Ir ao conteúdo
  • Cadastre-se

Malware possivelmente não removido por completo


Posts recomendados

Bom dia/Boa tarde/Boa noite, tudo certo?

 

Recentemente detectei um vírus em meu computador, trojan, removi ele via Virus Removal Tool do Kaspersky, certo, e agora aparentemente o computador está limpo, porém diferente de antes, o desempenho está inferior, em um dos jogos(csgo) anteriormente segurava a 110fps na qualidade alta, agora apenas 40fps,30fps..

Percebi também alguns picos de consumo de quase, ou de até 100% do processador, junto do uso da vram, sem justificativa nenhuma.

 

Config do meu pc:

 

Ryzen 5 3350G

16ram

SSD 250gb  + Hd secundário

 

 

Agradeço desde já a atenção.

ZA-Scan.txt

  • Curtir 1
Link para o post
Compartilhar em outros sites
  • Analista de Segurança

@Emanuel C A Floriano

 

Por favor, atente para o seguinte:

  • Sobre o Fórum: Este é um espaço privado, não público. Seu uso é um privilégio, não um direito;
  • O que será passado aqui, somente será com relação ao problema do seu computador portanto, não faça mais em nenhum outro;
  • IMPORTANTE: Caso tenha programas de ativação do windows ou de compartilhamento p2p/to44ent, sugiro desinstalar. Só irei dar procedimento na analise após a remoção. Regras do forum;
  • Siga, por favor, atentamente as instruções passadas e em caso de dúvidas não hesite em perguntá-las;
  • Respeite a ordem das instruções passadas;
  • Observação: Não tome outra medida além das passadas aqui; atente para que, caso peça ajuda em outro fórum, não deixe de nos informar, sob risco de desconfigurar seu computador!

Siga os passos abaixo:

 

ETAPA 1

 

Faça o download do AdwCleaner de um dos links abaixo e salve no desktop.

https://toolslib.net/downloads/viewdownload/1-adwcleaner/

http://www.bleepingcomputer.com/download/adwcleaner/

 

Clique em DOWNLOAD NOW para baixar o arquivo.

Execute o adwcleaner.exe

OBS: Usuários do Windows Vista, 7, 8/8.1 e windows 10 clique com o direito sobre o arquivo AdwCleaner.exe, depois clique em http://i.imgur.com/VRIfczU.png

Clique em VERIFICAR AGORA/SCAN NOW. Após o termino clique em LIMPAR/CLEAN e aguarde.

Será aberto o bloco de notas com o resultado.

 

ATENÇÃO: Selecione, copie e cole o seu conteúdo na próxima resposta.

 

ETAPA 2

 

Desative temporariamente seu antivirus, antispywares e firewall, para não causar conflitos.

 

Faça o download do ZHPCleaner no link abaixo e salve em sua Área de trabalho (Desktop)

https://www.majorgeeks.com/files/details/zhpcleaner.html

 

Execute o arquivo ZHPCleaner.exe Como Administrador

  • Clique no botão Scanner.
  • A ferramenta começara o exame do seu sistema.
  • Tenha paciência pois pode demorar um pouco dependendo da quantidades de itens a examinar.
  • Em seguida clique no botão Reparar.
  • Será gerado um log chamado ZHPCleaner.txt
  • Selecione, copie e cole o conteúdo deste log em sua sua próxima resposta.

OBS: Abra cada log em separado, copie e cole o conteudo na sua proxima resposta. Não necessita anexar.

 

Link para o post
Compartilhar em outros sites

Acabei fazendo duas varreduras pois não tinha encontrado a aba de pegar o log, mas segue agora dois logs das ambas vezes:

(estou indo agora para a etapa 2)

 

# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build:    10-08-2020
# Database: 2020-11-23.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    11-26-2020
# Duration: 00:00:00
# OS:       Windows 10 Pro
# Cleaned:  1
# Failed:   1


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

Deleted       Default
Not Deleted   Default

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1904 octets] - [26/11/2020 15:06:20]
AdwCleaner[C00].txt - [1944 octets] - [26/11/2020 15:06:45]
AdwCleaner[S01].txt - [1574 octets] - [26/11/2020 15:12:57]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########
 

 

 

--------------------------------------------------------------------------------------------------

 

# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build:    10-08-2020
# Database: 2020-11-23.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    11-26-2020
# Duration: 00:00:01
# OS:       Windows 10 Pro
# Cleaned:  8
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted       C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare
Deleted       C:\Program Files (x86)\IObit\Advanced SystemCare
Deleted       C:\ProgramData\IObit\Advanced SystemCare
Deleted       C:\Users\Pichau\AppData\LocalLow\IObit\Advanced SystemCare
Deleted       C:\Users\Pichau\AppData\Roaming\IObit\Advanced SystemCare

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted       HKLM\Software\Wow6432Node\IObit\Advanced SystemCare

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

Deleted       Default
Deleted       Default

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

image.png

 

 

 

 

 

 

~ ZHPCleaner v2020.11.24.257 by Nicolas Coolman (2020/11/24)
~ Run by Emanuel (Administrator)  (26/11/2020 15:33:46)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version KO
~ Type : Repair
~ Report : C:\Users\Pichau\Desktop\ZHPCleaner (R).txt
~ Quarantine : C:\Users\Pichau\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ System Restore Point : OK
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Pro, 64-bit  (Build 19042)


---\\  Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\  Services (0)
~ No malicious or unnecessary items found.


---\\  Browser internet (0)
~ No malicious or unnecessary items found.


---\\  Hosts file (1)
~ The hosts file is legitimate (21)


---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\  Explorer ( File, Folder) (4)
MOVED file: C:\Windows\AutoKMS\AutoKMS.log    =>HackTool.AutoKMS
MOVED folder: C:\ProgramData\Microsoft Toolkit  =>HackTool.AutoKMS
MOVED folder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico  =>HackTool.KMSpico
MOVED folder: C:\Windows\AutoKMS  =>HackTool.AutoKMS


---\\  Registry ( Key, Value, Data) (10)
DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{23F6B42E-BA8B-473F-A133-E7DC25D09346} [C:\Program Files\KMSpico\KMSELDI.exe]  =>HackTool.KMSpico
DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{EE6785CF-BCF6-4D22-8639-7E609352BEA2} [C:\Program Files\KMSpico\KMSELDI.exe]  =>HackTool.KMSpico
DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{DD5100C9-EAC3-4235-A2B7-8043A186FCC9} [C:\Program Files\KMSpico\AutoPico.exe]  =>HackTool.KMSpico
DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{24D24E4D-F256-4D02-A220-A564E1B2B101} [C:\Program Files\KMSpico\AutoPico.exe]  =>HackTool.KMSpico
DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{76D892DF-741D-48F2-9E3C-0DD5057468FC} [C:\Program Files\KMSpico\Service_KMS.exe]  =>HackTool.KMSpico
DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{671F9D32-04F8-479E-AE28-8D3B099D1598} [C:\Program Files\KMSpico\Service_KMS.exe]  =>HackTool.KMSpico
DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{980E71EE-4A1C-44A3-A283-5C21DFB7C728} [C:\Program Files\KMSpico\Service_KMS.exe]  =>HackTool.KMSpico
DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{EE0268B4-1D34-488E-AEA9-0432EE917B54} [C:\Program Files\KMSpico\Service_KMS.exe]  =>HackTool.KMSpico
DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{35C9DDFB-0F4B-418C-8430-8F80BF76E7BA} [C:\Program Files\KMSpico\AutoPico.exe]  =>HackTool.KMSpico
DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{7F8ECF38-43E2-4C66-9E35-5C604A1423F5} [C:\Program Files\KMSpico\AutoPico.exe]  =>HackTool.KMSpico


---\\  Summary of the elements found (2)
https://nicolascoolman.eu/2017/02/02/hacktool-autokms/  =>HackTool.AutoKMS
https://nicolascoolman.eu/2017/02/16/hacktool-kmspico/  =>HackTool.KMSpico


---\\  Other deletions. (6)
~ Registry Keys Tracing deleted (6)
~ Remove the old reports ZHPCleaner. (0)


---\\ Result of repair
~ Repair carried out successfully
~ Google Chrome OK
~ Mozilla Firefox OK
~ Internet Explorer OK


---\\ Statistics
~ Items scanned : 1392
~ Items found : 0
~ Items cancelled : 0
~ Space saving (bytes) : 0
~ Items options : 9/16


---\\ OPTIONS NOT ACTIVES
~ Temporary file analysis
~ Temporary folder analysis
~ Empty Folder CLSID Analysis
~ Empty Other Folder Analysis
~ Empty LocalLow Folder Analysis
~ Empty Local Folder Analysis
~ Obsolete Installer File Analysis

~ End of clean in 00h00mn17s

---\\  Reports (2)
ZHPCleaner-[S]-26112020-15_32_24.txt
ZHPCleaner-[R]-26112020-15_34_03.txt
 

 

---------------------------------------------------------------

~ ZHPCleaner v2020.11.24.257 by Nicolas Coolman (2020/11/24)
~ Run by Emanuel (Administrator)  (26/11/2020 15:23:33)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version KO
~ Type : Scan
~ Report : C:\Users\Pichau\Desktop\ZHPCleaner (S).txt
~ Quarantine : C:\Users\Pichau\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ System Restore Point : 
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Pro, 64-bit  (Build 19042)


---\\  Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.


---\\  Services (0)
~ No malicious or unnecessary items found.


---\\  Browser internet (0)
~ No malicious or unnecessary items found.


---\\  Hosts file (1)
~ The hosts file is legitimate (21)


---\\  Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.


---\\  Explorer ( File, Folder) (5)
FOUND file: C:\Windows\AutoKMS\AutoKMS.log    =>HackTool.AutoKMS
FOUND file: C:\ProgramData\Microsoft Toolkit\Settings.xml    =>HackTool.AutoKMS
FOUND folder: C:\ProgramData\Microsoft Toolkit  =>HackTool.AutoKMS
FOUND folder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico  =>HackTool.KMSpico
FOUND folder: C:\Windows\AutoKMS  =>HackTool.AutoKMS


---\\  Registry ( Key, Value, Data) (10)
FOUND value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{23F6B42E-BA8B-473F-A133-E7DC25D09346} [C:\Program Files\KMSpico\KMSELDI.exe]  =>HackTool.KMSpico
FOUND value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{EE6785CF-BCF6-4D22-8639-7E609352BEA2} [C:\Program Files\KMSpico\KMSELDI.exe]  =>HackTool.KMSpico
FOUND value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{DD5100C9-EAC3-4235-A2B7-8043A186FCC9} [C:\Program Files\KMSpico\AutoPico.exe]  =>HackTool.KMSpico
FOUND value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{24D24E4D-F256-4D02-A220-A564E1B2B101} [C:\Program Files\KMSpico\AutoPico.exe]  =>HackTool.KMSpico
FOUND value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{76D892DF-741D-48F2-9E3C-0DD5057468FC} [C:\Program Files\KMSpico\Service_KMS.exe]  =>HackTool.KMSpico
FOUND value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{671F9D32-04F8-479E-AE28-8D3B099D1598} [C:\Program Files\KMSpico\Service_KMS.exe]  =>HackTool.KMSpico
FOUND value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{980E71EE-4A1C-44A3-A283-5C21DFB7C728} [C:\Program Files\KMSpico\Service_KMS.exe]  =>HackTool.KMSpico
FOUND value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{EE0268B4-1D34-488E-AEA9-0432EE917B54} [C:\Program Files\KMSpico\Service_KMS.exe]  =>HackTool.KMSpico
FOUND value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{35C9DDFB-0F4B-418C-8430-8F80BF76E7BA} [C:\Program Files\KMSpico\AutoPico.exe]  =>HackTool.KMSpico
FOUND value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{7F8ECF38-43E2-4C66-9E35-5C604A1423F5} [C:\Program Files\KMSpico\AutoPico.exe]  =>HackTool.KMSpico


---\\  Summary of the elements found (2)
https://nicolascoolman.eu/2017/02/02/hacktool-autokms/  =>HackTool.AutoKMS
https://nicolascoolman.eu/2017/02/16/hacktool-kmspico/  =>HackTool.KMSpico


---\\ Result of repair
~ Any repair made
~ Google Chrome OK
~ Mozilla Firefox OK
~ Internet Explorer OK


---\\ Statistics
~ Items scanned : 107016
~ Items found : 21
~ Items cancelled : 0
~ Space saving (bytes) : 0
~ Items options : 9/16


---\\ OPTIONS NOT ACTIVES
~ Temporary file analysis
~ Temporary folder analysis
~ Empty Folder CLSID Analysis
~ Empty Other Folder Analysis
~ Empty LocalLow Folder Analysis
~ Empty Local Folder Analysis
~ Obsolete Installer File Analysis

~ End of search in 00h08mn51s

---\\  Reports (0)
ZHPCleaner-[S]-26112020-15_32_24.txt
 

KMSpico acabou aparecendo no resultado, mesmo após eu ter desinstalado e limpado todos os resquicios dele.

~ ZHPCleaner v2020.11.24.257 by Nicolas Coolman (2020/11/24) ~ Run by Emanuel (Administrator) (26/11/2020 15:33:46) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version KO ~ Certificate ZHPCleaner: Legal ~ Type : Repair ~ Report : C:\Users\Pichau\Desktop\ZHPCleaner (R).txt ~ Quarantine : C:\Users\Pichau\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 10 Pro, 64-bit (Build 19042) ---\ Alternate Data Stream (ADS). (0) ~ No malicious or unnecessary items found. (ADS) ---\ Services (0) ~ No malicious or unnecessary items found. (Service) ---\ Browser internet (0) ~ No malicious or unnecessary items found. (Browser) ---\ Hosts file (1) ~ The hosts file is legitimate (21) ---\ Scheduled automatic tasks. (0) ~ No malicious or unnecessary items found. (Task) ---\ Explorer ( File, Folder) (4) MOVED file: C:\Windows\AutoKMS\AutoKMS.log =>HackTool.AutoKMS MOVED folder: C:\ProgramData\Microsoft Toolkit =>HackTool.AutoKMS MOVED folder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico =>HackTool.KMSpico MOVED folder: C:\Windows\AutoKMS =>HackTool.AutoKMS ---\ Registry ( Key, Value, Data) (10) DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{23F6B42E-BA8B-473F-A133-E7DC25D09346} [C:\Program Files\KMSpico\KMSELDI.exe] =>HackTool.KMSpico DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{EE6785CF-BCF6-4D22-8639-7E609352BEA2} [C:\Program Files\KMSpico\KMSELDI.exe] =>HackTool.KMSpico DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{DD5100C9-EAC3-4235-A2B7-8043A186FCC9} [C:\Program Files\KMSpico\AutoPico.exe] =>HackTool.KMSpico DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{24D24E4D-F256-4D02-A220-A564E1B2B101} [C:\Program Files\KMSpico\AutoPico.exe] =>HackTool.KMSpico DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{76D892DF-741D-48F2-9E3C-0DD5057468FC} [C:\Program Files\KMSpico\Service_KMS.exe] =>HackTool.KMSpico DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{671F9D32-04F8-479E-AE28-8D3B099D1598} [C:\Program Files\KMSpico\Service_KMS.exe] =>HackTool.KMSpico DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{980E71EE-4A1C-44A3-A283-5C21DFB7C728} [C:\Program Files\KMSpico\Service_KMS.exe] =>HackTool.KMSpico DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{EE0268B4-1D34-488E-AEA9-0432EE917B54} [C:\Program Files\KMSpico\Service_KMS.exe] =>HackTool.KMSpico DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{35C9DDFB-0F4B-418C-8430-8F80BF76E7BA} [C:\Program Files\KMSpico\AutoPico.exe] =>HackTool.KMSpico DELETED value: HKLM\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\firewallRules\\{7F8ECF38-43E2-4C66-9E35-5C604A1423F5} [C:\Program Files\KMSpico\AutoPico.exe] =>HackTool.KMSpico ---\ Summary of the elements found (2) https://nicolascoolman.eu/2017/02/02/hacktool-autokms/ =>HackTool.AutoKMS https://nicolascoolman.eu/2017/02/16/hacktool-kmspico/ =>HackTool.KMSpico ---\ Other deletions. (6) ~ Registry Keys Tracing deleted (6) ~ Remove the old reports ZHPCleaner. (0) ---\ Result of repair ~ Repair carried out successfully ~ Google Chrome OK ~ Mozilla Firefox OK ~ Internet Explorer OK ---\ Statistics ~ Items scanned : 1392 ~ Items found : 0 ~ Items cancelled : 0 ~ Space saving (bytes) : 0 ~ Items options : 9/16 ---\ OPTIONS NOT ACTIVES ~ Temporary file analysis ~ Temporary folder analysis ~ Empty Folder CLSID Analysis ~ Empty Other Folder Analysis ~ Empty LocalLow Folder Analysis ~ Empty Local Folder Analysis ~ Obsolete Installer File Analysis ~ End of clean in 00h00mn17s ---\ Reports (2) ZHPCleaner-[S]-26112020-15_32_24.txt ZHPCleaner-[R]-26112020-15_34_03.txt

---------------------------------------------------------------------------------------------------
 

~ ZHPCleaner v2020.11.24.257 by Nicolas Coolman (2020/11/24) ~ Run by Emanuel (Administrator) (26/11/2020 15:39:19) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version KO ~ Certificate ZHPCleaner: Legal ~ Type : Scan ~ Report : C:\Users\Pichau\Desktop\ZHPCleaner (S).txt ~ Quarantine : C:\Users\Pichau\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 10 Pro, 64-bit (Build 19042) ---\ Alternate Data Stream (ADS). (0) ~ No malicious or unnecessary items found. (ADS) ---\ Services (0) ~ No malicious or unnecessary items found. (Service) ---\ Browser internet (0) ~ No malicious or unnecessary items found. (Browser) ---\ Hosts file (1) ~ The hosts file is legitimate (21) ---\ Scheduled automatic tasks. (0) ~ No malicious or unnecessary items found. (Task) ---\ Explorer ( File, Folder) (0) ~ No malicious or unnecessary items found. (Explorer) ---\ Registry ( Key, Value, Data) (2) FOUND data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{bc213d83-6e84-42c6-bcab-e24226a9f0ad}\\DhcpNameServer [Bad : 177.221.67.253 177.221.71.253] =>Hijacker.Browser FOUND data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer [Bad : 177.221.67.253 177.221.71.253] =>Hijacker.Browser ---\ Summary of the elements found (1) https://nicolascoolman.eu/2017/11/10/hijacker-browser-3/ =>Hijacker.Browser ---\ Result of repair ~ Any repair made ~ Google Chrome OK ~ Mozilla Firefox OK ~ Internet Explorer OK ---\ Statistics ~ Items scanned : 107009 ~ Items found : 2 ~ Items cancelled : 0 ~ Space saving (bytes) : 0 ~ Items options : 9/16 ---\ OPTIONS NOT ACTIVES ~ Temporary file analysis ~ Temporary folder analysis ~ Empty Folder CLSID Analysis ~ Empty Other Folder Analysis ~ Empty LocalLow Folder Analysis ~ Empty Local Folder Analysis ~ Obsolete Installer File Analysis ~ End of search in 00h08mn34s ---\ Reports (3) ZHPCleaner-[R]-26112020-15_34_03.txt ZHPCleaner-[S]-26112020-15_32_24.txt ZHPCleaner-[S]-26112020-15_47_53.txt

-------------------------------------------------------------------------------

Acredito que a partir disso, deu certo, pois me apresentou  ^Repair carried out successfully

~ ZHPCleaner v2020.11.24.257 by Nicolas Coolman (2020/11/24) ~ Run by Emanuel (Administrator) (26/11/2020 16:01:04) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version KO ~ Certificate ZHPCleaner: Legal ~ Type : Repair ~ Report : C:\Users\Pichau\Desktop\ZHPCleaner (R).txt ~ Quarantine : C:\Users\Pichau\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 10 Pro, 64-bit (Build 19042) ---\ Alternate Data Stream (ADS). (0) ~ No malicious or unnecessary items found. (ADS) ---\ Services (0) ~ No malicious or unnecessary items found. (Service) ---\ Browser internet (0) ~ No malicious or unnecessary items found. (Browser) ---\ Hosts file (1) ~ The hosts file is legitimate (21) ---\ Scheduled automatic tasks. (0) ~ No malicious or unnecessary items found. (Task) ---\ Explorer ( File, Folder) (0) ~ No malicious or unnecessary items found. (Explorer) ---\ Registry ( Key, Value, Data) (2) DELETED data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{bc213d83-6e84-42c6-bcab-e24226a9f0ad}\\DhcpNameServer [Bad : 177.221.67.253 177.221.71.253] =>Hijacker.Browser DELETED data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer [Bad : 177.221.67.253 177.221.71.253] =>Hijacker.Browser ---\ Summary of the elements found (1) https://nicolascoolman.eu/2017/11/10/hijacker-browser-3/ =>Hijacker.Browser ---\ Other deletions. (3) ~ Registry Keys Tracing deleted (3) ~ Remove the old reports ZHPCleaner. (0) ---\ Result of repair ~ Repair carried out successfully ~ Mozilla Firefox OK ~ Internet Explorer OK ---\ Statistics ~ Items scanned : 1389 ~ Items found : 0 ~ Items cancelled : 0 ~ Space saving (bytes) : 0 ~ Items options : 9/16 ---\ OPTIONS NOT ACTIVES ~ Temporary file analysis ~ Temporary folder analysis ~ Empty Folder CLSID Analysis ~ Empty Other Folder Analysis ~ Empty LocalLow Folder Analysis ~ Empty Local Folder Analysis ~ Obsolete Installer File Analysis ~ End of clean in 00h00mn20s ---\ Reports (2) ZHPCleaner-[S]-26112020-15_58_44.txt ZHPCleaner-[R]-26112020-16_01_24.txt

Link para o post
Compartilhar em outros sites

 Adentrei novamente no driver da AMD, e ainda me acontecem grandes picos de uso da GPU, e um uso excessivo da memória ram(obs: deixo apenas o necessário para inicializar com o windows)

Já no csgo, permanece a baixa de FPS que anteriormente não acontecia...

O que pode ser? O que me deixa encucado é que, antes rodava tranquilo, realmente não faço ideia de o que pode ser.

image.png

 

image.thumb.png.bd09f4af97fba09de19c0c84efc1a6c0.png

Link para o post
Compartilhar em outros sites
  • Analista de Segurança

@Emanuel C A Floriano

 

Faça o download do RogueKiller by Tigzy, e salve na sua área de trabalho (Desktop)

roguekiller.exe (x64) << link

  • Feche todos os programas
  • Execute o RogueKiller.exe.
    ** Usuários do Windows Vista, Windows 7, 8, 8.1 e Windows 10:Clique com o direito sobre o arquivo rogueKiller.exe, depois clique em http://i.imgur.com/VRIfczU.png.
  • Clique em SCAN
  • Clique no primeiro START "Standard Scan (recommended)" e aguarde o scan...
  • Clique no botão RESULTS
  • Clique na opção REPORT e em EXPORT e selecione a opção Text file...
  • Salve o arquivo na area de trabalho com o nome roguekiller_report

Atente para abrir o arquivo, copiar e colar todo o conteúdo na sua próxima resposta

 

Link para o post
Compartilhar em outros sites

Bom dia, acabei formatando o computador por necessidade, e, o pior é que o windows defender acusou novamente sobre um trojan.

Estarei fazendo o procedimento novamente, segue o log da primeira etapa:

 

# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build:    10-08-2020
# Database: 2020-11-23.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    11-28-2020
# Duration: 00:00:06
# OS:       Windows 10 Pro
# Cleaned:  6
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted       C:\Users\Emanuel\AppData\Roaming\DRPSu

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\zonemap\domains\drp.su
Deleted       HKCU\Software\drpsu
Deleted       HKLM\Software\Wow6432Node\drpsu

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

Deleted       Default
Deleted       Default

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1696 octets] - [28/11/2020 09:01:29]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
 

~ ZHPCleaner v2020.11.24.257 by Nicolas Coolman (2020/11/24) ~ Run by Emanuel (Administrator) (28/11/2020 09:06:10) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Certificate ZHPCleaner: Legal ~ Type : Scan ~ Report : C:\Users\Emanuel\Desktop\ZHPCleaner (S).txt ~ Quarantine : C:\Users\Emanuel\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 10 Pro, 64-bit (Build 19042) ---\ Alternate Data Stream (ADS). (0) ~ No malicious or unnecessary items found. (ADS) ---\ Services (0) ~ No malicious or unnecessary items found. (Service) ---\ Browser internet (0) ~ No malicious or unnecessary items found. (Browser) ---\ Hosts file (1) ~ The hosts file is legitimate (21) ---\ Scheduled automatic tasks. (0) ~ No malicious or unnecessary items found. (Task) ---\ Explorer ( File, Folder) (2) FOUND file: C:\Users\Emanuel\AppData\Local\Google\Chrome\User Data\Default\Preferences =>ChromiumPreference FOUND file: C:\Users\Emanuel\AppData\Local\Microsoft\Edge\User Data\Default\Preferences =>ChromiumPreference ---\ Registry ( Key, Value, Data) (2) FOUND data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2621f978-9e17-4385-9ec6-6ecb3b8d5a08}\\DhcpNameServer [Bad : 177.221.67.253 177.221.71.253] =>Hijacker.Browser FOUND data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer [Bad : 177.221.67.253 177.221.71.253] =>Hijacker.Browser ---\ Summary of the elements found (2) https://nicolascoolman.eu/2020/10/01/preferences-navigateurs-chromium/ =>ChromiumPreference https://nicolascoolman.eu/2017/11/10/hijacker-browser-3/ =>Hijacker.Browser ---\ Result of repair ~ Any repair made ~ Google Chrome OK ~ Internet Explorer OK ~ Opera OK ---\ Statistics ~ Items scanned : 91403 ~ Items found : 4 ~ Items cancelled : 0 ~ Space saving (bytes) : 0 ~ Items options : 9/16 ---\ OPTIONS NOT ACTIVES ~ Temporary file analysis ~ Temporary folder analysis ~ Empty Folder CLSID Analysis ~ Empty Other Folder Analysis ~ Empty LocalLow Folder Analysis ~ Empty Local Folder Analysis ~ Obsolete Installer File Analysis ~ End of search in 00h07mn02s ---\ Reports (0) ZHPCleaner-[S]-28112020-09_13_12.txt

~ ZHPCleaner v2020.11.24.257 by Nicolas Coolman (2020/11/24) ~ Run by Emanuel (Administrator) (28/11/2020 09:15:58) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook : https://www.facebook.com/nicolascoolman1 ~ State version : Version OK ~ Certificate ZHPCleaner: Legal ~ Type : Scan ~ Report : C:\Users\Emanuel\Desktop\ZHPCleaner (S).txt ~ Quarantine : C:\Users\Emanuel\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt ~ UAC : Activate ~ Boot Mode : Normal (Normal boot) Windows 10 Pro, 64-bit (Build 19042) ---\ Alternate Data Stream (ADS). (0) ~ No malicious or unnecessary items found. (ADS) ---\ Services (0) ~ No malicious or unnecessary items found. (Service) ---\ Browser internet (0) ~ No malicious or unnecessary items found. (Browser) ---\ Hosts file (1) ~ The hosts file is legitimate (21) ---\ Scheduled automatic tasks. (0) ~ No malicious or unnecessary items found. (Task) ---\ Explorer ( File, Folder) (2) FOUND file: C:\Users\Emanuel\AppData\Local\Google\Chrome\User Data\Default\Preferences =>ChromiumPreference FOUND file: C:\Users\Emanuel\AppData\Local\Microsoft\Edge\User Data\Default\Preferences =>ChromiumPreference ---\ Registry ( Key, Value, Data) (2) FOUND data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2621f978-9e17-4385-9ec6-6ecb3b8d5a08}\\DhcpNameServer [Bad : 177.221.67.253 177.221.71.253] =>Hijacker.Browser FOUND data: HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer [Bad : 177.221.67.253 177.221.71.253] =>Hijacker.Browser ---\ Summary of the elements found (2) https://nicolascoolman.eu/2020/10/01/preferences-navigateurs-chromium/ =>ChromiumPreference https://nicolascoolman.eu/2017/11/10/hijacker-browser-3/ =>Hijacker.Browser ---\ Result of repair ~ Any repair made ~ Google Chrome OK ~ Internet Explorer OK ~ Opera OK ---\ Statistics ~ Items scanned : 91417 ~ Items found : 4 ~ Items cancelled : 0 ~ Space saving (bytes) : 0 ~ Items options : 9/16 ---\ OPTIONS NOT ACTIVES ~ Temporary file analysis ~ Temporary folder analysis ~ Empty Folder CLSID Analysis ~ Empty Other Folder Analysis ~ Empty LocalLow Folder Analysis ~ Empty Local Folder Analysis ~ Obsolete Installer File Analysis ~ End of search in 00h04mn56s ---\ Reports (3) ZHPCleaner-[R]-28112020-09_15_13.txt ZHPCleaner-[S]-28112020-09_13_12.txt ZHPCleaner-[S]-28112020-09_20_54.txt

ZHPCleaner 

@Elias Pereira

 

RogueKiller Anti-Malware V14.8.0.0 (x64) [Nov 17 2020] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19042) 64 bits
Started in : Normal mode
User : Emanuel [Administrator]
Started from : C:\Users\Emanuel\Downloads\RogueKiller64.exe
Signatures : 20201126_165710, Driver : Loaded
Mode : Standard Scan, Scan -- Date : 2020/11/28 09:33:34 (Duration : 00:19:07)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> O87 - Firewall
  [PUP.DriverPack (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{2FC36D79-DC7F-4CF4-886B-493854307002} -- v2.30|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\Emanuel\AppData\Roaming\DRPSu\Alice\cloud.exe|Name=DriverPack-Alice| (C:\Users\Emanuel\AppData\Roaming\DRPSu\Alice\cloud.exe) (missing) -> Found
  [PUP.DriverPack (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{B504DA31-5CC5-4498-9648-3FB5F85FCCA7} -- v2.30|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\Emanuel\AppData\Roaming\DRPSu\Alice\cloud.exe|Name=DriverPack-Alice| (C:\Users\Emanuel\AppData\Roaming\DRPSu\Alice\cloud.exe) (missing) -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{5B462DC4-D3C6-4E86-8E4C-29BC1A9ABC5C} -- v2.30|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\Emanuel\AppData\Local\Temp\DriverPack-2020112891445\tools\aria2c.exe|Name=DriverPack aria2c.exe| (C:\Users\Emanuel\AppData\Local\Temp\DriverPack-2020112891445\tools\aria2c.exe) -> Found
>>>>>> XX - System Policies
  [PUM.Policies (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin -- 0 -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.DriverPack (Potentially Malicious)] (folder) DriverPack Cloud -- C:\Users\Emanuel\AppData\Roaming\DriverPack Cloud -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 

 

 

 

 

RogueKiller Anti-Malware V14.8.0.0 (x64) [Nov 17 2020] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19042) 64 bits
Started in : Normal mode
User : Emanuel [Administrator]
Started from : C:\Users\Emanuel\Downloads\RogueKiller64.exe
Signatures : 20201126_165710, Driver : Loaded
Mode : Standard Scan, Delete -- Date : 2020/11/28 09:57:44 (Duration : 00:19:07)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.DriverPack (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{2FC36D79-DC7F-4CF4-886B-493854307002} -- [%_Emanuel_appdata%\DRPSu\Alice\cloud.exe] -> Deleted
[PUP.DriverPack (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{B504DA31-5CC5-4498-9648-3FB5F85FCCA7} -- [%_Emanuel_appdata%\DRPSu\Alice\cloud.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{5B462DC4-D3C6-4E86-8E4C-29BC1A9ABC5C} -- [%localappdata%\Temp\DriverPack-2020112891445\Tools\aria2c.exe] -> Deleted
[PUM.Policies (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin --  -> Replaced (2)
[PUP.DriverPack (Potentially Malicious)] DriverPack Cloud -- %_Emanuel_appdata%\DriverPack Cloud -> Deleted
  => appUpdates -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\APPUPD~1 -> Deleted
  => dbVersion.txt -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\DBVERS~1.TXT -> Deleted
  => Event -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\Event -> Deleted
  => Event-mrview-325f745435293d256532744754e71d2e -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\EVENT-~1 -> Deleted
  => Event-mrview-5ded3776f460c591c678eb9965075ba0 -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\EVENT-~2 -> Deleted
  => Event-mrview-bf9f3c68883d3fc49aa42339223e2773 -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\EVENT-~3 -> Deleted
  => Log -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\Log -> Deleted
  => Log-mrview-1dc53652cceb47e2bf5ac31ef479b1a6 -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\LOG-MR~1 -> Deleted
  => Measurement -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\MEASUR~1 -> Deleted
  => Measurement-mrview-4b388b8907bb000c48a474054545fe34 -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\MEASUR~2 -> Deleted
  => Misc -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\Misc -> Deleted
  => db -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db -> Deleted
  => dbBackups -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\DBBACK~1 -> Deleted
  => DirectX.exe -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\download\DirectX.exe -> Deleted
  => download -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\download -> Deleted
  => temp -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\temp -> Deleted
  => triggers -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\triggers -> Deleted
  => unpack -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\unpack -> Deleted
 

Link para o post
Compartilhar em outros sites

@Elias Pereira

 

RogueKiller Anti-Malware V14.8.0.0 (x64) [Nov 17 2020] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19042) 64 bits
Started in : Normal mode
User : Emanuel [Administrator]
Started from : C:\Users\Emanuel\Downloads\RogueKiller64.exe
Signatures : 20201126_165710, Driver : Loaded
Mode : Standard Scan, Scan -- Date : 2020/11/28 09:33:34 (Duration : 00:19:07)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> O87 - Firewall
  [PUP.DriverPack (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{2FC36D79-DC7F-4CF4-886B-493854307002} -- v2.30|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\Emanuel\AppData\Roaming\DRPSu\Alice\cloud.exe|Name=DriverPack-Alice| (C:\Users\Emanuel\AppData\Roaming\DRPSu\Alice\cloud.exe) (missing) -> Found
  [PUP.DriverPack (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{B504DA31-5CC5-4498-9648-3FB5F85FCCA7} -- v2.30|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\Emanuel\AppData\Roaming\DRPSu\Alice\cloud.exe|Name=DriverPack-Alice| (C:\Users\Emanuel\AppData\Roaming\DRPSu\Alice\cloud.exe) (missing) -> Found
  [Suspicious.Path (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{5B462DC4-D3C6-4E86-8E4C-29BC1A9ABC5C} -- v2.30|Action=Allow|Active=TRUE|Dir=In|App=C:\Users\Emanuel\AppData\Local\Temp\DriverPack-2020112891445\tools\aria2c.exe|Name=DriverPack aria2c.exe| (C:\Users\Emanuel\AppData\Local\Temp\DriverPack-2020112891445\tools\aria2c.exe) -> Found
>>>>>> XX - System Policies
  [PUM.Policies (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin -- 0 -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.DriverPack (Potentially Malicious)] (folder) DriverPack Cloud -- C:\Users\Emanuel\AppData\Roaming\DriverPack Cloud -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
 

 

 

 

 

RogueKiller Anti-Malware V14.8.0.0 (x64) [Nov 17 2020] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19042) 64 bits
Started in : Normal mode
User : Emanuel [Administrator]
Started from : C:\Users\Emanuel\Downloads\RogueKiller64.exe
Signatures : 20201126_165710, Driver : Loaded
Mode : Standard Scan, Delete -- Date : 2020/11/28 09:57:44 (Duration : 00:19:07)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.DriverPack (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{2FC36D79-DC7F-4CF4-886B-493854307002} -- [%_Emanuel_appdata%\DRPSu\Alice\cloud.exe] -> Deleted
[PUP.DriverPack (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{B504DA31-5CC5-4498-9648-3FB5F85FCCA7} -- [%_Emanuel_appdata%\DRPSu\Alice\cloud.exe] -> Deleted
[Suspicious.Path (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{5B462DC4-D3C6-4E86-8E4C-29BC1A9ABC5C} -- [%localappdata%\Temp\DriverPack-2020112891445\Tools\aria2c.exe] -> Deleted
[PUM.Policies (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin --  -> Replaced (2)
[PUP.DriverPack (Potentially Malicious)] DriverPack Cloud -- %_Emanuel_appdata%\DriverPack Cloud -> Deleted
  => appUpdates -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\APPUPD~1 -> Deleted
  => dbVersion.txt -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\DBVERS~1.TXT -> Deleted
  => Event -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\Event -> Deleted
  => Event-mrview-325f745435293d256532744754e71d2e -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\EVENT-~1 -> Deleted
  => Event-mrview-5ded3776f460c591c678eb9965075ba0 -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\EVENT-~2 -> Deleted
  => Event-mrview-bf9f3c68883d3fc49aa42339223e2773 -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\EVENT-~3 -> Deleted
  => Log -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\Log -> Deleted
  => Log-mrview-1dc53652cceb47e2bf5ac31ef479b1a6 -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\LOG-MR~1 -> Deleted
  => Measurement -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\MEASUR~1 -> Deleted
  => Measurement-mrview-4b388b8907bb000c48a474054545fe34 -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\MEASUR~2 -> Deleted
  => Misc -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db\Misc -> Deleted
  => db -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\db -> Deleted
  => dbBackups -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\DBBACK~1 -> Deleted
  => DirectX.exe -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\download\DirectX.exe -> Deleted
  => download -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\download -> Deleted
  => temp -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\temp -> Deleted
  => triggers -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\triggers -> Deleted
  => unpack -- C:\Users\Emanuel\AppData\Roaming\DRIVER~1\unpack -> Deleted
 

Link para o post
Compartilhar em outros sites

Peço perdão pela demora do retorno...
Segue o log 

 

# -------------------------------
# Malwarebytes AdwCleaner 8.0.8.0
# -------------------------------
# Build:    10-08-2020
# Database: 2020-11-23.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    12-09-2020
# Duration: 00:00:00
# OS:       Windows 10 Pro
# Cleaned:  1
# Failed:   1


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

Deleted       Default
Not Deleted   Default

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1696 octets] - [28/11/2020 09:01:29]
AdwCleaner[C00].txt - [1772 octets] - [28/11/2020 09:01:51]
AdwCleaner[S01].txt - [1574 octets] - [09/12/2020 21:20:43]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########
 

Link para o post
Compartilhar em outros sites
  • Analista de Segurança

@Emanuel C A Floriano

 

  1. Clique no menu Iniciar, e após isso clique com o botão direito do mouse sob Este computador e selecione a opção Propriedades.
  2. Em Propriedades, selecione a opção Configurações avançadas do sistema.
  3. Vá na aba Proteção do Sistema, e em Restauração do Sistema, vá na opção Criar.
    fce2f587-5556-456b-93d4-00966ae7f59d
  4. Depois basta seguir as instruções em tela, para criar seu ponto de restauração.
    OBS: Lembre-se de colocar um nome de fácil entendimento para uma posterior restauração a partir deste ponto.

Pressione as teclas Windows conheca-atalhos-de-teclado-para-dominar-o-windows-8-2.jpg + R e digite: msconfig 
- Clique na guia Serviços, marque a opção Ocultar todos os serviços Microsoft e depois clique em Desativar tudo
- Clique na guia Inicialização de Programas e clique em Abrir Gerenciador de Tarefas
- Clique com o botão direito em cada entrada da inicialização e clique em Desabilitar/Desativar.

Volte para a tela de Configurações do Sistema e clique em Aplicar e depois em OK

Siga as mensagens ate que seja solicitado a reiniciar.Após isso me informe se os problemas em relação a malwares ainda persistem.

Link para o post
Compartilhar em outros sites
Visitante
Este tópico está impedido de receber novos posts.

Sobre o Clube do Hardware

No ar desde 1996, o Clube do Hardware é uma das maiores, mais antigas e mais respeitadas comunidades sobre tecnologia do Brasil. Leia mais

Direitos autorais

Não permitimos a cópia ou reprodução do conteúdo do nosso site, fórum, newsletters e redes sociais, mesmo citando-se a fonte. Leia mais

×
×
  • Criar novo...

Aprenda a ler resistores e capacitores

EBOOK GRÁTIS!

CLIQUE AQUI E BAIXE AGORA MESMO!