Ir ao conteúdo
  • Cadastre-se

Computador Lento com Algumas Funções Não Funcionando


Posts recomendados

Boa noite pessoal,

 

Estou tentando resolver alguns problemas do computador da minha namorada.

 

O computador dela está apresentando diversos problemas. Vou listar abaixo:

- Sistema de procura de arquivos e programas na barra de tarefas abre mas não consegue digitar nada para pesquisar;

- Não consigo digitar a senha no wifi mesmo com teclado que funciona;

- Yahoo virou a principal plataforma de pesquisa e nada adianta alterar no Chrome para o Google que ele continua pesquisando pelo Yahoo;

- Algumas teclas do teclado pararam de funcionar;

- Programas como Outlook e Chrome com extrema lentidão; 

- Lentidão na inicialização do Windows;

- McAfee está instalado no computador mas não consigo localiza-lo para desinstalar;

- Etc.

 

 

Segue o Log em anexo conforme solicitado.

ZA-Scan.txt

Link para o comentário
Compartilhar em outros sites

  • Analista de Segurança

@André Barros Fonseca

 

Por favor, atente para o seguinte:

  • Sobre o Fórum: Este é um espaço privado, não público. Seu uso é um privilégio, não um direito;
  • O que será passado aqui, somente será com relação ao problema do seu computador portanto, não faça mais em nenhum outro;
  • IMPORTANTE: Caso tenha programas de ativação do windows ou de compartilhamento p2p/toŕŕent, sugiro desinstalar. Só irei dar procedimento na analise após a remoção. Regras do forum;
  • Siga, por favor, atentamente as instruções passadas e em caso de dúvidas não hesite em perguntá-las;
  • Respeite a ordem das instruções passadas;
  • Observação: Não tome outra medida além das passadas aqui; atente para que, caso peça ajuda em outro fórum, não deixe de nos informar, sob risco de desconfigurar seu computador!


Regras da Área de Remoção de Malware << IMPORTANTE A LEITURA

Regras Gerais do Forum Clube do Hardware << IMPORTANTE A LEITURA
 

Siga os passos abaixo:

Desative temporariamente seu antivirus, antispywares e firewall, para não causar conflitos.

 

ETAPA 1

 

Faça o download do AdwCleaner de um dos links abaixo e salve no desktop.

https://toolslib.net/downloads/viewdownload/1-adwcleaner/

http://www.bleepingcomputer.com/download/adwcleaner/

Clique em DOWNLOAD NOW para baixar o arquivo.

Execute o adwcleaner.exe

OBS: Usuários do Windows Vista, 7, 8/8.1 e windows 10 clique com o direito sobre o arquivo AdwCleaner.exe, depois clique em image.png

Clique em VERIFICAR AGORA/SCAN NOW. Após o termino clique em LIMPAR/CLEAN e aguarde.

Será aberto o bloco de notas com o resultado.

 

ATENÇÃO: Selecione, copie e cole o seu conteúdo na próxima resposta.

 

ETAPA 2

 

Faça o download do ZHPCleaner no link abaixo e salve em sua Área de trabalho (Desktop)

https://www.majorgeeks.com/files/details/zhpcleaner.html

Execute o arquivo ZHPCleaner.exe Como Administrador

  • Clique no botão Scanner.
  • A ferramenta começara o exame do seu sistema.
  • Tenha paciência pois pode demorar um pouco dependendo da quantidades de itens a examinar.
  • Em seguida clique no botão Reparar.
  • Será gerado um log chamado ZHPCleaner.txt

ATENÇÃO: Selecione, copie e cole o seu conteúdo na próxima resposta.

Link para o comentário
Compartilhar em outros sites

Segue conforme solicitado:

 

# -------------------------------
# Malwarebytes AdwCleaner 8.1.0.0
# -------------------------------
# Build:    02-15-2021
# Database: 2021-01-11.1 (Local)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    03-18-2021
# Duration: 00:06:17
# OS:       Windows 10 Home Single Language
# Cleaned:  12
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted       C:\Program Files (x86)\Chromium
Deleted       C:\Program Files (x86)\Digital Communications
Deleted       C:\Program Files (x86)\SAFEWEB SEGURANÇA DA INFORMAÇÃO
Deleted       C:\SafeWeb

***** [ Files ] *****

Deleted       C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search Powered by Yahoo!.lnk

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted       HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|santivirusclient.exe
Deleted       HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|santivirusclient.vshost.exe
Deleted       HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|santivirusclient.exe
Deleted       HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|santivirusclient.vshost.exe
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|santivirusclient.exe
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|santivirusclient.vshost.exe
Deleted       HKLM\System\CurrentControlSet\Services\EventLog\Application\SAntivirusSvc

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [2743 octets] - [18/03/2021 17:00:21]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

 

~ ZHPCleaner v2021.3.10.285 by Nicolas Coolman (2021/03/10)
~ Run by Usuario (Administrator)  (18/03/2021 18:38:46)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version KO
~ Type : Repair
~ Report : D:\Users\Usuario\Desktop\ZHPCleaner (R).txt
~ Quarantine : C:\Users\Usuario\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ System Restore Point : OK
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Home Single Language, 64-bit  (Build 18363)


---\\  Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\  Services (0)
~ No malicious or unnecessary items found.


---\\  Browser internet (0)
~ No malicious or unnecessary items found.


---\\  Hosts file (1)
~ The hosts file is legitimate (21)


---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\  Explorer ( File, Folder) (133)
MOVED file: C:\Users\Public\Desktop\Safeweb Assinador.lnk  [Bad : C:\Program Files (x86)\Safeweb Segurança da Informação\Assinador\MonitorService.exe](..)  =>PUP.Optional.SafeWeb
MOVED file: C:\Users\Usuario\AppData\Local\Google\Chrome\User Data\Default\Preferences    =>Préférences Chromium
MOVED file: C:\Users\Usuario\AppData\Local\Microsoft\Edge\User Data\Default\Preferences    =>Préférences Chromium
MOVED file: C:\Windows\Prefetch\POPCORN-TIME.EXE-4C348A3D.pf    =>.SUP.PopcornTime
MOVED file: C:\Windows\Prefetch\POPCORNTIMEDESKTOP.EXE-2038099B.pf    =>.SUP.PopcornTime
MOVED file: D:\Users\Usuario\Desktop\Assistente Certificado Digital AC Safeweb.appref-ms    =>PUP.Optional.SafeWeb
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\background.html    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\e_.json    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\index.html    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\manifest.json    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\responseConfig.json    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\_metadata\verified_contents.json    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\bundle.v0.0.1.min.css    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\fonts\HelveticaNeueLT-Roman.woff    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\fonts\HelveticaNeue-Thin.otf    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\fonts\neue.woff    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\fonts\neue-bold.woff    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\angle-arrow-down.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\bing.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\bing_large.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\bluesky-bg.jpg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\blue-triangle.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\brush.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\bt.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\clock.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\cloud.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\cupcake-bg.jpg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\desk-bg.jpg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\doodle.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\down.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\eyeglass.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\eyeglass_transparent.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\gmail-circle.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\google.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\google_large.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\grid-world.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\group.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\hero-bg.jpg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\just-the-box.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\just-the-box-empty.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\magnifier.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\mail-black-envelope-symbol.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\mailru.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\mountain-bg.jpg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\outlook-circle.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\pointer2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\radio-selected.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\radio-unselected.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sea-bg.jpg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\search-D7D7D7.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\search-FFFFFF.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\settings.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\smallMagnifier.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\star.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\star-unselected.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\toggle-off.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\toggle-on.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\translate.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\transparent_img.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\triangle.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\yahoo.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\yahoo.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\yahoo_large.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\yahoo-circle.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\icons\128.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\icons\16.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\icons\48.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\icons\close.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\icons\favicon.ico    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\icons\trends.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\aliexpress.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\aliexpress_tile_v2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\amazon.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\amazon_tile_v2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\booking.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\booking_tile_v2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\ebay.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\ebay_tile_v2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\expedia.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\expedia_tile_v2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\facebook.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\facebook_tile_v2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\gmail.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\gmail_new.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\gmail_tile_v2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\google-translate-icon-FFFFFF.svg    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\gtranslte.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\outlook-mail.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\pinterest.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\pinterest_tile_v2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\twitter.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\twitter_tile_v2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\wix.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\wix_tile_v2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\yahoo.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\yahoo_tile_v2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\yahoo-mail.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\youtube.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails\youtube_tile_v2.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\css\style.css    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\fonts\HelveticaNeueLT-Roman.woff    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\fonts\HelveticaNeue-Thin.otf    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\fonts\neue.woff    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\fonts\neue-bold.woff    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\js\background.min.js    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\js\common.min.js    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\js\common.min.js.LICENSE    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\js\index.min.js    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\skin\icons\16.png    =>SUP.Optional.SearchManager
MOVED file: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\vendor\react-with-addons.min.js    =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod  =>SUP.Optional.SearchManager
MOVED folder: C:\Program Files (x86)\Skillbrains  =>SUP.Optional.Skillbrains
MOVED folder: C:\ProgramData\KMSAutoS  =>HackTool.WinActivator
MOVED folder: C:\ProgramData\Assistente de Certificado Digital Safeweb  =>PUP.Optional.SafeWeb
MOVED folder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safeweb Assinador  =>PUP.Optional.SafeWeb
MOVED folder: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn-Time  =>.SUP.PopcornTime
MOVED folder: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Safeweb Segurança da Infromação  =>PUP.Optional.SafeWeb
MOVED folder: C:\Users\Usuario\AppData\Local\MSfree Inc  =>HackTool.WinActivator
MOVED folder: C:\Users\Usuario\AppData\Local\Popcorn-Time  =>.SUP.PopcornTime
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\_metadata  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\addons  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\fonts  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\icons  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\content\images\sitesThumbnails  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\css  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\fonts  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\js  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\skin  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\skin\icons  =>SUP.Optional.SearchManager
MOVED folder: C:\Users\Usuario\AppData\Local\chromium\User Data\Default\Extensions\bnlfgalbnliphjafcnhjnnnfijekbnod\10.1.4.64_0\vendor  =>SUP.Optional.SearchManager


---\\  Registry ( Key, Value, Data) (11)
DELETED key*: [X64] HKLM\SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\ByteFence.exe [AdditionalScan 517]  =>SUP.Optional.ByteFence
DELETED key*: HKEY_USERS\S-1-5-21-2133162997-3375018457-2302470893-1001\SOFTWARE\Popcorn Time []  =>.SUP.PopcornTime
DELETED key*: HKEY_USERS\S-1-5-21-2133162997-3375018457-2302470893-1001\SOFTWARE\PopcornTime []  =>.SUP.PopcornTime
DELETED key*: HKEY_USERS\S-1-5-21-2133162997-3375018457-2302470893-1001\SOFTWARE\SkillBrains []  =>SUP.Optional.Skillbrains
DELETED key**: HKCU\Software\Popcorn Time []  =>.SUP.PopcornTime
DELETED key**: HKCU\Software\PopcornTime []  =>.SUP.PopcornTime
DELETED key**: HKCU\Software\SkillBrains []  =>SUP.Optional.Skillbrains
DELETED key*: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Popcorn-Time [Popcorn Time]  =>.SUP.PopcornTime
DELETED key^: [X64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KMSAutoNet []  =>HackTool.WinActivator
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Skillbrains []  =>SUP.Optional.Skillbrains
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1 [Skillbrains]  =>SUP.Optional.Skillbrains


---\\  Summary of the elements found (7)
https://nicolascoolman.eu/forum/Topic/safeweb-logiciel-potentiellement-indesirable-pup-lpi/  =>PUP.Optional.SafeWeb
https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/  =>Préférences Chromium
https://nicolascoolman.eu/2017/02/26/superfluous-popcorntime/  =>.SUP.PopcornTime
https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/  =>SUP.Optional.SearchManager
https://nicolascoolman.eu/2019/01/sup-skillbrains  =>SUP.Optional.Skillbrains
https://nicolascoolman.eu/2017/01/13/hacktool-winactivator/  =>HackTool.WinActivator
https://nicolascoolman.eu/2017/03/13/superfluous-bytefence/  =>SUP.Optional.ByteFence


---\\  Other deletions. (1)
~ Registry Keys Tracing deleted (1)
~ Remove the old reports ZHPCleaner. (0)


---\\ Result of repair
~ Repair carried out successfully
~ Google Chrome OK
~ Internet Explorer OK
~ The system has been restarted.


---\\ Statistics
~ Items scanned : 1365
~ Items found : 0
~ Items cancelled : 0
~ Space saving (bytes) : 0
~ Items options : 9/17


---\\ OPTIONS NOT ACTIVES
~ Temporary file analysis
~ Temporary folder analysis
~ Empty Folder CLSID Analysis
~ Empty Other Folder Analysis
~ Empty LocalLow Folder Analysis
~ Empty Local Folder Analysis
~ Obsolete Installer File Analysis
~ Start browsers with extensions removed

~ End of clean in 00h09mn20s

---\\  Reports (2)
ZHPCleaner-[S]-18032021-17_57_12.txt
ZHPCleaner-[R]-18032021-18_48_06.txt
 

Link para o comentário
Compartilhar em outros sites

  • Analista de Segurança

@André Barros Fonseca

 

Faça o download do RogueKiller by Tigzy, e salve na sua área de trabalho (Desktop)

roguekiller.exe (x64) << link

  • Feche todos os programas
  • Execute o RogueKiller.exe.
    ** Usuários do Windows Vista, Windows 7, 8, 8.1 e Windows 10:Clique com o direito sobre o arquivo rogueKiller.exe, depois clique em image.png
  • Clique em SCAN
  • Clique no primeiro START "Standard Scan (recommended)" e aguarde o scan...
  • Clique no botão RESULTS
  • Clique na opção REPORT e em EXPORT e selecione a opção Text file...
  • Salve o arquivo na area de trabalho com o nome roguekiller_report

Atente para abrir o arquivo, copiar e colar todo o conteúdo na sua próxima resposta

Link para o comentário
Compartilhar em outros sites

Segue conforme solicitado:

 

RogueKiller Anti-Malware V14.8.5.0 (x64) [Feb 12 2021] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.18363) 64 bits
Started in : Normal mode
User : Usuario [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20210318_104528, Driver : Loaded
Mode : Standard Scan, Scan -- Date : 2021/03/21 14:36:11 (Duration : 00:19:03)
Switches : -minimize

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> O87 - Firewall
  [PUP.Popcorn (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{4735391C-C094-4E66-AFFA-16D9DAD3F4A7}C:\users\usuario\appdata\local\popcorn-time\popcorn-time.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=C:\users\usuario\appdata\local\popcorn-time\popcorn-time.exe|Name=popcorn-time.exe|Desc=popcorn-time.exe|Defer=User| (C:\users\usuario\appdata\local\popcorn-time\popcorn-time.exe) (missing) -> Found
  [PUP.Popcorn (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{71A8D653-4A04-4FB9-8DF9-B4C591A5D393}C:\users\usuario\appdata\local\popcorn-time\popcorn-time.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|Profile=Public|App=C:\users\usuario\appdata\local\popcorn-time\popcorn-time.exe|Name=popcorn-time.exe|Desc=popcorn-time.exe|Defer=User| (C:\users\usuario\appdata\local\popcorn-time\popcorn-time.exe) (missing) -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{085B4852-BB9B-45EF-910C-52E4F18A36B3}C:\users\usuario\appdata\local\softdeluxe\free download manager\fdm.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\users\usuario\appdata\local\softdeluxe\free download manager\fdm.exe|Name=fdm.exe|Desc=fdm.exe|Edge=TRUE|Defer=App| (C:\users\usuario\appdata\local\softdeluxe\free download manager\fdm.exe) -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{9E7BFDDC-9E24-4D10-BD82-13263B723B04}C:\users\usuario\appdata\local\softdeluxe\free download manager\fdm.exe -- v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\users\usuario\appdata\local\softdeluxe\free download manager\fdm.exe|Name=fdm.exe|Desc=fdm.exe|Edge=TRUE|Defer=App| (C:\users\usuario\appdata\local\softdeluxe\free download manager\fdm.exe) -> Found
>>>>>> XX - System Policies
  [PUM.Policies (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin -- 0 -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 

Link para o comentário
Compartilhar em outros sites

Executei de novo o RogueKiller e removi as entradas. Segue o resultado final:

 

RogueKiller Anti-Malware V14.8.5.0 (x64) [Feb 12 2021] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.18363) 64 bits
Started in : Normal mode
User : Usuario [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20210324_143238, Driver : Loaded
Mode : Standard Scan, Delete -- Date : 2021/03/25 10:59:50 (Duration : 00:18:00)
Switches : -minimize

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.Popcorn (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{4735391C-C094-4E66-AFFA-16D9DAD3F4A7}C:\users\usuario\appdata\local\popcorn-time\popcorn-time.exe -- [%localappdata%\popcorn-time\popcorn-time.exe] -> Deleted
[PUP.Popcorn (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{71A8D653-4A04-4FB9-8DF9-B4C591A5D393}C:\users\usuario\appdata\local\popcorn-time\popcorn-time.exe -- [%localappdata%\popcorn-time\popcorn-time.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|UDP Query User{9E7BFDDC-9E24-4D10-BD82-13263B723B04}C:\users\usuario\appdata\local\softdeluxe\free download manager\fdm.exe -- [%localappdata%\softdeluxe\free download manager\fdm.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|TCP Query User{085B4852-BB9B-45EF-910C-52E4F18A36B3}C:\users\usuario\appdata\local\softdeluxe\free download manager\fdm.exe -- [%localappdata%\softdeluxe\free download manager\fdm.exe] -> Deleted
[PUM.Policies (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin --  -> Replaced (2)
 

 

 

Link para o comentário
Compartilhar em outros sites

  • Analista de Segurança

@André Barros Fonseca

 

  1. Clique no menu Iniciar, e após isso clique com o botão direito do mouse sob Este computador e selecione a opção Propriedades.
  2. Em Propriedades, selecione a opção Configurações avançadas do sistema.
  3. Vá na aba Proteção do Sistema, e em Restauração do Sistema, vá na opção Criar.
    fce2f587-5556-456b-93d4-00966ae7f59d
  4. Depois basta seguir as instruções em tela, para criar seu ponto de restauração.
    OBS: Lembre-se de colocar um nome de fácil entendimento para uma posterior restauração a partir deste ponto.

Pressione as teclas Windows conheca-atalhos-de-teclado-para-dominar-o-windows-8-2.jpg + R e digite: msconfig 
- Clique na guia Serviços, marque a opção Ocultar todos os serviços Microsoft e depois clique em Desativar tudo
- Clique na guia Inicialização de Programas e clique em Abrir Gerenciador de Tarefas
- Clique com o botão direito em cada entrada da inicialização e clique em Desabilitar/Desativar.

Volte para a tela de Configurações do Sistema e clique em Aplicar e depois em OK

Siga as mensagens ate que seja solicitado a reiniciar.Após isso me informe se os problemas em relação a malwares ainda persistem.

Link para o comentário
Compartilhar em outros sites

Boa tarde.

 

Fiz conforme solicitado mas no final não apareceu nenhuma mensagem para reiniciar o computador. Esta tudo desabilitado como pedido mas os problemas persistem.

 

O browser de pesquisa eu consegui voltar para o google, mas o teclado continua com algumas teclas sem funcionar e tanto a pesquisa da barra de tarefas quanto o local onde coloca a senha do wifi continuam sem funcionar. Para ligar o wifi eu preciso escrever num bloco de notas, copiar e na área da senha do wifi eu so consigo colar se clicar com o botão direito e clicar em colar. Não funciona o ctl+v.

 

A lentidão do computador melhorou mas não está 100%.

 

Obrigado.

Link para o comentário
Compartilhar em outros sites

  • Analista de Segurança

@André Barros Fonseca

Em 04/04/2021 às 14:03, André Barros Fonseca disse:

Sim, na verdade só consigo usar o computador utilizando outro teclado. Acha que é o teclado que está com problema e não algo de software?

Possivelmente é o teclado.

 

Em relação a malwares, não temos mais problemas.

MANTENHA O SO ATUALIZADO:
Mantenha como "automatica" as atualizações do windows. Novas brechas de segurança são descobertas com freqüência. Muitos malwares exploram essas brechas, infectando sistemas sem depender de nenhuma ação do usuário. A Microsoft corrige essas brechas através das atualizações. Por isso é fundamental manter o seu sistema atualizado.

Se não tiver mais problema em relação a malwares, clique em Denunciar Post localizado no topo da pagina e diga que seu topico está RESOLVIDO. Se você tiver alguma dúvida relacionada a informática e tecnologia, sinta-se à vontade para postar em qualquer área do CdH.

Link para o comentário
Compartilhar em outros sites

Meu amigo,

 

Acho que entendi errado sua pergunta. Em realção à pequisa na barra de tarefas e ao campo onde se coloca o wifi, não funciona nem com outro teclado. Você clica lá e nada escreve. É necessário escrever no bloco de notas com algum teclado que funcione 100%, copiar e colar no local. Não acho que isso seja problema de hardware. 

 

Só queria tirar essa dúvida antes de fechar o post.

Link para o comentário
Compartilhar em outros sites

  • Analista de Segurança

@André Barros Fonseca

 

Em relação ao teclado, se tu usou outro e funcionou as teclas, o problema é no teclado legado.

 

Em relação a não funcionar a pesquisa da barra de tarefas e senha do wifi pode ser problema do teu windows 10.

 

Abra um topico na area de Sistemas Operacionais > Windows > Windows 10.

 

Se não tiver mais problema em relação a malwares, clique em Denunciar Post localizado no topo da pagina e diga que seu topico está RESOLVIDO. Se você tiver alguma dúvida relacionada a informática e tecnologia, sinta-se à vontade para postar em qualquer área do CdH.

Link para o comentário
Compartilhar em outros sites

Visitante
Este tópico está impedido de receber novas respostas.

Sobre o Clube do Hardware

No ar desde 1996, o Clube do Hardware é uma das maiores, mais antigas e mais respeitadas comunidades sobre tecnologia do Brasil. Leia mais

Direitos autorais

Não permitimos a cópia ou reprodução do conteúdo do nosso site, fórum, newsletters e redes sociais, mesmo citando-se a fonte. Leia mais

×
×
  • Criar novo...