Ir ao conteúdo
  • Cadastre-se

PC Travando e alguns sites nao abrem


Posts recomendados

  • Analista de Segurança

@Antonio Cabello

 

Por favor, atente para o seguinte:

  • Sobre o Fórum: Este é um espaço privado, não público. Seu uso é um privilégio, não um direito;
  • O que será passado aqui, somente será com relação ao problema do seu computador portanto, não faça mais em nenhum outro;
  • IMPORTANTE: Caso tenha programas de ativação do windows ou de compartilhamento p2p/toŕŕent, sugiro desinstalar. Só irei dar procedimento na analise após a remoção. Regras do forum;
  • Siga, por favor, atentamente as instruções passadas e em caso de dúvidas não hesite em perguntá-las;
  • Respeite a ordem das instruções passadas;
  • Observação: Não tome outra medida além das passadas aqui; atente para que, caso peça ajuda em outro fórum, não deixe de nos informar, sob risco de desconfigurar seu computador!


Regras da Área de Remoção de Malware << IMPORTANTE A LEITURA

Regras Gerais do Forum Clube do Hardware << IMPORTANTE A LEITURA
 

Siga os passos abaixo:

Desative temporariamente seu antivirus, antispywares e firewall, para não causar conflitos.

 

ETAPA 1

 

Faça o download do AdwCleaner de um dos links abaixo e salve no desktop.

https://toolslib.net/downloads/viewdownload/1-adwcleaner/

http://www.bleepingcomputer.com/download/adwcleaner/

Clique em DOWNLOAD NOW para baixar o arquivo.

Execute o adwcleaner.exe

OBS: Usuários do Windows Vista, 7, 8/8.1 e windows 10 clique com o direito sobre o arquivo AdwCleaner.exe, depois clique em image.png

Clique em VERIFICAR AGORA/SCAN NOW. Após o termino clique em LIMPAR/CLEAN e aguarde.

Será aberto o bloco de notas com o resultado.

 

ATENÇÃO: Selecione, copie e cole o seu conteúdo na próxima resposta.

 

ETAPA 2

 

Faça o download do ZHPCleaner no link abaixo e salve em sua Área de trabalho (Desktop)

https://www.majorgeeks.com/files/details/zhpcleaner.html

Execute o arquivo ZHPCleaner.exe Como Administrador

  • Clique no botão Scanner.
  • A ferramenta começara o exame do seu sistema.
  • Tenha paciência pois pode demorar um pouco dependendo da quantidades de itens a examinar.
  • Em seguida clique no botão Reparar.
  • Será gerado um log chamado ZHPCleaner.txt

ATENÇÃO: Selecione, copie e cole o seu conteúdo na próxima resposta.

Link para o comentário
Compartilhar em outros sites

# Mode: Clean
# -------------------------------
# Start:    04-12-2021
# Duration: 00:00:02
# OS:       Windows 10 Pro
# Cleaned:  37
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted       C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare
Deleted       C:\Program Files (x86)\IObit\Advanced SystemCare
Deleted       C:\ProgramData\IObit\Advanced SystemCare
Deleted       C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare
Deleted       C:\ProgramData\Tencent
Deleted       C:\Users\T-Gamer\AppData\LocalLow\IObit\Advanced SystemCare
Deleted       C:\Users\T-Gamer\AppData\Local\Tencent
Deleted       C:\Users\T-Gamer\AppData\Roaming\IObit\Advanced SystemCare
Deleted       C:\Users\T-Gamer\AppData\Roaming\Tencent
Deleted       C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\IObit\Advanced SystemCare
Deleted       C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Tencent

***** [ Files ] *****

Deleted       C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\invalidprefs.js

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted       C:\Windows\System32\Tasks\DRIVER BOOSTER SCHEDULER

***** [ Registry ] *****

Deleted       HKCU\Software\IObit\Advanced SystemCare
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Deleted       HKLM\SOFTWARE\CLASSES\DIRECTORY\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
Deleted       HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
Deleted       HKLM\SOFTWARE\CLASSES\LNKFILE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
Deleted       HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Advanced SystemCare
Deleted       HKLM\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\Advanced SystemCare
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81730BFC-7CBA-4C35-A0EE-2EF5AF0D398F}
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler
Deleted       HKLM\Software\Classes\CLSID\{2803063F-4B8D-4dc6-8874-D1802487FE2D}
Deleted       HKLM\Software\Classes\Interface\{BA935377-E17C-4475-B1BF-DE3110613A99}
Deleted       HKLM\Software\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}
Deleted       HKLM\Software\Wow6432Node\IOBIT\ASC
Deleted       HKLM\Software\Wow6432Node\IObit\Advanced SystemCare
Deleted       HKLM\Software\Wow6432Node\IObit\RealTimeProtector
Deleted       HKLM\Software\Wow6432Node\\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Deleted       HKLM\Software\Wow6432Node\\Classes\Interface\{BA935377-E17C-4475-B1BF-DE3110613A99}
Deleted       HKLM\Software\Wow6432Node\\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}
Deleted       HKLM\Software\Wow6432Node\\Google\Chrome\NativeMessagingHosts\com.ascplugin.protect
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Deleted       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\Advanced SystemCare_is1

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

Deleted       IObit Surfing Protection & Ads Removal - [email protected]
Deleted       IObit Surfing Protection & Ads Removal - [email protected]

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner_Debug.log - [94658 octets] - [18/11/2019 14:32:19]
AdwCleaner[S00].txt - [2835 octets] - [18/11/2019 14:32:31]
AdwCleaner[C00].txt - [1946 octets] - [18/11/2019 14:33:10]
AdwCleaner[S01].txt - [5654 octets] - [23/11/2019 02:12:26]
AdwCleaner[S02].txt - [5567 octets] - [08/01/2020 12:15:13]
AdwCleaner[S03].txt - [4926 octets] - [11/03/2020 00:30:01]
AdwCleaner[S04].txt - [4987 octets] - [22/04/2020 02:20:42]
AdwCleaner[S05].txt - [5048 octets] - [02/08/2020 13:27:34]
AdwCleaner[S06].txt - [6213 octets] - [12/01/2021 03:14:39]
AdwCleaner[S07].txt - [5699 octets] - [12/04/2021 00:05:24]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C07].txt ##########

 

 

 

~ ZHPCleaner v2021.4.3.289 by Nicolas Coolman (2021/04/03)
~ Run by T-Gamer (Administrator)  (12/04/2021 00:11:26)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Scan
~ Report : C:\Users\T-Gamer\OneDrive\Área de Trabalho\ZHPCleaner (S).txt
~ Quarantine : C:\Users\T-Gamer\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ System Restore Point :
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Pro, 64-bit  (Build 19042)


---\\  Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\  Services (0)
~ No malicious or unnecessary items found.


---\\  Browser internet (0)
~ No malicious or unnecessary items found.


---\\  Hosts file (1)
~ The hosts file is legitimate (21)


---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\  Explorer ( File, Folder) (15)
FOUND file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\.metadata-v2    =>.SUP.iMesh
FOUND file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\idb\2042192966abrdc-.sqlite    =>.SUP.iMesh
FOUND file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\idb\301792106ttes.sqlite    =>.SUP.iMesh
FOUND file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\idb\993782502OBNDE__KSDISG_NLA.sqlite    =>.SUP.iMesh
FOUND file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\cache\.padding    =>.SUP.iMesh
FOUND file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\cache\caches.sqlite    =>.SUP.iMesh
FOUND file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\cache\morgue\250\{092107e7-2a47-478f-8268-c0d298a0d4fa}.final    =>.SUP.iMesh
FOUND file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\cache\morgue\200\{17d1e708-0305-45f4-b828-6a719dbc81c8}.final    =>.SUP.iMesh
FOUND file: C:\Users\T-Gamer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BS.Player FREE.lnk  [Bad : C:\Program Files (x86)\Webteh\BSPlayer\bsplayer.exe](.AB Team.)  =>.SUP.ABTeam
FOUND file: C:\Users\T-Gamer\AppData\Local\Microsoft\Edge\User Data\Default\Preferences    =>ChromiumPreference
FOUND file: C:\Windows\Prefetch\BROWSERPROTECT.EXE-C73693F7.pf    =>PUP.Optional.Eazel
FOUND file: C:\Users\Public\Desktop\Advanced SystemCare.lnk    =>SUP.Optional.AdvancedSystemCare
FOUND folder: C:\Program Files (x86)\Webteh\BSPlayer  =>.SUP.ABTeam
FOUND folder: C:\Program Files (x86)\Webteh  =>.SUP.ABTeam
FOUND folder: C:\ProgramData\IObit\ASCDownloader  =>SUP.Optional.AdvancedSystemCare


---\\  Registry ( Key, Value, Data) (5)
FOUND value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare ["C:\Program Files (x86)\IObit\Advanced SystemCare\]  =>SUP.Optional.AdvancedSystemCare
FOUND key: HKCU\Software\undefined [AdditionalScan 148]  =>.SUP.Downloader
FOUND data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{a282bfd4-7e72-4808-9dc5-f0f680eb6b7b}\\DhcpNameServer [Bad : 189.7.72.63 189.7.72.73]  =>Hijacker.Browser
FOUND data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer [Bad : 189.7.72.63 189.7.72.73]  =>Hijacker.Browser
FOUND key: [X64] HKLM\SOFTWARE\Wow6432Node\Webteh []  =>.SUP.ABTeam


---\\  Summary of the elements found (7)
https://nicolascoolman.eu/forum/Topic/imesh-logiciel-potentiellement-superflu-lps/ =>.SUP.iMesh
https://nicolascoolman.eu/forum/Topic/logiciels-potentiellement-superflus-lps/ =>.SUP.ABTeam
https://nicolascoolman.eu/2020/10/01/preferences-navigateurs-chromium/ =>ChromiumPreference
https://nicolascoolman.eu/2017/09/27/pup-optional-browserdefender/ =>PUP.Optional.Eazel
https://nicolascoolman.eu/wp-content/uploads/2017/12/26/sup-advancedsystemcare/ =>SUP.Optional.AdvancedSystemCare
https://nicolascoolman.eu/2017/12/22/sup-downloader/ =>.SUP.Downloader
https://nicolascoolman.eu/2017/11/10/hijacker-browser-3/ =>Hijacker.Browser


---\\ Result of repair
~ Any repair made
~ Mozilla Firefox OK
~ Internet Explorer OK
~ Opera Stable OK


---\\ Statistics
~ Items scanned : 115326
~ Items found : 23
~ Items cancelled : 0
~ Space saving (bytes) : 0
~ Items options : 9/17


---\\ OPTIONS NOT ACTIVES
~ Temporary file analysis
~ Temporary folder analysis
~ Empty Folder CLSID Analysis
~ Empty Other Folder Analysis
~ Empty LocalLow Folder Analysis
~ Empty Local Folder Analysis
~ Obsolete Installer File Analysis
~ Start browsers with extensions removed

 

 

 

----------------------------------

 

 

 ZHPCleaner v2021.4.3.289 by Nicolas Coolman (2021/04/03)
~ Run by T-Gamer (Administrator)  (12/04/2021 00:25:25)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Repair
~ Report : C:\Users\T-Gamer\OneDrive\Área de Trabalho\ZHPCleaner (R).txt
~ Quarantine : C:\Users\T-Gamer\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ System Restore Point : OK
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Pro, 64-bit  (Build 19042)


---\\  Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\  Services (0)
~ No malicious or unnecessary items found.


---\\  Browser internet (0)
~ No malicious or unnecessary items found.


---\\  Hosts file (1)
~ The hosts file is legitimate (21)


---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\  Explorer ( File, Folder) (14)
MOVED file: C:\Users\T-Gamer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\BS.Player FREE.lnk  [Bad : C:\Program Files (x86)\Webteh\BSPlayer\bsplayer.exe](.AB Team.)  =>.SUP.ABTeam
MOVED file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\.metadata-v2    =>.SUP.iMesh
MOVED file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\idb\2042192966abrdc-.sqlite    =>.SUP.iMesh
MOVED file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\idb\301792106ttes.sqlite    =>.SUP.iMesh
MOVED file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\idb\993782502OBNDE__KSDISG_NLA.sqlite    =>.SUP.iMesh
MOVED file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\cache\.padding    =>.SUP.iMesh
MOVED file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\cache\caches.sqlite    =>.SUP.iMesh
MOVED file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\cache\morgue\250\{092107e7-2a47-478f-8268-c0d298a0d4fa}.final    =>.SUP.iMesh
MOVED file: C:\Users\T-Gamer\AppData\Roaming\Mozilla\Firefox\Profiles\n7j1jyf2.default-release-1573692790606\storage\default\https+++animeshouse.net\cache\morgue\200\{17d1e708-0305-45f4-b828-6a719dbc81c8}.final    =>.SUP.iMesh
MOVED file: C:\Users\T-Gamer\AppData\Local\Microsoft\Edge\User Data\Default\Preferences    =>Préférences Chromium
MOVED file: C:\Windows\Prefetch\BROWSERPROTECT.EXE-C73693F7.pf    =>PUP.Optional.Eazel
MOVED file: C:\Users\Public\Desktop\Advanced SystemCare.lnk    =>SUP.Optional.AdvancedSystemCare
MOVED folder: C:\Program Files (x86)\Webteh  =>.SUP.ABTeam
MOVED folder: C:\ProgramData\IObit\ASCDownloader  =>SUP.Optional.AdvancedSystemCare


---\\  Registry ( Key, Value, Data) (5)
DELETED data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{a282bfd4-7e72-4808-9dc5-f0f680eb6b7b}\\DhcpNameServer [Bad : 189.7.72.63 189.7.72.73]  =>Hijacker.Browser
DELETED data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer [Bad : 189.7.72.63 189.7.72.73]  =>Hijacker.Browser
DELETED key*: HKCU\Software\undefined [AdditionalScan 148]  =>.SUP.Downloader
DELETED key*: [X64] HKLM\SOFTWARE\Wow6432Node\Webteh []  =>.SUP.ABTeam
DELETED value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Advanced SystemCare ["C:\Program Files (x86)\IObit\Advanced SystemCare\]  =>SUP.Optional.AdvancedSystemCare


---\\  Summary of the elements found (7)
https://nicolascoolman.eu/forum/Topic/logiciels-potentiellement-superflus-lps/ =>.SUP.ABTeam
https://nicolascoolman.eu/forum/Topic/imesh-logiciel-potentiellement-superflu-lps/ =>.SUP.iMesh
https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/ =>Préférences Chromium
https://nicolascoolman.eu/2017/09/27/pup-optional-browserdefender/ =>PUP.Optional.Eazel
https://nicolascoolman.eu/wp-content/uploads/2017/12/26/sup-advancedsystemcare/ =>SUP.Optional.AdvancedSystemCare
https://nicolascoolman.eu/2017/11/10/hijacker-browser-3/ =>Hijacker.Browser
https://nicolascoolman.eu/2017/12/22/sup-downloader/ =>.SUP.Downloader


---\\  Other deletions. (0)
~ Registry Keys Tracing deleted (0)
~ Remove the old reports ZHPCleaner. (0)


---\\ Result of repair
~ Repair carried out successfully
~ Mozilla Firefox OK
~ Internet Explorer OK
~ Opera Stable OK


---\\ Statistics
~ Items scanned : 2411
~ Items found : 0
~ Items cancelled : 0
~ Space saving (bytes) : 0
~ Items options : 9/17


---\\ OPTIONS NOT ACTIVES
~ Temporary file analysis
~ Temporary folder analysis
~ Empty Folder CLSID Analysis
~ Empty Other Folder Analysis
~ Empty LocalLow Folder Analysis
~ Empty Local Folder Analysis
~ Obsolete Installer File Analysis
~ Start browsers with extensions removed

~ End of clean in 00h00mn32s

---\\  Reports (2)
ZHPCleaner-[S]-12042021-00_20_22.txt
ZHPCleaner-[R]-12042021-00_25_57.txt

 

 

Link para o comentário
Compartilhar em outros sites

  • Analista de Segurança

@Antonio Cabello

 

Faça o download do RogueKiller by Tigzy, e salve na sua área de trabalho (Desktop)

roguekiller.exe (x64) << link

  • Feche todos os programas
  • Execute o RogueKiller.exe.
    ** Usuários do Windows Vista, Windows 7, 8, 8.1 e Windows 10:Clique com o direito sobre o arquivo rogueKiller.exe, depois clique em image.png
  • Clique em SCAN
  • Clique no primeiro START "Standard Scan (recommended)" e aguarde o scan...
  • Clique no botão RESULTS
  • Clique na opção REPORT e em EXPORT e selecione a opção Text file...
  • Salve o arquivo na area de trabalho com o nome roguekiller_report

Atente para abrir o arquivo, copiar e colar todo o conteúdo na sua próxima resposta

Link para o comentário
Compartilhar em outros sites

Operating System : Windows 10 (10.0.19042) 64 bits
Started in : Normal mode
User : T-Gamer [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20210412_114416, Driver : Loaded
Mode : Standard Scan, Scan -- Date : 2021/04/12 12:59:32 (Duration : 00:05:31)
Switches : -minimize

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> XX - Software
  [PUP.Gen1 (Potentially Malicious)] (X86) HKEY_LOCAL_MACHINE\Software\Tencent -- N/A -> Found
  [PUP.Gen1 (Potentially Malicious)] (X64) HKEY_USERS\S-1-5-21-1890022290-3169764334-925963813-1001\Software\Tencent -- N/A -> Found
>>>>>> XX - System Policies
  [PUM.Policies (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin -- 0 -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.HackTool (Potentially Malicious)] (folder) files -- C:\Windows\files -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

Link para o comentário
Compartilhar em outros sites

RogueKiller Anti-Malware V14.8.6.0 (x64) [Mar 24 2021] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19042) 64 bits
Started in : Normal mode
User : T-Gamer [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20210412_114416, Driver : Loaded
Mode : Standard Scan, Delete -- Date : 2021/04/13 13:18:29 (Duration : 00:04:40)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.Gen1 (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Tencent --  -> Deleted
[PUP.Gen1 (Potentially Malicious)] HKEY_USERS\S-1-5-21-1890022290-3169764334-925963813-1001\Software\Tencent --  -> Deleted
[PUM.Policies (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin --  -> Replaced (2)
[PUP.HackTool (Potentially Malicious)] files -- %SystemRoot%\files -> Deleted
  => Configure.xml -- C:\Windows\files\Configure.xml -> Deleted
  => Uninstall.xml -- C:\Windows\files\Uninstall.xml -> Deleted
  => cleanospp.exe -- C:\Windows\files\x64\cleanospp.exe -> Deleted
  => msvcr100.dll -- C:\Windows\files\x64\msvcr100.dll -> Deleted
  => x64 -- C:\Windows\files\x64 -> Deleted
  => cleanospp.exe -- C:\Windows\files\x86\cleanospp.exe -> Deleted
  => msvcr100.dll -- C:\Windows\files\x86\msvcr100.dll -> Deleted
  => x86 -- C:\Windows\files\x86 -> Deleted

Link para o comentário
Compartilhar em outros sites

  • Analista de Segurança

@Antonio Cabello

 

  1. Clique no menu Iniciar, e após isso clique com o botão direito do mouse sob Este computador e selecione a opção Propriedades.
  2. Em Propriedades, selecione a opção Configurações avançadas do sistema.
  3. Vá na aba Proteção do Sistema, e em Restauração do Sistema, vá na opção Criar.
    fce2f587-5556-456b-93d4-00966ae7f59d
  4. Depois basta seguir as instruções em tela, para criar seu ponto de restauração.
    OBS: Lembre-se de colocar um nome de fácil entendimento para uma posterior restauração a partir deste ponto.

Pressione as teclas Windows conheca-atalhos-de-teclado-para-dominar-o-windows-8-2.jpg + R e digite: msconfig 
- Clique na guia Serviços, marque a opção Ocultar todos os serviços Microsoft e depois clique em Desativar tudo
- Clique na guia Inicialização de Programas e clique em Abrir Gerenciador de Tarefas
- Clique com o botão direito em cada entrada da inicialização e clique em Desabilitar/Desativar.

Volte para a tela de Configurações do Sistema e clique em Aplicar e depois em OK

Siga as mensagens ate que seja solicitado a reiniciar.Após isso me informe se os problemas em relação a malwares ainda persistem.

Link para o comentário
Compartilhar em outros sites

Quando eu faço o scan com o  ZHPCleaner, ele diz "have you installed this server?" e me da dois endereços de IP, eu obviamente digo não e coloco repai, só que o negocio não some, pois eu faço scan depois e novamente ele me pergunta sobre se eu instalei os dois servidores de IP. Fora isso, a maquina deu uma boa melhorada mesmo, ta entrando nos sites normal e rodando as imagens que ficavam quebradas antes.

Link para o comentário
Compartilhar em outros sites

  • Analista de Segurança
22 horas atrás, Antonio Cabello disse:

Quando eu faço o scan com o  ZHPCleaner, ele diz "have you installed this server?"

São os endereços de DNS. Ele sempre faz essa solicitação. Tudo ok.

 

Em relação a malwares, não temos mais problemas.

MANTENHA O SO ATUALIZADO:
Mantenha como "automatica" as atualizações do windows. Novas brechas de segurança são descobertas com freqüência. Muitos malwares exploram essas brechas, infectando sistemas sem depender de nenhuma ação do usuário. A Microsoft corrige essas brechas através das atualizações. Por isso é fundamental manter o seu sistema atualizado.

Se não tiver mais problema em relação a malwares, clique em Denunciar Post localizado no topo da pagina e diga que seu topico está RESOLVIDO. Se você tiver alguma dúvida relacionada a informática e tecnologia, sinta-se à vontade para postar em qualquer área do CdH.

Link para o comentário
Compartilhar em outros sites

Visitante
Este tópico está impedido de receber novas respostas.

Sobre o Clube do Hardware

No ar desde 1996, o Clube do Hardware é uma das maiores, mais antigas e mais respeitadas comunidades sobre tecnologia do Brasil. Leia mais

Direitos autorais

Não permitimos a cópia ou reprodução do conteúdo do nosso site, fórum, newsletters e redes sociais, mesmo citando-se a fonte. Leia mais

×
×
  • Criar novo...