Este fórum foi descontinuado. LEIA AQUI e participe da Comunidade BABOO :)

Ir para conteúdo
julianocgn

Notebook muito lento

Mensagem Recomendada

Olá.

Já fiz todos os procedimentos solicitados no Tópico Oficial.

O meu problema é que meu notebook está muito lento na inicialização e na utilização de programas. Acho que podem ser malwares..

Segue meu log para exame:

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 00:18:32, on 21/04/2019
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.19326)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avpui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\igfxEM.exe
C:\Windows\system32\igfxHK.exe
C:\Windows\system32\igfxTray.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\HP\HP Deskjet 4640 series\Bin\ScanToPCActivationApp.exe
C:\Program Files\Steam\Steam.exe
C:\Users\Uicaa\AppData\Roaming\uTorrent\uTorrent.exe
C:\Users\Uicaa\AppData\Roaming\uTorrent\updates\3.5.5_45146\utorrentie.exe
C:\Users\Uicaa\AppData\Roaming\uTorrent\updates\3.5.5_45146\utorrentie.exe
C:\Program Files\Steam\bin\cef\cef.Windows 7\steamwebhelper.exe
C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksdeui.exe
C:\Program Files\Steam\bin\cef\cef.Windows 7\steamwebhelper.exe
C:\Program Files\Steam\bin\cef\cef.Windows 7\steamwebhelper.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\SwReporter\39.195.200.3\software_reporter_tool.exe
c:\users\uicaa\appdata\local\google\chrome\user data\swreporter\39.195.200.3\software_reporter_tool.exe
c:\users\uicaa\appdata\local\google\chrome\user data\swreporter\39.195.200.3\software_reporter_tool.exe
c:\users\uicaa\appdata\local\google\chrome\user data\swreporter\39.195.200.3\software_reporter_tool.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\HP\HP Deskjet 4640 series\Bin\HPNetworkCommunicatorCom.exe
C:\Users\Uicaa\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: ScriptInjectionPluginBrowserHelperObject - {2E38825B-8815-42CF-9126-C58BC28D4591} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O3 - Toolbar: Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 17.0.0\IEExt\ie_plugin.dll
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [HP Deskjet 4640 series (NET)] "C:\Program Files\HP\HP Deskjet 4640 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN45S3B0VF05Z4:NW" -scfn "HP Deskjet 4640 series (NET)" -AutoStart 1
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Uicaa\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO DE REDE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO DE REDE')
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Serviço do Kaspersky Anti-Virus 17.0.0 (AVP17.0.0) - AO Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe
O23 - Service: COM+ Leg Service (COMLegService) - Unknown owner - C:\Program Files\Legendas-3.7\srvlegendas.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\system32\IntelCpHeciSvc.exe
O23 - Service: Foxit Cloud Safe Update Service (FoxitCloudUpdateService) - Foxit Software Inc. - C:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google Inc. - C:\Program Files\Google\Chrome\Application\73.0.3683.103\elevation_service.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Intel Corporation - C:\Windows\system32\igfxCUIService.exe
O23 - Service: Serviço do Kaspersky Secure Connection 2.0.0 (KSDE2.0.0) - AO Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe
O23 - Service: Mobile Broadband HL Service - Unknown owner - C:\ProgramData\MobileBrServ\mbbservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe

--
End of file - 8217 bytes


Juliano

Compartilhar este post


Link para o post
Compartilhar em outros sites

Fiz o procedimento e não senti diferença.

Outro problema que esqueci de mencionar é que às vezes aparecem aqueles anúncios chatos no navegador.


Juliano

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixe o ZHPCleaner e salve no Desktop. (Área de Trabalho)

Usuários do Windows 7, 8, 8.1 ou 10: clique com o botão direito do mouse no ícone do Programa e selecione  executar-como-administrador.png

Dê um duplo-clique sobre o ZHPCleaner.exe.

Clique no botão Scanner.

A Ferramenta comecará o exame do seu Sistema. Tenha paciência pois pode demorar um pouco dependendo da quantidades de itens a examinar.

Ao final da Verificação, clique no botão Reparar.

Concluída a operação, um Log se abrirá. Caso isso não aconteça, clique no botão Relatório e salve o Log.

Selecione, copie e cole o conteúdo deste Log na sua próxima resposta + um novo Log do HijackThis.


assinatura-mrmillion.png65301516_windows-insider-mvp-logo(Custom).png.36263cb7b506cc6935fb37f39e504cec.png

Compartilhar este post


Link para o post
Compartilhar em outros sites

~ ZHPCleaner v2019.4.21.51 by Nicolas Coolman (2019/04/21)
~ Run by Uicaa (Administrator)  (24/04/2019 20:50:35)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Certificate ZHPCleaner: Legal
~ Type : Repair
~ Report : C:\Users\Uicaa\Desktop\ZHPCleaner (R).txt
~ Quarantine : C:\Users\Uicaa\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 7 Ultimate, 32-bit Service Pack 1 (Build 7601)


---\\  Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\  Services (0)
~ No malicious or unnecessary items found.


---\\  Browser internet (33)
DELETED Firefox: [dlsyaoqs.default] URL HomePage : http://home.tb.ask.com/index.jhtml?n=781c5002   =>Toolbar.Ask
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.homepage.savedPrev", "true");  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.homepage.tb", "http://home.tb.as[...]  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.page.savedPrev", 1);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.browser.startup.page.tb", 1);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.browser.version.last", "56.0");  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.competitorDNS", "{\"comment\":\"refresh every 1 [...]  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.firstKnownVersion", "7.38.8.46590");  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.homepage", "http://home.tb.ask.com/index.jhtml?n[...]  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.hp.enabled", true);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.hp.guardType", "HPR");  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.hp.user.defined", false);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.initialized", true);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.installation.dlpCountryCode", "BR");  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.installation.installDate", "2015121410");  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.installation.success", true);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.lastActivePing", "1530186913162");  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.lastKnownVersion", "7.38.8.46590");  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.lssState", "{\"previousLocales\":[\"pt-BR\",\"pt[...]  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.options.defaultSearch", false);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.options.homePageEnabled", false);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.options.keywordEnabled", false);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.options.tabEnabled", false);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.productDeliveryOption.language", "en");  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.productDeliveryOption.type", "Toolbar");  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.startupTasks", "{}");  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.successUrl", "http://productivityboss.dl.tb.ask.[...]  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.toolbar.versionChanged", false);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.toolbarCollapsed", true);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark._e5Members_.uninstallTasks", "{\"prefBranchesToDelete\":[\"e[...]  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark.hp.enabled", true);  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "productivityboss@mindspark.com");  =>Adware.Bandoo
DELETED: [dlsyaoqs.default] - user_pref("extensions.toolbar.mindspark.lastInstalled", "productivityboss@mindspark.com");  =>Adware.Bandoo


---\\  Hosts file (1)
~ The hosts file is legitimate (21)


---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\  Explorer ( File, Folder) (15)
MOVED file: C:\Users\Uicaa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\µTorrent.lnk  [Bad : C:\Users\Uicaa\AppData\Roaming\uTorrent\uTorrent.exe](.BitTorrent Inc..)  =>BitTorrent (P2P)
MOVED file: C:\Users\Uicaa\AppData\Roaming\Mozilla\Firefox\Profiles\dlsyaoqs.default\Extensions\_e5Members_@www.productivityboss.com\bootstrap.js    =>.SUP.ProductivityBoss
MOVED file^: C:\Users\Uicaa\AppData\Roaming\Mozilla\Firefox\Profiles\dlsyaoqs.default\Extensions\_e5Members_@www.productivityboss.com\chrome    =>.SUP.ProductivityBoss
MOVED file: C:\Users\Uicaa\AppData\Roaming\Mozilla\Firefox\Profiles\dlsyaoqs.default\Extensions\_e5Members_@www.productivityboss.com\chrome.manifest    =>.SUP.ProductivityBoss
MOVED file: C:\Users\Uicaa\AppData\Roaming\Mozilla\Firefox\Profiles\dlsyaoqs.default\Extensions\_e5Members_@www.productivityboss.com\chrome.manifest.restartless    =>.SUP.ProductivityBoss
MOVED file: C:\Users\Uicaa\AppData\Roaming\Mozilla\Firefox\Profiles\dlsyaoqs.default\Extensions\_e5Members_@www.productivityboss.com\install.rdf    =>.SUP.ProductivityBoss
MOVED file^: C:\Users\Uicaa\AppData\Roaming\Mozilla\Firefox\Profiles\dlsyaoqs.default\Extensions\_e5Members_@www.productivityboss.com\META-INF    =>.SUP.ProductivityBoss
MOVED file: C:\Users\Uicaa\AppData\Roaming\Mozilla\Firefox\Profiles\dlsyaoqs.default\ProductivityBoss_e5\A7BA2918-5852-482A-863B-DFE2FC17E115.sqlite    =>.SUP.ProductivityBoss
MOVED file: C:\Users\Uicaa\AppData\Roaming\Mozilla\Firefox\Profiles\dlsyaoqs.default\ProductivityBoss_e5\STUB.sqlite    =>.SUP.ProductivityBoss
MOVED file: C:\Users\Uicaa\Downloads\antimalwaresetup.exe [Plumbytes Software - Plumbytes Anti-Malware]  =>.SUP.Plumbytes
MOVED file: C:\Users\Uicaa\Downloads\Superdownloads_utorrent-utorrent-mtorrent [1].exe [BitTorrent Inc. - µTorrent]  =>BitTorrent (P2P)
MOVED file: C:\Users\Uicaa\AppData\Local\Temp\~DFCD4B0760D75F3F6F.TMP    =>.SUP.Temporary.Other
MOVED folder: C:\Users\Uicaa\AppData\Roaming\Mozilla\Firefox\Profiles\dlsyaoqs.default\Extensions\_e5Members_@www.productivityboss.com  =>.SUP.ProductivityBoss
MOVED folder: C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\File System\000  =>.SUP.Temporary.Chrome
MOVED folder: C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\File System\001  =>.SUP.Temporary.Chrome


---\\  Registry ( Key, Value, Data) (5)
DELETED key*: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\uTorrent [BitTorrent Inc.]  =>BitTorrent (P2P)
DELETED key*: HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} [ITool]  =>Toolbar.Ask
DELETED value: HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Users\Uicaa\AppData\Local\Temp\HPDiagnosticAlert\ [No Folder]  =>.SUP.Obsolete.NoFolder
DELETED value: HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE1.0.0\ [No Folder]  =>.SUP.Obsolete.NoFolder
DELETED value: HKLM64\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\ProgramData\Kaspersky Lab\KSDE1.0.0\Temp\ [No Folder]  =>.SUP.Obsolete.NoFolder


---\\  Summary of the elements found (8)
https://nicolascoolman.eu/2017/02/28/toolbar-ask/  =>Toolbar.Ask
https://nicolascoolman.eu/2017/02/23/adware-bandoo/  =>Adware.Bandoo
https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/  =>BitTorrent (P2P)
https://nicolascoolman.eu/2017/11/18/sup-productivityboss/  =>.SUP.ProductivityBoss
https://nicolascoolman.eu/2017/09/09/sup-plumbytes/  =>.SUP.Plumbytes
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Temporary.Other
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Temporary.Chrome
https://nicolascoolman.eu/2017/01/20/logiciels-superflus/  =>.SUP.Obsolete.NoFolder


---\\  Other deletions. (29)
~ Registry Keys Tracing deleted (29)
~ Remove the old reports ZHPCleaner. (0)


---\\ Result of repair
~ Repair carried out successfully
~ Browser not found (Opera Software)
~ The system has been restarted.


---\\ Statistics
~ Items scanned : 1129
~ Items found : 0
~ Items cancelled : 0
~ Items options : 12/12
~ Space saving (bytes) : 114688


~ End of clean in 00h00mn30s

---\\  Reports (2)
ZHPCleaner--24042019-20_48_15.txt
ZHPCleaner-[R]-24042019-20_51_05.txt
 

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:54:39, on 24/04/2019
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.19326)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\HP\HP Deskjet 4640 series\Bin\ScanToPCActivationApp.exe
C:\Program Files\Steam\Steam.exe
C:\Users\Uicaa\AppData\Roaming\uTorrent\uTorrent.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Users\Uicaa\AppData\Roaming\uTorrent\updates\3.5.5_45146\utorrentie.exe
C:\Users\Uicaa\AppData\Roaming\uTorrent\updates\3.5.5_45146\utorrentie.exe
C:\Windows\system32\igfxEM.exe
C:\Windows\system32\igfxHK.exe
C:\Windows\system32\igfxTray.exe
C:\Program Files\Steam\bin\cef\cef.Windows 7\steamwebhelper.exe
C:\Program Files\Steam\bin\cef\cef.Windows 7\steamwebhelper.exe
C:\Program Files\Steam\bin\cef\cef.Windows 7\steamwebhelper.exe
C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksdeui.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Uicaa\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\RunOnce: [ZHPCleaner_File1] CMD /c DEL "C:\Users\Uicaa\AppData\Roaming\Mozilla\Firefox\Profiles\dlsyaoqs.default\Extensions\_e5Members_@www.productivityboss.com\chrome" /F /Q
O4 - HKLM\..\RunOnce: [ZHPCleaner_File2] CMD /c DEL "C:\Users\Uicaa\AppData\Roaming\Mozilla\Firefox\Profiles\dlsyaoqs.default\Extensions\_e5Members_@www.productivityboss.com\META-INF" /F /Q
O4 - HKLM\..\RunOnce: [ZHPCleaner] Notepad C:\Users\Uicaa\AppData\Roaming\ZHP\ZHPCleaner.txt
O4 - HKCU\..\Run: [HP Deskjet 4640 series (NET)] "C:\Program Files\HP\HP Deskjet 4640 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN45S3B0VF05Z4:NW" -scfn "HP Deskjet 4640 series (NET)" -AutoStart 1
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Uicaa\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO DE REDE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO DE REDE')
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: COM+ Leg Service (COMLegService) - Unknown owner - C:\Program Files\Legendas-3.7\srvlegendas.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\system32\IntelCpHeciSvc.exe
O23 - Service: Foxit Cloud Safe Update Service (FoxitCloudUpdateService) - Foxit Software Inc. - C:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google Inc. - C:\Program Files\Google\Chrome\Application\73.0.3683.103\elevation_service.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Intel Corporation - C:\Windows\system32\igfxCUIService.exe
O23 - Service: Serviço do Kaspersky Secure Connection 2.0.0 (KSDE2.0.0) - AO Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe
O23 - Service: Mobile Broadband HL Service - Unknown owner - C:\ProgramData\MobileBrServ\mbbservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe

--
End of file - 7722 bytes


Juliano

Compartilhar este post


Link para o post
Compartilhar em outros sites

Download Malwarebytes Anti-Malware (MBAM) e salve ou imprima estas instruções:

Execute o mb3-setup.exe para instalar o programa.

Desmarque a caixa Ativar trial gratuito do MalwareBytes Anti-Malware PRO (se houver).

Verifique se as caixas Atualizar Malwarebytes Anti-Malware e Executar Malwarebytes Anti-Malware estão marcadas. Clique então, em Concluir.

Se houver atualizações a serem feitas, serão baixadas e instaladas.

Em Configurações, clique em Proteção, caso esteja desabilitado, marque Procura por Rootkits. Em Proteção contra ameaça em potencial, selecione Tratar PUPs e PUMs como Malware (recomendado).

Clique em Análise, em seguida Análise de Ameaça, por fim, clique em Iniciar Análise.

Começará então o exame. Aguarde, pois pode demorar.

Ao acabar o exame, se houver itens encontrados, clique no botão Exportar Resumo -> Arquivo texto (*.txt) e salve-o na sua Área de Trabalho (Desktop), se o Log da desinfecção não for salvo você  vai encontra-lo ali.

Clique em Aplicar Ações ou se não houver, clique em Enviar para a quarentena.

Ao final da desinfecção, poderá aparecer um aviso se quer reiniciar o PC.

O Log é automaticamente salvo pelo MBAM e será possível vê-lo clicando na aba Relatórios -> Relatórios de análise na Janela Principal do Programa após a desinfecção ter sido realizada.

NÃO USE O FORMATO ARQUIVO .XML PARA SALVAR O LOG.

Selecione, copie e cole todo o conteúdo do Log da desinfecção salvo pelo MBAM, na sua próxima resposta  e um novo Log do HijackThis.

NOTA: Se o MBAM encontrar arquivos que não consiga remover, poderá ter de reiniciar o PC (talvez mais de uma vez). Faça isso imediatamente, ao ser perguntado se quer reiniciar o PC.


assinatura-mrmillion.png65301516_windows-insider-mvp-logo(Custom).png.36263cb7b506cc6935fb37f39e504cec.png

Compartilhar este post


Link para o post
Compartilhar em outros sites

Malwarebytes
www.malwarebytes.com

-Detalhes de registro-
Data da análise: 27/04/2019
Hora da análise: 01:28
Arquivo de registro: e8026076-68a4-11e9-abb1-00ffc78637c8.json

-Informação do software-
Versão: 3.7.1.2839
Versão de componentes: 1.0.586
Versão do pacote de definições: 1.0.10360
Licença: Versão de Avaliação

-Informação do sistema-
Sistema operacional: Windows 7 Service Pack 1
CPU: x86
Sistema de arquivos: NTFS
Usuário: Uicaa-PC\Uicaa

-Resumo da análise-
Tipo de análise: Análise de Ameaças
Análise Iniciada Por: Manual
Resultado: Concluído
Objetos verificados: 166279
Ameaças detectadas: 65
Ameaças em quarentena: 0
Tempo decorrido: 9 min, 38 seg

-Opções da análise-
Memória: Habilitado
Inicialização: Habilitado
Sistema de arquivos: Habilitado
Arquivos compactados: Habilitado
Rootkits: Habilitado
Heurística: Habilitado
PUP: Detectar
PUM: Detectar

-Detalhes da análise-
Processo: 0
(Nenhum item malicioso detectado)

Módulo: 0
(Nenhum item malicioso detectado)

Chave de registro: 0
(Nenhum item malicioso detectado)

Valor de registro: 1
PUP.Optional.MindSpark.Generic, HKU\S-1-5-21-3642303166-1503609442-2024683328-1000\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|hhaalpeklfijljphgfkgppokkijcbpga, Nenhuma ação do usuário, [1749], [443121],1.0.10360

Dados de registro: 0
(Nenhum item malicioso detectado)

Fluxo de dados: 0
(Nenhum item malicioso detectado)

Pasta: 9
PUP.Optional.MindSpark.Generic, C:\USERS\UICAA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Local Extension Settings\hhaalpeklfijljphgfkgppokkijcbpga, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\_locales\en, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\_metadata, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\_locales, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\config, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\icons, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\USERS\UICAA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\HHAALPEKLFIJLJPHGFKGPPOKKIJCBPGA, Nenhuma ação do usuário, [1749], [443121],1.0.10360

Arquivo: 55
PUP.Optional.MindSpark, C:\USERS\UICAA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DLSYAOQS.DEFAULT\SEARCHPLUGINS\ASK-WEB-SEARCH.XML, Nenhuma ação do usuário, [627], [240303],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhaalpeklfijljphgfkgppokkijcbpga\000003.log, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhaalpeklfijljphgfkgppokkijcbpga\CURRENT, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhaalpeklfijljphgfkgppokkijcbpga\LOCK, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhaalpeklfijljphgfkgppokkijcbpga\LOG, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhaalpeklfijljphgfkgppokkijcbpga\LOG.old, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hhaalpeklfijljphgfkgppokkijcbpga\MANIFEST-000001, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\USERS\UICAA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\USERS\UICAA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\USERS\UICAA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\HHAALPEKLFIJLJPHGFKGPPOKKIJCBPGA\13.870.15.8329_0\MANIFEST.JSON, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\config\config.json, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\icons\icon128.png, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\icons\icon16.png, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\icons\icon19disabled.png, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\icons\icon19on.png, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\icons\icon48.png, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\meta.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\ajax.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\babAPI.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\babClickHandler.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\babContentScript.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\babContentScriptAPI.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\background.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\browserUtils.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\chrome.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\contentScriptConnectionManager.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\dateTimeUtils.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\dlp.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360

PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\dlpHelper.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\extensionDetect.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\index.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\localStorageContentScript.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\logger.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\offerService.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\pageUtils.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\PartnerId.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\polyfill.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\product.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\remoteConfigLoader.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\splashPageLocalStorageSetter.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\splashPageRedirectHandler.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\storageUtils.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\TemplateParser.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\ul.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\urlFragmentActions.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\urlUtils.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\util.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\webtooltabAPI.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\js\webTooltabAPIProxy.js, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\_locales\en\messages.json, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\_metadata\verified_contents.json, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.MindSpark.Generic, C:\Users\Uicaa\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhaalpeklfijljphgfkgppokkijcbpga\13.870.15.8329_0\newtabpage.html, Nenhuma ação do usuário, [1749], [443121],1.0.10360
PUP.Optional.OpenCandy, C:\USERS\UICAA\DOWNLOADS\PHOTOSCAPE-3-7-MULTI-WIN.EXE, Nenhuma ação do usuário, [1146], [297667],1.0.10360
Adware.InstallCore, C:\USERS\UICAA\DOWNLOADS\SUPERDOWNLOADS_UTORRENT-UTORRENT-MTORRENT.EXE, Nenhuma ação do usuário, [436], [615405],1.0.10360
Generic.Malware/Suspicious, C:\USERS\UICAA\DOWNLOADS\PHOTOSCAPE-3-7-MULTI-WIN.EXE, Nenhuma ação do usuário, [0], [392686],1.0.10360

Setor físico: 0
(Nenhum item malicioso detectado)

Instrumentação do Windows (WMI): 0
(Nenhum item malicioso detectado)


(end)

 

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 02:27:00, on 27/04/2019
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.19326)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\igfxEM.exe
C:\Windows\system32\igfxHK.exe
C:\Windows\system32\igfxTray.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files\HP\HP Software Update\hpwuschd2.exe
C:\Program Files\HP\HP Deskjet 4640 series\Bin\ScanToPCActivationApp.exe
C:\Program Files\Steam\Steam.exe
C:\Users\Uicaa\AppData\Roaming\uTorrent\uTorrent.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Users\Uicaa\AppData\Roaming\uTorrent\updates\3.5.5_45146\utorrentie.exe
C:\Users\Uicaa\AppData\Roaming\uTorrent\updates\3.5.5_45146\utorrentie.exe
C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksdeui.exe
C:\Program Files\Steam\bin\cef\cef.Windows 7\steamwebhelper.exe
C:\Program Files\Steam\bin\cef\cef.Windows 7\steamwebhelper.exe
C:\Program Files\Steam\bin\cef\cef.Windows 7\steamwebhelper.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Uicaa\Desktop\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\HP\HP Deskjet 4640 series\Bin\HPNetworkCommunicatorCom.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [HP Deskjet 4640 series (NET)] "C:\Program Files\HP\HP Deskjet 4640 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN45S3B0VF05Z4:NW" -scfn "HP Deskjet 4640 series (NET)" -AutoStart 1
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Uicaa\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVIÇO DE REDE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVIÇO DE REDE')
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: COM+ Leg Service (COMLegService) - Unknown owner - C:\Program Files\Legendas-3.7\srvlegendas.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\system32\IntelCpHeciSvc.exe
O23 - Service: Foxit Cloud Safe Update Service (FoxitCloudUpdateService) - Foxit Software Inc. - C:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google Inc. - C:\Program Files\Google\Chrome\Application\73.0.3683.103\elevation_service.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Intel Corporation - C:\Windows\system32\igfxCUIService.exe
O23 - Service: Serviço do Kaspersky Secure Connection 2.0.0 (KSDE2.0.0) - AO Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: Mobile Broadband HL Service - Unknown owner - C:\ProgramData\MobileBrServ\mbbservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer\TeamViewer_Service.exe

--
End of file - 7617 bytes


Juliano

Compartilhar este post


Link para o post
Compartilhar em outros sites

Desative temporariamente seu Antivírus.

Clique em esetsmartinstaller_enu.exe para baixar o ESET Smart Installer. Salve-o em seu Desktop (Área de Trabalho).

Dê um duplo clique no seu ícone no Desktop.

Marque "YES, I accept the Terms of Use." Clique em Start.

Aceite qualquer Aviso de Segurança de seu Navegador

Marque as Opções abaixo:

Enable detection of potencially unwanted applications.

Clique em Hide advanced settings e marque:

Remove found threats

Scan archives

Scan for potentially unsafe applications

Enable Anti-Stealth technology 

Clique Change e marque também a caixa Computador.

Clique em Start.

Ele vai atualizar por conta própria, e escanear o Computador. Tenha paciência, o processo pode demorar horas. Quando o Scan terminar, clique em List Threats.

Clique em Export to text file e salve o Log na sua Área de Trabalho.

Copie e cole o conteúdo em sua próxima resposta.

Obs: Se nada for encontrado, nenhum Log será gerado.

Clique em Back.

Clique em Finish.


assinatura-mrmillion.png65301516_windows-insider-mvp-logo(Custom).png.36263cb7b506cc6935fb37f39e504cec.png

Compartilhar este post


Link para o post
Compartilhar em outros sites

C:\Program Files\Easeware\DriverEasy\DriverEasy.exe    a variant of MSIL/DriverNavigator.A potentially unwanted application    cleaned by deleting
C:\Program Files\Legendas-3.7\nfregdrv.exe    Win32/RiskWare.NetFilter.V application    cleaned by deleting
C:\Users\Uicaa\AppData\Roaming\ZHP\Quarantine\ZHPCleaner\antimalwaresetup.exe    a variant of Win32/SafeBytes.A potentially unwanted application    cleaned by deleting
C:\Users\Uicaa\AppData\Roaming\ZHP\Quarantine\ZHPCleaner\bootstrap.js    JS/Mindspark.D potentially unwanted application    cleaned by deleting
C:\Users\Uicaa\AppData\Roaming\ZHP\Quarantine\ZHPCleaner\ffxtbr.jar    JS/Mindspark.B potentially unwanted application    deleted
C:\Users\Uicaa\AppData\Roaming\ZHP\Quarantine\ZHPCleaner\Superdownloads_utorrent-utorrent-mtorrent [1].exe    a variant of MSIL/WebCompanion.A potentially unwanted application    cleaned by deleting
C:\Users\Uicaa\Downloads\Legendas37.exe    multiple threats    cleaned by deleting
C:\Users\Uicaa\Downloads\Legendas37.zip    multiple threats    deleted
C:\Users\Uicaa\Downloads\Não confirmado 351434.crdownload    a variant of Win32/TrojanDownloader.Agent.EIM trojan    deleted
C:\Windows\AutoKMS.exe    MSIL/HackKMS.A potentially unsafe application    cleaned by deleting
C:\Windows\System32\drivers\legendasdrv.sys    a variant of Win32/NetFilter.A potentially unsafe application    cleaned by deleting
 


Juliano

Compartilhar este post


Link para o post
Compartilhar em outros sites
53 minutos atrás, julianocgn disse:

C:\Windows\AutoKMS.exe    MSIL/HackKMS.A potentially unsafe application    cleaned by deleting

Removendo o crack...

Ok, o PC está limpo. (Y)  

Download  DelFix, e salve no seu Desktop (Área de Trabalho). Dê um duplo-clique no delfix.exe para executá-lo.
 
No Windows 7, 8 e 10: Clique com o direito sobre o delfix.exe e selecione Executar como Administrador
 
Marque a caixa conforme a imagem.abaixo

DellFix.jpg

Clique no botão Executar. Isso removerá os Programas usados na desinfecção, Pastas e Arquivos criados por eles e o próprio DelFix.

 

 


assinatura-mrmillion.png65301516_windows-insider-mvp-logo(Custom).png.36263cb7b506cc6935fb37f39e504cec.png

Compartilhar este post


Link para o post
Compartilhar em outros sites

×
×
  • Criar Novo...