Resultado da Correção pela Farbar Recovery Scan Tool (x64) Versão:27-01-2016 Executado por Rafael Klauz (2016-01-31 03:16:35) Run:2 Executando a partir de C:\Users\Rafael Klauz\Desktop Perfis Carregados: Rafael Klauz (Perfis DisponÃveis: Rafael Klauz & Klauz) Modo da Inicialização: Normal ============================================== fixlist Conteúdo: ***************** start CloseProcesses: HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-13] (Adobe Systems Incorporated) HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\...\Run: [rbcwyzuafr] => wscript.exe //B "C:\Users\RAFAEL~1\AppData\Local\Temp\rbcwyzuafr.vbs" <===== ATENÃÃO HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\...\MountPoints2: {2bc06410-a86e-11e5-8de9-b8975a4dedf8} - E:\LG_PC_Programs.exe HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\...\MountPoints2: {2d8bf6f9-e463-11e4-9829-b8975a4dedf8} - K:\LGAutoRun.exe HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\...\MountPoints2: {d207d154-8b5a-11e4-92ac-b8975a4dedf8} - K:\Windows/AutoRun.exe GroupPolicy: Restrição - Chrome <======= ATENÃÃO CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÃÃO SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-1525506457-2769244486-1402065697-1000 -> DefaultScope {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-1525506457-2769244486-1402065697-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-1525506457-2769244486-1402065697-1000 -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE FF HKLM-x32\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files (x86)\:censurado:\:censurado: Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com => não encontrado (a) FF HKLM-x32\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files (x86)\:censurado:\:censurado: Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com => não encontrado (a) OPR Extension: (Sale Clipper) - C:\Users\Rafael Klauz\AppData\Roaming\Opera Software\Opera Stable\Extensions\iaofmdncmakgfhhlkpeohbidhaiedblo [2015-06-21] S2 bavsvc; "C:\Program Files (x86)\Baidu Security\Baidu Antivirus\bavsvc.exe" [X] S2 bhipssvc; "C:\Program Files (x86)\Baidu Security\Baidu Antivirus\bhipssvc.exe" [X] R1 Bfilter; C:\Windows\System32\drivers\Bfilter.sys [52032 2014-01-21] (Baidu, Inc.) R1 Bfmon; C:\Windows\System32\drivers\Bfmon.sys [34624 2014-01-21] (Baidu, Inc.) R1 Bprotect; C:\Windows\System32\drivers\Bprotect.sys [128992 2014-01-21] (Baidu, Inc.) S3 BdApiUtil; \??\C:\Program Files (x86)\Baidu Security\Baidu Antivirus\BdApiUtil64.sys [X] S3 BdCameraProtect; \??\C:\Program Files (x86)\Baidu Security\Baidu Antivirus\BdCameraProtect64.sys [X] S3 gkernel; \??\C:\Users\RAFAEL~1\AppData\Local\Temp\gkernel.sys [X] S3 NPF; system32\drivers\NPF.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] 2016-01-28 15:02 - 2016-01-30 12:31 - 00000823 _____ C:\Users\Rafael Klauz\Desktop\JRT.txt 2016-01-28 14:58 - 2016-01-28 14:59 - 01609032 _____ (Malwarebytes) C:\Users\Rafael Klauz\Downloads\JRT.exe 2016-01-28 04:17 - 2016-01-28 04:17 - 05822720 _____ (Advanced System Protector ) C:\Users\Rafael Klauz\Downloads\aspsetup.exe 2016-01-30 10:54 - 2015-06-26 01:25 - 00000682 _____ C:\Windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job 2016-01-30 10:54 - 2015-06-22 05:27 - 00007095 _____ C:\CE.txt Task: {3DB9D378-9942-4DB0-BD87-76A5339A7E2B} - System32\Tasks\{BB319A3A-557D-48F3-86D1-302C537F1AD9} => pcalua.exe -a E:\INSTALAR.exe -d E:\ Task: {4F774A48-8B99-4D2F-901F-1D4F6AD23AD3} - System32\Tasks\{A09B3242-BBED-4E53-A09D-352D3E29AC20} => pcalua.exe -a "C:\Users\Rafael Klauz\AppData\Roaming\webssearches\UninstallManager.exe" -c -ptid=irs <==== ATENÃÃO Task: {708AFF65-2DB9-4FC8-AB81-C75A7A5D627F} - System32\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935} => C:\Users\Rafael Klauz\AppData\Roaming\{2F3AA0F6-976C-4b02-A66A-5D1DEA00811F}\InstallHelp.exe <==== ATENÃÃO Task: {AAD36130-80CE-4AE9-AAEC-29C522536278} - System32\Tasks\{A97BD33E-73A7-4413-9A8A-7095CD9988EB} => pcalua.exe -a "C:\Users\Rafael Klauz\AppData\Roaming\webssearches\UninstallManager.exe" -c -ptid=irs <==== ATENÃÃO Task: C:\Windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job => C:\Users\Rafael Klauz\AppData\Roaming\{2F3AA0F6-976C-4b02-A66A-5D1DEA00811F}\InstallHelp.exe?-RunCheckUpdate C:\Users\Rafael Klauz\AppData\Roaming\{2F3AA0F6-976C-4b02-A66A-5D1DEA00811F}\CheckUpdate.exe <==== ATENÃÃO FirewallRules: [UDP Query User{149FD561-2141-4B5E-A96C-D76DFADE8421}C:\users\rafael klauz\appdata\local\popcorn time\node-webkit\popcorn time.exe] => (Allow) C:\users\rafael klauz\appdata\local\popcorn time\node-webkit\popcorn time.exe AlternateDataStreams: C:\ProgramData\TEMP:CB0AACC9 AlternateDataStreams: C:\Users\Rafael Klauz\Cookies:MU1O0DxGUamftfpe4MmxSruF8o7cGx AlternateDataStreams: C:\Users\Rafael Klauz\AppData\Local\X7R24amEEM:ybDID7fcaKbdiImqjIFJGU AlternateDataStreams: C:\Users\Todos os Usuários\TEMP:CB0AACC9 C:\Windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job C:\Program Files (x86)\Trojan Remover\Trjscan.exe Reg: reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f Reg: reg add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f DeleteKey: DeleteJunctionsIndirectory: C:\Program Files\Microsoft Security Client DeleteJunctionsIndirectory: C:\Program Files\Windows Defender CMD: dir /a "C:\Program Files" CMD: dir /a "C:\Program Files (x86)" CMD: dir /a "C:\Users\All Users" CreateRestorePoint: RemoveProxy: EmptyTemp: Reboot: Hosts: end ***************** Processos fechados com sucesso. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => valor não encontrado (a). HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\Software\Microsoft\Windows\CurrentVersion\Run\\rbcwyzuafr => valor não encontrado (a). HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => valor não encontrado (a). HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bc06410-a86e-11e5-8de9-b8975a4dedf8} => chave não encontrado (a). HKCR\CLSID\{2bc06410-a86e-11e5-8de9-b8975a4dedf8} => chave não encontrado (a). HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d8bf6f9-e463-11e4-9829-b8975a4dedf8} => chave não encontrado (a). HKCR\CLSID\{2d8bf6f9-e463-11e4-9829-b8975a4dedf8} => chave não encontrado (a). HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d207d154-8b5a-11e4-92ac-b8975a4dedf8} => chave não encontrado (a). HKCR\CLSID\{d207d154-8b5a-11e4-92ac-b8975a4dedf8} => chave não encontrado (a). C:\Windows\system32\GroupPolicy\Machine => movido com sucesso C:\Windows\system32\GroupPolicy\GPT.ini => movido com sucesso HKLM\SOFTWARE\Policies\Google => chave não encontrado (a). HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => valor restaurado com sucesso HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2f23ab71-4ac6-41f2-a955-ea576e553146} => chave não encontrado (a). HKCR\CLSID\{2f23ab71-4ac6-41f2-a955-ea576e553146} => chave não encontrado (a). HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => chave não encontrado (a). HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => chave não encontrado (a). HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => valor restaurado com sucesso HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => chave não encontrado (a). HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => chave não encontrado (a). HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => valor não encontrado (a). HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => chave não encontrado (a). HKCR\CLSID\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} => chave não encontrado (a). HKU\S-1-5-21-1525506457-2769244486-1402065697-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9} => chave não encontrado (a). HKCR\CLSID\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9} => chave não encontrado (a). HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\fmdownloader@gmail.com => valor não encontrado (a). HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ytfmdownloader@gmail.com => valor não encontrado (a). C:\Users\Rafael Klauz\AppData\Roaming\Opera Software\Opera Stable\Extensions\iaofmdncmakgfhhlkpeohbidhaiedblo => não encontrado (a). bavsvc => serviço não encontrado (a). bhipssvc => serviço não encontrado (a). Bfilter => serviço não encontrado (a). Bfmon => serviço não encontrado (a). Bprotect => serviço não encontrado (a). BdApiUtil => serviço não encontrado (a). BdCameraProtect => serviço não encontrado (a). gkernel => serviço não encontrado (a). NPF => serviço removido (a) com sucesso. VGPU => serviço não encontrado (a). "C:\Users\Rafael Klauz\Desktop\JRT.txt" => não encontrado (a). "C:\Users\Rafael Klauz\Downloads\JRT.exe" => não encontrado (a). "C:\Users\Rafael Klauz\Downloads\aspsetup.exe" => não encontrado (a). "C:\Windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job" => não encontrado (a). C:\CE.txt => movido com sucesso HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3DB9D378-9942-4DB0-BD87-76A5339A7E2B} => chave não encontrado (a). C:\Windows\System32\Tasks\{BB319A3A-557D-48F3-86D1-302C537F1AD9} => não encontrado (a). HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{BB319A3A-557D-48F3-86D1-302C537F1AD9} => chave não encontrado (a). HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F774A48-8B99-4D2F-901F-1D4F6AD23AD3} => chave não encontrado (a). C:\Windows\System32\Tasks\{A09B3242-BBED-4E53-A09D-352D3E29AC20} => não encontrado (a). HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A09B3242-BBED-4E53-A09D-352D3E29AC20} => chave não encontrado (a). HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{708AFF65-2DB9-4FC8-AB81-C75A7A5D627F} => chave não encontrado (a). C:\Windows\System32\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935} => não encontrado (a). HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935} => chave não encontrado (a). HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AAD36130-80CE-4AE9-AAEC-29C522536278} => chave não encontrado (a). C:\Windows\System32\Tasks\{A97BD33E-73A7-4413-9A8A-7095CD9988EB} => não encontrado (a). HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{A97BD33E-73A7-4413-9A8A-7095CD9988EB} => chave não encontrado (a). C:\Windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job => não encontrado (a). HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{149FD561-2141-4B5E-A96C-D76DFADE8421}C:\users\rafael klauz\appdata\local\popcorn time\node-webkit\popcorn time.exe => valor não encontrado (a). "C:\ProgramData\TEMP" => ":CB0AACC9" ADS não encontrado (a). "C:\Users\Rafael Klauz\Cookies" => ":MU1O0DxGUamftfpe4MmxSruF8o7cGx" ADS não encontrado (a). "C:\Users\Rafael Klauz\AppData\Local\X7R24amEEM" => ":ybDID7fcaKbdiImqjIFJGU" ADS não encontrado (a). "C:\Users\Todos os Usuários\TEMP" => ":CB0AACC9" ADS não encontrado (a). "C:\Windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job" => não encontrado (a). "C:\Program Files (x86)\Trojan Remover\Trjscan.exe" => não encontrado (a). ========= reg delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f ========= A operaâ¡Ão foi conclu¡da com Ëxito. ========= Fim de Reg: ========= ========= reg add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /f ========= A operaâ¡Ão foi conclu¡da com Ëxito. ========= Fim de Reg: ========= ========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f ========= A operaâ¡Ão foi conclu¡da com Ëxito. ========= Fim de Reg: ========= ========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f ========= A operaâ¡Ão foi conclu¡da com Ëxito. ========= Fim de Reg: ========= DeleteKey: => Não pode ser removidochave.: incorrect path. "C:\Program Files\Microsoft Security Client" => Deletando reparse point e desbloqueando começado: "C:\Program Files\Microsoft Security Client" =>Deletando reparse point e desbloqueando completado. "C:\Program Files\Windows Defender" => Deletando reparse point e desbloqueando começado: "C:\Program Files\Windows Defender" =>Deletando reparse point e desbloqueando completado. ========= dir /a "C:\Program Files" ========= O volume na unidade C nÆo tem nome. O N£mero de Srie do Volume BCC5-7131 Pasta de C:\Program Files 23/07/2015 05:24