Fórum PC Brasil
Gostaria de reagir a esta mensagem? Crie uma conta em poucos cliques ou inicie sessão para continuar.
Flux RSS


Yahoo! 
MSN 
AOL 
Netvibes 
Bloglines 


Social bookmarking

Social bookmarking reddit      

Conservar e compartilhar o endereço de PC Seguro em seu site de social bookmarking

Conservar e compartilhar o endereço de Fórum PC Brasil em seu site de social bookmarking

Estatísticas
Temos 14806 usuários registrados
O último membro registrado é King empero

Os nossos membros postaram um total de 36043 mensagens em 3684 assuntos
Últimos assuntos
» Possíveis vírus
por joram Sex 15 Mar 2024, 19:05

Quem está conectado?
14 usuários online :: 0 registrados, 0 invisíveis e 14 visitantes

Nenhum

O recorde de usuários online foi de 301 em Ter 26 Out 2021, 15:28
Procurar
 
 

Resultados por:
 


Rechercher Pesquisa avançada

março 2024
SegTerQuaQuiSexSábDom
    123
45678910
11121314151617
18192021222324
25262728293031

Calendário Calendário


Problemas na remoção do Search Protect

2 participantes

Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Problemas na remoção do Search Protect

Mensagem por kamia Dom 17 maio 2015, 17:03

Caros, boa tarde.

Recentemente instalei por engano um programa (tentei cancelar a instalação mas ela continuou rodando, não sei porque)
Desde então diariamente surgem programas no meu computador.
Acredito que o problema seja esse search protect, mas pode ser outro programa tbm.

Estou desinstalando todos pelo "desinstalar programas do windows" mas sei que não é raiz do problema.
Rodo diariamente o "adwcleaner". Ele consegue "aparentemente" retirar o programa, que some da minha barra de tarefas, mas depois de um tempo ele volta e instala novamente uma série de programas.

Vou rodar o Adwcleaner novamente e postar aqui o log do resultado.

Agradeço a ajuda.

Obrigado
kamia
kamia
Iniciante
Iniciante

Mensagens : 11
Reputação : 0
Data de inscrição : 16/05/2015

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por kamia Dom 17 maio 2015, 17:09

# AdwCleaner v4.204 - Relatório criado 17/05/2015 às 17:03:33
# Atualizado 12/05/2015 por Xplode
# Base de dados : 2015-05-12.2 [Servidor]
# Sistema operacional : Windows 7 Professional Service Pack 1 (x64)
# Usuário : Felipe Kamia - DUVA
# Executando de : C:\Users\Felipe Kamia\Desktop\adwcleaner_4.204.exe
# Opção : Limpar

***** [ Serviços ] *****

[#] Serviço Excluído : innfd_1_10_0_14

***** [ Arquivos / Pastas ] *****

Arquivo Excluído : C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\user.js

***** [ Tarefas agendadas ] *****

Tarefa Apagado : LaunchPreSignup

***** [ Atalhos ] *****


***** [ Registro ] *****

Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
Chave Apagado : [x64] HKLM\SOFTWARE\Classes\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}
Dados Apagado : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=127.0.0.1:62748;hxxps=127.0.0.1:62748
Dados Apagado : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyEnable] - 1
Dados Apagado : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>

***** [ Navegadores ] *****

-\\ Internet Explorer v10.0.9200.16537


-\\ Mozilla Firefox v34.0.5 (x86 pt-BR)


-\\ Google Chrome v


-\\ Chromium v


*************************

AdwCleaner[R0].txt - [15935 bytes] - [16/05/2015 15:55:54]
AdwCleaner[R1].txt - [27094 bytes] - [17/05/2015 16:36:35]
AdwCleaner[R2].txt - [2237 bytes] - [17/05/2015 16:59:45]
AdwCleaner[S0].txt - [13950 bytes] - [16/05/2015 15:56:39]
AdwCleaner[S1].txt - [21665 bytes] - [17/05/2015 16:37:05]
AdwCleaner[S2].txt - [1891 bytes] - [17/05/2015 17:03:33]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1950 bytes] ##########
kamia
kamia
Iniciante
Iniciante

Mensagens : 11
Reputação : 0
Data de inscrição : 16/05/2015

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por kamia Dom 17 maio 2015, 17:10

O relatório abaixo foi rodado ontem:

# AdwCleaner v4.204 - Relatório criado 16/05/2015 às 15:56:39
# Atualizado 12/05/2015 por Xplode
# Base de dados : 2015-05-12.2 [Servidor]
# Sistema operacional : Windows 7 Professional Service Pack 1 (x64)
# Usuário : Felipe Kamia - DUVA
# Executando de : C:\Users\Felipe Kamia\Desktop\adwcleaner_4.204.exe
# Opção : Limpar

***** [ Serviços ] *****

[#] Serviço Excluído : globalUpdate
[#] Serviço Excluído : globalUpdatem
[#] Serviço Excluído : IHProtect Service
[#] Serviço Excluído : YahooAUService

***** [ Arquivos / Pastas ] *****

Pasta Excluído : C:\ProgramData\WindowsMangerProtect
Pasta Excluído : C:\ProgramData\MailUpdate
Pasta Excluído : C:\ProgramData\Yahoo! Companion
Pasta Excluído : C:\ProgramData\IHProtectUpDate
Pasta Excluído : C:\ProgramData\{64188466-0abf-68d0-6418-884660ab1198}
Pasta Excluído : C:\Program Files (x86)\globalUpdate
Pasta Excluído : C:\Program Files (x86)\predm
Pasta Excluído : C:\Program Files (x86)\XTab
Pasta Excluído : C:\Program Files (x86)\GUPlayer
Pasta Excluído : C:\Users\Felipe Kamia\AppData\Local\globalUpdate
Pasta Excluído : C:\Users\Felipe Kamia\AppData\Local\Hola
Pasta Excluído : C:\Users\Felipe Kamia\AppData\Local\4C4C4544-1431784408-5210-8051-C2C04F325631
Pasta Excluído : C:\Users\Felipe Kamia\AppData\LocalLow\Yahoo! Companion
Pasta Excluído : C:\Users\Felipe Kamia\AppData\Roaming\MailUpdate
Pasta Excluído : C:\Users\Felipe Kamia\AppData\Roaming\zona
Pasta Excluído : C:\Users\Felipe Kamia\AppData\Roaming\ASPackage
Pasta Excluído : C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASPackage
Arquivo Excluído : C:\Users\FELIPE~1\AppData\Local\Temp\Uninstall.exe
Arquivo Excluído : C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\user.js

***** [ Tarefas agendadas ] *****

Tarefa Apagado : globalUpdateUpdateTaskMachineCore
Tarefa Apagado : globalUpdateUpdateTaskMachineUA

***** [ Atalhos ] *****


***** [ Registro ] *****

Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Chave Apagado : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Chave Apagado : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Chave Apagado : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Chave Apagado : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Chave Apagado : HKLM\SOFTWARE\19d75619-3764-102b-0b58-5574289ea6e9
Chave Apagado : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Chave Apagado : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Chave Apagado : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Chave Apagado : HKLM\SOFTWARE\Classes\CLSID\{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}
Chave Apagado : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Chave Apagado : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Chave Apagado : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chave Apagado : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chave Apagado : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Chave Apagado : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chave Apagado : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Chave Apagado : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Chave Apagado : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Chave Apagado : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Valor Apagado : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Chave Apagado : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Chave Apagado : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Dados Restaurado : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Chave Apagado : HKCU\Software\APN PIP
Chave Apagado : HKCU\Software\GlobalUpdate
Chave Apagado : HKCU\Software\HomeTab
Chave Apagado : HKCU\Software\Myfree Codec
Chave Apagado : HKCU\Software\Optimizer Pro
Chave Apagado : HKCU\Software\simplytech
Chave Apagado : HKCU\Software\Softonic
Chave Apagado : HKCU\Software\TNT2
Chave Apagado : HKCU\Software\zona
Chave Apagado : HKCU\Software\SearchProtectWS
Chave Apagado : HKCU\Software\Linkey
Chave Apagado : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Chave Apagado : HKCU\Software\AppDataLow\Software\Crossrider
Chave Apagado : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Chave Apagado : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Chave Apagado : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Chave Apagado : HKLM\SOFTWARE\AskPartnerNetwork
Chave Apagado : HKLM\SOFTWARE\Conduit
Chave Apagado : HKLM\SOFTWARE\GlobalUpdate
Chave Apagado : HKLM\SOFTWARE\Iminent
Chave Apagado : HKLM\SOFTWARE\Myfree Codec
Chave Apagado : HKLM\SOFTWARE\SearchProtect
Chave Apagado : HKLM\SOFTWARE\SupDp
Chave Apagado : HKLM\SOFTWARE\supWindowsMangerProtect
Chave Apagado : HKLM\SOFTWARE\mystartsearchSoftware
Chave Apagado : HKLM\SOFTWARE\IHProtect
Chave Apagado : HKLM\SOFTWARE\{12A61307-94CD-4F8E-94BC-918E511FAA81}
Chave Apagado : HKLM\SOFTWARE\SpeedBit
Chave Apagado : HKLM\SOFTWARE\AIM Toolbar
Chave Apagado : HKLM\SOFTWARE\oursurfingSoftware
Chave Apagado : HKLM\SOFTWARE\FFPluginHp
Chave Apagado : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Chave Apagado : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Chave Apagado : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Chave Apagado : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Chave Apagado : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Chave Apagado : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IMBoosterARP
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IminentToolbar
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WajIntEnhance
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ASPackage
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Vosteran.com
Chave Apagado : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Linkey
Dados Apagado : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyServer] - hxxp=127.0.0.1:62748;hxxps=127.0.0.1:62748
Dados Apagado : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyEnable] - 1
Dados Apagado : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <-loopback>

***** [ Navegadores ] *****

-\\ Internet Explorer v10.0.9200.16537

Configuração Restaurado : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Configuração Restaurado : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Configuração Restaurado : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Configuração Restaurado : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Mozilla Firefox v34.0.5 (x86 pt-BR)

[ng0a0zdc.default\prefs.js] - Linha Apagado : user_pref("browser.search.searchengine.alias", "mystartsearch");
[ng0a0zdc.default\prefs.js] - Linha Apagado : user_pref("browser.search.searchengine.iconURL", "hxxp://www.mystartsearch.com/favicon.ico");
[ng0a0zdc.default\prefs.js] - Linha Apagado : user_pref("browser.search.searchengine.name", "mystartsearch");
[ng0a0zdc.default\prefs.js] - Linha Apagado : user_pref("browser.search.searchengine.url", "hxxp://www.mystartsearch.com/web/?type=ds&ts=1431795126&z=ee97e127d0d320d071fbaddg8z2c5gem0t0wcg9o1b&from=slb2&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_4043&q={sea[...]

-\\ Google Chrome v

[C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] - Apagado [Startup_URLs] : [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

-\\ Chromium v


*************************

AdwCleaner[R0].txt - [15935 bytes] - [16/05/2015 15:55:54]
AdwCleaner[S0].txt - [13793 bytes] - [16/05/2015 15:56:39]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [13853 bytes] ##########
kamia
kamia
Iniciante
Iniciante

Mensagens : 11
Reputação : 0
Data de inscrição : 16/05/2015

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por caedurodrigues Dom 17 maio 2015, 21:43

Boa noite kamia,

  • Baixe: <[Tens de ter uma conta e sessão iniciada para poderes visualizar este link] ><[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]> ( ...Nicolas Coolman)
  • Salve-o no Disco local (C ou D).
  • Desabilite seu antivírus, e execute ZHPDiag.exe para instalar.
    [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]
  • Execute o ícone do pergaminho!
    [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]
  • Clique na opção "COMPLETA" e aguarde a conclusão.
  • Clique OK e,ao concluir, poste o relatório! ( ZHPDiag.txt )
  • Obs: O relatório por ser extenso deve ser postado em um desses sites:
  • Acesse: <[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]>
  • Ou acesse:<[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]>
  • Maiores informações:<[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]> << Hospedagem !

Um grande abraço.  problemas - Problemas na remoção do Search Protect 648673379
caedurodrigues
caedurodrigues
Analista
Analista

Mensagens : 947
Reputação : 161
Data de inscrição : 21/10/2013
Idade : 54
Localização : Apiacá

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por kamia Dom 17 maio 2015, 23:30

caedurodrigues,

Valeu pela rápida resposta.

O relatório está no link abaixo:
[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

Obrigado

Abraço!
kamia
kamia
Iniciante
Iniciante

Mensagens : 11
Reputação : 0
Data de inscrição : 16/05/2015

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por caedurodrigues Seg 18 maio 2015, 09:31

Bom dia kamia,

Desinstale um dos dois antivírus, pois podem ocorrer conflitos, tornando o seu PC inseguro e lento:
Trend Micro Titanium Internet Security v3.00
McAfee Security Scan Plus v3.8.130.10


  • Execute este script na ferramenta ZHPFix.
  • Copie estas informações que estão em vermelho para o Bloco de notas.
  • Com o Bloco de notas aberto, faça: ctrl+a >> ctrl+c.
  • À seguir, minimize o Bloco de notas.

    Script ZHPFix
    SysRestore
    P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\buscape.xml
    P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\mercadolivre.xml
    P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\navegaki.xml
    P2 - FPN:Firefox Plugin Navigator . (...) -- C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\yahoo-br.xml
    O2 - BHO: LuckyTab Class [64Bits] - {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F} . (...) -- C:\Program Files (x86)\XTab\SupTab.dll (.not file.)   =>PUP.LuckyTab
    O4 - GS\Desktop [Felipe Kamia]: Continue Live Installation.lnk . (...)  -- C:\Users\Felipe Kamia\AppData\Local\Temp\ICReinstall_nso7843.tmp  \RR (.not file.)   =>PUP.ContinueLiveInstallation
    O4 - HKLM\..\Run: [3D BubbleSound] C:\Program Files\BubbleSound\3D BubbleSound.exe (.not file.)   =>PUP.BubbleSound
    O4 - HKCU\..\Run: [AdobeBridge] Chave orfã
    O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_CD7E5BC00B5B80BC0D249F70637BC586] C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (.not file.)   =>PUP.CrossBrowser
    O4 - HKCU\..\Run: [DesktopSearch] C:\ProgramData\DesktopSearch\DesktopSearch.exe (.not file.)
    O4 - HKLM\..\Wow6432Node\Run: [mbot_br_759] Chave orfã
    O4 - HKLM\..\Wow6432Node\RunOnce: [Update] C:\Users\Felipe Kamia\AppData\Roaming\ASPackage\ASPackage.exe (.not file.)   =>PUP.ASPackage
    O4 - HKUS\S-1-5-21-174019988-414781078-1319990136-1000\..\Run: [AdobeBridge] Chave orfã
    O4 - HKUS\S-1-5-21-174019988-414781078-1319990136-1000\..\Run: [GoogleChromeAutoLaunch_CD7E5BC00B5B80BC0D249F70637BC586] C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe (.not file.)   =>PUP.CrossBrowser
    O4 - HKUS\S-1-5-21-174019988-414781078-1319990136-1000\..\Run: [DesktopSearch] C:\ProgramData\DesktopSearch\DesktopSearch.exe (.not file.)
    O23 - Service: mail update Service (mailUpdate) . (...) - C:\ProgramData\MailUpdate\mailUpdate.exe (.not file.)   =>PUP.MailUpdate
    O23 - Service: Util Edu App (Util Edu App) . (...) - C:\Program Files (x86)\Edu App\bin\utilEduApp.exe (.not file.)    
    [MD5.3A1D89B89C9D62951957F0839578DD9B] [APT] [p9Q3WgaiMUjm9sMDRiW0] (...) -- C:\Users\Felipe Kamia\AppData\Roaming\p9Q3WgaiMUjm9sMDRiW0.exe   [1579520]
    [MD5.AB6818A7FF17230A6E5119F6CDD1F85B] [APT] [W1BPMCOTWQ3Wk] (...) -- C:\Users\Felipe Kamia\AppData\Roaming\W1BPMCOTWQ3Wk.exe   [1246720]
    [MD5.1C7FF4BFACDDD04E3504DCB1BA5987ED] [APT] [WSUFTY] (.Cinema PlusV16.03.) -- C:\Users\Felipe Kamia\AppData\Roaming\WSUFTY.exe   [1380352]   =>PUP.CrossRider
    [MD5.00000000000000000000000000000000] [APT] [{34714184-0302-4695-97BF-3B0C4FFA8BA3}] (...) -- C:\Users\Felipe Kamia\AppData\Roaming\oursurfing\UninstallManager.exe (.not file.)   [0]   =>Hijacker.OurSurfing
    O39 - APT: WSUFTY - (.Cinema PlusV16.03.) -- C:\Windows\Tasks\WSUFTY.job   [1366]   =>PUP.CrossRider
    O39 - APT: WSUFTY - (.Cinema PlusV16.03.) -- C:\Windows\System32\Tasks\WSUFTY   [1366]   =>PUP.CrossRider
    [HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}]   =>Adware.Graftor
    [HKCU\Software\Baixaki]    
    [HKCU\Software\CinemaP-1.9cV16.03-nv-ie]   =>PUP.CrossRider
    [HKCU\Software\ProductSetup]   =>Adware.InstallCore
    [HKLM\Software\Wow6432Node\Infonaut_1.10.0.14]   =>PUP.Infonaut
    [HKLM\Software\Wow6432Node\navegaki]
    O45 - LFCP:[MD5.D99FC2C8B83E707F5483B8A64C53540E] - 17/05/2015 - 16:31:05 ---A- - C:\Windows\Prefetch\CROSSBROWSE.EXE-9D619136.pf   =>PUP.CrossBrowser
    O45 - LFCP:[MD5.5365BA525F948BBFF62E158012EFC3D7] - 17/05/2015 - 16:31:41 ---A- - C:\Windows\Prefetch\GLOBALUPDATE.EXE-AFA6DA21.pf   =>PUP.GlobalUpdate
    O45 - LFCP:[MD5.7DA6B808D35317BEBAC7AD15022DB849] - 17/05/2015 - 16:31:18 ---A- - C:\Windows\Prefetch\MAXCOMPUTERCLEANER.EXE-10ABA774.pf   =>PUP.MaxComputerCleaner
    O45 - LFCP:[MD5.464EC5746B793218229BCB99E8CD0998] - 17/05/2015 - 16:30:12 ---A- - C:\Windows\Prefetch\SMARTWEBAPP.EXE-7725F2FF.pf   =>PUP.SmartWeb
    O45 - LFCP:[MD5.86DA18E58ECCF0FD8E18C486582BF6AC] - 17/05/2015 - 16:30:10 ---A- - C:\Windows\Prefetch\SMARTWEBHELPER.EXE-8E35E612.pf   =>PUP.SmartWeb
    O45 - LFCP:[MD5.BA6722B80E49898D01D4A7C11509C6AA] - 17/05/2015 - 16:30:09 ---A- - C:\Windows\Prefetch\WPM_V20.0.0.2227.EXE-FA974C95.pf   =>PUP.WpManager
    O51 - MPSK:{e79fe302-145f-11e2-aac6-e006e6ddd7a0}\AutoRun\command. (.No owner - Sid Meiers Civilization Beyond Earth (c) 2K Setup.) -- E:\setup.exe
    O51 - MPSK:{eddb48d9-f1ae-11e1-86a7-e006e6ddd7a0}\AutoRun\command. (...) -- E:\SISetup.exe (.not file.)
    O61 - LFC: 16/05/2015 - 23:23:08 ---A- . (.Cinema PlusV16.03.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\8968.exe   [1480192]   =>PUP.CrossRider
    O61 - LFC: 16/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.401842\GoogleCrashHandler.exe   [72872]   =>PUP.GlobalUpdate
    O61 - LFC: 16/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.401842\GoogleUpdate.exe   [68608]   =>PUP.GlobalUpdate
    O61 - LFC: 16/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.401842\GoogleUpdateBroker.exe   [46080]   =>PUP.GlobalUpdate
    O61 - LFC: 16/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.401842\GoogleUpdateOnDemand.exe   [46080]   =>PUP.GlobalUpdate
    O61 - LFC: 16/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.401842\goopdate.dll   [761856]   =>PUP.GlobalUpdate
    O61 - LFC: 16/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.401842\goopdateres_en.dll   [26792]   =>PUP.GlobalUpdate
    O61 - LFC: 16/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.401842\npGoogleUpdate4.dll   [220672]   =>PUP.GlobalUpdate
    O61 - LFC: 16/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.401842\psmachine.dll   [155648]   =>PUP.GlobalUpdate
    O61 - LFC: 16/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.401842\psuser.dll   [155648]   =>PUP.GlobalUpdate
    O61 - LFC: 16/05/2015 - 23:23:09 ---A- . (.Cinema PlusV16.03.) -- C:\Users\Felipe Kamia\AppData\Roaming\WSUFTY.exe   [1380352]   =>PUP.CrossRider
    O61 - LFC: 17/05/2015 - 23:23:08 ---A- . (.Cinema PlusV17.05.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\1295.exe   [14117648]   =>PUP.CrossRider
    O61 - LFC: 17/05/2015 - 23:23:08 ---A- . (.Software.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\is-87KNH.tmp\package_BubbleSound_installer_multilang.exe   [484197]   =>PUP.BubbleSound
    O61 - LFC: 17/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.388329\globalupdate.exe   [68608]   =>PUP.GlobalUpdate
    O61 - LFC: 17/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.388329\globalupdateBroker.exe   [46080]   =>PUP.GlobalUpdate
    O61 - LFC: 17/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.388329\globalupdateCrashHandler.exe   [68608]   =>PUP.GlobalUpdate
    O61 - LFC: 17/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.388329\globalupdateOnDemand.exe   [46080]   =>PUP.GlobalUpdate
    O61 - LFC: 17/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.388329\goopdate.dll   [761856]   =>PUP.GlobalUpdate
    O61 - LFC: 17/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.388329\goopdateres_en.dll   [22528]   =>PUP.GlobalUpdate
    O61 - LFC: 17/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.388329\npglobalupdateUpdate4.dll   [220672]   =>PUP.GlobalUpdate
    O61 - LFC: 17/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.388329\psmachine.dll   [155648]   =>PUP.GlobalUpdate
    O61 - LFC: 17/05/2015 - 23:23:08 ---A- . (.globalUpdate.) -- C:\Users\Felipe Kamia\AppData\Local\Temp\comh.388329\psuser.dll   [155648]   =>PUP.GlobalUpdate
    O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) --  C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\Application\chrome.exe" [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]   =>PUP.StartSearch
    [MD5.3A1D89B89C9D62951957F0839578DD9B] [SPRF][20/04/2015] (...) -- C:\Users\Felipe Kamia\AppData\Roaming\p9Q3WgaiMUjm9sMDRiW0.exe   [1579520]
    [MD5.AB6818A7FF17230A6E5119F6CDD1F85B] [SPRF][20/04/2015] (...) -- C:\Users\Felipe Kamia\AppData\Roaming\W1BPMCOTWQ3Wk.exe   [1246720]
    [MD5.1C7FF4BFACDDD04E3504DCB1BA5987ED] [SPRF][16/05/2015] (.Cinema PlusV16.03 - CinemaP-1.9cV16.03 exe.) -- C:\Users\Felipe Kamia\AppData\Roaming\WSUFTY.exe   [1380352]   =>PUP.CrossRider
    SS - | Auto 22/07/1658 0 |  (mailUpdate) . (...) - C:\ProgramData\MailUpdate\mailUpdate.exe   =>PUP.MailUpdate
    SS - | Auto 22/07/1658 0 |  (Util Edu App) . (...) - C:\Program Files (x86)\Edu App\bin\utilEduApp.exe    
    [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}]   =>PUP.LuckyTab^
    [HKLM\SYSTEM\CurrentControlSet\Services\mailUpdate]   =>PUP.MailUpdate^
    [HKLM\Software\Classes\AppID\secman.DLL]   =>PUP.Babylon
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:3D BubbleSound   =>PUP.BubbleSound^
    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]:Update   =>PUP.ASPackage^
    C:\Users\Felipe Kamia\AppData\Roaming\WSUFTY.exe   =>PUP.CrossRider^
    C:\Windows\Tasks\WSUFTY.job   =>PUP.CrossRider^
    C:\Windows\System32\Tasks\WSUFTY   =>PUP.CrossRider^
    [HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}]   =>Adware.Graftor^
    [HKCU\Software\CinemaP-1.9cV16.03-nv-ie]   =>PUP.CrossRider^
    [HKCU\Software\ProductSetup]   =>Adware.InstallCore^
    [HKLM\Software\Wow6432Node\Infonaut_1.10.0.14]   =>PUP.Infonaut^
    ServiceStop:Util Edu App
    EmptyClsid
    FirewallRaz
    EmptyPrefetch
    EmptyTemp
    EmptyFlash


  • Abra a ferramenta ZHPFix. <[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]>
  • Clique em IMPORTAÇÃO > OK
  • Clique "GO".
  • Poste o Relatório!


Um grande abraço.  problemas - Problemas na remoção do Search Protect 648673379

[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem] Esse script foi elaborado somente para este computador, de acordo com os arquivos e chaves presentes.
Aos visitantes: Se estiverem com um problema semelhante, não utilizem esse script, pois o uso sem supervisão pode causar danos ao sistema.
caedurodrigues
caedurodrigues
Analista
Analista

Mensagens : 947
Reputação : 161
Data de inscrição : 21/10/2013
Idade : 54
Localização : Apiacá

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por kamia Seg 18 maio 2015, 11:33

caedurodrigues,

Obrigado pela rápida resposta.

- McAfee Security Scan Plus v3.8.130.10

Rodei o ZHPFix como explicado.
Segue o relatório abaixo:


Rapport de ZHPFix 2015.4.9.5 par Nicolas Coolman, Update du 18/03/2015
Fichier d'export Registre :
Run by Felipe Kamia at 18/05/2015 11:30:47
High Elevated Privileges : OK
Windows 7 Business Edition, 64-bit Service Pack 1 (Build 7601)

Reciclagem vazia (00mn 07s)
Prefetcher vazio

========== Processo memória ==========
ELIMINÉ: Memory Process: C:\Users\Felipe Kamia\AppData\Roaming\p9Q3WgaiMUjm9sMDRiW0.exe
ELIMINÉ: Memory Process: C:\Users\Felipe Kamia\AppData\Roaming\W1BPMCOTWQ3Wk.exe

========== Estado dos serviços ==========
Util Edu App Parado

========== Chaves do Registo ==========
ELIMINÉ: CLSID BHO: {51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}
ELIMINÉ: Service: mailUpdate
ELIMINÉ: Service: Util Edu App
ELIMINÉ: HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
ELIMINÉ: HKCU\Software\Baixaki
ELIMINÉ: HKCU\Software\CinemaP-1.9cV16.03-nv-ie
ELIMINÉ: HKCU\Software\ProductSetup
ELIMINÉ: HKLM\Software\Wow6432Node\Infonaut_1.10.0.14
ELIMINÉ: HKLM\Software\Wow6432Node\navegaki
ELIMINÉ CLSID MPSK: {e79fe302-145f-11e2-aac6-e006e6ddd7a0}
ELIMINÉ CLSID MPSK: {eddb48d9-f1ae-11e1-86a7-e006e6ddd7a0}
ELIMINÉ: HKLM\Software\Classes\AppID\secman.DLL

========== Valores do Registo ==========
ELIMINÉ RunValue: 3D BubbleSound
ELIMINÉ RunValue: AdobeBridge
ELIMINÉ RunValue: GoogleChromeAutoLaunch_CD7E5BC00B5B80BC0D249F70637BC586
ELIMINÉ RunValue: DesktopSearch
ELIMINÉ RunValue: mbot_br_759
Ausente Valor Perfil Padrão: FirewallRaz :
Ausente Valor Perfil Domínio FirewallRaz :
ELIMINÉ: FirewallRaz (None) : {6306E906-A0FA-4012-B803-7AA419CD2B09}

========== Pastas ==========
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{006AD24F-1C53-4600-84F9-EAC20F13E309}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{012C296A-FFCE-4238-870D-24C85F961D0B}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{018CD0C0-D1B0-4C4C-AA13-6551C05725BC}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{03648EFF-B733-4F0F-B27E-3FEE5FE4B188}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{04C38BCF-5DE9-4E5A-8CBC-D951FCFD480E}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{05581C6D-9232-4885-A4C9-CBA26B742472}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{06F5BBCD-1CF5-45A0-89A8-430DCEB33B4C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{0713458B-0CF5-4B80-BE32-B8624E032B5F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{0730E7EC-1ADB-49BD-B389-2C3E2C11EAB8}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{08DF6F40-064E-4EE1-8719-DCE9A3B00DC6}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{08F5A9BE-272F-432E-B3A1-618F76C93E09}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{092D1B12-89E4-4B67-BA74-F79DF8D1CB20}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{0A949090-FB8B-405B-A423-EA0369E1EA3B}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{0B4DC884-D067-4C6D-A82A-BB163A80CB84}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{0BC3E4BB-8315-4A2E-B4AD-76CF794B8F3B}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{0C6F4C4B-87A4-4DD0-BB7B-15E2D218E395}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{0C939A4F-9CDE-44E6-9121-4712143E8063}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{0DBFD1CF-68CF-48EE-A8DB-F3E171093473}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{0DD63BB7-1E53-43AB-8CBA-BE7D79546CEA}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{0E9E8AE9-26B0-4E81-AA45-28F2D1073805}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{0EC6031E-DF17-4722-B776-D8617C84C63A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{0ECD6164-B7C6-4F87-9626-FB99C795DA97}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{10261A1D-E3A4-4E44-8771-4739EFF8AD8F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{1242F8E8-5566-494A-90A5-5FD288A90F57}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{125E009E-BBC2-4E47-BAAA-573A3524E7F7}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{13BFDC2B-BA31-4EE4-8049-07DC1057238C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{141B02DE-624B-4068-8924-1C53773DDC82}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{1430DB0F-6F46-4303-80E9-EC8866B328EB}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{14457516-9745-4A3C-9F92-75CED9C63B14}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{15361689-02AE-484B-8195-3DDA8F1B4A77}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{169B3A8E-4EC5-4BD3-A0FF-152571343171}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{17ABCCAD-DF55-4B6B-9118-37AB7EF60D57}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{18D48E49-EC9C-48B3-B8C3-B46E975970CA}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{1904366F-B78D-46E5-B5ED-4C0AF0FECF89}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{1937F617-AF9D-4534-A778-73C7C86AC112}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{1BBE9295-FFAE-42E3-93E1-647BD669A417}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{1BD38F9F-5FE5-4D66-B06E-496A11C21B07}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{1DDCF71E-CFE9-4863-B8AE-2CEACF610E63}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{1DEE5289-8922-42F3-AFFA-CF3822052198}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{20F2CB87-9C2F-4F07-BC03-5CB9CBFB55E9}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{214BDF6F-7680-4E39-90A7-94D0FA185F1D}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{22E88457-EE69-4A80-B829-CE0514DCA789}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{247A87BF-B747-4B2E-BFBE-E1F5C7E39A30}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{253A6417-13BB-4625-B9BE-D4C5ABFA730F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{25B53655-D342-48C3-A7DD-7F4977DF7356}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{279758A3-4E84-4EDD-B2E7-457C833A7D57}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{281BD7BA-6F6C-4713-8F5B-78C2E2B81A1E}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{28B7617A-F130-4320-BBBD-E8552F7E5A0E}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{293D3A13-02AD-450B-94A0-D4898839F41C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{2BDB8903-4DDA-42F0-A22C-DDAA24CEC921}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{2BE78EE9-BD8F-4C2C-84D5-E98E76EFB413}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{2CFB0C45-7CAB-4CE0-B7D3-8186E6E678AD}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{2E00FF30-7A0C-460B-A7E8-0213F3344A8C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{2E914974-4A06-4649-82E5-41C88C76AF86}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{2FE0D708-E4A5-4C9F-BCAE-4CEA850E6208}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{31FC91CA-A131-4933-A84D-E6988A27131B}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{33239D1B-8C78-4936-8A5C-279F34DD124D}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{334FD619-8F3A-4DA1-8E3D-8063225F6225}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{3471102F-C9EB-418D-A288-4BE069E47D65}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{348E1231-E6CD-4359-9651-92FD55E3AFD3}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{35C5E657-7601-462B-A48E-E24F39062A52}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{37B23E9E-BC3A-4EF0-9A36-62956CB16E74}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{37BC33A7-99D3-4A77-85CC-282931A9AD40}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{38C7CE0C-133C-4C24-91BD-D5E8333E3938}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{3AC079B7-A468-48F0-AD2F-CF3536A87932}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{3B4903E4-EFA5-4468-AA86-43DFAD4CB938}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{3C21839C-70EB-43FA-A781-3EB4A604CC75}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{3E4646D9-B265-4891-8502-5E554057DEF8}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{3F0A807A-2C97-4ED9-8C18-1B1C40E11683}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{3F9109D4-52AB-4CB9-97A4-597536389099}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{40DCE700-A018-49D9-8C26-70A7DCC99873}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{414870C9-E223-44EC-A7E9-4FB38ADCA5AD}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{41FD11BC-5F99-4361-9FE0-017EDC56DA60}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{42F7B6D1-D152-4136-88B4-7B5143C6A1EA}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{44810156-11CA-4D0C-9326-27193FFA2190}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{452C5FB8-CBBB-4658-A9A7-641FC0C8C3D4}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{47108E80-B102-460E-9D99-C132AE3F7111}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{482C9AB3-285A-4AA5-A466-3EBC3556C921}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{498C04DD-C0D6-44FA-A527-7A43504DEF6F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{49C26C37-C320-4A48-AF9C-FB35B96AC200}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{49D2BEBE-F369-4F89-8AA7-70C5B70A8F65}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{4A1302FA-02D0-4436-B344-327061A08875}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{4A5FE923-ABC9-4102-82E0-BCCB20BE734E}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{4A8A280B-71B3-40D4-9084-1A56EFF96D11}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{4B02E854-5E2A-4242-8B36-380B8B373402}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{4CEC3E55-5489-4ABE-AAF2-72AD0806BB01}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{4E754A85-2346-4063-A081-829CCBFF0A29}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{4F1A3903-EBD9-4B33-99C8-372BC8D25AA0}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{4FAFBEED-073F-4805-99F1-1F94E452274A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{501103FD-5437-4EA6-9515-9A0DC383C3AA}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{50F17A43-C0EC-4D46-810B-C5E1C9D7D017}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{517ED41D-4953-405C-975C-684BF75A5434}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{5194072C-4F86-4B79-9B26-3297E1D7C076}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{51F3FB0D-7A97-4615-8E41-B2F51FAF58BE}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{523509F7-0297-4D4D-9BC1-5DF62B065E03}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{528804A7-0FDE-4B36-8F07-C3A6634A75A7}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{52A23DB0-1DCB-44C7-A766-0679D3E06B18}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{534BD088-69F3-4547-B982-EC7DDF17C43F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{5354B664-844A-4419-896D-5CA9C96BBA89}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{53C9A36B-7DD4-4A68-A71A-9F41DB14ACDD}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{543679FB-16AF-41BD-97BE-C8B44F0F074C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{54AD3735-2935-421D-AE93-C9E04E41E9BA}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{5520A9A1-9804-4D3B-ADFA-055F19F7E76A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{55996BBB-9942-4FE6-BE73-CF6FC04D97C5}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{59143811-AE4F-45F9-A3BA-CCE87BC86368}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{597A673A-35EB-48D5-988C-49F5F9318749}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{5B56EC34-11D6-45D0-ADAC-45CA46B7D4D4}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{5BDCADAF-7A17-431A-AEF8-E0949A989C56}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{5CD69F9B-C6DD-48FE-A3AD-75AC3D7619ED}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{5D918956-7F15-4F03-9A43-B057FA225C08}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{5DDF600B-60E0-402E-BC9A-95166A9184D0}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{5DFA3B57-A68A-440A-B74D-ED77CF329621}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{5E4F47D7-A494-4AAE-B095-20D1D9AC01B6}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{60AB9A4E-9CBA-4450-9530-8E071D14FC9A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{619ED81B-94A0-4CCE-AAFB-D829754CC18E}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{635B5073-7D24-4FE7-9B92-05C87D34B489}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{63B962D2-3DF3-4E1B-BD07-75AFE060AC90}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{63BB760E-AC50-4B12-97EB-33828ED13694}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{63C58CFE-C922-4621-9D3F-FCDC0F6C26B3}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{6521FD24-B8D0-4437-A37E-A3A4C09ECD44}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{65996F9B-2EEA-4559-BCB7-2894E0D6FA8B}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{68105E5E-AA18-4213-BC04-C603AC0057F8}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{689101DD-09E1-4B73-9EDE-50C19D1CF44D}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{694242DE-89CF-40EB-912F-4324B01CFF7F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{6A008280-D72D-4C46-BCF2-99491843CE1A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{6CC8E9F0-3A9D-434F-9A87-14DC28A3E86A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{6E048A5A-861E-49B7-B7A1-1038F8C9E398}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{6E0E7E26-F9E3-4B0B-9B30-F755277E4968}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{6ED1A8FE-FC17-432B-BC67-313585E93BE9}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{6F034177-47FB-4E4B-AC2D-915D2987575D}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{73CB7C28-8B1D-4338-9CC1-ABCC85F63840}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{75011F2E-C7D2-4AA0-AB98-3192B1AD5BCA}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{758E7475-6ADD-420A-BDE7-A7EF8046AB30}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7675F7CD-B0F4-4AEE-BA48-A40A85284534}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7683ED46-C2D8-4718-82F9-389FDCFBD988}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{780A9D31-227F-48A6-B8D1-ABBC1C8D4770}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{786FBF22-B65B-4439-8823-1996761385A5}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{792FFE6A-B540-4842-8A50-2E73E1D58062}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7A96EB53-0854-4BC2-84E7-D938CF01EB10}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7AFF00AD-2F3E-4636-B888-E0454432D073}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7BCD4756-A59E-4E77-8398-54D5E7B7C684}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7BED0804-4C72-4E80-B3EA-D777ED3564F7}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7BF69529-8FDD-419C-9777-FF9B66E7E15A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7C30B2A6-6368-4409-A601-8C069166BB57}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7C41FF0F-5F27-4C05-8455-1FDA806AE750}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7C586180-405C-4639-AE5E-6F87403F172D}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7D07ADE6-16C6-415F-8C4A-EF15391E1D6C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7D2ECB44-B669-4D6E-8F3D-AF788EC18AA2}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7E5B05D5-6BFF-4DBF-8F52-F419B789BFC6}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7EBDE132-2659-4635-98C8-32575F18F74F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7F5FC9D3-734A-4F7D-B6C9-EAFC3C300178}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{7F637530-75D2-4A64-9D63-661306A3DAAE}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{803E88E4-B5FA-4B26-B97C-BE7B5C7412B5}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{80F2002F-B0BB-492A-89DA-74489EEDD240}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{81BCFF50-F8C3-4F55-B862-E45F531453A0}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{81C1D65B-AF32-4F73-9800-73812ECF099C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{8889764B-B5B5-44F1-A709-8F5B7C6B6655}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{892E0BD3-8E51-49C4-8F3E-4D2A02DBD1F4}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{8CCB2630-A9DB-4798-9E46-3BF1C11BA926}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{8E404C16-0272-4426-93D4-21708055EB8D}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{8EB48297-E971-4405-9259-67698B9CC68F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{8FA7CBF5-1539-4B9F-B6F3-80B2EC34BF7F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{8FE1DB8F-C2F0-4CD1-96ED-5B34CB476FCB}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{908C189D-2B48-40E8-9880-70B83841AD37}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{90D128E8-1757-479D-A73F-D959D3F918A6}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{92AD8651-5444-49F2-86BB-F75AD137D67B}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{948614AA-B895-4F09-ACDD-95AC92A1F304}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{95D270F9-6648-4E3C-BA5A-D1D19698F652}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{979020B6-FC70-4E75-A56E-720807F9372B}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{97CFF749-9F14-405B-B261-6BCC565A74A2}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{9811F2CE-FF00-4238-B9D4-B3BECB1F12F7}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{9A95E3A9-A701-4BAC-B2B6-4A3FFF12037A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{9BD86D1D-E361-4F1A-83F2-EDB4DAB2B795}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{9CF28C74-84E8-444C-A443-197DAD63CC81}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{9F3F3151-2942-4EC8-9743-97EE41B1EAD9}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{A066B08A-5460-4A0E-A963-29357C995BAF}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{A1E37B72-F307-47D9-AC77-4A857594496E}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{A26FD04E-020B-4D95-867C-6A864084C900}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{A49E61A8-E4AE-4A47-8AED-7B85B2C50DC4}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{A6D07116-22A6-42CE-A304-617D3568475C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{A6DCFE54-E8A3-4BD6-B565-A25CD450C103}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{A6F3441E-C309-4913-B6C1-17E560EFB52F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{A8147050-FEB1-4D51-B7F6-6486B0A25C46}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{A9363AED-F176-4D85-95AC-D9FFB8E38CE4}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{A95144A5-D5FE-4671-AEEF-AD0B023DF41B}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{AA6601D5-98D7-480F-B028-132AA6E10E84}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{AAF2555A-14AA-421B-BE7E-8C3BB4B94904}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{AB04093B-18DA-4649-89D6-5F585346FD92}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{AC2A440D-07A6-485B-A24B-2DCCAF794683}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{AE1A647F-EA0D-4785-930B-24528FDB699E}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{AED27964-6DA5-4800-A5BD-C5C03D6814DD}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{AF19683B-E753-4CC5-864C-5F8D3E4A267A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{AF837B4D-6C5B-49BE-A550-C7FEA5F81A3C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B0089C5C-0871-4956-A6F4-ABA619448D79}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B02FE973-262B-4FEE-9635-2328F325F358}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B2F9E9F1-8023-4DFC-B77C-BEC79D3B4AEC}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B3DB650F-BEF5-4EDE-8916-D534DA715A02}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B56184E8-70AD-4AC7-A1B8-DAA374076B79}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B56DDBCB-16B8-46AD-9502-B4117C4E151B}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B573FD43-E9CB-49CD-AD63-58E94F1F83B2}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B63EFD34-5B49-48F0-B1BA-48DE284592DA}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B678C542-062E-405F-BBE5-E10CD27B3185}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B67C597F-42BA-4987-BCE8-A8393972CFB2}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B67D8559-8241-49FA-9CFB-10BBFA19958A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B72E2A20-7747-4697-AE17-B782B2B8B498}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B76438D8-3B46-401B-AB12-D0B0BD6E0CCE}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B7B07968-0B48-4284-B39B-0B5E09B04EBE}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B829617F-C64E-4244-B30F-53249F75612F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{B883DA1D-ED82-406C-810F-83AC87175EFF}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{BA56D509-E27E-46FF-8397-6EFDF348E59C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{BAE99A77-F418-47AA-B257-8187C4233EED}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{BB465F15-5ADC-4F3C-9E2B-67C0584AD4B6}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{BC7558E6-A691-4F0C-817D-8998A263B356}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{BD24DE6F-02AE-4076-A953-4CAFC7744558}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{BDB0B2E4-F46D-491D-8965-4188D64C84A7}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{BEA96815-01C2-438F-8508-7C18AEA83391}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{C0FAE393-AAC5-4AAF-8C1A-111E7EB2E798}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{C147CA52-7A43-430F-8AA4-52085C6972B5}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{C229788C-680D-4DE4-B54D-6516283D6DBD}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{C31A90C8-D1FB-4000-80A6-19276F58DA7D}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{C5F2E322-1665-4D66-A8D1-CC1F3479DEFA}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{C61653A5-1607-4BB5-92F7-F9B75536C331}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{C8E1C8E1-75D4-4FC2-9CF5-624F643E933A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{C9BD8461-161A-46E4-B732-BAA3FB1FB278}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{C9E9BFA5-ACDA-46C1-AB69-0546BF3A1A9D}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{CB47EFDF-3D44-4B0C-8A98-636C3E4DC4F4}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{CBFCAD43-EEAD-4D2B-A6F0-DB5753B3E2AC}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{CC239DB1-98B9-4B4C-A0C6-A134A0A7AF39}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{CC85A954-CDA3-4046-9F3A-E17ED6593654}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{CDB116C9-5F69-48C0-9F8B-6A5938427C2E}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{CE7687C7-2205-4EB1-9D75-1C994F8A0A7C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{D1918F92-2054-4835-AC30-D10FDBC5723D}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{D2B00F6C-3306-44DD-AFDF-928294524C94}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{D2D12FAC-9D0D-4E4D-A69F-D3486E0F75D1}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{D398612D-3AF3-45DC-9845-91FBC5812EE6}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{D3E5EE80-E084-4106-B584-1F85C933CEA8}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{D5B51AEB-9C52-4B85-A183-BBF2E3A89E28}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{D76FD8A5-C3A1-45E2-B45F-4F45EC5FC52D}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{D8516C97-FF88-48A8-9E67-F3A178A24211}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{DAEB489F-EA68-4538-91F6-B282E91E1680}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{DC427A4C-1E2D-4BC3-B99D-A0A950D4E0EC}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{DD02700B-B7B9-4275-B7C8-14E4C9564A2A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{DD7F455A-FCE8-4A79-8024-F89EAC3E268B}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{DDEB9BEE-1D72-4A59-91DB-A9BB7F581F81}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{DE429EA7-D531-4C3D-94D9-4C7E26C21FB4}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{E0D4EA57-F37D-451F-85F1-CE20D1C2EEA9}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{E0DC7009-CEE8-48F1-9927-0D2439A8F924}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{E2585FFC-759E-4BBD-9E85-BE3C5701DF5C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{E2B32DF5-8AA3-4AF0-B4B0-7E2500A4CFE1}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{E3A64219-35BE-4F2F-A06C-13DE22653F46}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{E53AE24A-7255-4C8B-8E79-9BF3581C1A33}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{E5545FC7-3C0D-4D43-947C-9A50A6FB6040}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{E944D57B-1DA5-4969-8991-378F065DFF53}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{EC0A1666-4893-4270-AA38-0BA9659F808B}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{EC7D13B8-AA73-47DF-8BE6-2A98C14E4AE6}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{EDE1AE9C-510B-408A-8AB3-940049221CB7}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{EEEAB574-5B88-49E7-B0E9-CBC2BAE83AA8}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{EF47D550-1818-4F07-9E43-429DB783A22F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{F01055A8-F234-4F0C-9CB1-4B88B412195D}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{F34B9EAE-9422-481D-9C56-DAA8C7A0CC12}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{F36DFAD3-3E07-419A-A1D5-25E9C6A0108F}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{F436CB9F-B38B-497E-9F3C-45C19B6FF961}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{F5520802-931D-4553-85B0-07B2A7ADDFBE}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{F5882784-E375-48DE-9349-5C0B5CF05BF5}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{F6EE7F9B-F8FF-4B3C-9EDD-A41B9FC2ED6C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{F75B79FC-5255-47EB-B43F-9D35087E991C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{F7E215F9-435F-4E27-92AB-4EC0C1EFF9FA}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{F82E5D95-464F-4026-B887-93205D838791}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{F885BB2E-A29A-4093-821A-7F4158EBAC5A}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{F8C81AA2-35AF-4A5C-A07F-0CD73265914C}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{FA000E9A-E0E5-426C-BF37-010AEDAE32EA}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{FCB5FC10-B1B6-4E33-B138-694605CC3425}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{FD2D6BB0-F40B-4B6F-BDC5-3E8E993C4498}
ELIMINÉ: C:\Users\Felipe Kamia\AppData\Local\{FF923CDA-9EFD-407B-BC78-D80DDC6A6D23}
ELIMINÉ Temporários windows (168)
ELIMINÉ Flash Cookies (0)

========== Ficheiros ==========
ELIMINÉ: c:\program files (x86)\mozilla firefox\browser\searchplugins\buscape.xml
ELIMINÉ: c:\windows\prefetch\crossbrowse.exe-9d619136.pf
ELIMINÉ: c:\windows\prefetch\globalupdate.exe-afa6da21.pf
ELIMINÉ: c:\windows\prefetch\maxcomputercleaner.exe-10aba774.pf
ELIMINÉ: c:\windows\prefetch\smartwebapp.exe-7725f2ff.pf
ELIMINÉ: c:\windows\prefetch\smartwebhelper.exe-8e35e612.pf
ELIMINÉ: c:\windows\prefetch\wpm_v20.0.0.2227.exe-fa974c95.pf
ELIMINA REINICIAR: e:\setup.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\8968.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.401842\googlecrashhandler.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.401842\googleupdate.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.401842\googleupdatebroker.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.401842\googleupdateondemand.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.401842\goopdate.dll
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.401842\goopdateres_en.dll
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.401842\npgoogleupdate4.dll
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.401842\psmachine.dll
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.401842\psuser.dll
ELIMINÉ: c:\users\felipe kamia\appdata\roaming\wsufty.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\1295.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\is-87knh.tmp\package_bubblesound_installer_multilang.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.388329\globalupdate.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.388329\globalupdatebroker.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.388329\globalupdatecrashhandler.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.388329\globalupdateondemand.exe
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.388329\goopdate.dll
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.388329\goopdateres_en.dll
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.388329\npglobalupdateupdate4.dll
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.388329\psmachine.dll
ELIMINÉ: c:\users\felipe kamia\appdata\local\temp\comh.388329\psuser.dll
ELIMINÉ Temporários windows (590) (120.352.914 octets)
ELIMINÉ Flash Cookies (0) (0 octets)

========== Tarefa planificada ==========
ELIMINÉ: p9Q3WgaiMUjm9sMDRiW0
ELIMINÉ: p9Q3WgaiMUjm9sMDRiW0
ELIMINÉ: W1BPMCOTWQ3Wk
ELIMINÉ: W1BPMCOTWQ3Wk
ELIMINÉ: WSUFTY
ELIMINÉ: WSUFTY
ELIMINÉ: {34714184-0302-4695-97BF-3B0C4FFA8BA3}

========== Restauração Sistema ==========
Ponto de restauro do sistema criado com sucesso


========== Recapitulativo ==========
2 : Processo memória
12 : Chaves do Registo
8 : Valores do Registo
276 : Pastas
32 : Ficheiros
1 : Estado dos serviços
7 : Tarefa planificada
1 : Restauração Sistema


End of clean in 00mn 54s

========== Caminho do ficheiro do relatório ==========
C:\Users\Felipe Kamia\AppData\Roaming\ZHP\ZHPFix[R1].txt - 18/05/2015 11:30:55 [27994]
kamia
kamia
Iniciante
Iniciante

Mensagens : 11
Reputação : 0
Data de inscrição : 16/05/2015

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por caedurodrigues Seg 18 maio 2015, 12:35

Boa tarde kamia,



Baixe e instale a nova versão do Malwarebytes:

  • Baixe:<[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]>  (...by Malwarebytes)
  • Dê um duplo-clique no mbam-setup.exe para instalar o programa.
  • Desmarque a caixa: "Ativar trial gratuito do Malwarebytes Anti-Malware PRO"
  • Clique "Concluir".
  • Atualize o programa !
  • Escolha Verificar! >> Verificação Personalizada >> Configurar Varredura!
  • Marque as caixinhas conforme figura abaixo:
    [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]
  • Desabilite programas de proteção,ao executar o malwarebytes.
  • Para Windows Vista ou 7, clique direito no arquivo e execute-o como administrador.
  • Ps: Para determinadas infecções,o programa pedirá reboot. << Confirme!
  • Ao concluir,clique em "Ok" >> "Ver Resultados" >> "Remover Selecionados".
  • O log é automaticamente salvo pelo MBAM, e para vê-lo clique na aba Histórico >> Logs de aplicativos. Utilize o formato
    .txt para exportar o log.
    [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]
  • NÃO UTILIZAR O FORMATO .XML PARA EXPORTAR O LOG.
  • O log de Proteção e desnecessário para uma Análise, exporte sempre o log Correto.


Um grande abraço. problemas - Problemas na remoção do Search Protect 648673379
caedurodrigues
caedurodrigues
Analista
Analista

Mensagens : 947
Reputação : 161
Data de inscrição : 21/10/2013
Idade : 54
Localização : Apiacá

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por kamia Seg 18 maio 2015, 13:22

caedurodrigues,

Segue abaixo o relatório do cleaner
Assim que rodar o malwarebytes posto o relatorio aqui

~ ZHPCleaner v2015.5.18.244 by Nicolas Coolman (2015\05\18)
~ Run by Felipe Kamia (Administrator) (18/05/2015 13:19:27)
~ Forum : [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
~ Facebook : [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
~ State version : Version OK
~ Type : Reparo
~ Report : C:\Users\Felipe Kamia\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\Felipe Kamia\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
~ Windows 7, 64-bit Service Pack 1 (Build 7601)


---\\ Serviços (0)


---\\ Navegadores de Internet (5)
SUPRIMIDO: [ng0a0zdc.default] - user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine"); (PUP.SearchEngine)
SUPRIMIDO: [ng0a0zdc.default] - user_pref("browser.search.searchengine.ptid", "ima"); (PUP.SearchEngine)
SUPRIMIDO: [ng0a0zdc.default] - user_pref("browser.search.searchengine.uid", "0XmSATAX32GBXXXXXXXXXXXXXXX_4043"); (PUP.SearchEngine)
SUPRIMIDO dados: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings [Bad : Port=62748 <-Loopback>] (Hijacker.Proxy)
SUPRIMIDO dados: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings [Bad : Port=62748 <-Loopback>]

(Hijacker.Proxy)


---\\ Arquivo hosts (1)
~ O arquivo hosts é legítimo (22)


---\\ Tarefas automáticas agendadas. (0)
~ Nenhum ítem malicioso foi encontrado.


---\\ Explorer ( Arquivos, Pastas) (20)
MOVIDO pasta: C:\Users\Felipe Kamia\AppData\Roaming\unins000.exe [ - Setup/Uninstall] (Adware.Pirrit)
MOVIDO pasta: C:\Users\Felipe Kamia\AppData\Roaming\unins001.exe [ - Setup/Uninstall] (Adware.Pirrit)
MOVIDO pasta: C:\Users\Felipe Kamia\AppData\Roaming\unins002.exe [ - Setup/Uninstall] (Adware.Pirrit)
MOVIDO pasta: C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431795010-5210-8051-C2C04F325631\jnss14AF.tmp (Heuristic.Salus)
MOVIDO pasta: C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431795010-5210-8051-C2C04F325631\nsn50EC.tmp (Heuristic.Salus)
MOVIDO pasta: C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431795010-5210-8051-C2C04F325631\hnsn2A34.tmp (Generic.Trojan)
MOVIDO pasta: C:\Users\Felipe Kamia\Downloads\SoftonicDownloader_para_ultrafobos.exe [Copyright (C) 2014 - Application Installer] (PUP.Softonic)
MOVIDO pasta*: C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage (PUP.BoostSaves)
MOVIDO pasta*: C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.boostsaves.com_0.localstorage-journal (PUP.BoostSaves)
MOVIDO pasta*: C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.boostsaves.com_0.localstorage (PUP.BoostSaves)
MOVIDO pasta*: C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.boostsaves.com_0.localstorage-journal (PUP.BoostSaves)
MOVIDO pasta*: C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage (PUP.SpecialSavings)
MOVIDO pasta*: C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal (PUP.SpecialSavings)
MOVIDO arquivo: C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg (PUP.DigitalMore)
MOVIDO arquivo: C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431795010-5210-8051-C2C04F325631 (Heuristic.Salus)
MOVIDO arquivo: C:\Program Files (x86)\c19efdb4-989b-420f-8273-2708865fc7d1 (Adware.CrossRider)
MOVIDO arquivo: C:\ProgramData\9c1c5f0000025b9 (Adware.CrossRider)
MOVIDO arquivo: C:\Users\Felipe Kamia\Documents\Optimizer Pro (PUP.OptimizerPro)
MOVIDO arquivo: C:\Users\Felipe Kamia\Music\Foster The People - Torches (PUP.Torch)
MOVIDO arquivo: C:\Users\Felipe Kamia\AppData\Local\CrashRpt (SUP.CrashReports)


---\\ Registro ( Chaves, Valores, Dados ) (24)
SUPRIMIDO dados: HKCR\ChromeHTML.ABJFME4MKS7XEMUPMYRVJB77QM\Shell\Open\Command\\Default [Bad : [html] "C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\Application\chrome.exe" --

"%1"] (Broken.OpenCommand)
SUPRIMIDO dados: [X64] HKLM\SOFTWARE\Classes\.html\\Default [Bad : CRSBRWSHTML] (PUP.CrossBrowse)
SUPRIMIDO chave*: HKLM\SYSTEM\CurrentControlSet\Services\nugilevu [C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431795010-5210-8051-C2C04F325631\jnss14AF.tmp (Not File)]

(Heuristic.Salus)
SUPRIMIDO chave*: HKLM\SYSTEM\CurrentControlSet\Services\qiqejyse [C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431795010-5210-8051-C2C04F325631\nsn50EC.tmp (Not File)]

(Heuristic.Salus)
SUPRIMIDO chave: [X64] HKLM\SYSTEM\CurrentControlSet\Services\nugilevu [C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431795010-5210-8051-C2C04F325631\jnss14AF.tmp (Not File)]

(Generic.Trojan)
SUPRIMIDO chave: [X64] HKLM\SYSTEM\CurrentControlSet\Services\qiqejyse [C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431795010-5210-8051-C2C04F325631\nsn50EC.tmp (Not File)]

(Generic.Trojan)
SUPRIMIDO chave*: [X64] HKLM\SYSTEM\CurrentControlSet\Services\xygefuzu [C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431795010-5210-8051-C2C04F325631\hnsn2A34.tmp (Not File)]

(Generic.Trojan)
SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoSearchAssistant [] (PUP.SearchAssist)
SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\ytbbroker.YTBAutoSearchAssistant.1 [] (PUP.SearchAssist)
SUPRIMIDO chave*: [X64] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\mailUpdate [] (PUP.MailUpdate)
SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\globalupdate.exe [] (PUP.GlobalUpdate)
SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Wow6432Node\SuperClick_1.10.0.16 [] (PUP.SuperClick)
SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Wow6432Node\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} [] (Adware.Graftor)
SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage [] (Adware.Downware)
SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\CLSID\{1386F2A3-FEB9-4C55-AD9A-B798EE57299B} [EqualizerAPO LFX Class] (PUP.BubbleSound)
SUPRIMIDO chave: [X64] HKLM\SOFTWARE\Classes\CLSID\{1386F2A3-FEB9-4C55-AD9A-B798EE57299B}\InprocServer32 [C:\Program Files\BubbleSound\BubbleSound.dll (Not File)]

(PUP.BubbleSound)
SUPRIMIDO chave*: [X64] HKLM\SOFTWARE\Classes\CLSID\{7FDF7A92-F901-4F93-9769-A8AC41C8E563} [EqualizerAPO GFX Class] (PUP.BubbleSound)
SUPRIMIDO chave: [X64] HKLM\SOFTWARE\Classes\CLSID\{7FDF7A92-F901-4F93-9769-A8AC41C8E563}\InprocServer32 [C:\Program Files\BubbleSound\BubbleSound.dll (Not File)]

(PUP.BubbleSound)
SUPRIMIDO valor: [X64] HKLM\Software\Classes\.htm\OpenWithProgIDs\\CRSBRWSHTML [] (PUP.CrossBrowse)
SUPRIMIDO valor: [X64] HKLM\Software\Classes\.html\OpenWithProgIDs\\CRSBRWSHTML [] (PUP.CrossBrowse)
SUPRIMIDO valor: [X64] HKLM\Software\Classes\.shtml\OpenWithProgIDs\\CRSBRWSHTML [] (PUP.CrossBrowse)
SUPRIMIDO valor: [X64] HKLM\Software\Classes\.webp\OpenWithProgIDs\\CRSBRWSHTML [] (PUP.CrossBrowse)
SUPRIMIDO valor: [X64] HKLM\Software\Classes\.xht\OpenWithProgIDs\\CRSBRWSHTML [] (PUP.CrossBrowse)
SUPRIMIDO valor: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_43577BD87E9EBE7447FA71619B12E56A ["C:\Users\Felipe Kamia\AppData\Local\Google\Chrome

\Application\chrome.exe" --no-startup-window] (PUP.Vosteran)


---\\ Resultado de reparação
Reparação efectuada com sucesso
~ Este navegador está faltando ! (Opera Software)


---\\ Estatísticas
~ Items scan : 5787
~ Items encontrado : 0
~ items cancelados : 0
~ Items réparo : 52


End of clean at 13:19:40
===================
ZHPCleaner-[R]-18052015-13_19_40.txt
ZHPCleaner-[S]-18052015-13_18_42.txt
kamia
kamia
Iniciante
Iniciante

Mensagens : 11
Reputação : 0
Data de inscrição : 16/05/2015

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por kamia Seg 18 maio 2015, 15:13

Caro caedurodrigues,

Executei os passos conforme explicado.
No entanto, quando o computador estava reiniciando, apareceu uma mensagem avisando que a "consistência do disco" precisava ser testada.
O testo não pode ser executado por algum motivo (foi rápido e não consegui pegar a informação)

Após isso o windows foi iniciado e surgiu a tela de login.

Segue abaixo o log do Anti-Malware:

Malwarebytes Anti-Malware
[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

Scan Date: 18/05/2015
Scan Time: 13:26:29
Logfile: malw.txt
Administrator: Yes

Version: 2.01.6.1022
Malware Database: v2015.05.18.04
Rootkit Database: v2015.05.16.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Felipe Kamia

Scan Type: Custom Scan
Result: Completed
Objects Scanned: 661098
Time Elapsed: 1 hr, 39 min, 11 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 1
PUP.Optional.PullUpdate.A, C:\ProgramData\fJdrhPbHX\IkPHAp.exe, 2968, Delete-on-Reboot, [40dc7421563444f2ad8ea5b750b6c739]

Modules: 0
(No malicious items detected)

Registry Keys: 10
PUP.Optional.PullUpdate.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IkPHAp, Quarantined, [40dc7421563444f2ad8ea5b750b6c739],
PUP.Optional.EduApp.A, HKU\S-1-5-21-174019988-414781078-1319990136-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{EBFBDD44-C0E0-4F63-A8E6-EE5F34765238}, Quarantined, [06161f764c3e2b0be22f8dc333d07e82],
PUP.Optional.EduApp.A, HKU\S-1-5-21-174019988-414781078-1319990136-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{EBFBDD44-C0E0-4F63-A8E6-EE5F34765238}, Quarantined, [06161f764c3e2b0be22f8dc333d07e82],
PUP.Optional.PortalSepeti, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E921F400-D383-4B1B-9DE6-FCFCACFC1173}, Quarantined, [fa227f16c9c10e28762fee685ba8e21e],
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\CLASSES\APPID\GLOBALUPDATE.EXE, Quarantined, [1ffd7f16503a87af3591cda19a6bc739],
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\GLOBALUPDATE.EXE, Quarantined, [081411840e7c4de96c5a93db45c0f20e],
PUP.Optional.CrossRider.C, HKLM\SOFTWARE\WOW6432NODE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [ce4e167f9dedaa8ce0bc4a8d48bbeb15],
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\GLOBALUPDATE.EXE, Quarantined, [24f8cdc8bbcfcf678d39b9b52bdaaa56],
PUP.Optional.SuperClick.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\scfd_1_10_0_16, Quarantined, [9c806f26226878be4ee2462a8085ba46],
PUP.Optional.Crossrider.C, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\_CrossriderRegNamePlaceHolder_, Quarantined, [2af2e6af830793a357eed697759030d0],

Registry Values: 6
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\CLASSES\APPID\GLOBALUPDATE.EXE|AppID, {3278F5CF-48F3-4253-A6BB-004CE84AF492}, Quarantined, [1ffd7f16503a87af3591cda19a6bc739]
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\GLOBALUPDATE.EXE|AppID, {3278F5CF-48F3-4253-A6BB-004CE84AF492}, Quarantined, [081411840e7c4de96c5a93db45c0f20e]
PUP.Optional.CrossBrowse.C, HKLM\SOFTWARE\REGISTEREDAPPLICATIONS|Crossbrowse, Software\Clients\StartMenuInternet\Crossbrowse\Capabilities, Quarantined, [b9637a1b1f6bfa3cfe46e38ad332ea16]
PUP.Optional.GlobalUpdate.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\GLOBALUPDATE.EXE|AppID, {3278F5CF-48F3-4253-A6BB-004CE84AF492}, Quarantined, [24f8cdc8bbcfcf678d39b9b52bdaaa56]
PUP.Optional.CrossBrowse.C, HKLM\SOFTWARE\WOW6432NODE\REGISTEREDAPPLICATIONS|Crossbrowse, Software\Clients\StartMenuInternet\Crossbrowse\Capabilities, Quarantined, [ca52771ebbcfca6c162e87e68a7bd927]
PUP.Vulnerable.DellSystemDetect, HKU\S-1-5-21-174019988-414781078-1319990136-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|DellSystemDetect, C:\Users\Felipe Kamia\AppData\Local\Apps\2.0\AQJJHYJJ.LK5\2LE7LZ6G.MT8\dell..tion_0f612f649c4a10af_0005.000a_17ece8424e43daec\DellSystemDetect.exe, Quarantined, [03199ff634564beb02f14098da296e92]

Registry Data: 0
(No malicious items detected)

Folders: 5
PUP.Optional.MultiPlug.A, C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431795156-5210-8051-C2C04F325631, Quarantined, [36e65144642690a69e6c6cfeaa5ba55b],
PUP.Optional.MultiPlug.A, C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431800567-5210-8051-C2C04F325631, Quarantined, [38e4197c90fada5ce7232e3c7c8947b9],
Rogue.Multiple, C:\ProgramData\2520434090, Quarantined, [6daf2273dbaf5adc30c1b9dbc24109f7],
PUP.Optional.PullUpdate.A, C:\ProgramData\fJdrhPbHX\dat, Delete-on-Reboot, [47d502930882fb3bd7c476e79c6a05fb],
PUP.Optional.PullUpdate.A, C:\ProgramData\fJdrhPbHX, Delete-on-Reboot, [47d502930882fb3bd7c476e79c6a05fb],

Files: 87
PUP.Optional.PullUpdate.A, C:\ProgramData\fJdrhPbHX\IkPHAp.exe, Delete-on-Reboot, [40dc7421563444f2ad8ea5b750b6c739],
PUP.RiskwareTool.CK, C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\AMTLib.dll, Quarantined, [07150e87553568ce818d944e5da59f61],
PUP.RiskwareTool.CK, C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\amtlib.dll, Quarantined, [d6468e07771345f128e66b77ca38a65a],
PUP.Optional.OneClickDownloader.A, C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\File System\007\t\00\00000000, Quarantined, [a07c0f863a504fe70d056cdac33e16ea],
Trojan.Inject, C:\Users\Felipe Kamia\AppData\Roaming\ZHP\Quarantine\jnss14AF.tmp, Quarantined, [e5374e4735554aec0ebb6ee1c63d37c9],
PUP.Optional.CrossRider.A, C:\Users\Felipe Kamia\AppData\Roaming\ZHP\Quarantine\p9q3wgaimujm9smdriw0.exe.VIR, Quarantined, [1a02573ee2a88caadfb32726897901ff],
PUP.Optional.Softonic, C:\Users\Felipe Kamia\AppData\Roaming\ZHP\Quarantine\SoftonicDownloader_para_ultrafobos.exe, Quarantined, [66b67322addd68ced72bb72361a01ee2],
PUP.Optional.CrossRider.A, C:\Users\Felipe Kamia\AppData\Roaming\ZHP\Quarantine\w1bpmcotwq3wk.exe.VIR, Quarantined, [fc206233d9b1db5b9bde70e7f907ca36],
PUP.Optional.CrossRider.A, C:\Users\Felipe Kamia\AppData\Roaming\ZHP\Quarantine\c19efdb4-989b-420f-8273-2708865fc7d1\57353fd6-02cf-4eb4-a90d-6c1605950d7d.dll, Quarantined, [cf4da3f2c0ca053138082c30ce384bb5],
PUP.Optional.Nova.A, C:\Users\Felipe Kamia\AppData\Roaming\ZHP\Quarantine\c19efdb4-989b-420f-8273-2708865fc7d1\7f7595cd-5013-4154-9587-da31f6ab10b6.dll, Quarantined, [8696d0c58406e650b160d83a9a68b947],
PUP.Optional.InstallRex, C:\Users\Felipe Kamia\Desktop\Arquivos de instalação\DownloadSetup.exe, Quarantined, [9587c3d24a40f54116ded30625dc3dc3],
PUP.Optional.InstallCore.SID.C, C:\Users\Felipe Kamia\Downloads\process-explorer-16-05-32-bits.exe, Quarantined, [72aa3d5832586fc70031b4a8ef1722de],
PUP.Optional.Amonetize, C:\Users\Felipe Kamia\Downloads\ynab keygen_10924_i8905846_il345.exe, Quarantined, [bb61593c3753b2845a8074c4db276898],
PUP.Optional.Zona, C:\Users\Felipe Kamia\Downloads\ZonaSetup_latest.exe, Quarantined, [3be1573e9cee0c2a7f340a6bcf3214ec],
PUP.RiskwareTool.CK, C:\Users\Felipe Kamia\Downloads\Adobe Photoshop CS6 Extended\DLL FILE\32bit\amtlib.dll, Quarantined, [4fcda2f3ef9bc670cb4340a21be7f30d],
PUP.RiskwareTool.CK, C:\Users\Felipe Kamia\Downloads\Adobe Photoshop CS6 Extended\DLL FILE\64bit\amtlib.dll, Quarantined, [f12bafe6b9d1221440cfaf330101916f],
PUP.Optional.AnyProtect.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\AnyProtectEx\AnyProtect.exe.vir, Quarantined, [9b81b9dc11794cea6e53acae66a0ec14],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\183c272c-e4a5-4ec2-be52-11b99919ac00-1-6.exe.vir, Quarantined, [ac70f1a43c4e5adc83cce76cc442fe02],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\183c272c-e4a5-4ec2-be52-11b99919ac00-1-7.exe.vir, Quarantined, [f329dfb6b4d65bdb2d229cb75caabd43],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\183c272c-e4a5-4ec2-be52-11b99919ac00-10.exe.vir, Quarantined, [78a45b3aeaa0de58cc83a6adea1ce61a],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\183c272c-e4a5-4ec2-be52-11b99919ac00-3.exe.vir, Quarantined, [f7258510563486b02b24262d040210f0],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\183c272c-e4a5-4ec2-be52-11b99919ac00-4.exe.vir, Quarantined, [69b33065117979bd87c8440f050141bf],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\183c272c-e4a5-4ec2-be52-11b99919ac00-5.exe.vir, Quarantined, [46d6eca96327261082cd7ad90ef8e917],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\183c272c-e4a5-4ec2-be52-11b99919ac00-6.exe.vir, Quarantined, [f626088dd7b372c474db59fa9571f907],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\183c272c-e4a5-4ec2-be52-11b99919ac00-64.exe.vir, Quarantined, [f626a5f0c4c6fb3b5af5094a44c2738d],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\183c272c-e4a5-4ec2-be52-11b99919ac00-7.exe.vir, Quarantined, [809c405558323ef80f403122996df60a],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\b6afa0b7-0255-4504-923f-a212df63bdea.dll.vir, Quarantined, [9983fe97addd9d99db65cd8f27df7b85],
PUP.Optional.Nova.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\f4964e55-7a9f-47ec-9173-d354a2cc4561.dll.vir, Quarantined, [c25a464fccbe79bd5fb2b55d887a7d83],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\Uninstall.exe.vir, Quarantined, [85972d686c1e7db930105a024abc2ad6],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\UninstallBrw.exe.vir, Quarantined, [6daf365fbbcf42f4420d5201a363639d],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaPlus-3.2cV17.05\utils.exe.vir, Quarantined, [a8748510f991f145351a064d1cea39c7],
PUP.Optional.ModGoog, C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe.vir, Quarantined, [69b302936e1c8ea88e174cfdf90939c7],
PUP.Optional.ModGoog, C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe.vir, Quarantined, [c359eea74d3dce68406574d58e7410f0],
PUP.Optional.ModGoog, C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe.vir, Quarantined, [74a8197c99f156e084213d0c887a946c],
PUP.Optional.ModGoog, C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe.vir, Quarantined, [e339257022689d994e57da6f1be7fa06],
PUP.Optional.ModGoog, C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe.vir, Quarantined, [d646098ca9e184b2aafb252404feb14f],
PUP.Optional.ModGoog, C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll.vir, Quarantined, [46d6b5e0464457df277e5bee2dd57c84],
PUP.Optional.ModGoog, C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdateres_en.dll.vir, Quarantined, [42da2273acde72c415902c1d877bf010],
PUP.Optional.ModGoog, C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll.vir, Quarantined, [be5e662f7b0fd75f05a0be8b2cd6966a],
PUP.Optional.ModGoog, C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll.vir, Quarantined, [f9235e37e2a82b0b8d1855f4e41e3ec2],
PUP.Optional.ModGoog, C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll.vir, Quarantined, [2fedc0d58a0074c2822362e7a45e31cf],
PUP.Optional.EORezo, C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_br_503\gamesdesktop_widget.exe.vir, Quarantined, [aa724154711968ce34a2302be2247e82],
PUP.Optional.Tuto4PC.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_br_503\gmsd_br_503.exe.vir, Quarantined, [6cb0ebaa95f5ec4aeadc38235bab4db3],
PUP.Optional.Tuto4PC.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\gmsd_br_503\predm.exe.vir, Quarantined, [2bf153429ded92a49036b6a57e88ab55],
PUP.Optional.Browserwatch, C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchCH.dll.vir, Quarantined, [55c797fecfbbbb7bc8e5967bba4c8b75],
PUP.Optional.Browserwatch, C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowerWatchFF.dll.vir, Quarantined, [a07c8d086b1f84b2802d6ca55da90cf4],
PUP.Optional.SearchProtect, C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\BrowserAction.dll.vir, Quarantined, [d14b603563272f07882279cc61a1c040],
PUP.Optional.Giner, C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\CmdShell.exe.vir, Quarantined, [d646deb7652587af5d9e64f702049a66],
PUP.Optional.Giner, C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\HPNotify.exe.vir, Quarantined, [170502934e3cc86eca31fe5d22e4fa06],
PUP.Optional.Giner, C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\IeWatchDog.dll.vir, Quarantined, [a3796a2b8a0052e44fac38232fd706fa],
PUP.Optional.XTab.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\ProtectService.exe.vir, Quarantined, [b06c41543357ca6cfb55f91c8280cf31],
PUP.Optional.Giner, C:\AdwCleaner\Quarantine\C\Program Files (x86)\XTab\SupTab.dll.vir, Quarantined, [5ac2f2a3e8a23df95d9eadaedf27fe02],
PUP.Optional.Elex, C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir, Quarantined, [63b9395cfe8ca096c63642335ca441bf],
PUP.Optional.OptimizerPro, C:\AdwCleaner\Quarantine\C\ProgramData\{64188466-0abf-68d0-6418-884660ab1198}\hqghumeaylnlf.exe.vir, Quarantined, [cd4f870e8efc75c13e2499aaa1618c74],
Trojan.Agent, C:\AdwCleaner\Quarantine\C\Users\Felipe Kamia\AppData\Local\4C4C4544-1431784408-5210-8051-C2C04F325631\snstE7A9.tmp.vir, Quarantined, [1dffa3f27e0cb581e03d0b51c83a8080],
PUP.Optional.Tuto4PC.A, C:\AdwCleaner\Quarantine\C\Users\Felipe Kamia\AppData\Local\gmsd_br_503\upgmsd_br_503.exe.vir, Quarantined, [4ad2f69f48420d2942845506788e45bb],
PUP.Optional.Tuto4PC.A, C:\AdwCleaner\Quarantine\C\Users\Felipe Kamia\AppData\Local\gmsd_br_503\Download\majmp_gentlelatam.exe.vir, Quarantined, [ea32bed74941171f16b07be01aec60a0],
PUP.Optional.SmartWeb.A, C:\AdwCleaner\Quarantine\C\Users\Felipe Kamia\AppData\Local\SmartWeb\SmartWebApp.exe.vir, Quarantined, [3ae24f46d2b8280ec5a941c230d221df],
PUP.Optional.SmartWeb.A, C:\AdwCleaner\Quarantine\C\Users\Felipe Kamia\AppData\Local\SmartWeb\SmartWebHelper.exe.vir, Quarantined, [1309583da6e4142293db54af62a0df21],
PUP.Optional.SmartWeb.A, C:\AdwCleaner\Quarantine\C\Users\Felipe Kamia\AppData\Local\SmartWeb\swhk.dll.vir, Quarantined, [f22ad5c08bff6acc0d6110f38a782bd5],
PUP.Optional.SmartWeb.A, C:\AdwCleaner\Quarantine\C\Users\Felipe Kamia\AppData\Local\SmartWeb\__u.exe.vir, Quarantined, [03193e57f694fe3807674db6b0529c64],
PUP.Optional.Infonaut.A, C:\AdwCleaner\Quarantine\C\Windows\System32\drivers\innfd_1_10_0_14.sys.vir, Quarantined, [eb312372c8c2c175346b1f3c788e5ca4],
PUP.RiskwareTool.CK, C:\Program Files (x86)\Adobe\Adobe Bridge CS6\AMTLib.dll, Quarantined, [2af26a2b45458aac6da17d65b44e1fe1],
PUP.RiskwareTool.CK, C:\Program Files (x86)\Adobe\Adobe Photoshop CS6\amtlib.dll, Quarantined, [20fc464f305a8ea833db1bc71ee420e0],
PUP.Optional.Nova.A, C:\Program Files (x86)\AIMP3\0f02d459-5475-4e5d-9a79-4a688dfbbb38.dll, Quarantined, [021a9cf9a9e1122452bf60b249b99c64],
PUP.Optional.CrossRider.A, C:\Program Files (x86)\AIMP3\c19efdb4-989b-420f-8273-2708865fc7d1.dll, Quarantined, [cb514b4ae5a539fd76caf765b6501de3],
PUP.Optional.ZombieInvasion.A, C:\ProgramData\fJdrhPbHX\dat\Idabyu.dll, Delete-on-Reboot, [d844a2f3f5954de93cb5b2574db91de3],
PUP.Optional.PullUpdate.A, C:\ProgramData\fJdrhPbHX\dat\jDfVlXWYDI.exe, Delete-on-Reboot, [021acfc62d5de254a09b421ae224ee12],
PUP.Optional.PullUpdate.A, C:\ProgramData\fJdrhPbHX\dat\OUCgyZVUC.dll, Delete-on-Reboot, [0a12791ca4e60f2785b6d389ef178080],
PUP.Optional.PullUpdate.A, C:\ProgramData\fJdrhPbHX\dat\qrOvebw.exe, Delete-on-Reboot, [8795761fd2b87eb8003be973af5746ba],
PUP.RiskwareTool.CK, C:\Photoshop\Adobe Photoshop CS6 Extended\DLL FILE\32bit\amtlib.dll, Quarantined, [0d0fb1e43d4de84e0c02934f1ee4da26],
PUP.RiskwareTool.CK, C:\Photoshop\Adobe Photoshop CS6 Extended\DLL FILE\64bit\amtlib.dll, Quarantined, [32ea7025b0dabc7a739cf5ed986ae719],
PUP.Optional.BoostSaves.A, C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage, Quarantined, [53c9a4f16f1bca6c04f5db0f50b3956b],
PUP.Optional.BoostSaves.A, C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage-journal, Quarantined, [fa222f66abdf003685749d4d26dd56aa],
PUP.Optional.Boost.A, C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage, Quarantined, [69b36f26860437ff9c19c73bfd079f61],
PUP.Optional.Boost.A, C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage-journal, Quarantined, [79a3ebaa0e7ccb6b9c19bf4337cd8e72],
PUP.Optional.MultiPlug.A, C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431795156-5210-8051-C2C04F325631\vnsd1974.tmp, Quarantined, [36e65144642690a69e6c6cfeaa5ba55b],
PUP.Optional.MultiPlug.A, C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431795156-5210-8051-C2C04F325631\Uninstall.exe, Quarantined, [36e65144642690a69e6c6cfeaa5ba55b],
PUP.Optional.MultiPlug.A, C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431800567-5210-8051-C2C04F325631\vnsw5ED5.tmp, Quarantined, [38e4197c90fada5ce7232e3c7c8947b9],
PUP.Optional.MultiPlug.A, C:\Users\Felipe Kamia\AppData\Roaming\4C4C4544-1431800567-5210-8051-C2C04F325631\Uninstall.exe, Quarantined, [38e4197c90fada5ce7232e3c7c8947b9],
PUP.Optional.SuperOptimizer.A, C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hqghumeaylnlf.lnk, Quarantined, [8a92e1b4008a74c2bcf81e511de87090],
Rogue.Multiple, C:\ProgramData\2520434090\BIT1600.tmp, Quarantined, [6daf2273dbaf5adc30c1b9dbc24109f7],
PUP.Optional.PullUpdate.A, C:\ProgramData\fJdrhPbHX\dat\jDfVlXWYDI.exe.config, Delete-on-Reboot, [47d502930882fb3bd7c476e79c6a05fb],
PUP.Optional.PullUpdate.A, C:\ProgramData\fJdrhPbHX\dat\qrOvebw.exe.config, Delete-on-Reboot, [47d502930882fb3bd7c476e79c6a05fb],
PUP.Optional.PullUpdate.A, C:\ProgramData\fJdrhPbHX\IkPHAp.dat, Delete-on-Reboot, [47d502930882fb3bd7c476e79c6a05fb],
PUP.Optional.PullUpdate.A, C:\ProgramData\fJdrhPbHX\IkPHAp.exe.config, Quarantined, [47d502930882fb3bd7c476e79c6a05fb],
PUP.Optional.PullUpdate.A, C:\ProgramData\fJdrhPbHX\info.dat, Delete-on-Reboot, [47d502930882fb3bd7c476e79c6a05fb],

Physical Sectors: 0
(No malicious items detected)


(end)
kamia
kamia
Iniciante
Iniciante

Mensagens : 11
Reputação : 0
Data de inscrição : 16/05/2015

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por caedurodrigues Seg 18 maio 2015, 18:23

Boa noite kamia,

  • Baixe:<[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem][Tens de ter uma conta e sessão iniciada para poderes visualizar este link]> (...by Smeenk)
  • Salve na sua Desktop (Área de trabalho) !
  • Execute o arquivo Zoek.exe.
  • Usuários do Windows Vista ou Windows 7 clique com o direito sobre o arquivo Zoek.exe, depois clique em
    [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]
  • Selecione as linhas em vermelho, clique com o direito sobre a seleção e escolha a opção copiar!

    createsrpoint;
    autoclean;
    emptyalltemp;
    iedefaults;
    resetieproxy;
    resethosts;
    shortcutfix;
    ffdefaults;
    firefoxlook;
    reset chrome;
    chrdefaults;
    chromelook;
    emptyfolderscheck;delete

    [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]
  • Clique com o direito em qualquer parte branca do Zoek e escolha a opção colar.
  • Clique [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem], aguarde o scan. Ao final abrirá o bloco de notas com o relatório.
  • Uma cópia também será salva no seu disco local com o nome zoek-results.txt.
  • Anexe o zoek-results.txt na sua próxima resposta.

Um grande abraço. problemas - Problemas na remoção do Search Protect 648673379
caedurodrigues
caedurodrigues
Analista
Analista

Mensagens : 947
Reputação : 161
Data de inscrição : 21/10/2013
Idade : 54
Localização : Apiacá

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por kamia Seg 18 maio 2015, 23:04

caedurodrigues,

Segue abaixo o log

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Felipe Kamia on 18/05/2015 at 22:24:35,98.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Felipe Kamia\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

18/05/2015 22:26:32 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~3\Oracle deleted successfully
C:\PROGRA~3\Validity deleted successfully
C:\Users\Felipe Kamia\AppData\Roaming\HpUpdate deleted successfully
C:\Users\Felipe Kamia\AppData\Roaming\Malwarebytes deleted successfully
C:\Users\Felipe Kamia\AppData\Local\Unity deleted successfully
C:\Users\Felipe Kamia\AppData\Local\Warface deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-174019988-414781078-1319990136-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8E66592B-8E7C-4A14-88A5-8BF21032F651} deleted successfully
HKEY_USERS\S-1-5-21-174019988-414781078-1319990136-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4E39681-15F8-4fda-B8A3-B5C98378F2F3} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\FELIPE~1\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\prefs.js:
user_pref("browser.search.defaultenginename", "navegaki");

Added to C:\Users\FELIPE~1\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\FELIPE~1\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default

user.js not found
---- Lines Sweet modified from prefs.js ----

user_pref("extensions.enabledAddons", "sweetsearch%40gmail.com:1.0.0.1031,searchffv2%40gmail.com:0.0.3,sweetsearch%40gmail.com:1.0.0.1031,searchffv2%4
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 1);
---- FireFox user.js and prefs.js backups ----

prefs_052015_2236_.backup

==== Deleting Files \ Folders ======================

C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\sweetsearch@gmail.com not found
C:\PROGRA~2\Paradox Interactive deleted
C:\PROGRA~2\Yahoo! deleted
C:\found.000 deleted
C:\Users\Felipe Kamia\AppData\Roaming\blemos89_gmail.com@ae.com.br_LOG_RECONEXAO.txt deleted
C:\Users\Felipe Kamia\AppData\Roaming\trace_FilterInstaller.txt deleted
C:\Users\Felipe Kamia\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt deleted
C:\Users\Felipe Kamia\AppData\Roaming\Rim.Desktop.Exception.log deleted
C:\Users\Felipe Kamia\AppData\Roaming\Rim.Desktop.HttpServerSetup.log deleted
C:\Users\Felipe Kamia\AppData\Roaming\Rim.DesktopHelper.Exception.log deleted
C:\Users\Felipe Kamia\AppData\Roaming\Yahoo! deleted
C:\PROGRA~3\Yahoo! deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Felipe Kamia\AppData\Local\nsgC94.tmp deleted
C:\Users\Felipe Kamia\AppData\Local\DesktopSearch deleted
C:\Users\Felipe Kamia\AppData\LocalLow\Yahoo! deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Users\FELIPE~1\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\jetpack deleted
C:\Users\FELIPE~1\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\jid1-4P0kohSJxU1qGg@jetpack deleted
"C:\Users\Felipe Kamia\AppData\Roaming\EAMLGBM" deleted
"C:\Users\Felipe Kamia\AppData\Roaming\p9Q3WgaiMUjm9sMDRiW0" deleted
"C:\Users\Felipe Kamia\AppData\Roaming\W1BPMCOTWQ3Wk" deleted
"C:\Users\Felipe Kamia\AppData\Roaming\WSUFTY" deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\FELIPE~1\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"otis@digitalpersona.com"="C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt" [17/08/2012 20:34]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"{87F8774F-B485-47E2-A755-A40A8A5E8873}"="C:\Users\Felipe Kamia\AppData\Local\GAS Tecnologia\GBBD\uni\xpi" [26/08/2014 10:11]

==== Firefox Extensions ======================

ProfilePath: C:\Users\FELIPE~1\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default
- Guardio - Ita 30 horas - C:\Users\Felipe Kamia\AppData\Local\GAS Tecnologia\GBBD\uni\xpi
- Undetermined - C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\searchffv2@gmail.com
- Undetermined - C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\sweetsearch@gmail.com
- Undetermined - C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.com

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default
08ACECEB47FAF053C468D8AFE44709AD - C:\Users\Felipe Kamia\AppData\Local\Google\Update\1.3.27.5\npGoogleUpdate3.dll - Google Update
9AE02005247DA91AB1743F5208DBEF76 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll - Shockwave Flash
49D429EBF5305FC9ADD7545B7C914333 - C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin
6BEAD7859E8A087BE04556AB5A78855C - C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer
21025F3A113559BF3D7BBE162BDA626D - C:\Users\Felipe Kamia\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
F6419D3B99616C80C947B9D7B427348B - C:\Users\Felipe Kamia\AppData\Local\GAS Tecnologia\GBBD\npsf_uni.dll - Guardião Itaú 30 horas
BFD1CDA328C83054154DD05EA233F79B - C:\Users\Felipe Kamia\AppData\Local\GAS Tecnologia\GBBD\npsf_bb.dll - Módulo de Proteção - Banco do Brasil
E3B4EA121F7BDEB0F6366E2BA9608CB5 - C:\Users\Felipe Kamia\AppData\Local\Citrix\Plugins\104\npappdetector.dll - Citrix Online Web Deployment Plugin 1.0.0.104
CE836F6F488E5C02AEB6E13421126ACA - C:\Users\Felipe Kamia\AppData\Local\GAS Tecnologia\GBBD\npsf_cef.dll - Módulo de Proteção - Caixa Economica Federal
E557911A8903410D52FF9B3245954F4F - C:\Users\Felipe Kamia\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll - Game Face Plugin
B8CFF778A75C685AAC275BFC00BB8FD8 - C:\Users\Felipe Kamia\AppData\Local\GAS Tecnologia\GBBD\npsf_uni_64.dll - Guardião Itaú 30 horas
FF7BE908352D36D50E308F49162FEA32 - C:\Users\Felipe Kamia\AppData\Local\GAS Tecnologia\GBBD\npsf_bb_64.dll - Módulo de Proteção - Banco do Brasil


==== Chromium Look ======================

HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions
lmjegmlicamnimmfhcmpkclmigmmcbeh - No path found[]

Google Slides - Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek
Google Docs - Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Google Sheets - Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap
Bookmark Manager - Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik
Google Wallet - Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Default_Page_URL"="http://www.google.com"
"Start Page"="http://www.google.com"
"Search Page"="http://www.google.com"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== shortcuts on Users Desktops ======================

C:\Users\Felipe Kamia\Desktop\Bibliotecas.lnk - C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Libraries
C:\Users\Felipe Kamia\Desktop\Evernote.lnk - C:\Program Files (x86)\Evernote\Evernote\Evernote.exe
C:\Users\Felipe Kamia\Desktop\Google Chrome.lnk - C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Felipe Kamia\Desktop\Google Drive.lnk - C:\Users\Felipe Kamia\Google Drive
C:\Users\Felipe Kamia\Desktop\Play Football Manager 2014.lnk - C:\Users\Felipe Kamia\Downloads\Football Manager 2014 PC game ^^nosTEAM^^\Football Manager 2014\fm.exe
C:\Users\Felipe Kamia\Desktop\Popcorn Time.lnk - C:\Users\Felipe Kamia\AppData\Local\Popcorn Time\node-webkit\Popcorn Time.exe .
C:\Users\Felipe Kamia\Desktop\YNAB 4.lnk - C:\Program Files (x86)\YNAB 4\YNAB 4.exe
C:\Users\Felipe Kamia\Desktop\ZHPCleaner.lnk - C:\Users\Felipe Kamia\AppData\Roaming\ZHP\ZHPCleaner.exe
C:\Users\Felipe Kamia\Desktop\ZHPDiag.lnk - C:\Program Files (x86)\ZHPDiag\ZHPhep.exe
C:\Users\Felipe Kamia\Desktop\ZHPFix.lnk - C:\Program Files (x86)\ZHPDiag\ZHPFix\ZHPhep.exe
C:\Users\Felipe Kamia\Desktop\Arquivos de instalação\asav.lnk -

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\Battle.net.lnk - C:\Program Files (x86)\Battle.net\Battle.net Launcher.exe
C:\Users\Public\Desktop\Battlefield 3.lnk - C:\Program Files (x86)\Origin Games\Battlefield 3\bf3.exe
C:\Users\Public\Desktop\Democracy 3.lnk - C:\GOG Games\Democracy 3\Democracy3.exe
C:\Users\Public\Desktop\Hearthstone.lnk - C:\Program Files (x86)\Hearthstone\Hearthstone Beta Launcher.exe
C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Public\Desktop\NCH Suite.lnk - C:\Program Files (x86)\NCH Software\SoundTap\soundtap.exe -suite
C:\Users\Public\Desktop\Rise of Nations Gold.lnk - C:\Program Files (x86)\Microsoft Games\Rise of Nations\thrones.exe
C:\Users\Public\Desktop\Sid Meiers Civilization Beyond Earth.lnk - C:\Program Files (x86)\Sid Meiers Civilization Beyond Earth\CivilizationBe_DX11.exe
C:\Users\Public\Desktop\SoundTap Streaming Audio Recorder.lnk - C:\Program Files (x86)\NCH Software\SoundTap\soundtap.exe
C:\Users\Public\Desktop\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Public\Desktop\Tableau 8.0.lnk - C:\Program Files (x86)\Tableau\Tableau 8.0\bin\tableau.exe
C:\Users\Public\Desktop\Tropico 4 Collectors Bundle.lnk - C:\Program Files (x86)\Kalypso Media\Tropico 4 Collectors Bundle\Tropico4.exe

==== shortcuts in Users Start Menu ======================

C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicativos do Google Chrome\Google Keep - notas e listas.lnk - C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox\Dropbox.lnk - C:\Users\Felipe Kamia\AppData\Roaming\Dropbox\bin\Dropbox.exe /home
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Inicializador de aplicativos do Google Chrome.lnk - C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup\Google+ Auto Backup.lnk - C:\Users\Felipe Kamia\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google+ Auto Backup\Uninstall.lnk - C:\Users\Felipe Kamia\AppData\Local\Programs\Google\Google+ Auto Backup\Uninstall.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Music Manager\Music Manager.lnk - C:\Users\Felipe Kamia\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk - C:\Users\Felipe Kamia\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk - C:\Windows\Installer\{AC76BA86-7AD7-1046-7B44-AB0000000001}\SC_Reader.ico
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved\AMD Gaming Evolved.lnk - C:\Program Files (x86)\Raptr\raptrstub.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\SupportAssist\PC Checkup.lnk - C:\Program Files\Dell\SupportAssist\pcdlauncher.exe -startingpage pccheckup -lloc pccheckup
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell\SupportAssist\SupportAssist.lnk - C:\Program Files\Dell\SupportAssist\pcdlauncher.exe -lloc dsc
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Docs.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_document
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Drive.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Sheets.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_spreadsheet
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive\Google Slides.lnk - C:\Program Files (x86)\Google\Drive\googledrivesync.exe --new_presentation
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\MAGIX Photostory 2015 Deluxe\MAGIX Music Editor 3.lnk - C:\Program Files (x86)\MAGIX\Photostory 2015 Deluxe\MusicEditor\MusicEditor.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\MAGIX Photostory 2015 Deluxe\MAGIX Photo Designer 7.lnk - C:\Program Files (x86)\MAGIX\Photostory 2015 Deluxe\PhotoDesigner\PhotoDesigner.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\MAGIX Photostory 2015 Deluxe\MAGIX Photostory 2015 Deluxe.lnk - C:\Program Files (x86)\MAGIX\Photostory 2015 Deluxe\Fotos_dlx.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\MAGIX Photostory 2015 Deluxe\MAGIX Xtreme Print Studio.lnk - C:\Program Files (x86)\MAGIX\Photostory 2015 Deluxe\coverlabel\cdprinter.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\MAGIX Photostory 2015 Deluxe\Documentation\MAGIX Music Editor 3 Help.lnk - C:\Program Files (x86)\MAGIX\Photostory 2015 Deluxe\MusicEditor\MusicEditor_EN.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\MAGIX Photostory 2015 Deluxe\Documentation\MAGIX Photo Designer 7 Help.lnk - C:\Program Files (x86)\MAGIX\Photostory 2015 Deluxe\PhotoDesigner\pa.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\MAGIX Photostory 2015 Deluxe\Documentation\MAGIX Photo Designer 7 Manual.lnk - C:\Program Files (x86)\MAGIX\Photostory 2015 Deluxe\PhotoDesigner\Manual.pdf
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\MAGIX Photostory 2015 Deluxe\Documentation\MAGIX Photostory 2015 Deluxe Help.lnk - C:\Program Files (x86)\MAGIX\Photostory 2015 Deluxe\Fotos_dlx_EN.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\MAGIX Photostory 2015 Deluxe\Documentation\MAGIX Photostory 2015 Deluxe Manual.lnk - C:\Program Files (x86)\MAGIX\Photostory 2015 Deluxe\Fotos_dlx_EN.pdf
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\MAGIX Photostory 2015 Deluxe\Documentation\MAGIX Xtreme Print Studio Help.lnk - C:\Program Files (x86)\MAGIX\Photostory 2015 Deluxe\coverlabel\HelpAndSupport\ENG\XaraX.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\MAGIX Photostory 2015 Deluxe\Service and Support\License Conditions.lnk - C:\Program Files (x86)\MAGIX\Photostory 2015 Deluxe\license.txt
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX\MAGIX Photostory 2015 Deluxe\Service and Support\Uninstall MAGIX Photostory 2015 Deluxe.lnk - C:\Program Files (x86)\Common Files\MAGIX Services\Uninstall\{C9302FCA-B414-4D09-8393-7CACF844BFD0}\Fotostory_2015_Deluxe_en-II_setup.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP\ZHPDiag.lnk - C:\Program Files (x86)\ZHPDiag\ZHPhep.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP\ZHPFix.lnk - C:\Program Files (x86)\ZHPDiag\ZHPFix\ZHPhep.exe

==== shortcuts in Quick Launch ======================

C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\GameSpy Arcade.lnk - C:\Program Files (x86)\GameSpy Arcade\Aphex.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk - C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE /recycle
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk - C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe /lite
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk - C:\Program Files (x86)\Samsung\Kies\KiesAgent.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Samsung Story Album Viewer.lnk - C:\Program Files (x86)\Samsung\Story Album Viewer\HTML5Viewer.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Yahoo Messenger.lnk -
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk -
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk - C:\Windows\system32\control.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft Excel 2010.lnk - C:\Windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\xlicons.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft Outlook 2010.lnk - C:\Windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\outicon.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft PowerPoint 2010.lnk - C:\Windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\pptico.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft Publisher 2010.lnk - C:\Windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\pubs.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Microsoft Word 2010.lnk - C:\Windows\Installer\{90140000-003D-0000-0000-0000000FF1CE}\wordicon.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Notepad.lnk - C:\Windows\system32\notepad.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Play Football Manager 2014.lnk - C:\Users\Felipe Kamia\Downloads\Football Manager 2014 PC game ^^nosTEAM^^\Football Manager 2014\fm.exe
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Popcorn Time.lnk - C:\Users\Felipe Kamia\AppData\Local\Popcorn Time\node-webkit\Popcorn Time.exe .
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Snipping Tool.lnk -
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Yahoo Messenger.lnk -
C:\Users\Felipe Kamia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\Trend Micro\Trend Micro Titanium.lnk - C:\Program Files (x86)\Trend Micro\Titanium\UIFramework\uiWinMgr.exe
C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -

==== Reset IE Proxy ======================

Value(s) before fix:
"ProxyEnable"=dword:00000000

Value(s) after fix:
"ProxyEnable"=dword:00000000

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelTBRunOnce deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Felipe Kamia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Felipe Kamia\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\Felipe Kamia\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=6746 folders=97 935670331 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Felipe Kamia\AppData\Local\Temp will be emptied at reboot
C:\Users\USURIO~1\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\FELIPE~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 18/05/2015 at 23:02:02,74 ======================
kamia
kamia
Iniciante
Iniciante

Mensagens : 11
Reputação : 0
Data de inscrição : 16/05/2015

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por caedurodrigues Ter 19 maio 2015, 10:00

Bom dia kamia,

  • Baixe:<[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]> <(...by Farbar)>
  • Ou aqui:<[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]>
  • Salve-a na Área de trabalho !
  • Execute a ferramenta ! Clique "Yes" >> "Scan".

    [Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]
  • Verifique se as caixinhas em "Whitelist" estão assinaladas.
  • Em "Optional Scan",deixe marcada a checkbox "Addition.txt".
  • Será gerado o relatório! (FRST.txt)
  • Ps: Será gerado,também,o relatório "Addition.txt" que estará disponibilizado na 1ª execução da ferramenta.
  • Acesse: <[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]>
  • Ou acesse:<[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]>
  • Ou anexe-o <[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]> << Link
  • Maiores informações:<[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]> << Hospedagem !


ATENÇÃO: para o correto funcionamento da ferramenta, ela tem de estar diretamente na área de trabalho, não pode ficar em uma pasta.
caedurodrigues
caedurodrigues
Analista
Analista

Mensagens : 947
Reputação : 161
Data de inscrição : 21/10/2013
Idade : 54
Localização : Apiacá

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por kamia Ter 19 maio 2015, 19:45

Caedurodrigues,

seguem os links:
[Tens de ter uma conta e sessão iniciada para poderes visualizar este link] (FRST.txt)


[Tens de ter uma conta e sessão iniciada para poderes visualizar este link] (addition)

Valeu

Felipe
kamia
kamia
Iniciante
Iniciante

Mensagens : 11
Reputação : 0
Data de inscrição : 16/05/2015

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por kamia Ter 19 maio 2015, 19:47

Ps: Acredito que alguma coisa está sempre desabilitando meu anti-virus.

Digo isso pq vira e mexe ele esta desativado
kamia
kamia
Iniciante
Iniciante

Mensagens : 11
Reputação : 0
Data de inscrição : 16/05/2015

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por caedurodrigues Ter 19 maio 2015, 20:03

Boa noite kamia, eu vou dar uma olhada no relatório da FRST, se for necessário eu postarei um script para a execução na ferramenta. Eu não sei como é o antivírus que você utiliza o Trend Micro Titanium Internet Security, mas eu utilizei o BitDefender free que utiliza a proteção nas nuvens, e ele sempre desabilitava era um problema. Um grande abraço.
caedurodrigues
caedurodrigues
Analista
Analista

Mensagens : 947
Reputação : 161
Data de inscrição : 21/10/2013
Idade : 54
Localização : Apiacá

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por caedurodrigues Ter 19 maio 2015, 20:38

Boa noite kamia,

  • Copie estas informações que estão em vermelho,para o Bloco de Notas.
  • Salve-a com o nome fixlist.txt
  • Salve-a no mesmo local em que se encontra a FRST

    start
    CreateRestorePoint:
    CloseProcesses:
    HKLM-x32\...\Run: [] => [X]
    Winlogon\Notify\igfxcui: igfxdev.dll [X]
    HKU\S-1-5-21-174019988-414781078-1319990136-1000\...\MountPoints2: {e79fe302-145f-11e2-aac6-e006e6ddd7a0} - E:\setup.exe
    CHR HKU\S-1-5-21-174019988-414781078-1319990136-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    SearchScopes: HKLM -> {8F59173F-37E0-4E35-95A1-38DB9D0B64A6} URL = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    SearchScopes: HKLM-x32 -> {8F59173F-37E0-4E35-95A1-38DB9D0B64A6} URL = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-174019988-414781078-1319990136-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
    FF Extension: No Name - C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\searchffv2@gmail.com [Not Found]
    FF Extension: No Name - C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\sweetsearch@gmail.com [Not Found]
    FF Extension: No Name - C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.com [Not Found]
    U2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [X]
    S3 Warsaw_PP; \??\C:\PROGRA~2\GbPlugin\wsftprp64.sys [X]
    C:\Users\Felipe Kamia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp68gmav.dll
    HOSTS:
    CMD: bitsadmin /reset /allusers
    CMD: ipconfig /flushdns
    emptytemp:
    end

  • Execute FRST/FRST64 >> Clique "Fix". << Aguarde!
  • Poste o relatório! (Fixlog.txt)

Um grande abraço.  problemas - Problemas na remoção do Search Protect 648673379

[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]
< Peço aos visitantes que não utilizem este script em outros computadores,sob risco de danos irreparáveis aos mesmos! >
caedurodrigues
caedurodrigues
Analista
Analista

Mensagens : 947
Reputação : 161
Data de inscrição : 21/10/2013
Idade : 54
Localização : Apiacá

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por kamia Ter 19 maio 2015, 21:00

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 19-05-2015
Ran by Felipe Kamia at 2015-05-19 20:53:40 Run:1
Running from C:\Users\Felipe Kamia\Desktop
Loaded Profiles: Felipe Kamia (Available profiles: Felipe Kamia)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-174019988-414781078-1319990136-1000\...\MountPoints2: {e79fe302-145f-11e2-aac6-e006e6ddd7a0} - E:\setup.exe
CHR HKU\S-1-5-21-174019988-414781078-1319990136-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> {8F59173F-37E0-4E35-95A1-38DB9D0B64A6} URL = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
SearchScopes: HKLM-x32 -> {8F59173F-37E0-4E35-95A1-38DB9D0B64A6} URL = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-174019988-414781078-1319990136-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
FF Extension: No Name - C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\searchffv2@gmail.com [Not Found]
FF Extension: No Name - C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\sweetsearch@gmail.com [Not Found]
FF Extension: No Name - C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.com [Not Found]
U2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 [X]
S3 Warsaw_PP; \??\C:\PROGRA~2\GbPlugin\wsftprp64.sys [X]
C:\Users\Felipe Kamia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp68gmav.dll
HOSTS:
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns
emptytemp:
end
*****************

Restore point was successfully created.
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui" => Key deleted successfully.
"HKU\S-1-5-21-174019988-414781078-1319990136-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e79fe302-145f-11e2-aac6-e006e6ddd7a0}" => Key deleted successfully.
HKCR\CLSID\{e79fe302-145f-11e2-aac6-e006e6ddd7a0} => Key not found.
"HKU\S-1-5-21-174019988-414781078-1319990136-1000\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8F59173F-37E0-4E35-95A1-38DB9D0B64A6}" => Key deleted successfully.
HKCR\CLSID\{8F59173F-37E0-4E35-95A1-38DB9D0B64A6} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{8F59173F-37E0-4E35-95A1-38DB9D0B64A6}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{8F59173F-37E0-4E35-95A1-38DB9D0B64A6} => Key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-174019988-414781078-1319990136-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => Key deleted successfully.
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => Key not found.
C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\searchffv2@gmail.com not found.
C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\sweetsearch@gmail.com not found.
C:\Users\Felipe Kamia\AppData\Roaming\Mozilla\Firefox\Profiles\ng0a0zdc.default\extensions\d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.com not found.
Amsp => Service deleted successfully.
Warsaw_PP => Service deleted successfully.
C:\Users\Felipe Kamia\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp68gmav.dll => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.

========= bitsadmin /reset /allusers =========


BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
(C) Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

{57108009-A895-495D-8F4F-B2EA8F06BABF} canceled.
{7DB5A339-DC56-4368-BC15-2206CBBC456C} canceled.
2 out of 2 jobs canceled.

========= End of CMD: =========


========= ipconfig /flushdns =========


Configura��o de IP do Windows

Libera��o do Cache do DNS Resolver bem-sucedida.

========= End of CMD: =========

EmptyTemp: => Removed 499.3 MB temporary data.


The system needed a reboot.

==== End of Fixlog 20:54:00 ====
kamia
kamia
Iniciante
Iniciante

Mensagens : 11
Reputação : 0
Data de inscrição : 16/05/2015

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por caedurodrigues Qua 20 maio 2015, 08:18

Bom dia kamia, como está o PC ?
caedurodrigues
caedurodrigues
Analista
Analista

Mensagens : 947
Reputação : 161
Data de inscrição : 21/10/2013
Idade : 54
Localização : Apiacá

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por caedurodrigues Seg 10 Ago 2015, 23:29

TÓPICO ARQUIVADO

Como o autor não respondeu por mais de 15 dias, o tópico foi arquivado. Caso o autor do tópico necessite, o mesmo será reaberto, para isso deverá entrar em contato com um dos membros da [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] solicitando o desbloqueio.
caedurodrigues
caedurodrigues
Analista
Analista

Mensagens : 947
Reputação : 161
Data de inscrição : 21/10/2013
Idade : 54
Localização : Apiacá

Ir para o topo Ir para baixo

problemas - Problemas na remoção do Search Protect Empty Re: Problemas na remoção do Search Protect

Mensagem por Conteúdo patrocinado


Conteúdo patrocinado


Ir para o topo Ir para baixo

Ir para o topo

- Tópicos semelhantes

 
Permissões neste sub-fórum
Não podes responder a tópicos