.pf C:\WINDOWS\Prefetch\LOLCLIENT.EXE-6394CF50.pf C:\WINDOWS\Prefetch\LOLCLIENT.EXE-DA035B19.pf C:\WINDOWS\Prefetch\LOLLAUNCHER.EXE-4C93E5FF.pf C:\WINDOWS\Prefetch\LOLLAUNCHER.EXE-D38F95EC.pf C:\WINDOWS\Prefetch\LOLPATCHERUX.EXE-8BB2FEE7.pf C:\WINDOWS\Prefetch\LOLPATCHERUX.EXE-B3C33482.pf C:\WINDOWS\Prefetch\MBAM.EXE-9FD52EFE.pf C:\WINDOWS\Prefetch\MCUICNT.EXE-D0E68351.pf C:\WINDOWS\Prefetch\MINECRAFTLAUNCHER.EXE-02D3855F.pf C:\WINDOWS\Prefetch\MOVIEMAKER.EXE-A6401490.pf C:\WINDOWS\Prefetch\MOVIEPLAYER.EXE-672CB04D.pf C:\WINDOWS\Prefetch\MPCMDRUN.EXE-6520183E.pf C:\WINDOWS\Prefetch\MSCORSVW.EXE-55FE3087.pf C:\WINDOWS\Prefetch\MSCORSVW.EXE-D593A5D9.pf C:\WINDOWS\Prefetch\MSDT.EXE-A16F1692.pf C:\WINDOWS\Prefetch\MSIEXEC.EXE-7D20CFB0.pf C:\WINDOWS\Prefetch\MSPAINT.EXE-512C7E1E.pf C:\WINDOWS\Prefetch\NGEN.EXE-383F81D5.pf C:\WINDOWS\Prefetch\NGEN.EXE-A8DBB043.pf C:\WINDOWS\Prefetch\NGENTASK.EXE-4DB88ADA.pf C:\WINDOWS\Prefetch\NGENTASK.EXE-CD4E002C.pf C:\WINDOWS\Prefetch\NOTEPAD.EXE-B28CC291.pf C:\WINDOWS\Prefetch\NOTEPAD.EXE-F0516D55.pf C:\WINDOWS\Prefetch\Op-EXPLORER.EXE-03C49D11-000000F5.pf C:\WINDOWS\Prefetch\OPENWITH.EXE-BA0DC300.pf C:\WINDOWS\Prefetch\OSK.EXE-C125D72B.pf C:\WINDOWS\Prefetch\PfPre_8d3568fd.db C:\WINDOWS\Prefetch\PfPre_8d3ea4a7.db C:\WINDOWS\Prefetch\PfSvPerfStats.bin C:\WINDOWS\Prefetch\PICKERHOST.EXE-103A256A.pf C:\WINDOWS\Prefetch\PING.EXE-167FE968.pf C:\WINDOWS\Prefetch\PING.EXE-CF0A440C.pf C:\WINDOWS\Prefetch\PLUGIN-NM-SERVER.EXE-ED85E0B3.pf C:\WINDOWS\Prefetch\POWERPNT.EXE-B4681A1E.pf C:\WINDOWS\Prefetch\PRESENTATIONFONTCACHE.EXE-E2702CF2.pf C:\WINDOWS\Prefetch\RADS_USER_KERNEL.EXE-87E9365D.pf C:\WINDOWS\Prefetch\RAVCPL64.EXE-C0BB540D.pf C:\WINDOWS\Prefetch\RDRCEF.EXE-4BD59348.pf C:\WINDOWS\Prefetch\READERDC_BR_RA_INSTALL.EXE-6170DAB4.pf C:\WINDOWS\Prefetch\READER_SL.EXE-0EC43704.pf C:\WINDOWS\Prefetch\ReadyBoot C:\WINDOWS\Prefetch\REG.EXE-CC1AF0A4.pf C:\WINDOWS\Prefetch\REGEDIT.EXE-FA6F6DA2.pf C:\WINDOWS\Prefetch\RICONMAN.EXE-D63AD6B8.pf C:\WINDOWS\Prefetch\ROBOCRAFT.EXE-9F1DC508.pf C:\WINDOWS\Prefetch\ROBOCRAFTCLIENT.EXE-7CF30033.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-0F905C08.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-29195783.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-2FF29840.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-348817CA.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-39817C35.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-4499C2C5.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-5C68AAB7.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-61EB51D2.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-63FF335C.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-650CA2EC.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-65CFC75C.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-6C843171.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-73CF5A71.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-86B26863.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-96AB8B4C.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-9965A5AF.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-9AF16C52.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-B704A367.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-C46C7B01.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-C5A4D4DA.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-F46B2937.pf C:\WINDOWS\Prefetch\RUNDLL32.EXE-FAB93EF2.pf C:\WINDOWS\Prefetch\RUNONCE.EXE-AAB0060C.pf C:\WINDOWS\Prefetch\RUNONCE.EXE-E874B0D0.pf C:\WINDOWS\Prefetch\RUNTIMEBROKER.EXE-17E2786F.pf C:\WINDOWS\Prefetch\SCHTASKS.EXE-0AD36442.pf C:\WINDOWS\Prefetch\SDIAGNHOST.EXE-D8BC1DC6.pf C:\WINDOWS\Prefetch\SEARCHFILTERHOST.EXE-10E4267C.pf C:\WINDOWS\Prefetch\SEARCHINDEXER.EXE-EF8503D3.pf C:\WINDOWS\Prefetch\SEARCHPROTOCOLHOST.EXE-C6CFE2A8.pf C:\WINDOWS\Prefetch\SED.DAT-1FD61BA3.pf C:\WINDOWS\Prefetch\SETTINGSYNCHOST.EXE-DD400067.pf C:\WINDOWS\Prefetch\SETUP_WM.EXE-5D2609E7.pf C:\WINDOWS\Prefetch\SFGBPCEF.TMP-8B1E50D5.pf C:\WINDOWS\Prefetch\SFTGC.EXE-540BE541.pf C:\WINDOWS\Prefetch\SHORTCUT.DAT-753BF043.pf C:\WINDOWS\Prefetch\SKYDRIVE.EXE-0DBB4667.pf C:\WINDOWS\Prefetch\SMSS.EXE-81AD91F0.pf C:\WINDOWS\Prefetch\SNDVOL.EXE-276AC160.pf C:\WINDOWS\Prefetch\SOFFICE.BIN-4DEC791F.pf C:\WINDOWS\Prefetch\SOFTWARE_REPORTER_TOOL.EXE-D1137C68.pf C:\WINDOWS\Prefetch\SORT.EXE-EA1A5446.pf C:\WINDOWS\Prefetch\SOUNDRECORDER.EXE-3D878C35.pf C:\WINDOWS\Prefetch\SPOOLSV.EXE-AC422BB0.pf C:\WINDOWS\Prefetch\SPPSVC.EXE-7B160CA5.pf C:\WINDOWS\Prefetch\SRTASKS.EXE-29C2E869.pf C:\WINDOWS\Prefetch\STEAM.EXE-E1CA0477.pf C:\WINDOWS\Prefetch\SVCHOST.EXE-3830BC72.pf C:\WINDOWS\Prefetch\SVCHOST.EXE-38BE90DD.pf C:\WINDOWS\Prefetch\SVCHOST.EXE-576FFE64.pf C:\WINDOWS\Prefetch\SVCHOST.EXE-93798CD2.pf C:\WINDOWS\Prefetch\SVCHOST.EXE-FEA1FDBE.pf C:\WINDOWS\Prefetch\SYNTPENH.EXE-2DD080ED.pf C:\WINDOWS\Prefetch\SYSTEMSETTINGS.EXE-D8CC3B5E.pf C:\WINDOWS\Prefetch\TASKENG.EXE-23205583.pf C:\WINDOWS\Prefetch\TASKHOST.EXE-29D61DAB.pf C:\WINDOWS\Prefetch\TASKHOST.EXE-3C5D03F7.pf C:\WINDOWS\Prefetch\TASKHOST.EXE-5CFABC16.pf C:\WINDOWS\Prefetch\TASKHOST.EXE-86081325.pf C:\WINDOWS\Prefetch\TASKHOST.EXE-985C34E6.pf C:\WINDOWS\Prefetch\TASKHOST.EXE-D687BE54.pf C:\WINDOWS\Prefetch\TASKHOST.EXE-E88B2240.pf C:\WINDOWS\Prefetch\TASKHOST.EXE-EEE98BDA.pf C:\WINDOWS\Prefetch\TASKHOST.EXE-F2C7AEBC.pf C:\WINDOWS\Prefetch\TASKHOSTEX.EXE-7356AAC0.pf C:\WINDOWS\Prefetch\TASKKILL.EXE-3D8A2F61.pf C:\WINDOWS\Prefetch\TASKLIST.EXE-74FDEEA1.pf C:\WINDOWS\Prefetch\TASKMGR.EXE-39AABA37.pf C:\WINDOWS\Prefetch\THUMBNAILEXTRACTIONHOST.EXE-C3FB8861.pf C:\WINDOWS\Prefetch\TIWORKER.EXE-78E80409.pf C:\WINDOWS\Prefetch\TIWORKER.EXE-B86BBFC7.pf C:\WINDOWS\Prefetch\TRUSTEDINSTALLER.EXE-B018CCBF.pf C:\WINDOWS\Prefetch\TS3CLIENT_WIN32.EXE-AC682A12.pf C:\WINDOWS\Prefetch\UNINS000.EXE-4CF95E16.pf C:\WINDOWS\Prefetch\UNINSTALL.EXE-FC2CB69D.pf C:\WINDOWS\Prefetch\UNINSTXP.EXE-70727FF1.pf C:\WINDOWS\Prefetch\UNS.EXE-9B1279FB.pf C:\WINDOWS\Prefetch\UNSECAPP.EXE-454AB5C0.pf C:\WINDOWS\Prefetch\USERACCOUNTBROKER.EXE-FE23DE65.pf C:\WINDOWS\Prefetch\USERACCOUNTCONTROLSETTINGS.EX-550E3008.pf C:\WINDOWS\Prefetch\USERINIT.EXE-7FD17ED1.pf C:\WINDOWS\Prefetch\UTILMAN.EXE-3520356C.pf C:\WINDOWS\Prefetch\VLC.EXE-F1ED81B3.pf C:\WINDOWS\Prefetch\VSSVC.EXE-206E55B3.pf C:\WINDOWS\Prefetch\W32TM.EXE-78C041DB.pf C:\WINDOWS\Prefetch\WERFAULT.EXE-44194444.pf C:\WINDOWS\Prefetch\WERFAULT.EXE-94CE7668.pf C:\WINDOWS\Prefetch\WERMGR.EXE-D948C216.pf C:\WINDOWS\Prefetch\WGET.DAT-A8AF41E2.pf C:\WINDOWS\Prefetch\WINLOGON.EXE-0D9AB72B.pf C:\WINDOWS\Prefetch\WINWORD.EXE-342B9A35.pf C:\WINDOWS\Prefetch\WLXPHOTOGALLERY.EXE-55FF63A1.pf C:\WINDOWS\Prefetch\WMI64.EXE-C08F456D.pf C:\WINDOWS\Prefetch\WMIADAP.EXE-7D63BB4C.pf C:\WINDOWS\Prefetch\WMIPRVSE.EXE-BB49B536.pf C:\WINDOWS\Prefetch\WMPLAYER.EXE-B0AD61F0.pf C:\WINDOWS\Prefetch\WMPNETWK.EXE-13D172B9.pf C:\WINDOWS\Prefetch\WORDPAD.EXE-505FE0CE.pf C:\WINDOWS\Prefetch\WUAUCLT.EXE-4A7CF88B.pf C:\WINDOWS\Prefetch\WWAHOST.EXE-B036CF2F.pf C:\WINDOWS\Prefetch\WYDFAK.EXE-384711A9.pf C:\WINDOWS\Prefetch\XWIZARD.EXE-8AD27557.pf C:\WINDOWS\Prefetch\_IU14D2N.TMP-3FA70189.pf C:\WINDOWS\Prefetch\ReadyBoot\rblayout.xin C:\WINDOWS\Prefetch\ReadyBoot\Trace2.fx C:\WINDOWS\Prefetch\ReadyBoot\Trace3.fx C:\WINDOWS\Prefetch\ReadyBoot\Trace4.fx C:\WINDOWS\Prefetch\ReadyBoot\Trace5.fx C:\WINDOWS\Prefetch\ReadyBoot\Trace6.fx Java Cache empty Fim do relatório. Pensez à vider la corbeille ! Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 12, 2015 /!\ Boa Tarde! Ionara /!\ > Seu notebook ainda apresenta lentidão? > Baixe: < > ( ... de Pierre 13 ) > Link alternativo! ( CTR.exe ) > Caso encontre dificuldades ou bloqueio ao realizar o download,utilize o navegador Internet Explorer. > Salve-a no desktop! > Para Windows 7 e 8,execute-a com clique direito do mouse. > Desabilite seu antivírus! > Escolha: Executar como administrador! ( Windows Vista, 7 ,8 e 8.1 ) (32 e 64 bits) > Para Windows XP,basta duplo-clique em CTR.exe. > Aguarde a finalização,que é rápida! > Poste o relatório! ( CTR.txt ) A+ Compartilhar este post Link para o post Compartilhar em outros sites
Ionara 2 Denunciar post Postado Agosto 13, 2015 Boa noite, já está mais rápido, porém ainda tem um programa em segundo plano que não identifiquei, segue log solicitado.. Rapport de Contrôle restrictions Pierre13 (CTR version 2.0.0.2 ) du 13\08\2015 à 19:54:34 PC de Ionara Windows 8.1 Single Language (64 bits) Réparation erreur 2203 impossible. Contrôle présence restrictions [TROJ_POWELIKS.B] clé feature_browser_emulation supprimée. [bKDR_BLACKEN.A] clé Check_Associations supprimée. [bKDR_BLACKEN.A] clé DisableFirstRunCustomize supprimée. [bKDR_BLACKEN.A] clé WarnOnClose corrigée. Autorisation installation sponsor Java(x86) supprimée. Autorisation installation sponsor Java(x64) supprimée. Restriction Affichage Documents récents supprimée. Restriction Affichage Documents supprimée. Restriction synchronisation en arrière-plan des flux d’informations et des Web Slices supprimée. Restriction découverte des flux RSS et des Web Slices supprimée. Pavé numérique activé. Restriction utilisateur pour Windows Installer supprimée. Configuration Windows Update rétablie. Recherche Windows Update rétablie. Service Pare feu Windows activé. Paramètres Pare feu Windows rétablis par défaut et activé. 237 restrictions contrôlées. 15 restriction(s) réparée(s). Re démarrer le PC pour prendre en compte la ou les réparations. Le rapport est sur le bureau (C:\Users\Valmor\Desktop\CTR.txt) Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 14, 2015 /!\ Boa Noite! Ionara /!\ > Otimize seu computador com o Toolwiz Care. > Estando na página clique em "Download@MajorGeeks" << > Salve-o em diretório adequado! ( Desktop ) > Instale-o e,à seguir,busque executar as funções que irão promover a aceleração do computador. > Clique no menu "Analisar" >> Examinar << Aguarde! > Ao concluir o scan,clique em "Corrigir". > Agora,acesse o menu "Limpar" >> Guia "Limpeza do Registro". > Marque as caixinhas que indiquem "x Problemas encontrados" > Clique "Limpar agora". << Aguarde! > Posteriormente,acesse o menu "Acelerar" > Estando na função "Acelerar",clique na guia "Otimizador do sistema". > À seguir,clique em "Otimizar". > Aguarde a conclusão,onde todos os ítens devem apresentar o status "Reparado". > O aumento no tempo do boot,pode ser obtido ao gerenciar a Inicialização,por um de seus menus. > Vá em "Acelerar" >> "Relatório da Inicialização". > Verifique no Comentário,o que pode ser interrompido. > Informe! A+ Compartilhar este post Link para o post Compartilhar em outros sites
Ionara 2 Denunciar post Postado Agosto 16, 2015 Boa noite, segui as orientações, foram corrigidos 1057 problemas, ao final no menu inicialização, ficou entre "componente do sistema" "não remover" e alguns "sem sugestão", nenhuma indicação direta de remoção... mas percebo que os programas estão rodando mais rapidamente, att. Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 16, 2015 /!\ Olá! Ionara /!\ > Podemos encerrar ou queres novas tentativas de aceleramento? A+ Compartilhar este post Link para o post Compartilhar em outros sites
DigRam 144 Denunciar post Postado Agosto 17, 2015 PROBLEMA RESOLVIDO Caso o autor necessite que o tópico seja reaberto basta enviar uma Mensagem Privada para um Moderador com um link para o tópico. Compartilhar este post Link para o post Compartilhar em outros sites