foram criados 2 logs:
1°
# AdwCleaner v1.801 - Logfile created 09/17/2012 at 01:03:58
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Ultimate (32 bits)
# User : WESLEY - PETROLEIRO
# Boot Mode : Normal
# Running from : C:\Users\WESLEY\Desktop\104139_adwcleaner_1_801.exe
# Option [Search]
***** [Services] *****
Found : Browser Manager
***** [Files / Folders] *****
Folder Found : C:\Users\Duaite\AppData\Local\APN
Folder Found : C:\Users\WESLEY\AppData\Local\Babylon
Folder Found : C:\Users\WESLEY\AppData\Local\Conduit
Folder Found : C:\Users\Duaite\AppData\LocalLow\BabylonToolbar
Folder Found : C:\Users\Duaite\AppData\LocalLow\facemoods.com
Folder Found : C:\Users\WESLEY\AppData\LocalLow\BabylonToolbar
Folder Found : C:\Users\WESLEY\AppData\LocalLow\Conduit
Folder Found : C:\Users\WESLEY\AppData\LocalLow\facemoods.com
Folder Found : C:\Users\Convidado\AppData\LocalLow\AskToolbar
Folder Found : C:\Users\Convidado\AppData\LocalLow\BabylonToolbar
Folder Found : C:\Users\Convidado\AppData\LocalLow\facemoods.com
Folder Found : C:\Users\Duaite\AppData\Roaming\Babylon
Folder Found : C:\Users\WESLEY\AppData\Roaming\Babylon
Folder Found : C:\Users\WESLEY\AppData\Roaming\Mozilla\Firefox\Profiles\72hdgek9.default\ConduitCommon
Folder Found : C:\Users\WESLEY\AppData\Roaming\Mozilla\Firefox\Profiles\72hdgek9.default\CT2851643
Folder Found : C:\Users\WESLEY\AppData\Roaming\Mozilla\Firefox\Profiles\72hdgek9.default\extensions\{e0301295-ab3e-4af3-979f-3d453c5f9f48}
Folder Found : C:\Users\WESLEY\AppData\Roaming\Mozilla\Firefox\Profiles\72hdgek9.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
Folder Found : C:\ProgramData\Ask
Folder Found : C:\ProgramData\Babylon
Folder Found : C:\ProgramData\Browser Manager
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly
Folder Found : C:\Program Files\Conduit
File Found : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
File Found : C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml
File Found : C:\user.js
***** [Registry] *****
[*] Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2851643
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\BabylonToolbar
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\DealPly
Key Found : HKCU\Software\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje
Key Found : HKCU\Software\Softonic
Key Found : HKLM\SOFTWARE\Babylon
Key Found : HKLM\SOFTWARE\BabylonToolbar
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Found : HKLM\SOFTWARE\Classes\b
Key Found : HKLM\SOFTWARE\Classes\Babylon.dskBnd
Key Found : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1
Key Found : HKLM\SOFTWARE\Classes\bbylnApp.appCore
Key Found : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1
Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Found : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Found : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc
Key Found : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1
Key Found : HKLM\SOFTWARE\Conduit
Key Found : HKLM\SOFTWARE\DealPly
Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje
Key Found : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif
***** [Registre - GUID] *****
Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
Key Found : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Key Found : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Key Found : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Key Found : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Key Found : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Key Found : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
[HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=108293&tt=120912_cpc_3712_6&babsrc=NT_ss&mntrId=c60097a6000000000000001d7df5ece4
-\\ Mozilla Firefox v15.0.1 (en-US)
Profile name : default
File : C:\Users\Duaite\AppData\Roaming\Mozilla\Firefox\Profiles\nuysoin6.default\prefs.js
[OK] File is clean.
Profile name : default
File : C:\Users\WESLEY\AppData\Roaming\Mozilla\Firefox\Profiles\72hdgek9.default\prefs.js
Found : user_pref("CT2851643..clientLogIsEnabled", false);
Found : user_pref("CT2851643..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Found : user_pref("CT2851643..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Found : user_pref("CT2851643.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Found : user_pref("CT2851643.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Found : user_pref("CT2851643.AppTrackingLastCheckTime", "Thu Jun 07 2012 10:08:03 GMT-0300 (Hora oficial do [...]
Found : user_pref("CT2851643.CTID", "CT2851643");
Found : user_pref("CT2851643.CurrentServerDate", "7-9-2012");
Found : user_pref("CT2851643.DSInstall", false);
Found : user_pref("CT2851643.DialogsAlignMode", "LTR");
Found : user_pref("CT2851643.DialogsGetterLastCheckTime", "Fri Sep 07 2012 11:36:18 GMT-0300 (Hora oficial d[...]
Found : user_pref("CT2851643.DownloadReferralCookieData", "");
Found : user_pref("CT2851643.EMailNotifierPollDate", "Fri Jun 08 2012 13:09:37 GMT-0300 (Hora oficial do Bra[...]
Found : user_pref("CT2851643.FeedLastCount1733423638652034402", 496);
Found : user_pref("CT2851643.FeedPollDate2429156812186649977", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.FeedPollDate2429156813040823546", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.FeedPollDate2429156813130095866", "Fri Jun 08 2012 12:24:13 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.FeedPollDate2429156813224203613", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.FeedPollDate2429156813230837251", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.FeedPollDate2429156813454291735", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.FeedPollDate2429156813729834876", "Fri Jun 08 2012 12:24:13 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.FeedPollDate2429156813860870021", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.FeedPollDate2429156814264681793", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.FeedPollDate2429156814863075366", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.FeedPollDate2429156815257761081", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.FeedTTL2429156813040823546", 15);
Found : user_pref("CT2851643.FeedTTL2429156813130095866", 10);
Found : user_pref("CT2851643.FeedTTL2429156813454291735", 5);
Found : user_pref("CT2851643.FeedTTL2429156814264681793", 5);
Found : user_pref("CT2851643.FirstServerDate", "25-5-2012");
Found : user_pref("CT2851643.FirstTime", true);
Found : user_pref("CT2851643.FirstTimeFF3", true);
Found : user_pref("CT2851643.FixPageNotFoundErrors", true);
Found : user_pref("CT2851643.GroupingServerCheckInterval", 1440);
Found : user_pref("CT2851643.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Found : user_pref("CT2851643.HPInstall", false);
Found : user_pref("CT2851643.HasUserGlobalKeys", true);
Found : user_pref("CT2851643.HomePageProtectorEnabled", false);
Found : user_pref("CT2851643.HomepageBeforeUnload", "hxxp://www.google.com.br/");
Found : user_pref("CT2851643.Initialize", true);
Found : user_pref("CT2851643.InitializeCommonPrefs", true);
Found : user_pref("CT2851643.InstallationAndCookieDataSentCount", 3);
Found : user_pref("CT2851643.InstallationId", "fftA392.tmp.exe");
Found : user_pref("CT2851643.InstallationType", "XPE");
Found : user_pref("CT2851643.InstalledDate", "Fri May 25 2012 13:34:59 GMT-0300 (Hora oficial do Brasil)");
Found : user_pref("CT2851643.IsAlertDBUpdated", true);
Found : user_pref("CT2851643.IsGrouping", false);
Found : user_pref("CT2851643.IsInitSetupIni", true);
Found : user_pref("CT2851643.IsMulticommunity", false);
Found : user_pref("CT2851643.IsOpenThankYouPage", true);
Found : user_pref("CT2851643.IsOpenUninstallPage", false);
Found : user_pref("CT2851643.LanguagePackLastCheckTime", "Fri Sep 07 2012 11:36:18 GMT-0300 (Hora oficial do[...]
Found : user_pref("CT2851643.LanguagePackReloadIntervalMM", 1440);
Found : user_pref("CT2851643.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Found : user_pref("CT2851643.LastLogin_3.12.0.8", "Fri May 25 2012 13:35:02 GMT-0300 (Hora oficial do Brasil[...]
Found : user_pref("CT2851643.LastLogin_3.12.2.3", "Sun Jun 03 2012 15:56:16 GMT-0300 (Hora oficial do Brasil[...]
Found : user_pref("CT2851643.LastLogin_3.13.0.6", "Tue Jul 17 2012 14:19:11 GMT-0300 (Hora oficial do Brasil[...]
Found : user_pref("CT2851643.LastLogin_3.14.1.0", "Wed Aug 29 2012 19:01:30 GMT-0300 (Hora oficial do Brasil[...]
Found : user_pref("CT2851643.LastLogin_3.15.1.0", "Fri Sep 07 2012 16:25:03 GMT-0300 (Hora oficial do Brasil[...]
Found : user_pref("CT2851643.LatestVersion", "3.14.1.0");
Found : user_pref("CT2851643.Locale", "pt");
Found : user_pref("CT2851643.MCDetectTooltipHeight", "83");
Found : user_pref("CT2851643.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Found : user_pref("CT2851643.MCDetectTooltipWidth", "295");
Found : user_pref("CT2851643.MyStuffEnabledAtInstallation", true);
Found : user_pref("CT2851643.OriginalFirstVersion", "3.12.0.8");
Found : user_pref("CT2851643.SearchCaption", "uTorrentBar_PT Customized Web Search");
Found : user_pref("CT2851643.SearchEngineBeforeUnload", "Google");
Found : user_pref("CT2851643.SearchFromAddressBarIsInit", true);
Found : user_pref("CT2851643.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT285[...]
Found : user_pref("CT2851643.SearchInNewTabEnabled", true);
Found : user_pref("CT2851643.SearchInNewTabIntervalMM", 1440);
Found : user_pref("CT2851643.SearchInNewTabLastCheckTime", "Fri Sep 07 2012 11:36:15 GMT-0300 (Hora oficial [...]
Found : user_pref("CT2851643.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Found : user_pref("CT2851643.SearchProtectorEnabled", false);
Found : user_pref("CT2851643.SearchProtectorToolbarDisabled", false);
Found : user_pref("CT2851643.SendProtectorDataViaLogin", true);
Found : user_pref("CT2851643.ServiceMapLastCheckTime", "Fri Sep 07 2012 11:36:16 GMT-0300 (Hora oficial do B[...]
Found : user_pref("CT2851643.SettingsLastCheckTime", "Fri Sep 07 2012 16:25:02 GMT-0300 (Hora oficial do Bra[...]
Found : user_pref("CT2851643.SettingsLastUpdate", "1346938891");
Found : user_pref("CT2851643.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2851643&SearchSource=13");
Found : user_pref("CT2851643.ThirdPartyComponentsInterval", 504);
Found : user_pref("CT2851643.ThirdPartyComponentsLastCheck", "Fri May 25 2012 13:34:50 GMT-0300 (Hora oficia[...]
Found : user_pref("CT2851643.ThirdPartyComponentsLastUpdate", "1331806008");
Found : user_pref("CT2851643.ToolbarShrinkedFromSetup", false);
Found : user_pref("CT2851643.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2851643");
Found : user_pref("CT2851643.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Found : user_pref("CT2851643.UserID", "UN96122472512042012");
Found : user_pref("CT2851643.ValidationData_Toolbar", 0);
Found : user_pref("CT2851643.WeatherNetwork", "");
Found : user_pref("CT2851643.WeatherPollDate", "Thu Jun 07 2012 10:37:55 GMT-0300 (Hora oficial do Brasil)")[...]
Found : user_pref("CT2851643.WeatherUnit", "C");
Found : user_pref("CT2851643.alertChannelId", "1243677");
Found : user_pref("CT2851643.autoDisableScopes", -1);
Found : user_pref("CT2851643.backendstorage.cbcountry_000", "4252");
Found : user_pref("CT2851643.backendstorage.cbfirsttime", "467269204D617920323520323031322031333A33353A30382[...]
Found : user_pref("CT2851643.backendstorage.pairingkey", "39414636364643463337433534323441393935373243333834[...]
Found : user_pref("CT2851643.backendstorage.scriptsource", "687474703A2F2F3132372E302E302E313A31303030302F67[...]
Found : user_pref("CT2851643.backendstorage.url_history0001", "6A6176617363726970743A3B3A3A3A636C69636B68616[...]
Found : user_pref("CT2851643.backendstorage.uttorrents", "7B226275696C64223A32373232302C226C6162656C223A5B5D[...]
Found : user_pref("CT2851643.components.1000234", false);
Found : user_pref("CT2851643.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Found : user_pref("CT2851643.globalFirstTimeInfoLastCheckTime", "Tue Jun 05 2012 07:12:00 GMT-0300 (Hora ofi[...]
Found : user_pref("CT2851643.homepageProtectorEnableByLogin", true);
Found : user_pref("CT2851643.initDone", true);
Found : user_pref("CT2851643.isAppTrackingManagerOn", true);
Found : user_pref("CT2851643.myStuffEnabled", true);
Found : user_pref("CT2851643.myStuffPublihserMinWidth", 400);
Found : user_pref("CT2851643.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Found : user_pref("CT2851643.myStuffServiceIntervalMM", 1440);
Found : user_pref("CT2851643.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Found : user_pref("CT2851643.navigateToUrlOnSearch", false);
Found : user_pref("CT2851643.oldAppsList", "129351530870587943,129351530870900444,1000234,129791406994403775[...]
Found : user_pref("CT2851643.revertSettingsEnabled", true);
Found : user_pref("CT2851643.searchProtectorDialogDelayInSec", 10);
Found : user_pref("CT2851643.searchProtectorEnableByLogin", true);
Found : user_pref("CT2851643.testingCtid", "");
Found : user_pref("CT2851643.toolbarAppMetaDataLastCheckTime", "Fri Sep 07 2012 11:36:20 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.toolbarContextMenuLastCheckTime", "Fri May 25 2012 13:35:03 GMT-0300 (Hora ofic[...]
Found : user_pref("CT2851643.usagesFlag", 2);
Found : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2851643/CT2851643[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2851643", [...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2851643",[...]
Found : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=pt", "\"5e9[...]
Found : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\WESLEY\\AppData\\Roaming\\Mozilla\\[...]
Found : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.13.0.6");
Found : user_pref("CommunityToolbar.ToolbarsList", "CT2851643");
Found : user_pref("CommunityToolbar.ToolbarsList2", "CT2851643");
Found : user_pref("CommunityToolbar.ToolbarsList4", "CT2851643");
Found : user_pref("CommunityToolbar.globalUserId", "d3076451-20dc-4783-8b1e-6a074f4d0c9f");
Found : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Found : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2851643");
Found : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Jun 03 2012 15:56:1[...]
Found : user_pref("CommunityToolbar.notifications.alertEnabled", false);
Found : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Found : user_pref("CommunityToolbar.notifications.locale", "en");
Found : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Found : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Fri Jun 08 2012 11:24:15 GMT-0300 (H[...]
Found : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Found : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Found : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Found : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Found : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Found : user_pref("CommunityToolbar.notifications.userId", "105f488d-ac4e-437a-9017-e97329675e57");
Found : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.google.com.br/");
Found : user_pref("CommunityToolbar.originalSearchEngine", "Google");
Found : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Found : user_pref("browser.search.defaultengine", "Ask.com");
Found : user_pref("extensions.BabylonToolbar.admin", false);
Found : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Found : user_pref("extensions.BabylonToolbar.babExt", "");
Found : user_pref("extensions.BabylonToolbar.babTrack", "affID=108380");
Found : user_pref("extensions.BabylonToolbar.bbDpng", 12);
Found : user_pref("extensions.BabylonToolbar.cntry", "BR");
Found : user_pref("extensions.BabylonToolbar.dfltSrch", false);
Found : user_pref("extensions.BabylonToolbar.excTlbr", false);
Found : user_pref("extensions.BabylonToolbar.firstRun", false);
Found : user_pref("extensions.BabylonToolbar.hdrMd5", "EF5B3401F11F5A8BAD0EDDF167BA6BC4");
Found : user_pref("extensions.BabylonToolbar.hmpg", false);
Found : user_pref("extensions.BabylonToolbar.id", "c60097a6000000000000001d7df5ece4");
Found : user_pref("extensions.BabylonToolbar.instlDay", "15325");
Found : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Found : user_pref("extensions.BabylonToolbar.lastActv", "31");
Found : user_pref("extensions.BabylonToolbar.lastDP", 12);
Found : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.171:22:01");
Found : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "9.0");
Found : user_pref("extensions.BabylonToolbar.newTab", true);
Found : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_bb");
Found : user_pref("extensions.BabylonToolbar.noFFXTlbr", false);
Found : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Found : user_pref("extensions.BabylonToolbar.propectorlck", 67645032);
Found : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Found : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Found : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Found : user_pref("extensions.BabylonToolbar.ptch_0717", true);
Found : user_pref("extensions.BabylonToolbar.smplGrp", "none");
Found : user_pref("extensions.BabylonToolbar.srcExt", "ss");
Found : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Found : user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17");
Found : user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.171:22:01");
Found : user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17");
Found : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Found : user_pref("extensions.BabylonToolbar_i.babExt", "");
Found : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=108380");
Found : user_pref("extensions.BabylonToolbar_i.hardId", "c60097a6000000000000001d7df5ece4");
Found : user_pref("extensions.BabylonToolbar_i.id", "c60097a6000000000000001d7df5ece4");
Found : user_pref("extensions.BabylonToolbar_i.instlDay", "15325");
Found : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Found : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Found : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Found : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Found : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Found : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
Found : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Found : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.171:22:01");
Found : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Found : user_pref("extensions.illimitux.ilx_pref_pt_veoh", true);
Found : user_pref("extensions.skipscreen.hostMatchStr", "hxxp://www.4shared.com/(get|audio|file|document|dir[...]
Profile name : default
File : C:\Users\Convidado\AppData\Roaming\Mozilla\Firefox\Profiles\r2lji0kw.default\prefs.js
Found : user_pref("browser.search.defaultengine", "Ask.com");
Found : user_pref("browser.search.defaultenginename", "Ask.com");
Found : user_pref("browser.search.order.1", "Ask.com");
Found : user_pref("extensions.asktb.ff-original-keyword-url", "");
Found : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ATU2&o=14670&locale=[...]
-\\ Opera v11.52.1100.0
File : C:\Users\Duaite\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
File : C:\Users\WESLEY\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
File : C:\Users\Convidado\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [25648 octets] - [17/09/2012 01:03:58]
########## EOF - C:\AdwCleaner[R1].txt - [25777 octets] ##########
2°
# AdwCleaner v1.801 - Logfile created 09/17/2012 at 01:04:44
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Ultimate (32 bits)
# User : WESLEY - PETROLEIRO
# Boot Mode : Normal
# Running from : C:\Users\WESLEY\Desktop\104139_adwcleaner_1_801.exe
# Option [Delete]
***** [Services] *****
Stopped & Deleted : Browser Manager
***** [Files / Folders] *****
Folder Deleted : C:\Users\Duaite\AppData\Local\APN
Folder Deleted : C:\Users\WESLEY\AppData\Local\Babylon
Folder Deleted : C:\Users\WESLEY\AppData\Local\Conduit
Folder Deleted : C:\Users\Duaite\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\Duaite\AppData\LocalLow\facemoods.com
Folder Deleted : C:\Users\WESLEY\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\WESLEY\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\WESLEY\AppData\LocalLow\facemoods.com
Folder Deleted : C:\Users\Convidado\AppData\LocalLow\AskToolbar
Folder Deleted : C:\Users\Convidado\AppData\LocalLow\BabylonToolbar
Folder Deleted : C:\Users\Convidado\AppData\LocalLow\facemoods.com
Folder Deleted : C:\Users\Duaite\AppData\Roaming\Babylon
Folder Deleted : C:\Users\WESLEY\AppData\Roaming\Babylon
Folder Deleted : C:\Users\WESLEY\AppData\Roaming\Mozilla\Firefox\Profiles\72hdgek9.default\ConduitCommon
Folder Deleted : C:\Users\WESLEY\AppData\Roaming\Mozilla\Firefox\Profiles\72hdgek9.default\CT2851643
Folder Deleted : C:\Users\WESLEY\AppData\Roaming\Mozilla\Firefox\Profiles\72hdgek9.default\extensions\{e0301295-ab3e-4af3-979f-3d453c5f9f48}
Folder Deleted : C:\Users\WESLEY\AppData\Roaming\Mozilla\Firefox\Profiles\72hdgek9.default\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\Babylon
Deleted on reboot : C:\ProgramData\Browser Manager
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DealPly
Folder Deleted : C:\Program Files\Conduit
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\fcmdSrch.xml
File Deleted : C:\user.js
***** [Registry] *****
[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2851643
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\BabylonToolbar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\DealPly
Key Deleted : HKCU\Software\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\BabylonToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\b
Key Deleted : HKLM\SOFTWARE\Classes\Babylon.dskBnd
Key Deleted : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1
Key Deleted : HKLM\SOFTWARE\Classes\bbylnApp.appCore
Key Deleted : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane
Key Deleted : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Key Deleted : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc
Key Deleted : HKLM\SOFTWARE\Classes\esrv.BabylonESrvc.1
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\DealPly
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\gaiilaahiahdejapggenmdmafpmbipje
Key Deleted : HKLM\SOFTWARE\Google\chrome\Extensions\ihflimipbcaljfnojhhknppphnnciiif
***** [Registre - GUID] *****
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{291BCCC1-6890-484A-89D3-318C928DAC1B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B8276A94-891D-453C-9FF3-715C042A2575}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FFB9ADCB-8C79-4C29-81D3-74D46A93D370}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{44C3C1DB-2127-433C-98EC-4C9412B5FC3A}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4D5132DD-BB2B-4249-B5E0-D145A8C982E1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{706D4A4B-184A-4434-B331-296B07493D2D}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8BE10F21-185F-4CA0-B789-9921674C3993}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{94C0B25D-3359-4B10-B227-F96A77DB773F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E393F82-2644-4AB6-B994-1AD39D6C59EE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B0B75FBA-7288-4FD3-A9EB-7EE27FA65599}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B173667F-8395-4317-8DD6-45AD1FE00047}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B32672B3-F656-46E0-B584-FE61C0BB6037}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2434722-5C85-4CA0-BA69-1B67E7AB3D68}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C2996524-2187-441F-A398-CD6CB6B3D020}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E047E227-5342-4D94-80F7-CFB154BF55BD}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F79BE9-24D4-4F4D-8C13-DF2C9899F82E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E77EEF95-3E83-4BB8-9C0D-4A5163774997}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{35C1605E-438B-4D64-AAB1-8885F097A9B1}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6E8BF012-2C85-4834-B10A-1B31AF173D70}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8375D9C8-634F-4ECB-8CF5-C7416BA5D542}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]
***** [Internet Browsers] *****
-\\ Internet Explorer v9.0.8112.16421
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=108293&tt=120912_cpc_3712_6&babsrc=NT_ss&mntrId=c60097a6000000000000001d7df5ece4 --> hxxp://www.google.com
-\\ Mozilla Firefox v15.0.1 (en-US)
Profile name : default
File : C:\Users\Duaite\AppData\Roaming\Mozilla\Firefox\Profiles\nuysoin6.default\prefs.js
[OK] File is clean.
Profile name : default
File : C:\Users\WESLEY\AppData\Roaming\Mozilla\Firefox\Profiles\72hdgek9.default\prefs.js
C:\Users\WESLEY\AppData\Roaming\Mozilla\Firefox\Profiles\72hdgek9.default\user.js ... Deleted !
Deleted : user_pref("CT2851643..clientLogIsEnabled", false);
Deleted : user_pref("CT2851643..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
Deleted : user_pref("CT2851643..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
Deleted : user_pref("CT2851643.ALLOW_SHOWING_HIDDEN_TOOLBAR", false);
Deleted : user_pref("CT2851643.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
Deleted : user_pref("CT2851643.AppTrackingLastCheckTime", "Thu Jun 07 2012 10:08:03 GMT-0300 (Hora oficial do [...]
Deleted : user_pref("CT2851643.CTID", "CT2851643");
Deleted : user_pref("CT2851643.CurrentServerDate", "7-9-2012");
Deleted : user_pref("CT2851643.DSInstall", false);
Deleted : user_pref("CT2851643.DialogsAlignMode", "LTR");
Deleted : user_pref("CT2851643.DialogsGetterLastCheckTime", "Fri Sep 07 2012 11:36:18 GMT-0300 (Hora oficial d[...]
Deleted : user_pref("CT2851643.DownloadReferralCookieData", "");
Deleted : user_pref("CT2851643.EMailNotifierPollDate", "Fri Jun 08 2012 13:09:37 GMT-0300 (Hora oficial do Bra[...]
Deleted : user_pref("CT2851643.FeedLastCount1733423638652034402", 496);
Deleted : user_pref("CT2851643.FeedPollDate2429156812186649977", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.FeedPollDate2429156813040823546", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.FeedPollDate2429156813130095866", "Fri Jun 08 2012 12:24:13 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.FeedPollDate2429156813224203613", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.FeedPollDate2429156813230837251", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.FeedPollDate2429156813454291735", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.FeedPollDate2429156813729834876", "Fri Jun 08 2012 12:24:13 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.FeedPollDate2429156813860870021", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.FeedPollDate2429156814264681793", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.FeedPollDate2429156814863075366", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.FeedPollDate2429156815257761081", "Fri Jun 08 2012 12:24:14 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.FeedTTL2429156813040823546", 15);
Deleted : user_pref("CT2851643.FeedTTL2429156813130095866", 10);
Deleted : user_pref("CT2851643.FeedTTL2429156813454291735", 5);
Deleted : user_pref("CT2851643.FeedTTL2429156814264681793", 5);
Deleted : user_pref("CT2851643.FirstServerDate", "25-5-2012");
Deleted : user_pref("CT2851643.FirstTime", true);
Deleted : user_pref("CT2851643.FirstTimeFF3", true);
Deleted : user_pref("CT2851643.FixPageNotFoundErrors", true);
Deleted : user_pref("CT2851643.GroupingServerCheckInterval", 1440);
Deleted : user_pref("CT2851643.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
Deleted : user_pref("CT2851643.HPInstall", false);
Deleted : user_pref("CT2851643.HasUserGlobalKeys", true);
Deleted : user_pref("CT2851643.HomePageProtectorEnabled", false);
Deleted : user_pref("CT2851643.HomepageBeforeUnload", "hxxp://www.google.com.br/");
Deleted : user_pref("CT2851643.Initialize", true);
Deleted : user_pref("CT2851643.InitializeCommonPrefs", true);
Deleted : user_pref("CT2851643.InstallationAndCookieDataSentCount", 3);
Deleted : user_pref("CT2851643.InstallationId", "fftA392.tmp.exe");
Deleted : user_pref("CT2851643.InstallationType", "XPE");
Deleted : user_pref("CT2851643.InstalledDate", "Fri May 25 2012 13:34:59 GMT-0300 (Hora oficial do Brasil)");
Deleted : user_pref("CT2851643.IsAlertDBUpdated", true);
Deleted : user_pref("CT2851643.IsGrouping", false);
Deleted : user_pref("CT2851643.IsInitSetupIni", true);
Deleted : user_pref("CT2851643.IsMulticommunity", false);
Deleted : user_pref("CT2851643.IsOpenThankYouPage", true);
Deleted : user_pref("CT2851643.IsOpenUninstallPage", false);
Deleted : user_pref("CT2851643.LanguagePackLastCheckTime", "Fri Sep 07 2012 11:36:18 GMT-0300 (Hora oficial do[...]
Deleted : user_pref("CT2851643.LanguagePackReloadIntervalMM", 1440);
Deleted : user_pref("CT2851643.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
Deleted : user_pref("CT2851643.LastLogin_3.12.0.8", "Fri May 25 2012 13:35:02 GMT-0300 (Hora oficial do Brasil[...]
Deleted : user_pref("CT2851643.LastLogin_3.12.2.3", "Sun Jun 03 2012 15:56:16 GMT-0300 (Hora oficial do Brasil[...]
Deleted : user_pref("CT2851643.LastLogin_3.13.0.6", "Tue Jul 17 2012 14:19:11 GMT-0300 (Hora oficial do Brasil[...]
Deleted : user_pref("CT2851643.LastLogin_3.14.1.0", "Wed Aug 29 2012 19:01:30 GMT-0300 (Hora oficial do Brasil[...]
Deleted : user_pref("CT2851643.LastLogin_3.15.1.0", "Fri Sep 07 2012 16:25:03 GMT-0300 (Hora oficial do Brasil[...]
Deleted : user_pref("CT2851643.LatestVersion", "3.14.1.0");
Deleted : user_pref("CT2851643.Locale", "pt");
Deleted : user_pref("CT2851643.MCDetectTooltipHeight", "83");
Deleted : user_pref("CT2851643.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
Deleted : user_pref("CT2851643.MCDetectTooltipWidth", "295");
Deleted : user_pref("CT2851643.MyStuffEnabledAtInstallation", true);
Deleted : user_pref("CT2851643.OriginalFirstVersion", "3.12.0.8");
Deleted : user_pref("CT2851643.SearchCaption", "uTorrentBar_PT Customized Web Search");
Deleted : user_pref("CT2851643.SearchEngineBeforeUnload", "Google");
Deleted : user_pref("CT2851643.SearchFromAddressBarIsInit", true);
Deleted : user_pref("CT2851643.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT285[...]
Deleted : user_pref("CT2851643.SearchInNewTabEnabled", true);
Deleted : user_pref("CT2851643.SearchInNewTabIntervalMM", 1440);
Deleted : user_pref("CT2851643.SearchInNewTabLastCheckTime", "Fri Sep 07 2012 11:36:15 GMT-0300 (Hora oficial [...]
Deleted : user_pref("CT2851643.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
Deleted : user_pref("CT2851643.SearchProtectorEnabled", false);
Deleted : user_pref("CT2851643.SearchProtectorToolbarDisabled", false);
Deleted : user_pref("CT2851643.SendProtectorDataViaLogin", true);
Deleted : user_pref("CT2851643.ServiceMapLastCheckTime", "Fri Sep 07 2012 11:36:16 GMT-0300 (Hora oficial do B[...]
Deleted : user_pref("CT2851643.SettingsLastCheckTime", "Fri Sep 07 2012 16:25:02 GMT-0300 (Hora oficial do Bra[...]
Deleted : user_pref("CT2851643.SettingsLastUpdate", "1346938891");
Deleted : user_pref("CT2851643.TBHomePageUrl", "hxxp://search.conduit.com/?ctid=CT2851643&SearchSource=13");
Deleted : user_pref("CT2851643.ThirdPartyComponentsInterval", 504);
Deleted : user_pref("CT2851643.ThirdPartyComponentsLastCheck", "Fri May 25 2012 13:34:50 GMT-0300 (Hora oficia[...]
Deleted : user_pref("CT2851643.ThirdPartyComponentsLastUpdate", "1331806008");
Deleted : user_pref("CT2851643.ToolbarShrinkedFromSetup", false);
Deleted : user_pref("CT2851643.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2851643");
Deleted : user_pref("CT2851643.TrustedApiDomains", "conduit.com,conduit-hosting.com,conduit-services.com,clien[...]
Deleted : user_pref("CT2851643.UserID", "UN96122472512042012");
Deleted : user_pref("CT2851643.ValidationData_Toolbar", 0);
Deleted : user_pref("CT2851643.WeatherNetwork", "");
Deleted : user_pref("CT2851643.WeatherPollDate", "Thu Jun 07 2012 10:37:55 GMT-0300 (Hora oficial do Brasil)")[...]
Deleted : user_pref("CT2851643.WeatherUnit", "C");
Deleted : user_pref("CT2851643.alertChannelId", "1243677");
Deleted : user_pref("CT2851643.autoDisableScopes", -1);
Deleted : user_pref("CT2851643.backendstorage.cbcountry_000", "4252");
Deleted : user_pref("CT2851643.backendstorage.cbfirsttime", "467269204D617920323520323031322031333A33353A30382[...]
Deleted : user_pref("CT2851643.backendstorage.pairingkey", "39414636364643463337433534323441393935373243333834[...]
Deleted : user_pref("CT2851643.backendstorage.scriptsource", "687474703A2F2F3132372E302E302E313A31303030302F67[...]
Deleted : user_pref("CT2851643.backendstorage.url_history0001", "6A6176617363726970743A3B3A3A3A636C69636B68616[...]
Deleted : user_pref("CT2851643.backendstorage.uttorrents", "7B226275696C64223A32373232302C226C6162656C223A5B5D[...]
Deleted : user_pref("CT2851643.components.1000234", false);
Deleted : user_pref("CT2851643.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.c[...]
Deleted : user_pref("CT2851643.globalFirstTimeInfoLastCheckTime", "Tue Jun 05 2012 07:12:00 GMT-0300 (Hora ofi[...]
Deleted : user_pref("CT2851643.homepageProtectorEnableByLogin", true);
Deleted : user_pref("CT2851643.initDone", true);
Deleted : user_pref("CT2851643.isAppTrackingManagerOn", true);
Deleted : user_pref("CT2851643.myStuffEnabled", true);
Deleted : user_pref("CT2851643.myStuffPublihserMinWidth", 400);
Deleted : user_pref("CT2851643.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
Deleted : user_pref("CT2851643.myStuffServiceIntervalMM", 1440);
Deleted : user_pref("CT2851643.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
Deleted : user_pref("CT2851643.navigateToUrlOnSearch", false);
Deleted : user_pref("CT2851643.oldAppsList", "129351530870587943,129351530870900444,1000234,129791406994403775[...]
Deleted : user_pref("CT2851643.revertSettingsEnabled", true);
Deleted : user_pref("CT2851643.searchProtectorDialogDelayInSec", 10);
Deleted : user_pref("CT2851643.searchProtectorEnableByLogin", true);
Deleted : user_pref("CT2851643.testingCtid", "");
Deleted : user_pref("CT2851643.toolbarAppMetaDataLastCheckTime", "Fri Sep 07 2012 11:36:20 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.toolbarContextMenuLastCheckTime", "Fri May 25 2012 13:35:03 GMT-0300 (Hora ofic[...]
Deleted : user_pref("CT2851643.usagesFlag", 2);
Deleted : user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2851643/CT2851643[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2851643", [...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=GottenApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=OtherApps&loc[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=SharedApps&lo[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://contextmenu.toolbar.conduit-services.com/?name=Toolbar&local[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2851643",[...]
Deleted : user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=pt", "\"5e9[...]
Deleted : user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\WESLEY\\AppData\\Roaming\\Mozilla\\[...]
Deleted : user_pref("CommunityToolbar.LatestToolbarVersionInstalled", "3.13.0.6");
Deleted : user_pref("CommunityToolbar.ToolbarsList", "CT2851643");
Deleted : user_pref("CommunityToolbar.ToolbarsList2", "CT2851643");
Deleted : user_pref("CommunityToolbar.ToolbarsList4", "CT2851643");
Deleted : user_pref("CommunityToolbar.globalUserId", "d3076451-20dc-4783-8b1e-6a074f4d0c9f");
Deleted : user_pref("CommunityToolbar.isAlertUrlAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.isClickActionAddedToFeedItemTable", true);
Deleted : user_pref("CommunityToolbar.keywordURLSelectedCTID", "CT2851643");
Deleted : user_pref("CommunityToolbar.notifications.alertDialogsGetterLastCheckTime", "Sun Jun 03 2012 15:56:1[...]
Deleted : user_pref("CommunityToolbar.notifications.alertEnabled", false);
Deleted : user_pref("CommunityToolbar.notifications.clientsServerUrl", "hxxp://alert.client.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.locale", "en");
Deleted : user_pref("CommunityToolbar.notifications.loginIntervalMin", 1440);
Deleted : user_pref("CommunityToolbar.notifications.loginLastCheckTime", "Fri Jun 08 2012 11:24:15 GMT-0300 (H[...]
Deleted : user_pref("CommunityToolbar.notifications.loginLastUpdateTime", "1313487611");
Deleted : user_pref("CommunityToolbar.notifications.messageShowTimeSec", 20);
Deleted : user_pref("CommunityToolbar.notifications.servicesServerUrl", "hxxp://alert.services.conduit.com");
Deleted : user_pref("CommunityToolbar.notifications.showTrayIcon", false);
Deleted : user_pref("CommunityToolbar.notifications.userCloseIntervalMin", 300);
Deleted : user_pref("CommunityToolbar.notifications.userId", "105f488d-ac4e-437a-9017-e97329675e57");
Deleted : user_pref("CommunityToolbar.originalHomepage", "hxxp://www.google.com.br/");
Deleted : user_pref("CommunityToolbar.originalSearchEngine", "Google");
Deleted : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Deleted : user_pref("extensions.BabylonToolbar.admin", false);
Deleted : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Deleted : user_pref("extensions.BabylonToolbar.babExt", "");
Deleted : user_pref("extensions.BabylonToolbar.babTrack", "affID=108380");
Deleted : user_pref("extensions.BabylonToolbar.bbDpng", 12);
Deleted : user_pref("extensions.BabylonToolbar.cntry", "BR");
Deleted : user_pref("extensions.BabylonToolbar.dfltSrch", false);
Deleted : user_pref("extensions.BabylonToolbar.excTlbr", false);
Deleted : user_pref("extensions.BabylonToolbar.firstRun", false);
Deleted : user_pref("extensions.BabylonToolbar.hdrMd5", "EF5B3401F11F5A8BAD0EDDF167BA6BC4");
Deleted : user_pref("extensions.BabylonToolbar.hmpg", false);
Deleted : user_pref("extensions.BabylonToolbar.id", "c60097a6000000000000001d7df5ece4");
Deleted : user_pref("extensions.BabylonToolbar.instlDay", "15325");
Deleted : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Deleted : user_pref("extensions.BabylonToolbar.lastActv", "31");
Deleted : user_pref("extensions.BabylonToolbar.lastDP", 12);
Deleted : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.5.3.171:22:01");
Deleted : user_pref("extensions.BabylonToolbar.mntrFFxVrsn", "9.0");
Deleted : user_pref("extensions.BabylonToolbar.newTab", true);
Deleted : user_pref("extensions.BabylonToolbar.newTabUrl", "hxxp://search.babylon.com/?babsrc=NT_bb");
Deleted : user_pref("extensions.BabylonToolbar.noFFXTlbr", false);
Deleted : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Deleted : user_pref("extensions.BabylonToolbar.propectorlck", 67645032);
Deleted : user_pref("extensions.BabylonToolbar.prtkDS", 0);
Deleted : user_pref("extensions.BabylonToolbar.prtkHmpg", 0);
Deleted : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Deleted : user_pref("extensions.BabylonToolbar.ptch_0717", true);
Deleted : user_pref("extensions.BabylonToolbar.smplGrp", "none");
Deleted : user_pref("extensions.BabylonToolbar.srcExt", "ss");
Deleted : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Deleted : user_pref("extensions.BabylonToolbar.vrsn", "1.5.3.17");
Deleted : user_pref("extensions.BabylonToolbar.vrsnTs", "1.5.3.171:22:01");
Deleted : user_pref("extensions.BabylonToolbar.vrsni", "1.5.3.17");
Deleted : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Deleted : user_pref("extensions.BabylonToolbar_i.babExt", "");
Deleted : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=108380");
Deleted : user_pref("extensions.BabylonToolbar_i.hardId", "c60097a6000000000000001d7df5ece4");
Deleted : user_pref("extensions.BabylonToolbar_i.id", "c60097a6000000000000001d7df5ece4");
Deleted : user_pref("extensions.BabylonToolbar_i.instlDay", "15325");
Deleted : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Deleted : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Deleted : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Deleted : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Deleted : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Deleted : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
Deleted : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Deleted : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.171:22:01");
Deleted : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Deleted : user_pref("extensions.illimitux.ilx_pref_pt_veoh", true);
Deleted : user_pref("extensions.skipscreen.hostMatchStr", "hxxp://www.4shared.com/(get|audio|file|document|dir[...]
Profile name : default
File : C:\Users\Convidado\AppData\Roaming\Mozilla\Firefox\Profiles\r2lji0kw.default\prefs.js
C:\Users\Convidado\AppData\Roaming\Mozilla\Firefox\Profiles\r2lji0kw.default\user.js ... Deleted !
Deleted : user_pref("browser.search.defaultengine", "Ask.com");
Deleted : user_pref("browser.search.defaultenginename", "Ask.com");
Deleted : user_pref("browser.search.order.1", "Ask.com");
Deleted : user_pref("extensions.asktb.ff-original-keyword-url", "");
Deleted : user_pref("keyword.URL", "hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=ATU2&o=14670&locale=[...]
-\\ Opera v11.52.1100.0
File : C:\Users\Duaite\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
File : C:\Users\WESLEY\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
File : C:\Users\Convidado\AppData\Roaming\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[R1].txt - [25779 octets] - [17/09/2012 01:03:58]
AdwCleaner[S1].txt - [26576 octets] - [17/09/2012 01:04:44]
########## EOF - C:\AdwCleaner[S1].txt - [26705 octets] ##########
+ o log do hijack
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 01:35:24, on 17/09/2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\Explorer.EXE
C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe
C:\Windows\RTHDCPL.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\PSafe\PSafeSysTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Users\WESLEY\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
C:\Windows\System32\StikyNot.exe
C:\Program Files\PSafe\Protege\psprotege.exe
C:\Program Files\PSafe\PSafeWDS.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Users\WESLEY\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [D-Link D-Link DWA-125] C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
O4 - HKLM\..\Run: [WZCSLDR2] C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [PSafeSysTray] "C:\Program Files\PSafe\PSafeSysTray.exe"
O4 - HKLM\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Octoshape Streaming Services] "C:\Users\WESLEY\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" -inv:bootrun
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Baixar Link Utiizando Gerenciador Mega... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {44EFE656-BA6F-401B-8474-1473CF3883E5} (Active_Clock Control) - file:///C:/Users/Duaite/AppData/Local/Microsoft/Windows%20Sidebar/Gadgets/activexclock.gadget/Clock.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: c:\PROGRA~2\BROWSE~1\22643~1.41\{16CDF~1\browsemngr.dll
O23 - Service: avast! antivírus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Context Manager Process Extension (cmpe) - LightComm - C:\Windows\system32\cmpe.exe
O23 - Service: D_Link_DWA-125 Service (D_Link_DWA-125) - Wireless Service - C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe
O23 - Service: D_Link_DWA-125_WPS Service (D_Link_DWA-125_WPS) - Unknown owner - C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Google Software Updater (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NitroPDFDriverCreatorReadSpool (NitroDriverReadSpool) - Nitro PDF Software - C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
O23 - Service: NLS Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\system32\NLSSRV32.EXE
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: PSafeLockBoxSvc - PSafe - C:\Program Files\PSafe\PSafeCategoryFinder.exe
O23 - Service: PSafeSVC - PSafe S/A - C:\Program Files\PSafe\PSafesvc.exe
O23 - Service: PSafeWD - PSafe - C:\Program Files\PSafe\PSafeWD.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 8222 bytes