Fórum PC Brasil
Gostaria de reagir a esta mensagem? Crie uma conta em poucos cliques ou inicie sessão para continuar.
Flux RSS


Yahoo! 
MSN 
AOL 
Netvibes 
Bloglines 


Social bookmarking

Social bookmarking reddit      

Conservar e compartilhar o endereço de PC Seguro em seu site de social bookmarking

Conservar e compartilhar o endereço de Fórum PC Brasil em seu site de social bookmarking

Estatísticas
Temos 14810 usuários registrados
O último membro registrado é Josevinil

Os nossos membros postaram um total de 36047 mensagens em 3685 assuntos
Últimos assuntos
» Problema no disco rígido do Windows 11
por joram Seg 01 Abr 2024, 06:35

Quem está conectado?
21 usuários online :: 0 registrados, 0 invisíveis e 21 visitantes :: 1 motor de busca

Nenhum

O recorde de usuários online foi de 301 em Ter 26 Out 2021, 15:28
Procurar
 
 

Resultados por:
 


Rechercher Pesquisa avançada

abril 2024
SegTerQuaQuiSexSábDom
1234567
891011121314
15161718192021
22232425262728
2930     

Calendário Calendário


Remoção SupraSavings - Já tentei de tudo !

2 participantes

Ir para baixo

Remoção SupraSavings - Já tentei de tudo ! Empty Remoção SupraSavings - Já tentei de tudo !

Mensagem por luorhan Dom 29 Jun 2014, 21:29

boa noite ! sou novo no fórum e to com uma duvida !

alguém aqui em casa deu algum mole e acabou instalando esse supra savings, essa bosta desse adware dos inferno..

bom, procurei em fórums e em artigos na web toda, e achei algumas coisas e tal..


mas nada, absolutamente NADA conseguiu tirar essa praga desse suprasavings..

já tentei a remoção manual, mas não deu em nada, continua com os Ads, já tentei também aquele AdWCleaner e também nada.

no log apareceu que o suprasavings foi removido, mas ai que entra o fato interessante: sempre que eu inicio o computador o suprasavings é AUTOMATICANTE instalado denovo, estou muito nervoso com isso, não sei mais o que fazer..

alguém pode me ajudar ?

já agradeço ! Vlw !
luorhan
luorhan
Iniciante
Iniciante

Mensagens : 4
Reputação : 0
Data de inscrição : 29/06/2014

Ir para o topo Ir para baixo

Remoção SupraSavings - Já tentei de tudo ! Empty Re: Remoção SupraSavings - Já tentei de tudo !

Mensagem por Power Max Dom 29 Jun 2014, 21:32

Olá.

* Na sua próxima resposta poste o log (relatório) do Adwcleaner que está em C:\AdwCleaner\AdwCleaner[S0].txt para que possamos analisá-lo.

Ficamos na espera.
Power Max
Power Max
Colaborador
Colaborador

Mensagens : 9086
Reputação : 1499
Data de inscrição : 14/04/2009

Ir para o topo Ir para baixo

Remoção SupraSavings - Já tentei de tudo ! Empty Re: Remoção SupraSavings - Já tentei de tudo !

Mensagem por luorhan Dom 29 Jun 2014, 21:36

bom, eu tentei duas vezes, então vou postar o primeiro log, em seguida posto o segundo

# AdwCleaner v3.214 - Relatório criado 29/06/2014 às 21:01:10
# Atualizado 29/06/2014 por Xplode
# Sistema Operacional : Windows 8 Single Language (64 bits)
# Usuário : Luorhan - PATRICIA
# Executando de : C:\Users\Luorhan\Downloads\AdwCleaner.exe
# Opção : Limpar

***** [ Serviços ] *****

[#] Serviço Deletada : 64af91bf
[#] Serviço Deletada : IePluginServices

***** [ Arquivos / Pastas ] *****

Pasta Deletada : C:\ProgramData\374311380
Pasta Deletada : C:\ProgramData\baidu
Pasta Deletada : C:\ProgramData\fast and safe
Pasta Deletada : C:\ProgramData\IePluginServices
Pasta Deletada : C:\ProgramData\PriceMeterLiveUpdate
Pasta Deletada : C:\ProgramData\WPM
Pasta Deletada : C:\Program Files (x86)\AnyProtectEx
Pasta Deletada : C:\Program Files (x86)\globalUpdate
Pasta Deletada : C:\Program Files (x86)\IminentToolbar
Pasta Deletada : C:\Program Files (x86)\predm
Pasta Deletada : C:\Program Files (x86)\PriceMeterLiveUpdate
Pasta Deletada : C:\Program Files (x86)\Speedial
Pasta Deletada : C:\Program Files (x86)\SupTab
Pasta Deletada : C:\Program Files\003
Pasta Deletada : C:\Program Files\SupraSavings
Pasta Deletada : C:\Users\Convidado\AppData\Local\fst_br_138
Pasta Deletada : C:\Users\Convidado\AppData\LocalLow\HomeTab
Pasta Deletada : C:\Users\Convidado\AppData\LocalLow\IminentToolbar
Pasta Deletada : C:\Users\Convidado\AppData\LocalLow\SimplyTech
Pasta Deletada : C:\Users\Luorhan\Documents\Mobogenie
Pasta Deletada : C:\Users\Paty\AppData\Local\globalUpdate
Pasta Deletada : C:\Users\Paty\AppData\Local\PriceMeter
Pasta Deletada : C:\Users\Paty\AppData\Local\PriceMeterLiveUpdate
Pasta Deletada : C:\Users\Paty\AppData\Roaming\Activeris
Pasta Deletada : C:\Users\Paty\AppData\Roaming\AppCloudUpdater
Pasta Deletada : C:\Users\Paty\AppData\Roaming\baidu
Pasta Deletada : C:\Users\Paty\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl
Pasta Deletada : C:\Users\Paty\AppData\Roaming\IminentToolbar
Pasta Deletada : C:\Users\Paty\AppData\Roaming\PriceMeterUpdater
Pasta Deletada : C:\Users\Paty\AppData\Roaming\Speedial
Pasta Deletada : C:\Users\Paty\AppData\Roaming\sweet-page
Pasta Deletada : C:\Users\Paty\Documents\Mobogenie
Pasta Deletada : C:\Users\Paty\Documents\Optimizer Pro
Pasta Deletada : C:\Users\Public\Documents\baidu
Pasta Deletada : C:\Users\Luorhan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakijjialdiiboeaknfpmflphhmljfkd
Arquivo Deletada : C:\END
Arquivo Deletada : C:\Users\gabriel\daemonprocess.txt
Arquivo Deletada : C:\Users\Luorhan\daemonprocess.txt
Arquivo Deletada : C:\Users\Paty\daemonprocess.txt
Arquivo Deletada : C:\Users\Paty\AppData\Local\AnyProtectScannerSetup.exe
Arquivo Deletada : C:\Users\Paty\Desktop\Continue VuuPC Installation.lnk
Arquivo Deletada : C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
Arquivo Deletada : C:\Users\Paty\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
Arquivo Deletada : C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Arquivo Deletada : C:\Users\Luorhan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Arquivo Deletada : C:\Users\Paty\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Arquivo Deletada : C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Arquivo Deletada : C:\Users\Luorhan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Arquivo Deletada : C:\Users\Paty\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Arquivo Deletada : C:\Windows\Tasks\AppCloudUpdater.job
Arquivo Deletada : C:\Windows\System32\Tasks\AppCloudUpdater
Arquivo Deletada : C:\Windows\System32\Tasks\FinishInstall igdhbblpcellaljokkpfhcjlagemhgjl
Arquivo Deletada : C:\Windows\System32\Tasks\pricemetertask
Arquivo Deletada : C:\Windows\System32\Tasks\pricemeterwatcher
Arquivo Deletada : C:\Windows\Tasks\Speedial.job
Arquivo Deletada : C:\Windows\System32\Tasks\Speedial

***** [ Atalhos ] *****


***** [ Registro ] *****

Chave Deletedo : HKLM\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd
Chave Deletedo : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\bakijjialdiiboeaknfpmflphhmljfkd
Chave Deletedo : HKLM\SOFTWARE\Classes\Iminent
Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASAPI32
Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\HomeTab_RASMANCS
Chave Deletedo : HKLM\SOFTWARE\Microsoft\Tracing\SoftwareUpdater_RASAPI32
Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Chave Deletedo : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Chave Deletedo : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Chave Deletedo : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{84FF7BD6-B47F-46F8-9130-01B2696B36CB}
Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Chave Deletedo : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Chave Deletedo : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Chave Deletedo : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Chave Deletedo : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Chave Deletedo : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{31090377-0740-419E-BEFC-A56E50500D5B}
Chave Deletedo : HKCU\Software\SoftwareUpdater
Chave Deletedo : HKCU\Software\AppDataLow\Software\ViewPassword
Chave Deletedo : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Chave Deletedo : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Chave Deletedo : HKLM\Software\Conduit
Chave Deletedo : HKLM\Software\Iminent
Chave Deletedo : HKLM\Software\InstallCore
Chave Deletedo : HKLM\Software\SoftwareUpdater
Chave Deletedo : HKLM\Software\SupDp
Chave Deletedo : HKLM\Software\suprasavings
Chave Deletedo : HKLM\Software\SupTab
Chave Deletedo : HKLM\Software\supWPM
Chave Deletedo : HKLM\Software\sweet-pageSoftware
Chave Deletedo : HKLM\Software\Vittalia
Chave Deletedo : [x64] HKLM\SOFTWARE\Iminent
Chave Deletedo : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Chave Deletedo : [x64] HKLM\SOFTWARE\Supra Savings
Chave Deletedo : [x64] HKLM\SOFTWARE\suprasavings
Dados Deletedo : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\suptab\search~1.dll
Dados Deletedo : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL
Chave Deletedo : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DatamngrCoordinator.exe

***** [ Navegadores ] *****

-\\ Internet Explorer v10.0.9200.16921

Configurações Restauradas : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Configurações Restauradas : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Configurações Restauradas : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Default_Page_URL]
Configurações Restauradas : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Bar]
Configurações Restauradas : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Page]
Configurações Restauradas : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Start Default_Page_URL]
Configurações Restauradas : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Default_Search_URL]
Configurações Restauradas : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Bar]
Configurações Restauradas : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [Search Page]
Configurações Restauradas : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl []
Configurações Restauradas : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Configurações Restauradas : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Google Chrome v35.0.1916.153

[ Arquivo : C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deletedo [Startup_urls] : [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
Deletedo [Homepage] : [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
Deletedo [Extension] : bakijjialdiiboeaknfpmflphhmljfkd
Deletedo [Extension] : nhjnmokdaalmckkikjklibeakholpham

[ Arquivo : C:\Users\Luorhan\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deletedo [Extension] : bakijjialdiiboeaknfpmflphhmljfkd

[ Arquivo : C:\Users\Paty\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deletedo [Startup_urls] : [Tens de ter uma conta e sessão iniciada para poderes visualizar este link]
Deletedo [Extension] : bakijjialdiiboeaknfpmflphhmljfkd
Deletedo [Extension] : nhjnmokdaalmckkikjklibeakholpham

*************************

AdwCleaner[R0].txt - [12191 octets] - [29/06/2014 20:57:42]
AdwCleaner[S0].txt - [9907 octets] - [29/06/2014 21:01:10]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9967 octets] ##########


-----------------------------------

2º log

# AdwCleaner v3.214 - Relatório criado 29/06/2014 às 21:13:28
# Atualizado 29/06/2014 por Xplode
# Sistema Operacional : Windows 8 Single Language (64 bits)
# Usuário : Luorhan - PATRICIA
# Executando de : C:\Users\Luorhan\Desktop\AdwCleaner.exe
# Opção : Limpar

***** [ Serviços ] *****


***** [ Arquivos / Pastas ] *****

Pasta Deletada : C:\Program Files\SupraSavings

***** [ Atalhos ] *****


***** [ Registro ] *****


***** [ Navegadores ] *****

-\\ Internet Explorer v10.0.9200.16921


-\\ Google Chrome v35.0.1916.153

[ Arquivo : C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\preferences ]


[ Arquivo : C:\Users\Luorhan\AppData\Local\Google\Chrome\User Data\Default\preferences ]


[ Arquivo : C:\Users\Paty\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [12191 octets] - [29/06/2014 20:57:42]
AdwCleaner[R1].txt - [1134 octets] - [29/06/2014 21:09:46]
AdwCleaner[R2].txt - [1194 octets] - [29/06/2014 21:11:36]
AdwCleaner[S0].txt - [10091 octets] - [29/06/2014 21:01:10]
AdwCleaner[S1].txt - [1111 octets] - [29/06/2014 21:13:28]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1171 octets] ##########

luorhan
luorhan
Iniciante
Iniciante

Mensagens : 4
Reputação : 0
Data de inscrição : 29/06/2014

Ir para o topo Ir para baixo

Remoção SupraSavings - Já tentei de tudo ! Empty Re: Remoção SupraSavings - Já tentei de tudo !

Mensagem por Power Max Dom 29 Jun 2014, 21:41

Remoção SupraSavings - Já tentei de tudo ! 772309  No seu PC está constando o antivirus Baidu instalado. Você quer removê-lo ou quer continuar com ele? Seja qual for a sua resposta para esta pergunta, siga também as dicas abaixo:

Desative temporariamente seu antivírus para evitar conflitos.

 Acesse este link abaixo e clique no primeiro botão da esquerda que é o botão Download Zoek.exe:
[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

* Dê um duplo clique com o botão esquerdo do mouse no Zoek.exe para abri-lo.

* Selecione e copie todo este texto destacado em vermelho que te passei e cole-o no espaço em branco do Zoek

*Clique [Run Script]

*Durante o scan uma mensagem parecida com esta abaixo mostrando o progresso do escaneamento será apresentada. Aguarde o término...pode demorar!

[Tens de ter uma conta e sessão iniciada para poderes visualizar esta imagem]

*Caso a reinicialização do PC seja solicitada, clique [OK]

* Poste o log do Zoek que estará em C:\zoek-results.txt em sua próxima resposta.


Última edição por Power Max em Dom 20 Jul 2014, 14:55, editado 1 vez(es)
Power Max
Power Max
Colaborador
Colaborador

Mensagens : 9086
Reputação : 1499
Data de inscrição : 14/04/2009

Ir para o topo Ir para baixo

Remoção SupraSavings - Já tentei de tudo ! Empty Re: Remoção SupraSavings - Já tentei de tudo !

Mensagem por luorhan Dom 29 Jun 2014, 22:12


Zoek.exe v5.0.0.0 Updated 28-06-2014
Tool run by Luorhan on 29/06/2014 at 21:47:35,48.
Microsoft Windows 8 Single Language 6.2.9200 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Luorhan\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

29/06/2014 21:50:40 Zoek.exe System Restore Point Created Succesfully.

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\Users\Luorhan\.android deleted
C:\Users\Paty\.android deleted
C:\found.000 deleted
C:\found.001 deleted
C:\found.002 deleted
C:\found.003 deleted
C:\PROGRA~3\Application Data deleted
C:\Users\Luorhan\Searches deleted
C:\Users\Luorhan\Downloads\SoftonicDownloader_para_atube-catcher.exe deleted
C:\Users\Luorhan\Downloads\SoftonicDownloader_para_daemon-tools.exe deleted
C:\windows\SysNative\drivers\{8d0275ed-1f40-4baa-8113-425210cf69e4}w64.sys deleted

==== Folders Found ======================

2014-06-30 00:01:11 2014-06-30 00:01:11 -------- d-----w- C:\AdwCleaner\Quarantine\C\ProgramData\baidu
2014-06-30 00:01:24 2014-06-30 00:01:24 -------- d-----w- C:\AdwCleaner\Quarantine\C\Users\Paty\AppData\Roaming\baidu
2014-06-30 00:01:24 2014-06-30 00:01:24 -------- d-----w- C:\AdwCleaner\Quarantine\C\Users\Paty\AppData\Roaming\baidu\Baidu Antivirus
2014-06-30 00:01:31 2014-06-30 00:01:31 -------- d-----w- C:\AdwCleaner\Quarantine\C\Users\Public\Documents\baidu
2014-06-02 02:07:21 2014-06-06 16:12:15 -------- d-----w- C:\Program Files (x86)\Baidu Security
2014-06-02 02:07:21 2014-06-02 10:55:02 -------- d-----w- C:\Program Files (x86)\Baidu Security\Baidu Antivirus
2014-06-02 02:08:31 2014-06-12 23:40:54 -------- d-----w- C:\ProgramData\Baidu Security
2013-12-23 16:12:22 2013-12-23 16:12:22 -------- d-----w- C:\Users\Luorhan\Documents\Baidu Security
2014-06-06 16:14:20 2014-06-06 16:14:20 -------- d-----w- C:\Users\Paty\AppData\Roaming\Baidu Security
2013-11-02 18:05:53 2013-11-14 16:43:54 -------- d-----w- C:\Users\Public\Documents\Baidu Security
2014-06-10 18:13:01 2014-06-10 18:13:01 -------- d-----w- C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster

==== Files Found ======================


==== Registry Search Results for "Baidu" ======================


[HKEY_LOCAL_MACHINE\SOFTWARE\baidu]

[HKEY_LOCAL_MACHINE\SOFTWARE\baidu\CommonDll]

[HKEY_LOCAL_MACHINE\SOFTWARE\baidu\CommonDll\Splitupload]

[HKEY_LOCAL_MACHINE\SOFTWARE\baidu\CommonDll\Splitupload\bav]

[HKEY_LOCAL_MACHINE\SOFTWARE\baidu\CommonDll\Splitupload\bav]
"DllVersion_2.0"="C:\\ProgramData\\baidu\\commondll\\splitupload\\DllVersion_2.0\\FileSplitUpLoad.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Baidu Security]

[HKEY_LOCAL_MACHINE\SOFTWARE\Baidu Security\Antivirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Baidu Security\Antivirus]
"uuurl"="http://sync.br.bav.baidu.com/cgi-bin/report_uu_msg_bavv2.cgi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Baidu Security\DuplicateRecord]

[HKEY_LOCAL_MACHINE\SOFTWARE\Baidu Security\PC Faster]

[HKEY_LOCAL_MACHINE\SOFTWARE\Baidu Security\PC Faster\LogUp]

[HKEY_LOCAL_MACHINE\SOFTWARE\Baidu_Drp_pos]

[HKEY_LOCAL_MACHINE\SOFTWARE\Baidu_Drp_pos\DRP]

[HKEY_LOCAL_MACHINE\SOFTWARE\Baidu_Drp_pos\DRP\Processing]

[HKEY_LOCAL_MACHINE\SOFTWARE\Baidu_Drp_pos\DRP\Temp]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697}]
"DllName"="baidubar.dll;BaiduBarX.dll;BaiduBarX.dll;BaiduBarX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{B580CF65-E151-49C3-B73F-70B13FCA8E86}]
"DllName"="baidubar.dll;BaiduBarX.dll;BaiduBarX.dll;BaiduBarX.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Baidu Antivirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bav\shell\open\command]
@="\"C:\\Program Files (x86)\\Baidu Security\\Baidu Antivirus\\Bav.exe\" UI_Start_From_IE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BLPFILE\shell\open\command]
@="\"C:\\Program Files (x86)\\Baidu Security\\Baidu Antivirus\\Translator.exe\" \"%1\""

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Bfilter]
"DisplayName"="Baidu Antivirus Minifilter Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Bfmon]
"DisplayName"="Baidu FS Monitor Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Bndef]
"DisplayName"="Baidu NetDefense"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Bprotect]
"InstPath"="C:\\Program Files (x86)\\Baidu Security\\Baidu Antivirus"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Bprotect]
"DisplayName"="Baidu Protect"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BprotectEx]
"DisplayName"="Baidu ProtectEx"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BprotectEx]
"InstPath"="C:\\Program Files (x86)\\Baidu Security\\PC Faster\\4.0.0.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCFApiUtil]
"ImagePath"="\\??\\C:\\Program Files (x86)\\Baidu Security\\PC Faster\\4.0.0.0\\PCFApiUtil64.sys"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Bfilter]
"DisplayName"="Baidu Antivirus Minifilter Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Bfmon]
"DisplayName"="Baidu FS Monitor Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Bndef]
"DisplayName"="Baidu NetDefense"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Bprotect]
"InstPath"="C:\\Program Files (x86)\\Baidu Security\\Baidu Antivirus"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Bprotect]
"DisplayName"="Baidu Protect"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BprotectEx]
"DisplayName"="Baidu ProtectEx"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BprotectEx]
"InstPath"="C:\\Program Files (x86)\\Baidu Security\\PC Faster\\4.0.0.0"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCFApiUtil]
"ImagePath"="\\??\\C:\\Program Files (x86)\\Baidu Security\\PC Faster\\4.0.0.0\\PCFApiUtil64.sys"

[HKEY_USERS\.DEFAULT\Software\Baidu]

[HKEY_USERS\.DEFAULT\Software\Baidu\Application Bug]

[HKEY_USERS\.DEFAULT\Software\Baidu\Application Bug\Bav]

[HKEY_USERS\.DEFAULT\Software\Baidu\Application Bug\Bav\log]

[HKEY_USERS\.DEFAULT\Software\Baidu\Application Bug\Bav\log\BavSvc.exe]

[HKEY_USERS\.DEFAULT\Software\Baidu Security]

[HKEY_USERS\.DEFAULT\Software\Baidu Security\PC Faster]

[HKEY_USERS\.DEFAULT\Software\Baidu Security\PC Faster\bug]

[HKEY_USERS\.DEFAULT\Software\Baidu Security\PC Faster\bug\driver]

[HKEY_USERS\.DEFAULT\Software\Baidu Security\PC Faster\bug\driver\060214-60125-01.dmp]

[HKEY_USERS\S-1-5-21-4061941331-2985922947-4173166966-1002\Software\Baidu]

[HKEY_USERS\S-1-5-21-4061941331-2985922947-4173166966-1002\Software\Baidu\Hao123-br]

[HKEY_USERS\S-1-5-21-4061941331-2985922947-4173166966-1002\Software\Baidu\Hao123-br\hao123desk]

[HKEY_USERS\S-1-5-21-4061941331-2985922947-4173166966-1002\Software\Baidu\Hao123-br\hao123desk]
"ToyPath"="C:\\Users\\Luorhan\\AppData\\Roaming\\baidu\\hao123-br\\hao123.1.0.0.1111.exe"

[HKEY_USERS\S-1-5-21-4061941331-2985922947-4173166966-1002\Software\Baidu\Hao123-br\hao123desk]
"BaiduTn"="tn=incore_pay_sc_05_hao123_br"

[HKEY_USERS\S-1-5-21-4061941331-2985922947-4173166966-1002\Software\Baidu\Hao123-br\hao123desk]
"NewBaiduTn"="tn=incore_pay_sc_05_hao123_br"

[HKEY_USERS\S-1-5-18\Software\Baidu]

[HKEY_USERS\S-1-5-18\Software\Baidu\Application Bug]

[HKEY_USERS\S-1-5-18\Software\Baidu\Application Bug\Bav]

[HKEY_USERS\S-1-5-18\Software\Baidu\Application Bug\Bav\log]

[HKEY_USERS\S-1-5-18\Software\Baidu\Application Bug\Bav\log\BavSvc.exe]

[HKEY_USERS\S-1-5-18\Software\Baidu Security]

[HKEY_USERS\S-1-5-18\Software\Baidu Security\PC Faster]

[HKEY_USERS\S-1-5-18\Software\Baidu Security\PC Faster\bug]

[HKEY_USERS\S-1-5-18\Software\Baidu Security\PC Faster\bug\driver]

[HKEY_USERS\S-1-5-18\Software\Baidu Security\PC Faster\bug\driver\060214-60125-01.dmp]

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"{4ED1F68A-5463-4931-9384-8FFF5ED91D92}"="C:\Program Files (x86)\McAfee\SiteAdvisor" [17/06/2014 23:17]

==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
fheoggkfdfchfphceeifdbepaooicaho - No path found[]
oedoknoijoakeplhlghdcggkclkbmaje - C:\Users\Paty\AppData\Local\PriceMeter Express\PriceMeterExpress.crx[]

Google Docs - Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Google Wallet - Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Convidado\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
Google Docs - Luorhan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
Google Drive - Luorhan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf
YouTube - Luorhan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo
Google Search - Luorhan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf
Google Wallet - Luorhan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
Gmail - Luorhan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia
Google Wallet - Paty\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda

==== Chrome Fix ======================

C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully
C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_portugues.babylon.com_0.localstorage deleted successfully
C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_portugues.babylon.com_0.localstorage-journal deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://search.certified-toolbar.com?si=80415&st=home&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F"
"Start Default_Page_URL"="http://search.certified-toolbar.com?si=80415&st=home&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F"
"Default_Search_URL"="http://search.certified-toolbar.com?si=80415&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&st=chrome&q="
"Search Bar"="http://search.certified-toolbar.com?si=80415&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&st=chrome&q="
"Search Page"="http://search.certified-toolbar.com?si=80415&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&st=chrome&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://search.certified-toolbar.com?si=80415&st=home&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F"
"Start Default_Page_URL"="http://search.certified-toolbar.com?si=80415&st=home&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F"
"Default_Search_URL"="http://search.certified-toolbar.com?si=80415&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&st=chrome&q="
"Search Bar"="http://search.certified-toolbar.com?si=80415&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&st=chrome&q="
"Search Page"="http://search.certified-toolbar.com?si=80415&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&st=chrome&q="
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Search Page"="http://www.google.com"
"Start Default_Page_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.google.com"
"Search Page"="http://www.google.com"
"Start Default_Page_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI]
@="http://search.certified-toolbar.com?si=80415&st=bs&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI]
@="http://search.certified-toolbar.com?si=80415&st=bs&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://search.certified-toolbar.com?si=80415&st=bs&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI]
@="http://search.certified-toolbar.com?si=80415&st=bs&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://search.certified-toolbar.com?si=80415&st=bs&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI]
@="http://search.certified-toolbar.com?si=80415&st=bs&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="http://br.hao123.com/?tn=incore_pay_hp_01_hao123_br"
"newtab"="about:tabs"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="http://br.hao123.com/?tn=incore_pay_hp_01_hao123_br"
"newtab"="about:tabs"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search]
"Start Page"="http://search.certified-toolbar.com?si=80415&st=home&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F"
"Start Default_Page_URL"="http://search.certified-toolbar.com?si=80415&st=home&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F"
"Default_Search_URL"="http://search.certified-toolbar.com?si=80415&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&st=chrome&q="
"Search Bar"="http://search.certified-toolbar.com?si=80415&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&st=chrome&q="
"Search Page"="http://search.certified-toolbar.com?si=80415&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&st=chrome&q="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search]
"Start Page"="http://search.certified-toolbar.com?si=80415&st=home&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F"
"Start Default_Page_URL"="http://search.certified-toolbar.com?si=80415&st=home&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F"
"Default_Search_URL"="http://search.certified-toolbar.com?si=80415&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&st=chrome&q="
"Search Bar"="http://search.certified-toolbar.com?si=80415&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&st=chrome&q="
"Search Page"="http://search.certified-toolbar.com?si=80415&tid=23890&ver=6.4&ts=1401850800000.000000&tguid=80415-23890-1401887377183-9116D0C8FDFB2C96B4A54AB152AB143F&st=chrome&q="
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Start Page"="http://www.google.com"
"Start Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"Start Page"="http://www.google.com"
"Start Default_Page_URL"="http://www.google.com"
"Default_Search_URL"="http://www.google.com"
"Search Bar"="http://www.google.com"
"Search Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\SearchURI]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"

==== Reset Google Chrome ======================

C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\Luorhan\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Paty\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Luorhan\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Paty\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-4061941331-2985922947-4173166966-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00f782f3-b496-4f0f-be51-8a51eba1acb1} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{00f782f3-b496-4f0f-be51-8a51eba1acb1} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00f782f3-b496-4f0f-be51-8a51eba1acb1} deleted successfully

==== Deleting CLSID Registry Values ======================


==== shortcuts on Users Desktops ======================

C:\Users\Convidado\Desktop\Hao123.lnk - C:\Users\Luorhan\AppData\Roaming\Baidu\hao123-br\hao123.1.0.0.1111.exe
C:\Users\gabriel\Desktop\Hao123.lnk - C:\Users\Luorhan\AppData\Roaming\Baidu\hao123-br\hao123.1.0.0.1111.exe

==== shortcuts on All Users Desktop ======================

C:\Users\Public\Desktop\Buy Admin or VIP status.lnk - C:\Counter-Strike 1.6 [cswos.com]\buy_vip.htm
C:\Users\Public\Desktop\Counter-Strike 1.6 - Options.lnk - C:\Counter-Strike 1.6 [cswos.com]\hl.exe -steam -game cstrike -noipx -nojoy -noforcemparms -noforcemaccel
C:\Users\Public\Desktop\Counter-Strike 1.6 - Play.lnk - C:\Counter-Strike 1.6 [cswos.com]\hl.exe -steam -game cstrike -noipx -nojoy -noforcemparms -noforcemaccel +connect cswos.com
C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Public\Desktop\LOL.lnk - C:\Riot Games\League of Legends\lol.launcher.exe
C:\Users\Public\Desktop\McAfee Security Center.lnk - C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe /desktopicon /platui
C:\Users\Public\Desktop\Play League of Legends.lnk - C:\Riot Games\League of Legends\lol.launcher.exe

==== shortcuts in Users Start Menu ======================

C:\Users\Convidado\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Luorhan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Paty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe

==== shortcuts in All Users Start Menu ======================

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hao123-Brazil\Desinstalar hao123.lnk - C:\Users\Luorhan\AppData\Roaming\Baidu\hao123-br\hao123.1.0.0.1111.exe -uninstall
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hao123-Brazil\Hao123.lnk - C:\Users\Luorhan\AppData\Roaming\Baidu\hao123-br\hao123.1.0.0.1111.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe -tab about
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe -tab update
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk - C:\Program Files (x86)\Java\jre7\bin\javacpl.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee\McAfee SecurityCenter.lnk - C:\Program Files (x86)\McAfee.com\Agent\mcagent.exe /desktopicon /platui
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\Silverlight.Configuration.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony\MiPony.lnk - C:\Program Files (x86)\MiPony\MiPony.exe

==== shortcuts in Quick Launch ======================

C:\Users\Convidado\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Convidado\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Hao123.lnk - C:\Users\Luorhan\AppData\Roaming\Baidu\hao123-br\hao123.1.0.0.1111.exe
C:\Users\Convidado\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Convidado\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Convidado\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Convidado\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk - C:\Users\Luorhan\AppData\Roaming\Microsoft\Windows\Libraries
C:\Users\Convidado\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Convidado\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Convidado\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Movie Maker.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
C:\Users\Convidado\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Photo Gallery.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Hao123.lnk - C:\Users\Luorhan\AppData\Roaming\Baidu\hao123-br\hao123.1.0.0.1111.exe
C:\Users\gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\gabriel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Luorhan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Luorhan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Hao123.lnk - C:\Users\Luorhan\AppData\Roaming\Baidu\hao123-br\hao123.1.0.0.1111.exe
C:\Users\Luorhan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Luorhan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Luorhan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Luorhan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk - C:\Users\Luorhan\AppData\Roaming\Microsoft\Windows\Libraries
C:\Users\Luorhan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Luorhan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Luorhan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Movie Maker.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
C:\Users\Luorhan\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Photo Gallery.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
C:\Users\Paty\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Paty\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Paty\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Paty\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Paty\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk - C:\Users\Luorhan\AppData\Roaming\Microsoft\Windows\Libraries
C:\Users\Paty\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Paty\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Paty\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Movie Maker.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
C:\Users\Paty\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Photo Gallery.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\WLXPhotoGallery.exe
C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -

==== Reset IE Proxy ======================

Value(s) before fix:
"ProxyEnable"=dword:00000000

Value(s) after fix:
"ProxyEnable"=dword:00000000

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\fheoggkfdfchfphceeifdbepaooicaho deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\oedoknoijoakeplhlghdcggkclkbmaje deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Convidado\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Convidado\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Luorhan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Luorhan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Paty\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Paty\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\Convidado\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Luorhan\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Paty\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=41 folders=11 6568310 bytes)

==== Empty Temp Folders ======================

C:\Users\Administrator\AppData\Local\Temp emptied successfully
C:\Users\Convidado\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\gabriel\AppData\Local\Temp emptied successfully
C:\Users\Luorhan\AppData\Local\Temp will be emptied at reboot
C:\Users\Paty\AppData\Local\Temp emptied successfully
C:\Users\USURIO~1\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Reset Hosts File ======================

Hosts File Reset Successfully

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Luorhan\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 29/06/2014 at 22:09:12,25 ======================
luorhan
luorhan
Iniciante
Iniciante

Mensagens : 4
Reputação : 0
Data de inscrição : 29/06/2014

Ir para o topo Ir para baixo

Remoção SupraSavings - Já tentei de tudo ! Empty Re: Remoção SupraSavings - Já tentei de tudo !

Mensagem por Power Max Dom 29 Jun 2014, 22:23

faltou responder a pergunta:

No seu PC está constando o antivirus Baidu instalado. Você quer removê-lo ou quer continuar com ele?
Power Max
Power Max
Colaborador
Colaborador

Mensagens : 9086
Reputação : 1499
Data de inscrição : 14/04/2009

Ir para o topo Ir para baixo

Remoção SupraSavings - Já tentei de tudo ! Empty Re: Remoção SupraSavings - Já tentei de tudo !

Mensagem por luorhan Dom 29 Jun 2014, 22:24

na verdade ele não interfere em nada, pelo menos pra mim, então é não. Só quero retirar essa bosta de suprasavings mesmo !
luorhan
luorhan
Iniciante
Iniciante

Mensagens : 4
Reputação : 0
Data de inscrição : 29/06/2014

Ir para o topo Ir para baixo

Remoção SupraSavings - Já tentei de tudo ! Empty Re: Remoção SupraSavings - Já tentei de tudo !

Mensagem por Power Max Dom 29 Jun 2014, 22:41

Baixe o programa Junkware Removal Tool no link abaixo:
[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

Para executar corretamente o programa acima é só seguir as dicas deste tutorial:

[Tens de ter uma conta e sessão iniciada para poderes visualizar este link]

* Na sua próxima resposta poste o log (relatório) do Junkware Removal Tool que estará salvo em sua área de trabalho com o nome de JRT.txt

Ficamos na espera.
Power Max
Power Max
Colaborador
Colaborador

Mensagens : 9086
Reputação : 1499
Data de inscrição : 14/04/2009

Ir para o topo Ir para baixo

Remoção SupraSavings - Já tentei de tudo ! Empty Re: Remoção SupraSavings - Já tentei de tudo !

Mensagem por Power Max Dom 20 Jul 2014, 14:56

TÓPICO ARQUIVADO

Como o autor não respondeu por mais de 15 dias, o tópico foi arquivado. Caso o autor do tópico necessite, o mesmo será reaberto, para isso deverá entrar em contato com um dos membros da [Tens de ter uma conta e sessão iniciada para poderes visualizar este link] solicitando o desbloqueio.
Power Max
Power Max
Colaborador
Colaborador

Mensagens : 9086
Reputação : 1499
Data de inscrição : 14/04/2009

Ir para o topo Ir para baixo

Remoção SupraSavings - Já tentei de tudo ! Empty Re: Remoção SupraSavings - Já tentei de tudo !

Mensagem por Conteúdo patrocinado


Conteúdo patrocinado


Ir para o topo Ir para baixo

Ir para o topo

- Tópicos semelhantes

 
Permissões neste sub-fórum
Não podes responder a tópicos