Fórum PC Brasil
Gostaria de reagir a esta mensagem? Crie uma conta em poucos cliques ou inicie sessão para continuar.
Flux RSS


Yahoo! 
MSN 
AOL 
Netvibes 
Bloglines 


Social bookmarking

Social bookmarking reddit      

Conservar e compartilhar o endereço de PC Seguro em seu site de social bookmarking

Conservar e compartilhar o endereço de Fórum PC Brasil em seu site de social bookmarking

Estatísticas
Temos 14807 usuários registrados
O último membro registrado é Costa24

Os nossos membros postaram um total de 36044 mensagens em 3685 assuntos
Últimos assuntos
» Problema no disco rígido do Windows 11
por Costa24 Hoje à(s) 10:19

Quem está conectado?
18 usuários online :: 0 registrados, 0 invisíveis e 18 visitantes

Nenhum

O recorde de usuários online foi de 301 em Ter 26 Out 2021, 15:28
Procurar
 
 

Resultados por:
 


Rechercher Pesquisa avançada

março 2024
SegTerQuaQuiSexSábDom
    123
45678910
11121314151617
18192021222324
25262728293031

Calendário Calendário


ganhei um notebook bichado

2 participantes

Página 2 de 2 Anterior  1, 2

Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por Silvana Alfredo Sex 28 Nov 2014, 09:37

Olá,

Não consigo fazer esse procedimento. Não abre o Zoek mesmo renomeado. Aparece mensagem do WinRar e msg de erro (final inesperado). Tentei várias vezes e não sei como resolver.
Silvana Alfredo
Silvana Alfredo
Membro
Membro

Mensagens : 58
Reputação : 1
Data de inscrição : 08/08/2014
Idade : 64
Localização : São Paulo

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por joram Sex 28 Nov 2014, 10:06

Silvana Alfredo escreveu:Olá,

Não consigo fazer esse procedimento. Não abre o Zoek mesmo renomeado. Aparece mensagem do WinRar e msg de erro (final inesperado). Tentei várias vezes e não sei como resolver.
/!\ Bom Dia! Silvana Alfredo /!\

> Se está ocorrendo a mensagem do WinRar,é porque vc baixou a Zoek errada e que necessita ser descompactada

> Baixe: < [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] > ( ... by OldTimer )

> Salve-o no desktop ou C:\.
> Duplo-clique em OTS.exe.
> Ps: Para Windows Vista ou 7,dê clique direito e execute OTS.exe como administrador.

[Tens de ter uma conta e sessão iniciada para poderes visualizar este link] 

> Na opção "Additional Scans",clique em "Extras".

[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]

> Marque,também,as caixinhas:

[] Reg - NetSvcs
[] File - Lop Check

[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]

> Para SO 64 bits,marque a caixinha!

> Em "Basic Scans",marque a caixinha: Skip Microsoft

> Marque: [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]

Código:
%systemdrive%\*.*
%systemdrive%\drivers\*.exe
%systemroot%\system32\drivers\*.* /90
%programfiles%\*.*
%localappdata%\*.exe
%localappdata%\*.txt
%localappdata%\*.ini
%localappdata%\*.dll
%localappdata%\*.dat
%userprofile%\*.exe
%userprofile%\*.txt
%userprofile%\*.ini
%userprofile%\*.dll
%userprofile%\*.dat /30
%appdata%\*.*
%systemroot%\system32\tasks\*.*
%windir%\tasks\*.*
HKLM\System\CCS\Services\Tcpip\Parameters
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT

[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]

> Copie e cole estas informações que estão no Código,para o campo "Custom Scans".
> À seguir,clique em [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem] 

> Ao concluir,abrir-se-á o Bloco de Notas,com o relatório. ( OTS.txt )
> Poste-o em sua resposta!
> Acesse para isso! ( [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] ou [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] )

Abs!
joram
joram
Administrador
Administrador

Mensagens : 4160
Reputação : 471
Data de inscrição : 26/01/2014
Localização : Rio de Janeiro

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por Silvana Alfredo Sáb 29 Nov 2014, 18:18


==== Startup Registry Enabled ======================

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="%ProgramFiles%\Windows\Sidebar.exe /autoRun"

[HKEY_USERS\S-1-5-21-2770409014-1854213450-1300532065-1000\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun"
"Google Update"="C:\Users\Usuario\AppData\Local\Google\Update\GoogleUpdate.exe /c"

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"="C:\Windows\System32\mctadmin.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\Program Files\Microsoft Security Client\msseces.exe -hide -runkey"
"IgfxTray"="C:\Windows\system32\igfxtray.exe"
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe"
"Persistence"="C:\Windows\system32\igfxpers.exe"
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"
"ControlCenter4"="C:\Program Files\ControlCenter4\BrCcBoot.exe /autorun"
"BrStsMon00"="C:\Program Files\Browny02\Brother\BrStMonW.exe /AUTORUN"
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe"
"AvastUI.exe"="C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui"

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
"Skype"="C:\Program Files\Skype\Phone\Skype.exe /minimized /regrun"
"Google Update"="C:\Users\Usuario\AppData\Local\Google\Update\GoogleUpdate.exe /c"

==== Startup Registry Disabled ======================

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run-]
"Google Update"="\"C:\\Users\\Usuario\\AppData\\Local\\Google\\Update\\GoogleUpdate.exe\" /c"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run-]
"SunJavaUpdateSched"="\"C:\\Program Files\\Common Files\\Java\\Java Update\\jusched.exe\""
"Adobe ARM"="\"C:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\""
"HP Software Update"="C:\\Program Files\\Hp\\HP Software Update\\HPWuSchd2.exe"


==== Task Scheduler Jobs ======================

C:\Windows\tasks\Adobe Flash Player Updater.job --a------ C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [26/10/2012 11:08]
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [20/10/2014 20:25]
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job --a------ C:\Program Files\Google\Update\GoogleUpdate.exe [20/10/2014 20:25]
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2770409014-1854213450-1300532065-1000Core.job --a------ C:\Users\Usuario\AppData\Local\Google\Update\GoogleUpdate.exe [26/10/2012 11:06]
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2770409014-1854213450-1300532065-1000UA.job --a------ [Undetermined Task]
C:\Windows\tasks\HP Photo Creations Communicator.job --a------ C:\ProgramData\HP Photo Creations\Communicator.exe [06/11/2012 15:12]

==== Other Scheduled Tasks ======================

"C:\Windows\system32\tasks\Adobe Flash Player Updater" [C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe]
"C:\Windows\system32\tasks\GlaryInitialize" [C:\Program Files\Glary Utilities\initialize.exe]
"C:\Windows\system32\tasks\Google Updater and Installer" [C:\Users\Usuario\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA" [C:\Program Files\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-2770409014-1854213450-1300532065-1000Core" [C:\Users\Usuario\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\GoogleUpdateTaskUserS-1-5-21-2770409014-1854213450-1300532065-1000UA" [C:\Users\Usuario\AppData\Local\Google\Update\GoogleUpdate.exe]
"C:\Windows\system32\tasks\HP Photo Creations Communicator" [C:\ProgramData\HP Photo Creations\Communicator.exe]
"C:\Windows\system32\tasks\HpWebReg.exe" [C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HpWebReg.exe]
"C:\Windows\system32\tasks\Java Update Scheduler" [C:\Program Files\Common Files\Java\Java Update\jusched.exe]

==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[26/11/2014 10:36]


==== IE Start and Search Settings ======================

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SAVJ_pt-BRBR509"

==== HijackThis Entries ======================

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Auxiliar de Conexão do Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll

==== EOF on 29/11/2014 at 18:09:20,25 ======================
Silvana Alfredo
Silvana Alfredo
Membro
Membro

Mensagens : 58
Reputação : 1
Data de inscrição : 08/08/2014
Idade : 64
Localização : São Paulo

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty ganhei um notebook bichado

Mensagem por Silvana Alfredo Sáb 29 Nov 2014, 18:41

Eu demorei neste procedimento por não conseguir enviar o aquivo. Espero que tenha consegido.
Silvana Alfredo
Silvana Alfredo
Membro
Membro

Mensagens : 58
Reputação : 1
Data de inscrição : 08/08/2014
Idade : 64
Localização : São Paulo

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por joram Dom 30 Nov 2014, 08:40

Bom Dia! Silvana Alfredo

> Vc tem 2 antivírus! ( Avast e Microsoft Security Essentials )
> Desinstale o Avast,pois consome mais recursos de seu Notebook.

> Abra a ferramenta OTS.

[Unregister Dlls]
[kill explorer before fix]
[Processes - Safe List]
YY -> teamviewer_service.exe -> C:\Arquivos de Programas\TeamViewer\Version7\TeamViewer_Service.exe
[Win32 Services - Safe List]
YY -> (TeamViewer7) TeamViewer 7 [Auto | Running] -> C:\Arquivos de Programas\TeamViewer\Version7\TeamViewer_Service.exe
[Registry - Safe List]
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
YY -> HKLM\software\mozilla\Firefox\Extensions\\wrc@avast.com -> C:\Arquivos de Programas\AVAST Software\Avast\WebRep\FF [C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YY -> "NeroFilterCheck" -> C:\Arquivos de Programas\Common Files\Ahead\Lib\NeroCheck.exe [C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe]
YN -> "UnlockerAssistant" -> ["C:\Program Files\Unlocker\UnlockerAssistant.exe"]
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YN -> "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck]
[Registry - Additional Scans - Safe List]
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\
YN -> livecall:{828030A1-22C1-4009-854F-8E305202313F} [HKLM] -> Reg Error: Key error.[Reg Error: Key error.]
YN -> msnim:{828030A1-22C1-4009-854F-8E305202313F} [HKLM] -> Reg Error: Key error.[Reg Error: Key error.]
< Uninstall List [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
YN -> {18455581-E099-4BA8-BC6B-F34B2F06600C} -> Google Toolbar for Internet Explorer
YN -> {2318C2B1-4965-11d4-9B18-009027A5CD4F} -> Google Toolbar for Internet Explorer
YN -> {45B3A3BD-F90D-48FE-A147-D74878A51046} -> Nero 7 Essentials
YN -> {56C049BE-79E9-4502-BEA7-9754A3E60F9B} -> neroxml
YN -> Glary Utilities_is1 -> Glary Utilities 2.50.0.1632
YN -> TeamViewer 7 -> TeamViewer 7
[Files/Folders - Created Within 30 Days]
NY ->  zoek_backup -> C:\zoek_backup
[Files/Folders - Modified Within 30 Days]
NY ->  ZA-Scan.exe -> C:\Users\Usuario\Desktop\ZA-Scan.exe
[Files - No Company Name]
NY ->  ZA-Scan.exe -> C:\Users\Usuario\Desktop\ZA-Scan.exe
[File - Lop Check]
NY ->  TuneUp Software -> C:\Users\geomapas\AppData\Roaming\TuneUp Software
NY ->  TuneUp Software -> C:\Users\Usuario\AppData\Roaming\TuneUp Software
NY ->  SCHEDLGU.TXT -> C:\Windows\Tasks\SCHEDLGU.TXT
[Custom Scans]
YY ->  ZA-Scan.txt -> C:\ZA-Scan.txt
YY ->  zoek-results2014-11-26-131825.log -> C:\zoek-results2014-11-26-131825.log
YY ->  zoek-results2014-11-27-013544.log -> C:\zoek-results2014-11-27-013544.log
YY ->  zoek-results2014-11-27-013614.log -> C:\zoek-results2014-11-27-013614.log
YY ->  zoek-results2014-11-29-200734.log -> C:\zoek-results2014-11-29-200734.log
YY ->  GlaryInitialize -> C:\Windows\system32\tasks\GlaryInitialize
YY ->  SCHEDLGU.TXT -> C:\Windows\tasks\SCHEDLGU.TXT
[empty temp folders]
[empty flash folders]
[empty java folders]
[CreateRestorePoint]
[start explorer after fix]
[reboot machine after fix]


> Cole estas informações que estão em vermelho,para o campo: "Paste Fix Here"

[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]

> Clique em Run Fix >> Aguarde!
> Terminando,poste o relatório: C:\_OTS\MovedFiles\OTS.txt 

A+
joram
joram
Administrador
Administrador

Mensagens : 4160
Reputação : 471
Data de inscrição : 26/01/2014
Localização : Rio de Janeiro

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por Silvana Alfredo Seg 01 Dez 2014, 09:18

Olá bom dia,
Tenhos dois usuários nesse notebook. É possivel eliminar o usuário Geomapas só que não tenho a senha....

Segue relatório.



All Processes Killed
[Processes - Safe List]
Process teamviewer_service.exe killed successfully!
C:\Arquivos de Programas\TeamViewer\Version7\TeamViewer_Service.exe moved successfully.
[Win32 Services - Safe List]
Service TeamViewer7 stopped successfully!
Service TeamViewer7 deleted successfully!
File C:\Arquivos de Programas\TeamViewer\Version7\TeamViewer_Service.exe not found.
[Registry - Safe List]
Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\wrc@avast.com not found.
File C:\Arquivos de Programas\AVAST Software\Avast\WebRep\FF not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NeroFilterCheck deleted successfully.
C:\Arquivos de Programas\Common Files\Ahead\Lib\NeroCheck.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\UnlockerAssistant deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
[Registry - Additional Scans - Safe List]
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{828030A1-22C1-4009-854F-8E305202313F}\ not found.
[Files/Folders - Created Within 30 Days]
C:\zoek_backup\Low.tmp\SkypeClickToCall\Logs folder moved successfully.
C:\zoek_backup\Low.tmp\SkypeClickToCall folder moved successfully.
C:\zoek_backup\Low.tmp folder moved successfully.
C:\zoek_backup\C_Windows_system32_GroupPolicy_User folder moved successfully.
C:\zoek_backup\C_Windows_system32_GroupPolicy_Machine folder moved successfully.
C:\zoek_backup\C_Windows_system32_config_systemprofile_Searches folder moved successfully.
C:\zoek_backup folder moved successfully.
[Files/Folders - Modified Within 30 Days]
C:\Users\Usuario\Desktop\ZA-Scan.exe moved successfully.
[Files - No Company Name]
File C:\Users\Usuario\Desktop\ZA-Scan.exe not found!
[File - Lop Check]
C:\Users\geomapas\AppData\Roaming\TuneUp Software\TuneUp Utilities 2014\TuningIndex folder moved successfully.
C:\Users\geomapas\AppData\Roaming\TuneUp Software\TuneUp Utilities 2014\StartUp Manager folder moved successfully.
C:\Users\geomapas\AppData\Roaming\TuneUp Software\TuneUp Utilities 2014\Dashboard folder moved successfully.
C:\Users\geomapas\AppData\Roaming\TuneUp Software\TuneUp Utilities 2014\Backups folder moved successfully.
C:\Users\geomapas\AppData\Roaming\TuneUp Software\TuneUp Utilities 2014 folder moved successfully.
C:\Users\geomapas\AppData\Roaming\TuneUp Software folder moved successfully.
C:\Users\Usuario\AppData\Roaming\TuneUp Software\TuneUp Utilities 2014\TuningIndex folder moved successfully.
C:\Users\Usuario\AppData\Roaming\TuneUp Software\TuneUp Utilities 2014\StartUp Manager folder moved successfully.
C:\Users\Usuario\AppData\Roaming\TuneUp Software\TuneUp Utilities 2014\Dashboard folder moved successfully.
C:\Users\Usuario\AppData\Roaming\TuneUp Software\TuneUp Utilities 2014\Backups folder moved successfully.
C:\Users\Usuario\AppData\Roaming\TuneUp Software\TuneUp Utilities 2014 folder moved successfully.
C:\Users\Usuario\AppData\Roaming\TuneUp Software folder moved successfully.
File move failed. C:\Windows\Tasks\SCHEDLGU.TXT scheduled to be moved on reboot.
[Custom Scans]
C:\ZA-Scan.txt moved successfully.
C:\zoek-results2014-11-26-131825.log moved successfully.
C:\zoek-results2014-11-27-013544.log moved successfully.
C:\zoek-results2014-11-27-013614.log moved successfully.
C:\zoek-results2014-11-29-200734.log moved successfully.
C:\Windows\system32\tasks\GlaryInitialize moved successfully.
File move failed. C:\Windows\tasks\SCHEDLGU.TXT scheduled to be moved on reboot.
[empty temp folders]


User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: geomapas
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Todos os Usuários

User: Usuario
->Temp folder emptied: 103169 bytes
->Temporary Internet Files folder emptied: 300212 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 193385210 bytes
->Flash cache emptied: 0 bytes

User: Usuário Padrão
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 548780 bytes
RecycleBin emptied: 8379484 bytes

Total Files Cleaned = 193,00 mb

Cannot create restore point. Unable to start RPC service!
< End of fix log >
OTS by OldTimer - Version 3.1.47.2 fix logfile created on 12012014_090746

Files\Folders moved on Reboot...
File move failed. C:\Windows\Tasks\SCHEDLGU.TXT scheduled to be moved on reboot.
File move failed. C:\Windows\temp\Low\SkypeClickToCall\Logs\AutoUpdateSvc.log scheduled to be moved on reboot.

Registry entries deleted on Reboot...
Silvana Alfredo
Silvana Alfredo
Membro
Membro

Mensagens : 58
Reputação : 1
Data de inscrição : 08/08/2014
Idade : 64
Localização : São Paulo

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por joram Seg 01 Dez 2014, 10:59

Bom Dia! Silvana Alfredo

Silvana Alfredo escreveu:Tenhos dois usuários nesse notebook. É possivel eliminar o usuário Geomapas só que não tenho a senha....
> Acesse-o por este comando: control userpasswords2
> Dê uma nova senha ao Usuário que queira acessar e depois,caso queira,pode removê-lo.
Ps: Vc desinstalou o Avast?

A+
joram
joram
Administrador
Administrador

Mensagens : 4160
Reputação : 471
Data de inscrição : 26/01/2014
Localização : Rio de Janeiro

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por Silvana Alfredo Seg 01 Dez 2014, 11:15

Sim desinstalei antes de fazer o procedimento com o OTS.
Silvana Alfredo
Silvana Alfredo
Membro
Membro

Mensagens : 58
Reputação : 1
Data de inscrição : 08/08/2014
Idade : 64
Localização : São Paulo

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por joram Seg 01 Dez 2014, 12:06

Silvana Alfredo escreveu:Sim desinstalei antes de fazer o procedimento com o OTS.
Boa Tarde! Silvana Alfredo

> Houve melhoras em seu Notebook?

> Baixe: < [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] > ( ... by OldTimer Tools )

> Clique em Salvar! 

< [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem] >

> Salve-o no desktop! 

< [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem] >

> Duplo clique em OTL.exe 

> Clique Executar

< [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem] >

> Execute a OTL,em seu rápido escaneamento. ( Verificação rápida )
> Ps: Para Windows 7,clique direito e execute-o como "Administrador".
> Copie e poste o relatório. ( C:\_OTL\MovedFiles\xxxx2014_xxxxxx.log )
> Poste,também,o relatório "Extras". 

A+
joram
joram
Administrador
Administrador

Mensagens : 4160
Reputação : 471
Data de inscrição : 26/01/2014
Localização : Rio de Janeiro

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por Silvana Alfredo Seg 01 Dez 2014, 12:28

Olá Joram, o meu notebook está muito melhor sim.

Segue um relatório, mas não sei se fiz certo porque não consegui salvar com "binary files"

-------------------
OTL logfile created on: 01/12/2014 12:16:36 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Usuario\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17420)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy

1,83 Gb Total Physical Memory | 0,76 Gb Available Physical Memory | 41,37% Memory free
3,67 Gb Paging File | 2,25 Gb Available in Paging File | 61,24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465,66 Gb Total Space | 399,27 Gb Free Space | 85,74% Space Free | Partition Type: NTFS

Computer Name: ACER-001 | User Name: Usuario | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2014/12/01 12:09:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Usuario\Desktop\OTL.exe
PRC - [2014/09/12 07:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) -- C:\Arquivos de Programas\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2014/08/22 13:44:44 | 000,022,192 | ---- | M] (Microsoft Corporation) -- c:\Arquivos de Programas\Microsoft Security Client\MsMpEng.exe
PRC - [2014/08/22 13:44:40 | 000,288,120 | ---- | M] (Microsoft Corporation) -- c:\Arquivos de Programas\Microsoft Security Client\NisSrv.exe
PRC - [2014/08/22 13:41:00 | 000,974,432 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Microsoft Security Client\msseces.exe
PRC - [2014/07/14 19:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
PRC - [2014/07/14 19:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
PRC - [2012/11/23 00:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012/09/06 22:11:30 | 001,327,104 | ---- | M] (Brother Industries, Ltd.) -- C:\Arquivos de Programas\ControlCenter4\BrCcUxSys.exe
PRC - [2012/09/06 22:06:14 | 000,393,216 | ---- | M] (Brother Industries, Ltd.) -- C:\Arquivos de Programas\ControlCenter4\BrCtrlCntr.exe
PRC - [2011/02/25 03:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/11/20 10:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Windows Media Player\wmpnetwk.exe
PRC - [2009/02/26 18:36:46 | 000,030,040 | ---- | M] (Microsoft Corporation) -- C:\Arquivos de Programas\Microsoft Office\Office12\GrooveMonitor.exe


========== Modules (No Company Name) ==========

MOD - [2014/10/22 02:04:57 | 008,910,664 | ---- | M] () -- C:\Users\Usuario\AppData\Local\Google\Chrome\Application\38.0.2125.111\pdf.dll
MOD - [2014/10/22 02:04:51 | 001,042,760 | ---- | M] () -- C:\Users\Usuario\AppData\Local\Google\Chrome\Application\38.0.2125.111\libglesv2.dll
MOD - [2014/10/22 02:04:49 | 000,211,272 | ---- | M] () -- C:\Users\Usuario\AppData\Local\Google\Chrome\Application\38.0.2125.111\libegl.dll
MOD - [2014/10/22 02:04:48 | 001,681,224 | ---- | M] () -- C:\Users\Usuario\AppData\Local\Google\Chrome\Application\38.0.2125.111\ffmpegsumo.dll
MOD - [2012/01/05 07:24:32 | 000,094,208 | ---- | M] () -- C:\Windows\System32\IccLibDll.dll
MOD - [2009/02/27 17:38:20 | 000,139,264 | R--- | M] () -- C:\Arquivos de Programas\Brother\BrUtilities\BrLogAPI.dll


========== Services (SafeList) ==========

SRV - [2014/11/06 00:59:34 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2014/09/12 07:43:06 | 000,064,704 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Arquivos de Programas\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2014/08/22 13:44:44 | 000,022,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Arquivos de Programas\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2014/08/22 13:44:40 | 000,288,120 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Arquivos de Programas\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2014/07/14 19:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014/07/14 19:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2013/05/27 02:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de Programas\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012/11/09 11:20:06 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Arquivos de Programas\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/10/29 08:11:30 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2012/10/26 11:08:42 | 000,250,808 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/06/05 16:56:28 | 000,266,240 | ---- | M] (Brother Industries, Ltd.) [On_Demand | Stopped] -- C:\Arquivos de Programas\Browny02\BrYNSvc.exe -- (BrYNSvc)
SRV - [2012/01/16 00:54:26 | 000,274,200 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IntelCpHeciSvc.exe -- (cphs)
SRV - [2011/07/20 05:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de Programas\Common Files\microsoft shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2010/11/20 10:17:56 | 001,121,792 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Arquivos de Programas\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc)
SRV - [2009/07/13 23:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/02/26 18:36:22 | 000,064,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de Programas\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service)
SRV - [2006/10/26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Arquivos de Programas\Common Files\microsoft shared\Source Engine\OSE.EXE -- (ose)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] -- c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{F53A69CF-DFE5-48EA-A46C-6BCDECC3DD0F}\MpKsl7654c6bf.sys -- (MpKsl7654c6bf)
DRV - [2014/07/17 19:05:08 | 000,095,920 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012/02/14 02:34:32 | 000,021,520 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Smb_driver.sys -- (SmbDrv)
DRV - [2012/02/01 07:06:18 | 000,219,240 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtsBaStor.sys -- (RSBASTOR)
DRV - [2012/01/20 05:31:30 | 002,231,808 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2011/11/10 00:52:02 | 000,046,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (MEI)
DRV - [2011/05/13 04:21:06 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011/05/13 04:21:06 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2011/05/13 04:21:06 | 000,114,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadserd.sys -- (ssadserd)
DRV - [2011/05/13 04:21:06 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdfl.sys -- (ssadmdfl)
DRV - [2011/05/13 04:21:04 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadadb.sys -- (androidusb)
DRV - [2010/11/20 08:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 07:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/13 21:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = pt-BR
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}: "URL" = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Usuario\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Usuario\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\gastecnologia.com.br/sf/cef: C:\Users\Usuario\AppData\Local\GAS Tecnologia\GBBD\npsf_cef.dll (GAS Tecnologia)



========== Chrome ==========

CHR - plugin: Error reading preferences file
CHR - Extension: No name found = C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.8_0\
CHR - Extension: No name found = C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: No name found = C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: No name found = C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: No name found = C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.0_0\
CHR - Extension: No name found = C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\
CHR - Extension: No name found = C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2014/11/26 12:03:52 | 000,000,768 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Arquivos de Programas\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de Programas\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Auxiliar de Conexão do Windows Live) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Arquivos de Programas\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Skype Click to Call for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Arquivos de Programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Arquivos de Programas\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter4] C:\Program Files\ControlCenter4\BrCcBoot.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xportar para o Microsoft Excel - C:\Arquivos de Programas\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Arquivos de Programas\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Arquivos de Programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Arquivos de Programas\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{75018F28-2841-41AB-901A-1B457F9C271D}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AE060D19-6145-4D4E-B445-E7BED150DF38}: DhcpNameServer = 200.204.0.10 200.204.0.138
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Arquivos de Programas\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Arquivos de Programas\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Arquivos de Programas\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Arquivos de Programas\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Arquivos de Programas\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Arquivos de Programas\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Arquivos de Programas\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 19:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2014/12/01 12:09:07 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Usuario\Desktop\OTL.exe
[2014/12/01 09:07:46 | 000,000,000 | ---D | C] -- C:\_OTS
[2014/11/28 11:34:13 | 000,646,656 | ---- | C] (OldTimer Tools) -- C:\Users\Usuario\Desktop\OTS.exe
[2014/11/26 23:19:35 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2014/11/26 20:07:26 | 000,000,000 | ---D | C] -- C:\Users\Usuario\Desktop\FRST-OlderVersion
[2014/11/26 11:18:34 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014/11/26 11:11:55 | 000,000,000 | ---D | C] -- C:\Windows\Temp
[2014/11/26 11:11:55 | 000,000,000 | ---D | C] -- C:\Users\Usuario\AppData\Local\Temp
[2014/11/26 09:25:15 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/11/25 14:07:27 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2014/11/25 13:42:43 | 000,000,000 | -HSD | C] -- C:\Users\Usuario\AppData\Local\EmieBrowserModeList
[2014/11/25 08:02:13 | 000,000,000 | ---D | C] -- C:\FRST
[2014/11/03 19:51:04 | 000,000,000 | ---D | C] -- C:\Windows\System32\vbox

========== Files - Modified Within 30 Days ==========

[2014/12/01 12:09:26 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Usuario\Desktop\OTL.exe
[2014/12/01 11:54:10 | 000,000,328 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job
[2014/12/01 11:49:02 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/12/01 11:32:00 | 000,001,086 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2770409014-1854213450-1300532065-1000UA.job
[2014/12/01 10:50:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/12/01 09:16:32 | 000,022,464 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/12/01 09:16:32 | 000,022,464 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/12/01 09:09:34 | 000,001,054 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/12/01 09:08:57 | 1477,201,920 | -HS- | M] () -- C:\hiberfil.sys
[2014/11/29 22:32:01 | 000,001,034 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2770409014-1854213450-1300532065-1000Core.job
[2014/11/28 11:34:33 | 000,646,656 | ---- | M] (OldTimer Tools) -- C:\Users\Usuario\Desktop\OTS.exe
[2014/11/27 19:28:46 | 000,705,782 | ---- | M] () -- C:\Windows\System32\prfh0416.dat
[2014/11/27 19:28:46 | 000,654,238 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/11/27 19:28:46 | 000,147,622 | ---- | M] () -- C:\Windows\System32\prfc0416.dat
[2014/11/27 19:28:46 | 000,122,110 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/11/26 15:55:54 | 000,034,808 | ---- | M] () -- C:\Windows\System32\drivers\TrueSight.sys
[2014/11/26 12:03:52 | 000,000,768 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2014/11/26 08:06:11 | 000,415,328 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/11/25 14:09:21 | 000,000,008 | RHS- | M] () -- C:\Users\Usuario\ntuser.pol
[2014/11/25 14:07:20 | 242,529,036 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2014/11/16 22:27:25 | 000,001,058 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/11/04 13:30:46 | 266,163,743 | ---- | M] () -- C:\Users\Usuario\Documents\video apocalipse.wmv

========== Files Created - No Company Name ==========

[2014/11/26 11:50:48 | 000,034,808 | ---- | C] () -- C:\Windows\System32\drivers\TrueSight.sys
[2014/11/25 14:07:20 | 242,529,036 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2014/11/10 21:06:46 | 266,163,743 | ---- | C] () -- C:\Users\Usuario\Documents\video apocalipse.wmv
[2014/04/11 14:09:47 | 000,000,029 | ---- | C] () -- C:\Windows\System32\config.ini
[2014/02/20 15:02:06 | 000,030,631 | ---- | C] () -- C:\Users\Usuario\AppData\Roaming\unins000.dat
[2013/08/13 16:51:50 | 000,000,008 | RHS- | C] () -- C:\Users\Usuario\ntuser.pol
[2013/05/22 13:32:40 | 000,000,114 | ---- | C] () -- C:\Windows\System32\BRLMW03A.INI
[2013/05/22 13:32:40 | 000,000,050 | ---- | C] () -- C:\Windows\System32\BRADM10A.DAT
[2013/05/22 13:32:38 | 000,045,056 | ---- | C] () -- C:\Windows\System32\BRTCPCON.DLL
[2012/11/06 14:37:13 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini

========== ZeroAccess Check ==========

[2009/07/14 02:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/06/24 23:41:30 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 10:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/13 23:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2014/04/21 10:52:27 | 000,000,000 | ---D | M] -- C:\Users\Usuario\AppData\Roaming\ControlCenter4
[2014/11/12 20:27:57 | 000,000,000 | ---D | M] -- C:\Users\Usuario\AppData\Roaming\Dropbox
[2014/02/14 17:37:57 | 000,000,000 | ---D | M] -- C:\Users\Usuario\AppData\Roaming\Lightcomm
[2014/05/06 18:41:01 | 000,000,000 | ---D | M] -- C:\Users\Usuario\AppData\Roaming\rmi
[2014/02/14 17:36:22 | 000,000,000 | ---D | M] -- C:\Users\Usuario\AppData\Roaming\Telefonica
[2012/11/06 15:13:40 | 000,000,000 | ---D | M] -- C:\Users\Usuario\AppData\Roaming\Visan

========== Purity Check ==========



< End of report >

---------------------------------------
OTL Extras logfile created on: 01/12/2014 12:16:36 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Usuario\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17420)
Locale: 00000416 | Country: Brasil | Language: PTB | Date Format: dd/MM/yyyy

1,83 Gb Total Physical Memory | 0,76 Gb Available Physical Memory | 41,37% Memory free
3,67 Gb Paging File | 2,25 Gb Available in Paging File | 61,24% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465,66 Gb Total Space | 399,27 Gb Free Space | 85,74% Space Free | Partition Type: NTFS

Computer Name: ACER-001 | User Name: Usuario | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- Reg Error: Value error.
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MIF5BA~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{001F2968-CE99-4441-984F-9F36BAD10CF3}" = rport=445 | protocol=6 | dir=out | app=system |
"{1C4621E0-B7A2-4AAB-8463-C0270C531C4E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2B0C17CE-5F37-4278-A751-088EEFC3B9CF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2D0940AE-A757-466E-8DA3-0C78C49CC905}" = lport=10243 | protocol=6 | dir=in | app=system |
"{3AA9CC6D-8827-49FC-AAE0-615F309CFB96}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{40D83248-835B-4CC7-8C88-5EDDFDFF0D4F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{52BEE99F-6462-4446-AB89-F9ABEBBC491F}" = rport=138 | protocol=17 | dir=out | app=system |
"{52E30988-2130-4D76-9BC9-A702FA6F1FF7}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{566EAFFF-6F09-4532-8A82-3A418375C0CC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{59EC9174-B87D-4662-A730-A93D9B1EA4F0}" = rport=139 | protocol=6 | dir=out | app=system |
"{636A5CA2-4BFB-4D23-BCF9-D93BD7C21E4D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{738FF8F0-C7B7-4A72-B627-0BC7745F5E3C}" = lport=137 | protocol=17 | dir=in | app=system |
"{900EAF56-A503-4B87-86C6-CBB274F839B4}" = lport=138 | protocol=17 | dir=in | app=system |
"{92E6B2BE-CDE0-41C8-B5C6-332127DE531B}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{A33238B5-EFFF-490D-9CB7-933CACD4D18F}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A70E487B-5ABB-495A-84B3-8D82C8607ED9}" = rport=137 | protocol=17 | dir=out | app=system |
"{AB8EDF10-EC6A-480C-8516-BBA909AFCE84}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B16F0EFF-07E5-4B06-AFA4-3C12704D3611}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B8EAD419-6154-4B0B-92AF-AEDA7A5F8FF9}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{CD9951C1-9FAE-4EE8-B367-DD5F99BA6C80}" = lport=445 | protocol=6 | dir=in | app=system |
"{CF864A6B-1B9B-4AD3-8431-CE90C40E6594}" = rport=10243 | protocol=6 | dir=out | app=system |
"{D8DC3010-5516-474F-8C89-F9B713FE6359}" = lport=139 | protocol=6 | dir=in | app=system |
"{E0FFF571-E1AE-4D09-82C2-132FC404E95B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E4495AF8-3492-486C-A3AB-0C448ACF9784}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F605DCC2-614E-4114-B493-CAA52E283383}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FD7A3B60-E395-485D-B4F9-C5AC2D2DE989}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04C9D04B-1D88-49CF-BE64-6DAE977950DC}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\devicesetup.exe |
"{089AA551-6E0A-4739-A44C-3B30B98108BF}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{13A65892-B20C-44CC-BDE9-73C8F9640041}" = protocol=6 | dir=in | app=c:\program files\avast software\avast\ng\vbox\aswfe.exe |
"{189AA042-DA25-4251-9125-ACC7F66EC3B1}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1C02DED5-7BF3-4B73-BA98-9DFD44DEAC7D}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{225BCF9D-FDF0-4F36-9E9C-1B378742FDE5}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{2E2894AA-F0F3-4052-A7E3-F12D89DA0026}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{38CC5A44-49F9-483E-9B44-A0DBED48F2F0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3CAD9FCE-39BF-4009-9691-7225E15A30F1}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3FD92954-B15E-4C9B-B064-37FED9B9493B}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version7\teamviewer_service.exe |
"{400CEE51-41C7-4958-88A1-00ABC71DD384}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4B8134A3-C3D6-47D4-B7CB-E8203F71A9BD}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{55FEED63-1982-4A00-B150-BE9CFDB2ECD0}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5B272035-0AD8-4CC9-995E-E4140C6F02CA}" = protocol=6 | dir=out | app=system |
"{5C1436E7-F8CD-4421-97D1-80FD2C74BBB0}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{629EE2ED-E8F5-4A93-BE3F-4ECDFBFB4953}" = protocol=17 | dir=in | app=c:\users\usuario\appdata\roaming\dropbox\bin\dropbox.exe |
"{6902134E-C81E-4D3D-A929-290A3011F676}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{6F7E986C-FB67-4755-B49F-4D0A2D35FAEB}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{801833BE-2EB6-44EB-B879-77C3696A2BA4}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{90681D79-FB34-440A-82CA-027D1290D458}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version7\teamviewer_service.exe |
"{9C9AC0AC-752D-4B4D-BA1E-F259D60F63E2}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A3DC27F8-9C4F-4F4D-9DFE-CBBDFF63F7D0}" = protocol=17 | dir=in | app=c:\program files\avast software\avast\ng\vbox\aswfe.exe |
"{ABB21BDC-9F8E-403D-B03C-CEA842D76C15}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version7\teamviewer.exe |
"{ACB4400A-429D-459B-8DC7-515FC701BCAC}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{B30756DF-2980-4D32-A1A6-C8E7A8EBC5C1}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"{B4A6FA03-9E51-49C2-B79D-979CABA86293}" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"{B5983E87-3AC9-4CFA-BC1D-BBAEEE516222}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{C4593591-9B9F-497A-80A0-F1340B715BA1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{C5232222-1774-4FBB-9A07-425C66D0B4F0}" = protocol=6 | dir=in | app=c:\users\usuario\appdata\roaming\dropbox\bin\dropbox.exe |
"{D2CCC67C-4250-4F8E-8288-C2A2640EAF93}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version7\teamviewer.exe |
"{D7B5C052-11B1-4B00-9F45-DA1D867A9A1B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D8BFDEDF-0A0C-422D-8B7D-B344F64632DE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DFA6B9F1-2047-4642-8ED6-30DBBB68C973}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\groove.exe |
"{FABE4982-072C-48FE-BDEC-B85525F1FD50}" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\devicesetup.exe |
"TCP Query User{B565A4A0-3608-4115-9665-43B97840EAE6}C:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe" = protocol=6 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"UDP Query User{6CF5FA23-DE8F-4113-B849-05A7FECC789D}C:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe" = protocol=17 | dir=in | app=c:\program files\hp\hp deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{0FFEA8EE-7BC7-4C9D-8CC6-5B8C891BA3F2}" = Windows Live Essentials
"{107F27B7-8EE4-4B3A-9CE5-497B120369DC}" = Microsoft Security Client
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Ferramenta de Carregamento do Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83217009FF}" = Java 7 Update 9
"{2DF215E0-BD3C-4C98-8616-AFEF09747285}" = Windows Live Sync
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{31495D38-0A7A-3D27-845B-9210E6ED8CFE}" = Microsoft .NET Framework 4.5.1 (PTB)
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}" = Brother MFL-Pro Suite DCP-7065DN
"{4903D172-DCCB-392F-93A3-34CA9D47FE3D}" = Microsoft .NET Framework 4.5.1
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51A9E3DD-37B8-47BB-8E67-5B76B3EFBC48}" = Assistente de Conexão do Windows Live
"{590035D9-BFA0-406A-A7F0-479C72C0DDB2}" = Windows Live Call
"{5d01f486-f32d-462e-8830-cc1d116e8ece}_is1" = GBBD Caixa Economica Federal
"{6D1221A9-17BF-4EC0-81F2-27D30EC30701}" = Skype Click to Call
"{6D4A54DD-C9E2-4647-B872-2E83C188584B}" = Windows Live Movie Maker
"{6FC163A1-3774-4918-8565-47F4FF0DF8B7}" = Software básico do dispositivo HP Deskjet 3050 J610 series
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74AD1846-2010-4FB1-8E24-B6F2B87150C2}" = Windows Live Mail
"{87A9C015-C2BA-44EE-9C20-6E1A764B8E23}" = Windows Live Galeria de Fotos
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0015-0416-0000-0000000FF1CE}" = Microsoft Office Access MUI (Portuguese (Brazil)) 2007
"{90120000-0015-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0416-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Portuguese (Brazil)) 2007
"{90120000-0016-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0416-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2007
"{90120000-0018-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0416-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Portuguese (Brazil)) 2007
"{90120000-0019-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0416-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Portuguese (Brazil)) 2007
"{90120000-001A-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0416-0000-0000000FF1CE}" = Microsoft Office Word MUI (Portuguese (Brazil)) 2007
"{90120000-001B-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2007
"{90120000-001F-0416-0000-0000000FF1CE}_ENTERPRISE_{8A524694-0CA4-476A-9301-B1E9D70FC952}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0416-0000-0000000FF1CE}" = Microsoft Office Proofing (Portuguese (Brazil)) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0416-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2007
"{90120000-0044-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0416-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Portuguese (Brazil)) 2007
"{90120000-006E-0416-0000-0000000FF1CE}_ENTERPRISE_{51530CD1-8244-4E0F-B536-BCCC05325C7F}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0416-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Portuguese (Brazil)) 2007
"{90120000-00A1-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0416-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Portuguese (Brazil)) 2007
"{90120000-00BA-0416-0000-0000000FF1CE}_ENTERPRISE_{AD3E8EF1-E885-4068-BC73-16C0649FEBF0}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1046" = Microsoft .NET Framework 4.5.1 (Português do Brasil)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9ADC3E4F-34DA-48CD-8727-BB26D90257BD}" = Windows Live Messenger
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1046-7B44-AB0000000001}" = Adobe Reader XI (11.0.09) - Português
"{B515962D-C979-44AC-9912-F7BB499B4B2C}" = VirtualDJ Home FREE
"{EA17F4FC-FDBF-4CF8-A529-2D983132D053}" = Skype™ 6.0
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}" = HP Deskjet 3050 J610 series Ajuda
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Biblia Eletrônica_is1" = Biblia Eletrônica 3.6.3
"ENTERPRISE" = Microsoft Office Enterprise 2007
"HP Photo Creations" = HP Photo Creations
"KLiteCodecPack_is1" = K-Lite Codec Pack 9.4.0 (Full)
"Microsoft Security Client" = Microsoft Security Essentials
"wifi_is1" = Discador WiFi Telefonica
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR 4.20 (32-bit)

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 26/11/2014 08:34:05 | Computer Name = Acer-001 | Source = VSS | ID = 8194
Description =

Error - 26/11/2014 18:06:10 | Computer Name = Acer-001 | Source = Application Hang | ID = 1002
Description = O programa FRST.exe versão 23.11.2014.0 parou de interagir com o Windows
e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique
o histórico de problemas no painel de controle da Central de Ações. ID de Processo:
cc Hora de Início: 01d009c5224adcef Hora de Término: 0 Caminho do Aplicativo: C:\Users\Usuario\Desktop\FRST.exe

Id
do Relatório: 69b667ba-75b8-11e4-bac0-047d7bbb5ddb

Error - 26/11/2014 18:06:47 | Computer Name = Acer-001 | Source = Application Hang | ID = 1002
Description = O programa FRST.exe versão 23.11.2014.0 parou de interagir com o Windows
e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique
o histórico de problemas no painel de controle da Central de Ações. ID de Processo:
10a0 Hora de Início: 01d009c5333e7875 Hora de Término: 0 Caminho do Aplicativo: C:\Users\Usuario\Desktop\FRST.exe

Id
do Relatório: 771ae0d0-75b8-11e4-bac0-047d7bbb5ddb

Error - 01/12/2014 06:53:25 | Computer Name = Acer-001 | Source = VSS | ID = 8194
Description =

[ OSession Events ]
Error - 08/05/2013 00:47:31 | Computer Name = Acer-001 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6668.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 308
seconds with 300 seconds of active time. This session ended with a crash.

Error - 08/08/2013 11:20:24 | Computer Name = Acer-001 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 71296
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 26/11/2014 09:07:37 | Computer Name = Acer-001 | Source = Service Control Manager | ID = 7030
Description = O serviço PEVSystemStart está marcado como um serviço interativo.
No entanto, o sistema está configurado para não permitir serviços interativos. Esse
serviço pode não funcionar corretamente.

Error - 26/11/2014 22:28:54 | Computer Name = Acer-001 | Source = DCOM | ID = 10010
Description =

Error - 27/11/2014 17:19:05 | Computer Name = Acer-001 | Source = DCOM | ID = 10010
Description =

Error - 28/11/2014 07:30:39 | Computer Name = Acer-001 | Source = Service Control Manager | ID = 7011
Description = Tempo limite esgotado (30000 milissegundos) ao aguardar a resposta
de uma transação do serviço ShellHWDetection.

Error - 29/11/2014 07:25:20 | Computer Name = Acer-001 | Source = DCOM | ID = 10010
Description =

Error - 29/11/2014 15:39:04 | Computer Name = Acer-001 | Source = Microsoft-Windows-Application-Experience | ID = 205
Description = O serviço Auxiliar de Compatibilidade de Programas não pôde executar
a inicialização da fase dois.

Error - 29/11/2014 18:05:33 | Computer Name = Acer-001 | Source = Service Control Manager | ID = 7011
Description = Tempo limite esgotado (30000 milissegundos) ao aguardar a resposta
de uma transação do serviço TeamViewer7.

Error - 29/11/2014 18:06:02 | Computer Name = Acer-001 | Source = DCOM | ID = 10010
Description =

Error - 30/11/2014 14:16:05 | Computer Name = Acer-001 | Source = DCOM | ID = 10010
Description =

Error - 01/12/2014 07:07:48 | Computer Name = Acer-001 | Source = Service Control Manager | ID = 7031
Description = O serviço TeamViewer 7 foi finalizado inesperadamente. Isto aconteceu
1 vez(es). A seguinte ação corretiva será tomada em 2000 milissegundos: Reiniciar
o serviço.


< End of report >
Silvana Alfredo
Silvana Alfredo
Membro
Membro

Mensagens : 58
Reputação : 1
Data de inscrição : 08/08/2014
Idade : 64
Localização : São Paulo

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por Silvana Alfredo Seg 01 Dez 2014, 12:32

Apareceu este relatório em algum momento anterior ao executado acima salvo automaticamente com o nome "desktop.ini":



[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
IconResource=%SystemRoot%\system32\imageres.dll,-183
Silvana Alfredo
Silvana Alfredo
Membro
Membro

Mensagens : 58
Reputação : 1
Data de inscrição : 08/08/2014
Idade : 64
Localização : São Paulo

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por joram Seg 01 Dez 2014, 13:22

Silvana Alfredo escreveu:Apareceu este relatório em algum momento anterior ao executado acima salvo automaticamente com o nome "desktop.ini":



[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
IconResource=%SystemRoot%\system32\imageres.dll,-183
Boa Tarde! Silvana Alfredo

> Pode deletar esse desktop.ini que apareceu!

> Abra a ferramenta OTL.

[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]
 
> Clique Limpeza.
> Confirme essa solicitação!
> Aceite o reboot!

> Vamos remover as ferramentas que foram utilizadas na desinfecção!

> Baixe: < [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] > ( ... de Xplode )

[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]

> Estando na página,clique em Download Now
> Salve-a em um local conveniente! ( desktop! )
> Feche aplicativos que estejam abertos.

[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]

> Remover ferramentas de desinfecção
> Criar backup do registro
> Limpar pontos da restauração do sistema

> Com estas caixinhas marcadas,clique Executar!
> Reinicie o computador ao concluir!
> Tudo Ok?

A+
joram
joram
Administrador
Administrador

Mensagens : 4160
Reputação : 471
Data de inscrição : 26/01/2014
Localização : Rio de Janeiro

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por Silvana Alfredo Seg 01 Dez 2014, 13:59

Olá Joram

Com isso sua valiosa ajuda foi terminada?
Você não pediu mais segue o relatório.

--------------------------------------------------------------------------------------
# DelFix v10.8 - Relatório criado 01/12/2014 às 13:53:18
# Atualizado 29/07/2014 por Xplode
# Usuário : Usuario - ACER-001
# Sistema Operacional : Windows 7 Home Premium Service Pack 1 (32 bits)

~ Removendo ferramentas de desinfecção ...

Removido : C:\Users\Usuario\Desktop\FRST-OlderVersion
Removido : C:\Users\Usuario\Downloads\Addition.txt
Removido : C:\Users\Usuario\Downloads\Fixlog.txt
Removido : C:\Users\Usuario\Downloads\FRST.txt
Removido : C:\Users\Usuario\Downloads\FRST64.exe
Removido : C:\Users\Usuario\Downloads\OTL (1).exe
Removido : C:\Users\Usuario\Downloads\OTS (1).exe
Removido : C:\Users\Usuario\Downloads\OTS.Txt
Removido : HKLM\SOFTWARE\AdwCleaner
Removido : HKLM\SOFTWARE\TrendMicro\Hijackthis

~ Criando backup do registro ... OK

~ Limpando pontos da restauração do sistema ...

Removido : RP #157 [Windows Update | 09/18/2014 18:56:43]
Removido : RP #158 [Windows Update | 09/18/2014 19:07:43]
Removido : RP #159 [Windows Update | 09/25/2014 18:08:07]
Removido : RP #160 [Windows Update | 09/25/2014 20:39:52]
Removido : RP #161 [Windows Update | 10/20/2014 21:40:05]
Removido : RP #162 [Windows Update | 10/21/2014 00:04:43]
Removido : RP #163 [Windows Update | 10/21/2014 22:05:58]
Removido : RP #164 [Windows Update | 10/22/2014 21:59:50]
Removido : RP #165 [Windows Update | 10/22/2014 22:20:30]
Removido : RP #166 [Windows Update | 10/27/2014 21:42:17]
Removido : RP #168 [avast! antivirus system restore point | 10/29/2014 22:28:26]
Removido : RP #169 [Windows Update | 11/03/2014 21:37:42]
Removido : RP #170 [Windows Update | 11/10/2014 21:48:57]
Removido : RP #171 [Windows Update | 11/18/2014 22:07:28]
Removido : RP #172 [Windows Update | 11/22/2014 04:54:07]
Removido : RP #173 [Windows Update | 11/24/2014 21:56:31]
Removido : RP #174 [Removido TuneUp Utilities 2014 | 11/25/2014 15:40:46]
Removido : RP #175 [Removido TuneUp Utilities 2014 (pt-BR) | 11/25/2014 15:42:37]
Removido : RP #176 [Windows Update | 11/26/2014 09:46:30]
Removido : RP #178 [avast! antivirus system restore point | 11/26/2014 12:34:05]
Removido : RP #179 [zoek.exe restore point | 11/26/2014 12:54:30]
Removido : RP #180 [Windows Update | 11/29/2014 20:01:29]
Removido : RP #182 [avast! antivirus system restore point | 12/01/2014 10:53:28]

Novo ponto de restauração criado !

########## - EOF - ##########
Silvana Alfredo
Silvana Alfredo
Membro
Membro

Mensagens : 58
Reputação : 1
Data de inscrição : 08/08/2014
Idade : 64
Localização : São Paulo

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por joram Seg 01 Dez 2014, 14:14

Boa Tarde! Silvana Alfredo

Silvana Alfredo escreveu:Com isso sua valiosa ajuda foi terminada? 
---
---
1,83 Gb Total Physical Memory | 0,76 Gb Available Physical Memory | 41,37% Memory free
> Sim! O resto será procedimentos de manutenção,que incluem desfragmentação do disco,limpeza do Registro com o CCleaner,atualização do Java,Flash Player.
> Ps: Reparei que houve um aumento significativo da memória livre. isso aí! 
> O log da DelFix foi salutar,pois apagou muitos Pontos de Restauro,incluindo o que foi estabelecido pelo Avast,que não é mais seu antivírus.
> Bom trabalho!   ganhei um notebook bichado - Página 2 648673379 

Abs!
joram
joram
Administrador
Administrador

Mensagens : 4160
Reputação : 471
Data de inscrição : 26/01/2014
Localização : Rio de Janeiro

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por Silvana Alfredo Seg 01 Dez 2014, 14:18

Agradeço muito pois esse notebook era para um trabalho especifico e estava difícil trabalhar com ele "daquele jeito".

Agradeço demais a ajuda do Fórum e em especial a sua.

Abraços

Silvana Alfredo
Silvana Alfredo
Membro
Membro

Mensagens : 58
Reputação : 1
Data de inscrição : 08/08/2014
Idade : 64
Localização : São Paulo

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por joram Seg 01 Dez 2014, 14:21

Caso Resolvido

Necessitando novo auxílio para este computador,basta abrir "Novo Tópico" e relatar o problema.

_________________
[Tens de ter uma conta e sessão iniciada para poderes visualizar este link] >> O que há de melhor,para desinfectar seu computador!
[Tens de ter uma conta e sessão iniciada para poderes visualizar este link] >> Não deixem de conhecer!
[Tens de ter uma conta e sessão iniciada para poderes visualizar este link] >> Tradição em informática!
joram
joram
Administrador
Administrador

Mensagens : 4160
Reputação : 471
Data de inscrição : 26/01/2014
Localização : Rio de Janeiro

Ir para o topo Ir para baixo

ganhei um notebook bichado - Página 2 Empty Re: ganhei um notebook bichado

Mensagem por Conteúdo patrocinado


Conteúdo patrocinado


Ir para o topo Ir para baixo

Página 2 de 2 Anterior  1, 2

Ir para o topo

- Tópicos semelhantes

 
Permissões neste sub-fórum
Não podes responder a tópicos