Este fórum foi descontinuado. LEIA AQUI e participe da Comunidade BABOO :)

A área de Remoção de Malwares está aberta na Comunidade BABOO. LEIA AQUI

Ir para conteúdo
rbraida

Log analise

Mensagem Recomendada


Faz uns dias que Kaspersky vem informando esse relatório.

O que eu fiz: Desinstalei e reinstalei o Chrome. Passei o Kasperky em todo sistema. Passei o CCleaner.

Persiste.

Segue o log.

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 09:58:54, on 26/02/2019
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17134.0001)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\avpui.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
C:\Users\Ricardo\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo17win10.msn.com/?PC=LCTE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo17win10.msn.com/?PC=LCTE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=
O2 - BHO: ScriptInjectionPluginBrowserHelperObject - {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\IEExt\ie_plugin.dll
O3 - Toolbar: Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\IEExt\ie_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Ricardo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: Windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Intel® SGX AESM (AESMService) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_1781f8bae8fdf5c0\aesm_service.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Unknown owner - C:\Windows\system32\DRIVERS\AdminService.exe (file missing)
O23 - Service: Serviço do Kaspersky Anti-Virus 19.0.0 (AVP19.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\avp.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Dolby DAX2 API Service - Dolby Laboratories, Inc. - C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: Fredaikis Anti-Cheat: TheNewZ (FacSvc_TheNewZ) - Unknown owner - C:\Users\Ricardo\AppData\Roaming\FAC\TheNewZ\FacSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google Inc. - C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.119\elevation_service.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Heroes & Generals Steam Service (HnGSteamService) - Reto-Moto ApS - C:\Program Files (x86)\Steam\steamapps\common\Heroes & Generals\hngservice.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxCUIService.exe
O23 - Service: @oem29.inf,%ImcSvcDisplayName%;System Interface Foundation Service (ImControllerService) - Lenovo Group Ltd. - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: klvssbridge64_18.0.0 - Unknown owner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\vssbridge64.exe (file missing)
O23 - Service: klvssbridge64_19.0.0 - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\x64\vssbridge64.exe
O23 - Service: Serviço do Kaspersky Secure Connection 3.0.0 (KSDE3.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: Qualcomm Atheros WLAN Driver Service (QcomWlanSrv) - Unknown owner - C:\Windows\System32\drivers\QcomWlanSrvx64.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\Windows\system32\SgrmBroker.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 13 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\Windows\system32\xbgmsvc.exe (file missing)

--
End of file - 9897 bytes

< Sem título.jpg

 

Editado por Mr.Million

Usar Citar desnecessariamente

Compartilhar este post


Link para o post
Compartilhar em outros sites

Nada demais excesso nas Informações do KIS, reveja suas Configurações..

Baixe o ZHPCleaner e salve no Desktop. (Área de Trabalho)

Usuários do Windows 7, 8, 8.1 ou 10: clique com o botão direito do mouse no ícone do Programa e selecione  executar-como-administrador.png

Dê um duplo-clique sobre o ZHPCleaner.exe.

Clique no botão Scanner.

A Ferramenta comecará o exame do seu Sistema. Tenha paciência pois pode demorar um pouco dependendo da quantidades de itens a examinar.

Ao final da Verificação, clique no botão Reparar.

Concluída a operação, um Log se abrirá. Caso isso não aconteça, clique no botão Relatório e salve o Log.

Selecione, copie e cole o conteúdo deste Log na sua próxima resposta + um novo Log do HijackThis.


assinatura-mrmillion.png65301516_windows-insider-mvp-logo(Custom).png.36263cb7b506cc6935fb37f39e504cec.png

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ontem a noite rodei o ZHP, e fui estudar, deixei em suspensão o notebook, hoje startei o notebook e em seguida apareceu aqueles relatórios de novas conexões SSL pelo Kaspersky, em seguida passei o Hijackthis, segue:

Log ZHP

Citar

~ ZHPCleaner v2019.2.24.26 by Nicolas Coolman (2019/02/26)
~ Run by Ricardo (Administrator)  (26/02/2019 20:36:10)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Certificate ZHPCleaner: Legal
~ Type : Repair
~ Report : C:\Users\Ricardo\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Ricardo\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Home Single Language, 64-bit  (Build 17134)


---\\  Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\  Services (0)
~ No malicious or unnecessary items found.


---\\  Browser internet (0)
~ No malicious or unnecessary items found.


---\\  Hosts file (1)
~ The hosts file is legitimate (21)


---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\  Explorer ( File, Folder) (22)
MOVED file: C:\Users\Ricardo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk  [Bad : C:\Users\Ricardo\AppData\Roaming\BitTorrent\BitTorrent.exe](.BitTorrent Inc..)  =>BitTorrent (P2P)
MOVED file: C:\Windows\Installer\wix{9CBA860F-7437-4A75-941C-8EF559F2D145}.SchedServiceConfig.rmi    =>.SUP.Empty
MOVED file: C:\Windows\Installer\wix{C5FDDED7-DEC7-48B4-AFD8-DFB8A0FD199A}.SchedServiceConfig.rmi    =>.SUP.Empty
MOVED file: C:\Windows\Installer\wix{C99F4AFA-B32C-4063-865C-D7B5CC0A78FB}.SchedServiceConfig.rmi    =>.SUP.Empty
MOVED file: C:\Windows\Installer\wix{F814D094-197F-43C8-87FA-3210BB780486}.SchedServiceConfig.rmi    =>.SUP.Empty
MOVED file: C:\ProgramData\Lenovo\ImController\Plugins\GenericMessagingPlugin\x86\SLSCore.dll [SweetLabs, Inc. - SLSCore]  =>.SUP.SweetLabs
MOVED file: C:\ProgramData\Lenovo\ImController\Plugins\GenericMessagingPlugin\x86\SLSLib.dll [SweetLabs, Inc. - SLSLib]  =>.SUP.SweetLabs
MOVED file: C:\Users\Ricardo\AppData\Local\Temp\aria-debug-14904.log    =>.SUP.Temporary.OneDrive
MOVED file: C:\Users\Ricardo\AppData\Local\Temp\aria-debug-21448.log    =>.SUP.Temporary.OneDrive
MOVED file: C:\Users\Ricardo\AppData\Local\Temp\wct2A4.tmp    =>.SUP.Temporary.Office
MOVED file: C:\Users\Ricardo\AppData\Local\Temp\wctFB7F.tmp    =>.SUP.Temporary.Office
MOVED folder: C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej  =>.SUP.SearchManager
MOVED folder: C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\File System\000  =>.SUP.Temporary.Chrome
MOVED folder: C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\File System\001  =>.SUP.Temporary.Chrome
MOVED folder: C:\Windows\Installer\MSI61A8.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSI6B9C.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSI79F5.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSI7D90.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSI88AD.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSID1DD.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSID3C3.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSIEB2F.tmp-  =>.SUP.Empty


---\\  Registry ( Key, Value, Data) (6)
DELETED key*: HKCU\SOFTWARE\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej []  =>.SUP.SearchManager
DELETED key*: [X64] HKLM\SOFTWARE\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej []  =>.SUP.SearchManager
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej []  =>.SUP.SearchManager
DELETED key*: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrent [BitTorrent Inc.]  =>BitTorrent (P2P)
DELETED value: HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\AVP18.0.0\ [No Folder]  =>.SUP.Obsolete.NoFolder
DELETED value: HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\AVP18.0.0\Temp\ [No Folder]  =>.SUP.Obsolete.NoFolder


---\\  Summary of the elements found (8)
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/  =>BitTorrent (P2P)
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Empty
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.SweetLabs
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Temporary.OneDrive
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Temporary.Office
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.SearchManager
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Temporary.Chrome
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Obsolete.NoFolder


---\\  Other deletions. (8)
~ Registry Keys Tracing deleted (8)
~ Remove the old reports ZHPCleaner. (0)


---\\ Result of repair
~ Repair carried out successfully
~ Browser not found (Opera Software)


---\\ Statistics
~ Items scanned : 973
~ Items found : 0
~ Items cancelled : 0
~ Items options : 12/12
~ Space saving (bytes) : 13885


~ End of clean in 00h00mn23s

---\\  Reports (2)
ZHPCleaner--26022019-11_40_59.txt
ZHPCleaner-[R]-26022019-20_36_33.txt
 

Log Hijackthis

Citar

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 08:22:22, on 27/02/2019
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17134.0001)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\avpui.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Ricardo\Downloads\HijackThis.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo17win10.msn.com/?PC=LCTE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo17win10.msn.com/?PC=LCTE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=
O2 - BHO: ScriptInjectionPluginBrowserHelperObject - {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\IEExt\ie_plugin.dll
O3 - Toolbar: Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\IEExt\ie_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Ricardo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: Windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Intel® SGX AESM (AESMService) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_1781f8bae8fdf5c0\aesm_service.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Unknown owner - C:\Windows\system32\DRIVERS\AdminService.exe (file missing)
O23 - Service: Serviço do Kaspersky Anti-Virus 19.0.0 (AVP19.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\avp.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Dolby DAX2 API Service - Dolby Laboratories, Inc. - C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: Fredaikis Anti-Cheat: TheNewZ (FacSvc_TheNewZ) - Unknown owner - C:\Users\Ricardo\AppData\Roaming\FAC\TheNewZ\FacSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google Inc. - C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.119\elevation_service.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Heroes & Generals Steam Service (HnGSteamService) - Reto-Moto ApS - C:\Program Files (x86)\Steam\steamapps\common\Heroes & Generals\hngservice.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxCUIService.exe
O23 - Service: @oem29.inf,%ImcSvcDisplayName%;System Interface Foundation Service (ImControllerService) - Lenovo Group Ltd. - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: klvssbridge64_18.0.0 - Unknown owner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\vssbridge64.exe (file missing)
O23 - Service: klvssbridge64_19.0.0 - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\x64\vssbridge64.exe
O23 - Service: Serviço do Kaspersky Secure Connection 3.0.0 (KSDE3.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: Qualcomm Atheros WLAN Driver Service (QcomWlanSrv) - Unknown owner - C:\Windows\System32\drivers\QcomWlanSrvx64.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\Windows\system32\SgrmBroker.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 13 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\Windows\system32\xbgmsvc.exe (file missing)

--
End of file - 10110 bytes
 

 

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ontem a noite rodei o ZHP, e fui estudar, deixei em suspensão o notebook, hoje startei o notebook e em seguida apareceu aqueles relatórios de novas conexões SSL pelo Kaspersky, em seguida passei o Hijackthis, segue:

~ ZHPCleaner v2019.2.24.26 by Nicolas Coolman (2019/02/26)
~ Run by Ricardo (Administrator)  (26/02/2019 20:36:10)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Certificate ZHPCleaner: Legal
~ Type : Repair
~ Report : C:\Users\Ricardo\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Ricardo\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Home Single Language, 64-bit  (Build 17134)


---\\  Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\  Services (0)
~ No malicious or unnecessary items found.


---\\  Browser internet (0)
~ No malicious or unnecessary items found.


---\\  Hosts file (1)
~ The hosts file is legitimate (21)


---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\  Explorer ( File, Folder) (22)
MOVED file: C:\Users\Ricardo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BitTorrent.lnk  [Bad : C:\Users\Ricardo\AppData\Roaming\BitTorrent\BitTorrent.exe](.BitTorrent Inc..)  =>BitTorrent (P2P)
MOVED file: C:\Windows\Installer\wix{9CBA860F-7437-4A75-941C-8EF559F2D145}.SchedServiceConfig.rmi    =>.SUP.Empty
MOVED file: C:\Windows\Installer\wix{C5FDDED7-DEC7-48B4-AFD8-DFB8A0FD199A}.SchedServiceConfig.rmi    =>.SUP.Empty
MOVED file: C:\Windows\Installer\wix{C99F4AFA-B32C-4063-865C-D7B5CC0A78FB}.SchedServiceConfig.rmi    =>.SUP.Empty
MOVED file: C:\Windows\Installer\wix{F814D094-197F-43C8-87FA-3210BB780486}.SchedServiceConfig.rmi    =>.SUP.Empty
MOVED file: C:\ProgramData\Lenovo\ImController\Plugins\GenericMessagingPlugin\x86\SLSCore.dll [SweetLabs, Inc. - SLSCore]  =>.SUP.SweetLabs
MOVED file: C:\ProgramData\Lenovo\ImController\Plugins\GenericMessagingPlugin\x86\SLSLib.dll [SweetLabs, Inc. - SLSLib]  =>.SUP.SweetLabs
MOVED file: C:\Users\Ricardo\AppData\Local\Temp\aria-debug-14904.log    =>.SUP.Temporary.OneDrive
MOVED file: C:\Users\Ricardo\AppData\Local\Temp\aria-debug-21448.log    =>.SUP.Temporary.OneDrive
MOVED file: C:\Users\Ricardo\AppData\Local\Temp\wct2A4.tmp    =>.SUP.Temporary.Office
MOVED file: C:\Users\Ricardo\AppData\Local\Temp\wctFB7F.tmp    =>.SUP.Temporary.Office
MOVED folder: C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej  =>.SUP.SearchManager
MOVED folder: C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\File System\000  =>.SUP.Temporary.Chrome
MOVED folder: C:\Users\Ricardo\AppData\Local\Google\Chrome\User Data\Default\File System\001  =>.SUP.Temporary.Chrome
MOVED folder: C:\Windows\Installer\MSI61A8.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSI6B9C.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSI79F5.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSI7D90.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSI88AD.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSID1DD.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSID3C3.tmp-  =>.SUP.Empty
MOVED folder: C:\Windows\Installer\MSIEB2F.tmp-  =>.SUP.Empty


---\\  Registry ( Key, Value, Data) (6)
DELETED key*: HKCU\SOFTWARE\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej []  =>.SUP.SearchManager
DELETED key*: [X64] HKLM\SOFTWARE\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej []  =>.SUP.SearchManager
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\pilplloabdedfmialnfchjomjmpjcoej []  =>.SUP.SearchManager
DELETED key*: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\BitTorrent [BitTorrent Inc.]  =>BitTorrent (P2P)
DELETED value: HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\AVP18.0.0\ [No Folder]  =>.SUP.Obsolete.NoFolder
DELETED value: HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\AVP18.0.0\Temp\ [No Folder]  =>.SUP.Obsolete.NoFolder


---\\  Summary of the elements found (8)
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/  =>BitTorrent (P2P)
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Empty
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.SweetLabs
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Temporary.OneDrive
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Temporary.Office
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.SearchManager
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Temporary.Chrome
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Obsolete.NoFolder


---\\  Other deletions. (8)
~ Registry Keys Tracing deleted (8)
~ Remove the old reports ZHPCleaner. (0)


---\\ Result of repair
~ Repair carried out successfully
~ Browser not found (Opera Software)


---\\ Statistics
~ Items scanned : 973
~ Items found : 0
~ Items cancelled : 0
~ Items options : 12/12
~ Space saving (bytes) : 13885


~ End of clean in 00h00mn23s

---\\  Reports (2)
ZHPCleaner--26022019-11_40_59.txt
ZHPCleaner-[R]-26022019-20_36_33.txt

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 08:22:22, on 27/02/2019
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17134.0001)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\avpui.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Ricardo\Downloads\HijackThis.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo17win10.msn.com/?PC=LCTE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo17win10.msn.com/?PC=LCTE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=
O2 - BHO: ScriptInjectionPluginBrowserHelperObject - {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\IEExt\ie_plugin.dll
O3 - Toolbar: Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\IEExt\ie_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Ricardo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: Windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Intel® SGX AESM (AESMService) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_1781f8bae8fdf5c0\aesm_service.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Unknown owner - C:\Windows\system32\DRIVERS\AdminService.exe (file missing)
O23 - Service: Serviço do Kaspersky Anti-Virus 19.0.0 (AVP19.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\avp.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Dolby DAX2 API Service - Dolby Laboratories, Inc. - C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: Fredaikis Anti-Cheat: TheNewZ (FacSvc_TheNewZ) - Unknown owner - C:\Users\Ricardo\AppData\Roaming\FAC\TheNewZ\FacSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google Inc. - C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.119\elevation_service.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Heroes & Generals Steam Service (HnGSteamService) - Reto-Moto ApS - C:\Program Files (x86)\Steam\steamapps\common\Heroes & Generals\hngservice.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxCUIService.exe
O23 - Service: @oem29.inf,%ImcSvcDisplayName%;System Interface Foundation Service (ImControllerService) - Lenovo Group Ltd. - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: klvssbridge64_18.0.0 - Unknown owner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\vssbridge64.exe (file missing)
O23 - Service: klvssbridge64_19.0.0 - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\x64\vssbridge64.exe
O23 - Service: Serviço do Kaspersky Secure Connection 3.0.0 (KSDE3.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: Qualcomm Atheros WLAN Driver Service (QcomWlanSrv) - Unknown owner - C:\Windows\System32\drivers\QcomWlanSrvx64.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\Windows\system32\SgrmBroker.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 13 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\Windows\system32\xbgmsvc.exe (file missing)

--
End of file - 10110 bytes
 

Compartilhar este post


Link para o post
Compartilhar em outros sites

Download Malwarebytes Anti-Malware (MBAM) e salve ou imprima estas instruções:

Execute o mb3-setup.exe para instalar o programa.

Desmarque a caixa Ativar trial gratuito do MalwareBytes Anti-Malware PRO (se houver).

Verifique se as caixas Atualizar Malwarebytes Anti-Malware e Executar Malwarebytes Anti-Malware estão marcadas. Clique então, em Concluir.

Se houver atualizações a serem feitas, serão baixadas e instaladas.

Em Configurações, clique em Proteção, caso esteja desabilitado, marque Procura por Rootkits. Em Proteção contra ameaça em potencial, selecione Tratar PUPs e PUMs como Malware (recomendado).

Clique em Análise, em seguida Análise de Ameaça, por fim, clique em Iniciar Análise.

Começará então o exame. Aguarde, pois pode demorar.

Ao acabar o exame, se houver itens encontrados, clique no botão Exportar Resumo -> Arquivo texto (*.txt) e salve-o na sua Área de Trabalho (Desktop), se o Log da desinfecção não for salvo você  vai encontra-lo ali.

Clique em Aplicar Ações ou se não houver, clique em Enviar para a quarentena.

Ao final da desinfecção, poderá aparecer um aviso se quer reiniciar o PC.

O Log é automaticamente salvo pelo MBAM e será possível vê-lo clicando na aba Relatórios -> Relatórios de análise na Janela Principal do Programa após a desinfecção ter sido realizada.

NÃO USE O FORMATO ARQUIVO .XML PARA SALVAR O LOG.

Selecione, copie e cole todo o conteúdo do Log da desinfecção salvo pelo MBAM, na sua próxima resposta  e um novo Log do HijackThis.

NOTA: Se o MBAM encontrar arquivos que não consiga remover, poderá ter de reiniciar o PC (talvez mais de uma vez). Faça isso imediatamente, ao ser perguntado se quer reiniciar o PC.


assinatura-mrmillion.png65301516_windows-insider-mvp-logo(Custom).png.36263cb7b506cc6935fb37f39e504cec.png

Compartilhar este post


Link para o post
Compartilhar em outros sites

Malwarebytes
www.malwarebytes.com

-Detalhes de registro-
Data da análise: 28/02/2019
Hora da análise: 08:15
Arquivo de registro: 27e6e744-3b4a-11e9-a917-641c678a2a57.json

-Informação do software-
Versão: 3.7.1.2839
Versão de componentes: 1.0.538
Versão do pacote de definições: 1.0.9482
Licença: Versão de Avaliação

-Informação do sistema-
Sistema operacional: Windows 10 (Build 17134.590)
CPU: x64
Sistema de arquivos: NTFS
Usuário: LAPTOP-6HPVMJGD\Ricardo

-Resumo da análise-
Tipo de análise: Análise de Ameaças
Análise Iniciada Por: Manual
Resultado: Concluído
Objetos verificados: 329232
Ameaças detectadas: 191
Ameaças em quarentena: 191
Tempo decorrido: 10 min, 21 seg

-Opções da análise-
Memória: Habilitado
Inicialização: Habilitado
Sistema de arquivos: Habilitado
Arquivos compactados: Habilitado
Rootkits: Habilitado
Heurística: Habilitado
PUP: Detectar
PUM: Detectar

-Detalhes da análise-
Processo: 0
(Nenhum item malicioso detectado)

Módulo: 0
(Nenhum item malicioso detectado)

Chave de registro: 0
(Nenhum item malicioso detectado)

Valor de registro: 1
PUP.Optional.SearchManager.BITSRST, HKU\S-1-5-21-3989824072-2803591782-1867561148-1002\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|pilplloabdedfmialnfchjomjmpjcoej, Quarentena, [266], [626738],1.0.9482

Dados de registro: 0
(Nenhum item malicioso detectado)

Fluxo de dados: 0
(Nenhum item malicioso detectado)

Pasta: 22
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\converter, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\icons, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\tiles, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\maps, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_locales\pt_BR, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\fonts, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_locales\en, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_locales\fr, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_locales\hi, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_locales\vi, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\skin\icons, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_metadata, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_locales, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\vendor, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\skin, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\USERS\USUARIO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej, Quarentena, [266], [626738],1.0.9482

Arquivo: 168
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\fonts\HelveticaNeue-Thin.otf, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\fonts\HelveticaNeueLT-Roman.woff, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\fonts\neue-bold.woff, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\fonts\neue.woff, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\converter\close-FF8A5A.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\converter\collection-9B9B9B.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\converter\collection-FF691E.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\converter\doc-icon-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\converter\error-FF691E.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\converter\pdf-2-doc-9B9B9B.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\converter\pdf-2-doc-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\converter\pdf-icon-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\converter\success-FF8A5A.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\converter\tab-arrow-FF691E.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\converter\upload-FF691E.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\amazon-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\amazon.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\close.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\enlarge-000000-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\enlarge-FFCA00-000000.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\hulu-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\hulu.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\minimize-000000-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\netflix-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\netflix.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\refresh-FFFFFF-000000.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\shrink-FFCA00-000000.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\shuffle-000000.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\shuffle-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\vudu-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films\vudu.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\icons\128.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\icons\16.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\icons\48.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\icons\close.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\icons\favicon.ico, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\icons\trends.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\maps\bing-maps-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\maps\from-to-icon-8881FF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\maps\google-maps-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\maps\location-icon-8881FF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\maps\search-4A4A4A.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\maps\search-8881FF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\maps\switch-8881FF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\maps\tab-arrow-8881FF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\maps\whereto-logo-8881FF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\maps\whereto-logo-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\facebook_tile_v2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\aliexpress.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\aliexpress_tile_v2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\amazon.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\amazon_tile_v2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\booking.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\booking_tile_v2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\ebay.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\ebay_tile_v2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\expedia.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\expedia_tile_v2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\facebook.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\gmail.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\gmail_tile_v2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\google-translate-icon-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\gtranslte.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\pinterest.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\pinterest_tile_v2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\twitter.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\twitter_tile_v2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\wix.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\wix_tile_v2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\yahoo.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\yahoo_tile_v2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\YouTube.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sitesThumbnails\youtube_tile_v2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\tiles\DOC-to-PDF.jpg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\tiles\PDF-to-DOC.jpg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\tiles\Translation.jpg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\tiles\View-PDF.jpg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\01d.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\01n.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\02d.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\02n.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\03d.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\03n.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\04d.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\04n.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\09d.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\09n.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\10d.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\10n.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\11d.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\11n.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\13d.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\13n.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\50d.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\weather\50n.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\down.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\alot.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\angle-arrow-down.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\bing.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\bing_large.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\bluesky-bg.jpg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\brush.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\bt.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\clock.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\cloud.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\cupcake-bg.jpg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\desk-bg.jpg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\doodle.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\enhanced_google.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\eyeglass.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\eyeglass_transparent.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\films-bg.jpg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\gmx_large.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\google.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\google_large.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\hero-bg.jpg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\just-the-box-empty.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\just-the-box.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\mountain-bg.jpg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\pointer2.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\radio-selected.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\radio-unselected.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\sea-bg.jpg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\search-D7D7D7.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\search-FFFFFF.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\settings.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\smallMagnifier.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\star-unselected.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\star.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\todoc.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\toggle-off.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\toggle-on.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\topdf.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\transparent_img.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\yahoo.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\yahoo.svg, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\yahoo_large.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\yandex.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\_enhanced_google.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\images\_gmx_large.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\content\bundle.v0.0.1.min.css, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\skin\icons\16.png, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\vendor\md5.min.js, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\vendor\react-dom.min.js, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\vendor\react-with-addons.min.js, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_locales\en\messages.json, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_locales\fr\messages.json, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_locales\hi\messages.json, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_locales\pt_BR\messages.json, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_locales\vi\messages.json, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\_metadata\verified_contents.json, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\2bfc185be71f44cd73ac81511fc1f5a5.woff, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\b495e340f4ef8924fea0284c1bf9e7ac.woff, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\background.html, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\background.v0.0.1.min.js, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\c5a5cbf4dbcaa7064f2bc77f52101aec.otf, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\client.v0.0.1.min.js, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\common.js.v0.0.1.min.js, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\e5d3501d500d07b0a1e952b0f8a81d78.woff, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\e_.json, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\index.html, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\manifest.json, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\popupTab2.html, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.55_0\responseConfig.json, Quarentena, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\USERS\USUARIO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Substituído, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\USERS\USUARIO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Substituído, [266], [626738],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\USERS\USUARIO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Substituído, [266], [626729],1.0.9482
PUP.Optional.SearchManager.BITSRST, C:\USERS\USUARIO\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Substituído, [266], [626729],1.0.9482

Setor físico: 0
(Nenhum item malicioso detectado)

Instrumentação do Windows (WMI): 0
(Nenhum item malicioso detectado)


(end)

 

 

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 08:41:08, on 28/02/2019
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.17134.0001)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\avpui.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksdeui.exe
C:\Users\Ricardo\Downloads\HijackThis.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.CompanionApp.exe
C:\Program Files (x86)\Lenovo\iMController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo17win10.msn.com/?PC=LCTE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo17win10.msn.com/?PC=LCTE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: ScriptInjectionPluginBrowserHelperObject - {EC1E29BB-F56A-45D8-B023-D3EF710FA0E0} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\IEExt\ie_plugin.dll
O3 - Toolbar: Kaspersky Protection Toolbar - {C500C267-63BF-451F-8797-4D720C9A2ED9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\IEExt\ie_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Ricardo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-21-3989824072-2803591782-1867561148-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02282019083525134\..\Run: [OneDrive] "C:\Users\Ricardo\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background (User '?')
O4 - HKUS\S-1-5-21-3989824072-2803591782-1867561148-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02282019083525134\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent (User '?')
O4 - HKUS\S-1-5-21-3989824072-2803591782-1867561148-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02282019083525134\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart (User '?')
O4 - HKUS\S-1-5-21-3989824072-2803591782-1867561148-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-02282019083525134\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR (User '?')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: Windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Intel® SGX AESM (AESMService) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_1781f8bae8fdf5c0\aesm_service.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Unknown owner - C:\Windows\system32\DRIVERS\AdminService.exe (file missing)
O23 - Service: Serviço do Kaspersky Anti-Virus 19.0.0 (AVP19.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\avp.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Dolby DAX2 API Service - Dolby Laboratories, Inc. - C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: Fredaikis Anti-Cheat: TheNewZ (FacSvc_TheNewZ) - Unknown owner - C:\Users\Ricardo\AppData\Roaming\FAC\TheNewZ\FacSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google Inc. - C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.119\elevation_service.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Heroes & Generals Steam Service (HnGSteamService) - Reto-Moto ApS - C:\Program Files (x86)\Steam\steamapps\common\Heroes & Generals\hngservice.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_1a33d2f73651d989\igfxCUIService.exe
O23 - Service: @oem29.inf,%ImcSvcDisplayName%;System Interface Foundation Service (ImControllerService) - Lenovo Group Ltd. - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: klvssbridge64_18.0.0 - Unknown owner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\x64\vssbridge64.exe (file missing)
O23 - Service: klvssbridge64_19.0.0 - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 19.0.0\x64\vssbridge64.exe
O23 - Service: Serviço do Kaspersky Secure Connection 3.0.0 (KSDE3.0.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 3.0\ksde.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: Qualcomm Atheros WLAN Driver Service (QcomWlanSrv) - Unknown owner - C:\Windows\System32\drivers\QcomWlanSrvx64.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\Windows\system32\SgrmBroker.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 13 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\Windows\system32\xbgmsvc.exe (file missing)

--
End of file - 11132 bytes
 

Compartilhar este post


Link para o post
Compartilhar em outros sites

Desative temporariamente seu Antivírus.

Clique em esetsmartinstaller_enu.exe para baixar o ESET Smart Installer. Salve-o em seu Desktop (Área de Trabalho).

Dê um duplo clique no seu ícone no Desktop.

Marque "YES, I accept the Terms of Use." Clique em Start.

Aceite qualquer Aviso de Segurança de seu Navegador

Marque as Opções abaixo:

Enable detection of potencially unwanted applications.

Clique em Hide advanced settings e marque:

Remove found threats

Scan archives

Scan for potentially unsafe applications

Enable Anti-Stealth technology 

Clique Change e marque também a caixa Computador.

Clique em Start.

Ele vai atualizar por conta própria, e escanear o Computador. Tenha paciência, o processo pode demorar horas. Quando o Scan terminar, clique em List Threats.

Clique em Export to text file e salve o Log na sua Área de Trabalho.

Copie e cole o conteúdo em sua próxima resposta.

Obs: Se nada for encontrado, nenhum Log será gerado.

Clique em Back.

Clique em Finish.


assinatura-mrmillion.png65301516_windows-insider-mvp-logo(Custom).png.36263cb7b506cc6935fb37f39e504cec.png

Compartilhar este post


Link para o post
Compartilhar em outros sites

C:\Users\Ricardo\Downloads\Net-Broadcom-Broadcom-NetXtreme-Gigabit-Ethernet.exe    a variant of Win32/InnovativeSolutions.B potentially unwanted application    cleaned by deleting
D:\Instaladores\BitTorrent.exe    a variant of MSIL/WebCompanion.A potentially unwanted application    cleaned by deleting
D:\Instaladores\UCBrowser_V7.0.6.1618_windows_pf101_(Build17092714).exe    a variant of Win32/Taobao.D potentially unwanted application    cleaned by deleting
 

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ok, o PC está limpo. (Y)  

Download  DelFix, e salve no seu Desktop (Área de Trabalho). Dê um duplo-clique no delfix.exe para executá-lo.
 
No Windows 7, 8 e 10: Clique com o direito sobre o delfix.exe e selecione Executar como Administrador
 
Marque a caixa conforme a imagem.abaixo

DellFix.jpg

Clique no botão Executar. Isso removerá os Programas usados na desinfecção, Pastas e Arquivos criados por eles e o próprio DelFix.


assinatura-mrmillion.png65301516_windows-insider-mvp-logo(Custom).png.36263cb7b506cc6935fb37f39e504cec.png

Compartilhar este post


Link para o post
Compartilhar em outros sites

Mr. Million, ainda não executei o DelFix pois o problema persistiu.

Vou rodar todas as ferramentas anteriormente sugeridas novamente, uma após a outra.

certificado.jpg

Compartilhar este post


Link para o post
Compartilhar em outros sites

×
×
  • Criar Novo...