Ir ao conteúdo
  • Comunicados

    • diego_moicano

      Gostaria de se tornar um analista em Remoção de Malware?   07-12-2015

      Gostaria de se tornar um analista em Remoção de Malware? O Fórum Clube do Hardware deu início a um programa de treinamento em análises de log. Os interessados deverão enviar um email para aprendizes (arroba) clubedohardware (ponto) com (ponto) br respondendo as seguintes perguntas: Por que você gostaria de aprender a analisar logs? Possui tempo hábil para o treinamento? Tem conhecimentos em informática? Se sim descreva-os. Possui inglês para leitura? Qual seu objetivo após completar o treinamento?   Não se esqueça de incluir no e-mail o seu nome de usuário (fornecer o link também), idade e cidade onde vive. Adicione também qualquer experiência e/ou razão sobre o porquê você seria um bom Analista. É digno de nota que apenas os que forem selecionados receberão resposta por MP (Mensagem Pessoal), não existe um padrão na escolha dos futuros aprendizes, todos os e-mails serão lidos e serão analisados de forma imparcial, portanto não será permitido reclamações neste aspecto. O treinamento é dado no próprio fórum. Quando um aprendiz é selecionado ele é movido para um novo grupo, onde terá acesso a fóruns fechados para os demais usuários onde poderá dar inicio ao seu treinamento. Importante: A cada 30 dias os e-mails não selecionados serão apagados, portanto você pode enviar um novo e-mail após 1 mês, e-mails enviados antes serão desconsiderados.  
    • Gabriel Torres

      Seja um moderador do Clube do Hardware!   12-02-2016

      Prezados membros do Clube do Hardware, Está aberto o processo de seleção de novos moderadores para diversos setores ou áreas do Clube do Hardware. Os requisitos são:   Pelo menos 500 posts e um ano de cadastro; Boa frequência de participação; Ser respeitoso, cordial e educado com os demais membros; Ter bom nível de português; Ter razoável conhecimento da área em que pretende atuar; Saber trabalhar em equipe (com os moderadores, coordenadores e administradores).   Os interessados deverão enviar uma mensagem privada para o usuário @Equipe Clube do Hardware com o título "Candidato a moderador". A mensagem deverá conter respostas às perguntas abaixo:   Qual o seu nome completo? Qual sua data de nascimento? Qual sua formação/profissão? Já atuou como moderador em algo outro fórum, se sim, qual? De forma sucinta, explique o porquê de querer ser moderador do fórum e conte-nos um pouco sobre você.   OBS: Não se trata de função remunerada. Todos que fazem parte do staff são voluntários.
Kevyn Poggian

PC reiniciando e abrindo pastas

Recommended Posts

A mais ou menos um mês comprei um teclado novo e depois de usá-lo por alguns minutos, o PC fica abrindo o media player, pastas, calculadora, fazendo logoff, hibernando e até mesmo desligando sozinho. No início logo achei que fosse problema no teclado, mas eu levei ele para testar aonde comprei e essas coisas só acontecem no meu Computador.

Segue anexo do log.

Obs: como não sei se realmente é problema no teclado ou vírus, postei nessa área.

 

 

ZA-Scan.txt

Compartilhar este post


Link para o post
Compartilhar em outros sites

@Kevyn Poggian

 

Por favor, atente para o seguinte:

  • Sobre o Fórum: Este é um espaço privado, não público. Seu uso é um privilégio, não um direito;
  • O que será passado aqui, somente será com relação ao problema do seu computador portanto, não faça mais em nenhum outro;
  • IMPORTANTE: Caso tenha programas de ativação do windows ou de compartilhamento de torrent, sugiro desinstalar. Só irei dar procedimento na analise após a remoção. Regras do forum;
  • Siga, por favor, atentamente as instruções passadas e em caso de dúvidas não hesite em perguntá-las;
  • Respeite a ordem das instruções passadas;
  • Observação: Não tome outra medida além das passadas aqui; atente para que, caso peça ajuda em outro fórum, não deixe de nos informar, sob risco de desconfigurar seu computador!

Apague o za-scan e faça download novamente. Dessa vez salve na Área de Trabalho e execute ele desse local. No aguardo do log.

Compartilhar este post


Link para o post
Compartilhar em outros sites

@Kevyn Poggian

 

Siga os passos abaixo:

ETAPA 1

Baixe o Malwarebytes Anti-Malware (MBAM) do link abaixo e salve no seu desktop.
https://downloads.malwarebytes.org/file/mbam_current/
 
Clique duas vezes no mbam-setup.exe e siga o solicitado para instalar o programa.

  • Na aba Análise > Analise Personalizada marque a opção Procurar rootkits e as entradas referente a instalação do sistema operacional. Normalmente é o drive C:;
  • Clique em Analisar Agora. Aguarde, pois o scan pode demorar;
  • Ao acabar o scan, se houver itens encontrados, certifique-se que estejam todas marcados e clique no botão Remover Selecionadas ou Colocar em Quarentena;
  • Ao final da desinfecção, poderá aparecer um aviso se quer reiniciar o PC. (Ver Nota abaixo);
  • Caso o mbam não seja executado automaticamente após a reinicialização, execute manualmente;
  • O log é automaticamente salvo pelo MBAM e para vê-lo, clique na aba Relatórios na janela principal do programa;
  • Clique duas vezes no log (Registro de verificação). Clique no botão Exportar e utilize o formato .txt para exportar o log. Salve na Área de Trabalho;
  • Abra o arquivo, selecione tudo, copie e cole o conteúdo deste log em sua próxima resposta.



NOTA: Se o MBAM encontrar arquivos que não consiga remover, poderá ter de reiniciar o PC (talvez mais de uma vez). Faça isso imediatamente, ao ser perguntado se quer reiniciar o PC.

ETAPA 2

Faça o download do AdwCleaner de um dos links abaixo e salve no desktop.
https://toolslib.net/downloads/viewdownload/1-adwcleaner/
http://www.bleepingcomputer.com/download/adwcleaner/

Clique em DOWNLOAD NOW para baixar o arquivo.

Execute o adwcleaner.exe

OBS: Usuários do Windows Vista, 7, 8/8.1 e windows 10 clique com o direito sobre o arquivo AdwCleaner.exe, depois clique em VRIfczU.png

Clique em EXAMINAR. Após o termino clique em LIMPAR e aguarde.

Será aberto o bloco de notas com o resultado.

Selecione, copie e cole o seu conteúdo na próxima resposta.

ETAPA 3

Desative temporariamente seu antivirus, antispywares e firewall, para não causar conflitos.

Baixe jrt.exe do link abaixo e salve no desktop.
http://www.bleepingcomputer.com/download/junkware-removal-tool/

Dê um duplo-clique para executar o Junkware Removal Tool (JRT).

OBS: Usuários do Windows Vista, 7, 8/8.1 e windows 10 clique com o direito sobre o arquivo jrt.exe, depois clique em VRIfczU.png

A ferramenta comecará o exame do seu sistema. Tenha paciência pois pode demorar um pouco dependendo da quantidades de ítens a examinar.

Ao final, um log se abrirá. É salvo no desktop com o nome de JRT.txt.

Selecione, copie e cole o conteúdo deste log na sua próxima resposta.

Compartilhar este post


Link para o post
Compartilhar em outros sites
  • Autor do tópico
  • @Elias Pereira 1- MBAM

    Malwarebytes
    www.malwarebytes.com

    -Detalhes de registro-
    Data da análise: 15/09/17
    Hora da análise: 18:00
    Arquivo de registro: f93e1770-9a58-11e7-8307-d05099af03f4.json
    Administrador: Sim

    -Informação do software-
    Versão: 3.2.2.2029
    Versão de componentes: 1.0.188
    Versão do pacote de definições: 1.0.2815
    Licença: Versão de Avaliação

    -Informação do sistema-
    Sistema operacional: Windows 7 Service Pack 1
    CPU: x64
    Sistema de arquivos: NTFS
    Usuário: Yachiru-PC\Yachiru

    -Resumo da análise-
    Tipo de análise: Análise Customizada
    Resultado: Cancelado
    Objetos verificados: 167565
    Ameaças detectadas: 1
    Ameaças em quarentena: 1
    Tempo decorrido: 2 hr, 45 min, 45 seg

    -Opções da análise-
    Memória: Habilitado
    Inicialização: Habilitado
    Sistema de arquivos: Habilitado
    Arquivos compactados: Habilitado
    Rootkits: Habilitado
    Heurística: Habilitado
    PUP: Detectar
    PUM: Detectar

    -Detalhes da análise-
    Processo: 0
    (Nenhum item malicioso detectado)

    Módulo: 0
    (Nenhum item malicioso detectado)

    Chave de registro: 0
    (Nenhum item malicioso detectado)

    Valor de registro: 0
    (Nenhum item malicioso detectado)

    Dados de registro: 0
    (Nenhum item malicioso detectado)

    Fluxo de dados: 0
    (Nenhum item malicioso detectado)

    Pasta: 0
    (Nenhum item malicioso detectado)

    Arquivo: 1
    PUP.Optional.DriverUpdate, C:\Windows\System32\drivers\SWDUMon.sys, Quarentena, [961], [337087],0.0.0

    Setor físico: 0
    (Nenhum item malicioso detectado)


    (end)

     

     

    2- ADWCLEANER

     

    # AdwCleaner 7.0.2.1 - Logfile created on Sat Sep 16 01:45:36 2017
    # Updated on 2017/29/08 by Malwarebytes 
    # Database: 09-15-2017.1
    # Running on Windows 7 Ultimate (X64)
    # Mode: scan
    # Support: https://www.malwarebytes.com/support

    ***** [ Services ] *****

    No malicious services found.

    ***** [ Folders ] *****

    PUP.Optional.Legacy, C:\Users\All Users\Documents\Downloaded Installers
    PUP.Optional.Legacy, C:\Users\Public\Documents\Downloaded Installers
    PUP.Optional.Legacy, C:\Users\Todos os Usuários\Documents\Downloaded Installers
    PUP.Optional.SlimCleanerPlus, C:\Users\Yachiru\AppData\Local\slimware utilities inc
    PUP.Optional.SlimCleanerPlus, C:\Users\Yachiru\AppData\Local\SlimWare Utilities Inc


    ***** [ Files ] *****

    No malicious files found.

    ***** [ DLL ] *****

    No malicious DLLs found.

    ***** [ WMI ] *****

    No malicious WMI found.

    ***** [ Shortcuts ] *****

    No malicious shortcuts found.

    ***** [ Tasks ] *****

    No malicious tasks found.

    ***** [ Registry ] *****

    PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\952BA647474611149866C1269F6A0E36
    PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Installer\Features\952BA647474611149866C1269F6A0E36
    PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Installer\Products\952BA647474611149866C1269F6A0E36
    PUP.Optional.ProductSetup.A, [Key] - HKU\S-1-5-21-3681131249-3799211891-317176267-1000\Software\PRODUCTSETUP
    PUP.Optional.ProductSetup.A, [Key] - HKCU\Software\PRODUCTSETUP
    PUP.Optional.SlimCleanerPlus, [Key] - HKLM\SOFTWARE\SlimWare Utilities Inc
    PUP.Optional.SlimCleanerPlus, [Key] - HKU\S-1-5-21-3681131249-3799211891-317176267-1000\Software\SlimWare Utilities Inc
    PUP.Optional.SlimCleanerPlus, [Key] - HKCU\Software\SlimWare Utilities Inc
    PUP.Optional.SlimCleanerPlus, [Key] - HKLM\SOFTWARE\SLIMWARE UTILITIES, INC.


    ***** [ Firefox (and derivatives) ] *****

    No malicious Firefox entries.

    ***** [ Chromium (and derivatives) ] *****

    PUP.Optional.Legacy, SearchProvider found: webssearches - istart.webssearches.com
    PUP.Optional.Legacy, SearchProvider found: webssearches - webssearches
    PUP.Optional.Legacy, SearchProvider found: Web Search - search.certified-toolbar.com
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hp&ts=1399080940&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399117617&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399139216&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399146106&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399173881&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399211635&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.google.com/
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399236402&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399248159&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399252906&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399290624&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399333000&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399383702&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399467843&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399481189&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399551810&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399560985&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399631597&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399648367&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399663430&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399722097&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399724388&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399739796&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399806500&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hp&ts=1400809549&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401642544&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401665368&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401717279&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401733819&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401812257&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401833252&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401927012&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401983881&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402010229&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402055905&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402406959&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402481091&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402493578&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402515871&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402519086&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402581973&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402614574&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402711062&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: chrome://newtab/?source=home
    PUP.Optional.Legacy, Startpage found: http://feed.helperbar.com/?p=mKO_AwFzXIpYRa0ymfMnbpqxFRcw9bO9KVavhRaCksnt3bQgejRBHVR7LnarL5U7xTo-EijVPLRlh_2C6cr0j29ccSNgtzQEj_IaC4iH88_aoxIILcj85IHaqd2UMjUz3a2z8qjVC6ikIN9__B1RS-55jnixufrhhgTcu-eUfywAkuFYxA,,
    PUP.Optional.Legacy, Startpage found: http://search.certified-toolbar.com/?si=82443&st=home&tid=24086&ver=6.4&ts=1402711977076&tguid=82443-24086-1402711977076-087700476358ADF656057E384DEC6296
    PUP.Optional.Legacy, Startpage found: http://start.iminent.com/?appId=E0F78416-BF34-42DF-810D-8FA417FA7122
    PUP.Optional.Legacy, Startpage found: http://istart.webssearches.com/?type=hp&ts=1407349310&from=bxk1&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://istart.webssearches.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://istart.%3Chtml%3E%3Chead%3E%3Cmeta%20http-equiv%3D%22pragma%22%20content%3D%22no-cache%22%3E%3Cscript%20language%3D%27javascript%27%3Eparent.location%3D%22/login.htm%22%3C/script%3E%3C/head%3E%3Cbody%3E%3C/body%3E%3C/html%3E.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.oursurfing.com/?type=hp&ts=1430931536&z=390f8ef624fcf9ca68ecc8fg1zcc0eatec0gfw8o4w&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.oursurfing.com/?type=hppp&ts=1430931752&z=52297ec0e4fe03552f7ac68gbz9ceect2ccgfm3zbo&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hp&ts=1399080940&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399117617&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399139216&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399146106&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399173881&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399211635&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.google.com/
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399236402&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399248159&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399252906&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399290624&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399333000&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399383702&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399467843&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399481189&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399551810&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399560985&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399631597&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399648367&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399663430&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399722097&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399724388&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399739796&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399806500&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hp&ts=1400809549&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401642544&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401665368&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401717279&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401733819&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401812257&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401833252&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401927012&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401983881&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402010229&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402055905&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402406959&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402481091&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402493578&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402515871&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402519086&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402581973&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402614574&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402711062&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: chrome://newtab/?source=home
    PUP.Optional.Legacy, Startpage found: http://feed.helperbar.com/?p=mKO_AwFzXIpYRa0ymfMnbpqxFRcw9bO9KVavhRaCksnt3bQgejRBHVR7LnarL5U7xTo-EijVPLRlh_2C6cr0j29ccSNgtzQEj_IaC4iH88_aoxIILcj85IHaqd2UMjUz3a2z8qjVC6ikIN9__B1RS-55jnixufrhhgTcu-eUfywAkuFYxA,,
    PUP.Optional.Legacy, Startpage found: http://search.certified-toolbar.com/?si=82443&st=home&tid=24086&ver=6.4&ts=1402711977076&tguid=82443-24086-1402711977076-087700476358ADF656057E384DEC6296
    PUP.Optional.Legacy, Startpage found: http://start.iminent.com/?appId=E0F78416-BF34-42DF-810D-8FA417FA7122
    PUP.Optional.Legacy, Startpage found: http://istart.webssearches.com/?type=hp&ts=1407349310&from=bxk1&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://istart.webssearches.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://istart.%3Chtml%3E%3Chead%3E%3Cmeta%20http-equiv%3D%22pragma%22%20content%3D%22no-cache%22%3E%3Cscript%20language%3D%27javascript%27%3Eparent.location%3D%22/login.htm%22%3C/script%3E%3C/head%3E%3Cbody%3E%3C/body%3E%3C/html%3E.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.oursurfing.com/?type=hp&ts=1430931536&z=390f8ef624fcf9ca68ecc8fg1zcc0eatec0gfw8o4w&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.oursurfing.com/?type=hppp&ts=1430931752&z=52297ec0e4fe03552f7ac68gbz9ceect2ccgfm3zbo&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hp&ts=1399080940&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399117617&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399139216&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399146106&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399173881&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399211635&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.google.com/
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399236402&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399248159&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399252906&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399290624&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399333000&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399383702&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399467843&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399481189&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399551810&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399560985&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399631597&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399648367&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399663430&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399722097&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399724388&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399739796&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399806500&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hp&ts=1400809549&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401642544&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401665368&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401717279&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401733819&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401812257&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401833252&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401927012&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401983881&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402010229&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402055905&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402406959&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402481091&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402493578&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402515871&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402519086&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402581973&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402614574&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402711062&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: chrome://newtab/?source=home
    PUP.Optional.Legacy, Startpage found: http://feed.helperbar.com/?p=mKO_AwFzXIpYRa0ymfMnbpqxFRcw9bO9KVavhRaCksnt3bQgejRBHVR7LnarL5U7xTo-EijVPLRlh_2C6cr0j29ccSNgtzQEj_IaC4iH88_aoxIILcj85IHaqd2UMjUz3a2z8qjVC6ikIN9__B1RS-55jnixufrhhgTcu-eUfywAkuFYxA,,
    PUP.Optional.Legacy, Startpage found: http://search.certified-toolbar.com/?si=82443&st=home&tid=24086&ver=6.4&ts=1402711977076&tguid=82443-24086-1402711977076-087700476358ADF656057E384DEC6296
    PUP.Optional.Legacy, Startpage found: http://start.iminent.com/?appId=E0F78416-BF34-42DF-810D-8FA417FA7122
    PUP.Optional.Legacy, Startpage found: http://istart.webssearches.com/?type=hp&ts=1407349310&from=bxk1&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://istart.webssearches.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://istart.%3Chtml%3E%3Chead%3E%3Cmeta%20http-equiv%3D%22pragma%22%20content%3D%22no-cache%22%3E%3Cscript%20language%3D%27javascript%27%3Eparent.location%3D%22/login.htm%22%3C/script%3E%3C/head%3E%3Cbody%3E%3C/body%3E%3C/html%3E.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.oursurfing.com/?type=hp&ts=1430931536&z=390f8ef624fcf9ca68ecc8fg1zcc0eatec0gfw8o4w&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.oursurfing.com/?type=hppp&ts=1430931752&z=52297ec0e4fe03552f7ac68gbz9ceect2ccgfm3zbo&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hp&ts=1399080940&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399117617&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399139216&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399146106&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399173881&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399211635&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.google.com/
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399236402&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399248159&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399252906&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399290624&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399333000&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399383702&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399467843&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399481189&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399551810&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399560985&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399631597&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399648367&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399663430&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399722097&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399724388&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399739796&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399806500&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hp&ts=1400809549&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401642544&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401665368&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401717279&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401733819&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401812257&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401833252&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401927012&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401983881&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402010229&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402055905&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402406959&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402481091&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402493578&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402515871&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402519086&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402581973&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402614574&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402711062&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: chrome://newtab/?source=home
    PUP.Optional.Legacy, Startpage found: http://feed.helperbar.com/?p=mKO_AwFzXIpYRa0ymfMnbpqxFRcw9bO9KVavhRaCksnt3bQgejRBHVR7LnarL5U7xTo-EijVPLRlh_2C6cr0j29ccSNgtzQEj_IaC4iH88_aoxIILcj85IHaqd2UMjUz3a2z8qjVC6ikIN9__B1RS-55jnixufrhhgTcu-eUfywAkuFYxA,,
    PUP.Optional.Legacy, Startpage found: http://search.certified-toolbar.com/?si=82443&st=home&tid=24086&ver=6.4&ts=1402711977076&tguid=82443-24086-1402711977076-087700476358ADF656057E384DEC6296
    PUP.Optional.Legacy, Startpage found: http://start.iminent.com/?appId=E0F78416-BF34-42DF-810D-8FA417FA7122
    PUP.Optional.Legacy, Startpage found: http://istart.webssearches.com/?type=hp&ts=1407349310&from=bxk1&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://istart.webssearches.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://istart.%3Chtml%3E%3Chead%3E%3Cmeta%20http-equiv%3D%22pragma%22%20content%3D%22no-cache%22%3E%3Cscript%20language%3D%27javascript%27%3Eparent.location%3D%22/login.htm%22%3C/script%3E%3C/head%3E%3Cbody%3E%3C/body%3E%3C/html%3E.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.oursurfing.com/?type=hp&ts=1430931536&z=390f8ef624fcf9ca68ecc8fg1zcc0eatec0gfw8o4w&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.oursurfing.com/?type=hppp&ts=1430931752&z=52297ec0e4fe03552f7ac68gbz9ceect2ccgfm3zbo&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hp&ts=1399080940&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399117617&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399139216&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399146106&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399173881&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399211635&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.google.com/
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399236402&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399248159&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399252906&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399290624&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399333000&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399383702&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399467843&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399481189&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399551810&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399560985&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399631597&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399648367&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399663430&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399722097&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399724388&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399739796&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399806500&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hp&ts=1400809549&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401642544&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401665368&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401717279&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401733819&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401812257&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401833252&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401927012&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401983881&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402010229&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402055905&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402406959&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402481091&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402493578&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402515871&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402519086&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402581973&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402614574&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402711062&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: chrome://newtab/?source=home
    PUP.Optional.Legacy, Startpage found: http://feed.helperbar.com/?p=mKO_AwFzXIpYRa0ymfMnbpqxFRcw9bO9KVavhRaCksnt3bQgejRBHVR7LnarL5U7xTo-EijVPLRlh_2C6cr0j29ccSNgtzQEj_IaC4iH88_aoxIILcj85IHaqd2UMjUz3a2z8qjVC6ikIN9__B1RS-55jnixufrhhgTcu-eUfywAkuFYxA,,
    PUP.Optional.Legacy, Startpage found: http://search.certified-toolbar.com/?si=82443&st=home&tid=24086&ver=6.4&ts=1402711977076&tguid=82443-24086-1402711977076-087700476358ADF656057E384DEC6296
    PUP.Optional.Legacy, Startpage found: http://start.iminent.com/?appId=E0F78416-BF34-42DF-810D-8FA417FA7122
    PUP.Optional.Legacy, Startpage found: http://istart.webssearches.com/?type=hp&ts=1407349310&from=bxk1&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://istart.webssearches.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://istart.%3Chtml%3E%3Chead%3E%3Cmeta%20http-equiv%3D%22pragma%22%20content%3D%22no-cache%22%3E%3Cscript%20language%3D%27javascript%27%3Eparent.location%3D%22/login.htm%22%3C/script%3E%3C/head%3E%3Cbody%3E%3C/body%3E%3C/html%3E.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.oursurfing.com/?type=hp&ts=1430931536&z=390f8ef624fcf9ca68ecc8fg1zcc0eatec0gfw8o4w&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.oursurfing.com/?type=hppp&ts=1430931752&z=52297ec0e4fe03552f7ac68gbz9ceect2ccgfm3zbo&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hp&ts=1399080940&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399117617&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399139216&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399146106&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399173881&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399211635&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.google.com/
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399236402&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399248159&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399252906&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399290624&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399333000&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399383702&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399467843&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399481189&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399551810&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399560985&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399631597&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399648367&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399663430&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399722097&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399724388&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399739796&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://start.qone8.com/?type=hppp&ts=1399806500&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hp&ts=1400809549&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401642544&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401665368&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401717279&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401733819&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401812257&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401833252&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401927012&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1401983881&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402010229&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402055905&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402406959&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402481091&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402493578&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402515871&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402519086&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402581973&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402614574&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.sweet-page.com/?type=hppp&ts=1402711062&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: chrome://newtab/?source=home
    PUP.Optional.Legacy, Startpage found: http://feed.helperbar.com/?p=mKO_AwFzXIpYRa0ymfMnbpqxFRcw9bO9KVavhRaCksnt3bQgejRBHVR7LnarL5U7xTo-EijVPLRlh_2C6cr0j29ccSNgtzQEj_IaC4iH88_aoxIILcj85IHaqd2UMjUz3a2z8qjVC6ikIN9__B1RS-55jnixufrhhgTcu-eUfywAkuFYxA,,
    PUP.Optional.Legacy, Startpage found: http://search.certified-toolbar.com/?si=82443&st=home&tid=24086&ver=6.4&ts=1402711977076&tguid=82443-24086-1402711977076-087700476358ADF656057E384DEC6296
    PUP.Optional.Legacy, Startpage found: http://start.iminent.com/?appId=E0F78416-BF34-42DF-810D-8FA417FA7122
    PUP.Optional.Legacy, Startpage found: http://istart.webssearches.com/?type=hp&ts=1407349310&from=bxk1&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://istart.webssearches.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://istart.%3Chtml%3E%3Chead%3E%3Cmeta%20http-equiv%3D%22pragma%22%20content%3D%22no-cache%22%3E%3Cscript%20language%3D%27javascript%27%3Eparent.location%3D%22/login.htm%22%3C/script%3E%3C/head%3E%3Cbody%3E%3C/body%3E%3C/html%3E.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.oursurfing.com/?type=hp&ts=1430931536&z=390f8ef624fcf9ca68ecc8fg1zcc0eatec0gfw8o4w&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    PUP.Optional.Legacy, Startpage found: http://www.oursurfing.com/?type=hppp&ts=1430931752&z=52297ec0e4fe03552f7ac68gbz9ceect2ccgfm3zbo&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862

    /!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271


    *************************

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########

     

     

     

    3- JRT

     

     

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Malwarebytes
    Version: 8.1.4 (07.09.2017)
    Operating System: Windows 7 Ultimate x64 
    Ran by Yachiru (Administrator) on 15/09/2017 at 22:52:55,09
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


    File System: 24 

    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\06CYLOFC (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3I8OSYX2 (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4M7NH6XU (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\645T4QI9 (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\76H8WYYY (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FMPGG35N (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GL57NQLK (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S1RTVK5H (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\06CYLOFC (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3I8OSYX2 (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4M7NH6XU (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\645T4QI9 (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\76H8WYYY (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FMPGG35N (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GL57NQLK (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S1RTVK5H (Temporary Internet Files Folder) 

    Registry: 1 

    Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\SWDUMon (Registry Key) 


    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 15/09/2017 at 22:55:36,80
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    @Kevyn Poggian

     

    Faça o download do RogueKiller by Tigzy, e salve na sua área de trabalho (Desktop).
    roguekiller.exe (x64) << link

    • Feche todos os programas
    • Execute o RogueKiller.exe.
      ** Usuários do Windows Vista, Windows 7, 8, 8.1 e Windows 10:
      Clique com o direito sobre o arquivo rogueKiller.exe, depois clique em VRIfczU.png.
    • Quando a janela da Eula aparecer, clique em Accept.
    • Selecione a aba SCAN
    • Clique em START SCAN
    • Aguarde ate que o scan termine...
    • Clique no botão OPEN REPORT
    • Clique na opção EXPORT TXT e salve na Área de Trabalho com o nome de roguekiller.txt
    • Clique em OK e feche o RogueKiller.



    Atente para abrir o arquivo, copiar e colar todo o conteúdo na sua próxima resposta

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • @Elias Pereira pronto

     

    RogueKiller V12.11.14.0 (x64) [Sep 11 2017] (Free) por Adlice Software
    mail : http://www.adlice.com/contact/
    Feedback : https://forum.adlice.com
    Site : http://www.adlice.com/download/roguekiller/
    Blog : http://www.adlice.com

    Sistema Operacional : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Iniciou : Modo normal
    Usuário : Yachiru [Administrador]
    Started from : C:\Users\Yachiru\Desktop\RogueKiller_portable64.exe
    Modo : Escanear -- Data : 09/17/2017 22:44:21 (Duration : 00:11:14)

    ¤¤¤ Processos : 0 ¤¤¤

    ¤¤¤ Registro : 0 ¤¤¤

    ¤¤¤ Tarefas : 0 ¤¤¤

    ¤¤¤ Arquivos : 0 ¤¤¤

    ¤¤¤ WMI : 0 ¤¤¤

    ¤¤¤ Arquivos de hosts : 0 ¤¤¤

    ¤¤¤ Antirootkit : 0 (Driver: Carregado) ¤¤¤

    ¤¤¤ Navegadores : 2 ¤¤¤
    [PUP.Gen1|PUM.HomePage][Chrome:Config] Default [SecurePrefs] : homepage [http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=] -> Encontrado
    [PUP.Gen1|PUM.HomePage][Chrome:Config] Default [SecurePrefs] : session.startup_urls [http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=|http://start.qone8.com/?type=hp&ts=1399080940&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399117617&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=|http://start.qone8.com/?type=hppp&ts=1399139216&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399146106&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399173881&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399211635&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.google.com/|http://start.qone8.com/?type=hppp&ts=1399236402&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399248159&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399252906&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399290624&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399333000&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399383702&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399467843&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399481189&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399551810&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399560985&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399631597&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399648367&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399663430&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399722097&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399724388&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399739796&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399806500&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hp&ts=1400809549&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401642544&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401665368&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401717279&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401733819&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401812257&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401833252&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401927012&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401983881&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402010229&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402055905&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402406959&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402481091&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402493578&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402515871&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402519086&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402581973&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402614574&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402711062&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|chrome://newtab/?source=home|http://feed.helperbar.com/?p=mKO_AwFzXIpYRa0ymfMnbpqxFRcw9bO9KVavhRaCksnt3bQgejRBHVR7LnarL5U7xTo-EijVPLRlh_2C6cr0j29ccSNgtzQEj_IaC4iH88_aoxIILcj85IHaqd2UMjUz3a2z8qjVC6ikIN9__B1RS-55jnixufrhhgTcu-eUfywAkuFYxA,,|http://search.certified-toolbar.com/?si=82443&st=home&tid=24086&ver=6.4&ts=1402711977076&tguid=82443-24086-1402711977076-087700476358ADF656057E384DEC6296|http://start.iminent.com/?appId=E0F78416-BF34-42DF-810D-8FA417FA7122|http://istart.webssearches.com/?type=hp&ts=1407349310&from=bxk1&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://istart.webssearches.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://istart.%3Chtml%3E%3Chead%3E%3Cmeta%20http-equiv%3D%22pragma%22%20content%3D%22no-cache%22%3E%3Cscript%20language%3D%27javascript%27%3Eparent.location%3D%22/login.htm%22%3C/script%3E%3C/head%3E%3Cbody%3E%3C/body%3E%3C/html%3E.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.oursurfing.com/?type=hp&ts=1430931536&z=390f8ef624fcf9ca68ecc8fg1zcc0eatec0gfw8o4w&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.oursurfing.com/?type=hppp&ts=1430931752&z=52297ec0e4fe03552f7ac68gbz9ceect2ccgfm3zbo&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|https://encrypted.google.com] -> Encontrado

    ¤¤¤ Verificação da MBR : ¤¤¤
    +++++ PhysicalDrive0: ST500DM002-1BD142 ATA Device +++++
    --- User ---
    [MBR] d7de0b614497fe1e531e85f0815947b5
    [BSP] 1febb2db7569877a849f09d0d32fa0aa : Windows Vista/7/8 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 276838 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 567171072 | Size: 200000 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    User = LL1 ... OK
    User = LL2 ... OK

     

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    @Kevyn Poggian

     

    Feche todos os programas

    • Execute RogueKiller.exe.
      ** Usuários do Windows Vista, 7, 8/8.1 e windows 10:
      Clique com o direito sobre o arquivo rogueKiller.exe, depois clique em VRIfczU.png
    • Quando a Eula aparecer, clique em Accept.
    • Selecione a aba SCAN e clique em START SCAN
    • Aguarde ate que o scan termine.
    • >>>>>>> Navegue entre as abas e marque todas as entradas encontradas <<<<<<<
    • Clique em REMOVE SELECTED
    • Aguarde ate que o programa termine de deletar as infecções.
    • Clique no botão OPEN REPORT e depois em EXPORT TXT
    • Salve como report.txt na sua Área de Trabalho

    Abra o arquivo report.txt salvo no sua Área de Trabalho, copie e cole todo o conteudo na sua próxima resposta.

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • @Elias Pereira

    RogueKiller V12.11.14.0 (x64) [Sep 11 2017] (Free) por Adlice Software
    mail : http://www.adlice.com/contact/
    Feedback : https://forum.adlice.com
    Site : http://www.adlice.com/download/roguekiller/
    Blog : http://www.adlice.com

    Sistema Operacional : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Iniciou : Modo normal
    Usuário : Yachiru [Administrador]
    Started from : C:\Users\Yachiru\Desktop\RogueKiller_portable64.exe
    Modo : Deletar -- Data : 09/19/2017 07:16:04 (Duration : 00:12:23)

    ¤¤¤ Processos : 0 ¤¤¤

    ¤¤¤ Registro : 0 ¤¤¤

    ¤¤¤ Tarefas : 0 ¤¤¤

    ¤¤¤ Arquivos : 0 ¤¤¤

    ¤¤¤ WMI : 0 ¤¤¤

    ¤¤¤ Arquivos de hosts : 0 ¤¤¤

    ¤¤¤ Antirootkit : 0 (Driver: Carregado) ¤¤¤

    ¤¤¤ Navegadores : 2 ¤¤¤
    [PUP.Gen1|PUM.HomePage][Chrome:Config] Default [SecurePrefs] : homepage [http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=] -> Deletado
    [PUP.Gen1|PUM.HomePage][Chrome:Config] Default [SecurePrefs] : session.startup_urls [http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=|http://start.qone8.com/?type=hp&ts=1399080940&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399117617&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=|http://start.qone8.com/?type=hppp&ts=1399139216&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399146106&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399173881&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399211635&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.google.com/|http://start.qone8.com/?type=hppp&ts=1399236402&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399248159&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399252906&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399290624&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399333000&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399383702&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399467843&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399481189&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399551810&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399560985&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399631597&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399648367&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399663430&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399722097&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399724388&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399739796&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://start.qone8.com/?type=hppp&ts=1399806500&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hp&ts=1400809549&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401642544&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401665368&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401717279&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401733819&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401812257&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401833252&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401927012&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1401983881&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402010229&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402055905&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402406959&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402481091&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402493578&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402515871&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402519086&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402581973&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402614574&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.sweet-page.com/?type=hppp&ts=1402711062&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|chrome://newtab/?source=home|http://feed.helperbar.com/?p=mKO_AwFzXIpYRa0ymfMnbpqxFRcw9bO9KVavhRaCksnt3bQgejRBHVR7LnarL5U7xTo-EijVPLRlh_2C6cr0j29ccSNgtzQEj_IaC4iH88_aoxIILcj85IHaqd2UMjUz3a2z8qjVC6ikIN9__B1RS-55jnixufrhhgTcu-eUfywAkuFYxA,,|http://search.certified-toolbar.com/?si=82443&st=home&tid=24086&ver=6.4&ts=1402711977076&tguid=82443-24086-1402711977076-087700476358ADF656057E384DEC6296|http://start.iminent.com/?appId=E0F78416-BF34-42DF-810D-8FA417FA7122|http://istart.webssearches.com/?type=hp&ts=1407349310&from=bxk1&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://istart.webssearches.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://istart.%3Chtml%3E%3Chead%3E%3Cmeta%20http-equiv%3D%22pragma%22%20content%3D%22no-cache%22%3E%3Cscript%20language%3D%27javascript%27%3Eparent.location%3D%22/login.htm%22%3C/script%3E%3C/head%3E%3Cbody%3E%3C/body%3E%3C/html%3E.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.oursurfing.com/?type=hp&ts=1430931536&z=390f8ef624fcf9ca68ecc8fg1zcc0eatec0gfw8o4w&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|http://www.oursurfing.com/?type=hppp&ts=1430931752&z=52297ec0e4fe03552f7ac68gbz9ceect2ccgfm3zbo&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862|https://encrypted.google.com] -> Deletado

    ¤¤¤ Verificação da MBR : ¤¤¤
    +++++ PhysicalDrive0: ST500DM002-1BD142 ATA Device +++++
    --- User ---
    [MBR] d7de0b614497fe1e531e85f0815947b5
    [BSP] 1febb2db7569877a849f09d0d32fa0aa : Windows Vista/7/8 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 276838 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 567171072 | Size: 200000 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    User = LL1 ... OK
    User = LL2 ... OK

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    @Kevyn Poggian

     

    Faça o download Zemana AntiMalware do seguinte local e salve-o em sua área de trabalho:
    https://www.zemana.com/download (sugiro a versão portable)

    • Uma vez baixado, feche todos os programas e janelas abertas no seu computador.
    • Agora clique duas vezes no ícone na área de trabalho Zemana.AntiMalware.Setup.exe
    • Isto irá iniciar a instalação do Zemana AntiMalware em seu computador.
    • Quando a instalação começar, continue seguindo as instruções, a fim de continuar com o processo de instalação. Não faça quaisquer alterações nas configurações padrão e quando o programa estiver instalado, Zemana irá iniciar e exibir a tela principal automaticamente.
    • Clique no botão SCAN
    • Zemana AntiMalware vai agora começar a varredura de malware no computador. Este processo pode demorar um pouco, por isso sugerimos que você fazer outra coisa e verificar periodicamente sobre o estado da verificação para ver quando ele for concluído.
    • Quando Zemana terminar o scan ele irá exibir uma tela com os malwareres que foram detectados. Por favor, note que as infecções encontradas pode ser diferente do que é mostrado na imagem abaixo.
      yeabests.cc-zemana.png
    • Verifique os resultados da verificação e, quando estiver pronto para continuar com o processo de limpeza, clique no botão para eliminar ou reparar todos os resultados selecionados. Depois de clicar no botão Avançar, Zemana irá remover quaisquer arquivos indesejados e corrigir quaisquer arquivos legítimos modificados. Se você receber um aviso de que Zemana precisa fechar seus navegadores abertos, por favor, feche todos e, em seguida, clique no OK para continuar.
    • Zemana agora irá criar um ponto de restauração e remover os arquivos detectados e reparar quaisquer arquivos que foram modificados.

    Poste o resultado no seu proximo post.

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • Zemana AntiMalware 2.74.2.150 (instalado)

    -------------------------------------------------------
    Scan Result            : Concluído
    Scan Date              : 2017/9/20
    Operating System       : Windows 7 64-bit
    Processor              : 2X AMD A4-6300 APU with Radeon(tm) HD Graphics
    BIOS Mode              : Legacy
    CUID                   : 124CAA4338EAFA14FC63D7
    Scan Type              : Análise do Sistema
    Duration               : 3m 59s
    Scanned Objects        : 27957
    Detected Objects       : 53
    Excluded Objects       : 0
    Read Level             : SCSI
    Auto Upload            : Activado
    Detect All Extensions  : Desactivado
    Scan Documents         : Desactivado
    Domain Info            : WORKGROUP,0,2

    Detected Objects
    -------------------------------------------------------

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.oursurfing.com/?type=hppp&ts=1430931752&z=52297ec0e4fe03552f7ac68gbz9ceect2ccgfm3zbo&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.oursurfing.com/?type=hp&ts=1430931536&z=390f8ef624fcf9ca68ecc8fg1zcc0eatec0gfw8o4w&from=age&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://istart.%3Chtml%3E%3Chead%3E%3Cmeta%20http-equiv%3D%22pragma%22%20content%3D%22no-cache%22%3E%3Cscript%20language%3D%27javascript%27%3Eparent.location%3D%22/login.htm%22%3C/script%3E%3C/head%3E%3Cbody%3E%3C/body%3E%3C/html%3E.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://istart.webssearches.com/?type=hppp&ts=1421263344&from=pcm&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://istart.webssearches.com/?type=hp&ts=1407349310&from=bxk1&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.iminent.com/?appId=E0F78416-BF34-42DF-810D-8FA417FA7122
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://search.certified-toolbar.com/?si=82443&st=home&tid=24086&ver=6.4&ts=1402711977076&tguid=82443-24086-1402711977076-087700476358ADF656057E384DEC6296
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://feed.helperbar.com/?p=mKO_AwFzXIpYRa0ymfMnbpqxFRcw9bO9KVavhRaCksnt3bQgejRBHVR7LnarL5U7xTo-EijVPLRlh_2C6cr0j29ccSNgtzQEj_IaC4iH88_aoxIILcj85IHaqd2UMjUz3a2z8qjVC6ikIN9__B1RS-55jnixufrhhgTcu-eUfywAkuFYxA,,
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1402711062&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1402614574&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1402581973&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1402519086&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1402515871&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1402493578&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1402481091&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1402406959&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1402055905&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1402010229&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1401983881&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1401927012&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1401833252&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1401812257&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1401733819&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1401717279&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1401665368&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hppp&ts=1401642544&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://www.sweet-page.com/?type=hp&ts=1400809549&from=wpc&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399806500&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399739796&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399724388&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399722097&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399663430&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399648367&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399631597&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399560985&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399551810&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399481189&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399467843&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399383702&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399333000&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399290624&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399252906&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399248159&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399236402&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399211635&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399173881&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399146106&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399139216&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hppp&ts=1399117617&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://start.qone8.com/?type=hp&ts=1399080940&from=tt4u&uid=ST320LM001XHN-M320MBB_S2W1J5AC806862
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Startup Url
    Status             : Analisados
    Object             : http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Startup Url

    Chrome Homepage
    Status             : Analisados
    Object             : http://search.conduit.com/?gd=&ctid=CT3324332&octid=EB_ORIGINAL_CTID&ISID=MF758B8B9-2DDE-486A-A5CD-91C723147574&SearchSource=55&CUI=&UM=5&UP=SPB25F17C5-1374-4870-977F-E4787C971209&SSPV=
    MD5                : -
    Publisher          : -
    Size               : -
    Version            : -
    Detection          : Configuração do navegador suspeito
    Cleaning Action    : Reparar
    Related Objects    :
                    Configuração do navegador - Chrome Homepage


    Cleaning Result
    -------------------------------------------------------
    Cleaned               : 53
    Reported as safe      : 0
    Failed                : 0
     

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • @Elias Pereira MBAM

    Malwarebytes
    www.malwarebytes.com

    -Detalhes de registro-
    Data da análise: 22/09/17
    Hora da análise: 08:26
    Arquivo de registro: ed215936-9f88-11e7-a50c-d05099af03f4.json
    Administrador: Sim

    -Informação do software-
    Versão: 3.2.2.2029
    Versão de componentes: 1.0.188
    Versão do pacote de definições: 1.0.2863
    Licença: Versão de Avaliação

    -Informação do sistema-
    Sistema operacional: Windows 7 Service Pack 1
    CPU: x64
    Sistema de arquivos: NTFS
    Usuário: Yachiru-PC\Yachiru

    -Resumo da análise-
    Tipo de análise: Análise de Ameaças
    Resultado: Concluído
    Objetos verificados: 290365
    Ameaças detectadas: 0
    (Nenhum item malicioso detectado)
    Ameaças em quarentena: 0
    (Nenhum item malicioso detectado)
    Tempo decorrido: 2 min, 51 seg

    -Opções da análise-
    Memória: Habilitado
    Inicialização: Habilitado
    Sistema de arquivos: Habilitado
    Arquivos compactados: Habilitado
    Rootkits: Desabilitado
    Heurística: Habilitado
    PUP: Detectar
    PUM: Detectar

    -Detalhes da análise-
    Processo: 0
    (Nenhum item malicioso detectado)

    Módulo: 0
    (Nenhum item malicioso detectado)

    Chave de registro: 0
    (Nenhum item malicioso detectado)

    Valor de registro: 0
    (Nenhum item malicioso detectado)

    Dados de registro: 0
    (Nenhum item malicioso detectado)

    Fluxo de dados: 0
    (Nenhum item malicioso detectado)

    Pasta: 0
    (Nenhum item malicioso detectado)

    Arquivo: 0
    (Nenhum item malicioso detectado)

    Setor físico: 0
    (Nenhum item malicioso detectado)


    (end)

     

     

    ADW-

     

    # AdwCleaner 7.0.2.1 - Logfile created on Fri Sep 22 11:34:39 2017
    # Updated on 2017/29/08 by Malwarebytes 
    # Database: 09-20-2017.1
    # Running on Windows 7 Ultimate (X64)
    # Mode: scan
    # Support: https://www.malwarebytes.com/support

    ***** [ Services ] *****

    No malicious services found.

    ***** [ Folders ] *****

    No malicious folders found.

    ***** [ Files ] *****

    No malicious files found.

    ***** [ DLL ] *****

    No malicious DLLs found.

    ***** [ WMI ] *****

    No malicious WMI found.

    ***** [ Shortcuts ] *****

    No malicious shortcuts found.

    ***** [ Tasks ] *****

    No malicious tasks found.

    ***** [ Registry ] *****

    No malicious registry entries found.

    ***** [ Firefox (and derivatives) ] *****

    No malicious Firefox entries.

    ***** [ Chromium (and derivatives) ] *****

    PUP.Optional.Legacy, SearchProvider found: webssearches - istart.webssearches.com
    PUP.Optional.Legacy, SearchProvider found: webssearches - webssearches
    PUP.Optional.Legacy, SearchProvider found: Web Search - search.certified-toolbar.com

    /!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271


    *************************

    C:/AdwCleaner/AdwCleaner[C0].txt - [14153312 B] - [2017/9/16 1:48:3]
    C:/AdwCleaner/AdwCleaner[S0].txt - [51664 B] - [2017/9/16 1:45:36]


    ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt ##########

     

     

    JRT

     

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Malwarebytes
    Version: 8.1.4 (07.09.2017)
    Operating System: Windows 7 Ultimate x64 
    Ran by Yachiru (Administrator) on 22/09/2017 at  8:39:45,68
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


    File System: 6 

    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4M7NH6XU (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FMPGG35N (Temporary Internet Files Folder) 
    Successfully deleted: C:\Users\Yachiru\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S1RTVK5H (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4M7NH6XU (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FMPGG35N (Temporary Internet Files Folder) 
    Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S1RTVK5H (Temporary Internet Files Folder) 

    Registry: 0 

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on 22/09/2017 at  8:42:07,70
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     

     

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    @Kevyn Poggian

     

    Pressione as teclas Windows tecla-windows.gif + R e digite: msconfig
     
    - Clique na guia Serviços, marque a opção Ocultar todos os serviços Microsoft e depois clique em Desativar tudo
    - Clique na guia Inicialização de Programas e clique em Desativar tudo
     
    Siga as mensagens ate que seja solicitado a reiniciar.

    Após isso me informe se os problemas em relação a malwares ainda persistem.

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
  • Autor do tópico
  • @Elias Pereira Realmente limpou bastante coisas do meu pc, ficou até mais leve, mas infeliz mente o problema do teclado continua o mesmo. E como eu disse, ele só fica abrindo coisas e desligando o pc, só no meu computador.

    aí fica difícil de saber se é problema dele ou do meu computador mesmo. Mas obrigado pela ajuda

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites

    @Kevyn Poggian

     

    É improvável que esse problema do teclado tenha a ver com malwares. Está mais para hardware. Sugiro que abra um tópico na área de periféricos.

    http://www.clubedohardware.com.br/forums/forum/62-teclados-mouses-joysticks-etc/

     

    Em relação a malwares, não temos mais problemas.

    Ultimas instruções.
     

    Baixe o Delfix by Xplode do link abaixo e salve na sua área de trabalho.
    http://www.bleepingcomputer.com/download/delfix/dl/281/

    Dê dois cliques no delfix.exe para executá-lo. Marque as caixas conforme imagem.

    *** Usuários do Windows Vista, 7, 8/8.1 e Windows 10clique com o direito sobre o arquivo delfix.exe, depois clique emVRIfczU.png

    ipb9zl.png

    Clique no botão Executar.

    Ao final será gerado um log, mas não é necessário postar.

    Faça o download do TFC by Oldtimer<-link:

    ** Usuários do Windows Vista e Windows 7:
    Clique com o direito sobre o arquivo TFC.exe, depois clique em VRIfczU.png.

    Clique em Start e aguarde ate que o programa realize a limpeza.

    MANTENHA O SO ATUALIZADO:
    Mantenha como "automatica" as atualizações do windows. Novas brechas de segurança são descobertas com freqüência. Muitos malwares exploram essas brechas, infectando sistemas sem depender de nenhuma ação do usuário. A Microsoft corrige essas brechas através das atualizações. Por isso é fundamental manter o seu sistema atualizado.

    Se não tiver mais problema em relação a malwares, clique em Denunciar Post localizado no topo da pagina e diga que seu topico está RESOLVIDO. Se você tiver alguma dúvida relacionada a informática e tecnologia, sinta-se à vontade para postar em qualquer área do CdH.

    Att.
    Elias Pereira

    Compartilhar este post


    Link para o post
    Compartilhar em outros sites
    Visitante
    Este tópico está impedido de receber novos posts.





    Sobre o Clube do Hardware

    No ar desde 1996, o Clube do Hardware é uma das maiores, mais antigas e mais respeitadas publicações sobre tecnologia do Brasil. Leia mais

    Direitos autorais

    Não permitimos a cópia ou reprodução do conteúdo do nosso site, fórum, newsletters e redes sociais, mesmo citando-se a fonte. Leia mais

    ×