cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão:27-01-2016
Executado por Debora (administrador) em NOTE (02-02-2016 10:11:22)
Executando a partir de C:\Users\Debora\Downloads
Perfis Carregados: Debora (Perfis Disponíveis: Debora)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Idioma: Português (Brasil)
Internet Explorer Versão 11 (Navegador padrão: Chrome)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\gbpsv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
() C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe
(Banco Bradesco S.A.) C:\Program Files (x86)\Scpad\scpVista.exe
() C:\Program Files\shopperz250120161400\Lojtiuf.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
() C:\Program Files (x86)\WeatherTool\2.0.0.11150\WeatherService.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
() C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE\hnsgEEA4.tmp
() C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE\jnsgBC5C.tmp
() C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE\knseAE56.tmp
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\gbpsv.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(ShenZhen Enode Techology co,.Ltd) C:\Program Files (x86)\WeatherTool\2.0.0.11150\weather.exe
(Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe
() C:\Program Files\Andy\HandyAndy.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
() C:\Program Files (x86)\CalendarTool\2.0.0.11189\CalendarServ.exe
() C:\Program Files (x86)\CalendarTool\2.0.0.11189\calendar.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files (x86)\Pokemon Showdown\pokemonshowdown.exe
() C:\Program Files (x86)\Pokemon Showdown\pokemonshowdown.exe
() C:\Program Files (x86)\Pokemon Showdown\pokemonshowdown.exe
() C:\Program Files (x86)\Pokemon Showdown\pokemonshowdown.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registro (Whitelisted) ===========================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM-x32\...\Run: [fst_br_103] => [X]
HKLM-x32\...\Run: [gmsd_br_005010218] => [X]
HKLM-x32\...\Run: [rec_en_77] => [X]
HKLM-x32\...\Run: [LightGate] => c:\programdata\lightgate.exe [1081344 2015-12-04] ()
HKLM-x32\...\Run: [HomePageHelper] => c:\programdata\homepage.exe [1100288 2015-11-25] ()
HKLM\...\Winlogon: [Userinit] wscript C:\windows\run.vbs,
Winlogon\Notify\ GbPluginBb: C:\Program Files (x86)\GbPlugin\gbieh.dll [2015-06-02] (Banco do Brasil)
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\Run: [msiql] => c:\programdata\msiql.exe [2415616 2016-01-26] ()
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\Run: [taskhost] => rundll32.exe C:\ProgramData\WindowsMsg\A3FB110AD80824E309242083833A556D.dll Start /DEFAULT
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {1f87cb15-fb97-11e1-a001-e81132b3beff} - F:\AutoRun.exe
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {752b0a4a-0115-11e2-8032-e81132b3beff} - F:\AutoRun.exe
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {99949252-5221-11e3-8eb5-e81132b3befe} - F:\iLinker.exe
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {a0fdee8b-8187-11e5-8899-ec0747cc5307} - F:\LGAutoRun.exe
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {bb1fa51a-6502-11e3-bb98-e81132b3befe} - F:\AutoRun.exe
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {c6e67129-043c-11e2-b313-e81132b3beff} - F:\AutoRun.exe
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {e6c95d5d-f2ee-11e1-8377-e81132b3beff} - F:\AutoRun.exe
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {e6c95d6f-f2ee-11e1-8377-e81132b3beff} - F:\AutoRun.exe
SSODL-x32: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Program Files (x86)\Scpad\scpLIB.dll (Banco Bradesco S.A.)
ShellExecuteHooks-x32: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399F83} - C:\Program Files (x86)\GbPlugin\gbieh.dll [1889664 2015-06-02] (Banco do Brasil)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HandyAndy.lnk [2016-02-01]
ShortcutTarget: HandyAndy.lnk -> C:\Program Files\Andy\HandyAndy.exe ()
GroupPolicy: Restrição - Chrome <======= ATENÇÃO
CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Winsock: Catalog9 01 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-07-16] (Lavasoft Limited)
Winsock: Catalog9 02 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-07-16] (Lavasoft Limited)
Winsock: Catalog9 03 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-07-16] (Lavasoft Limited)
Winsock: Catalog9 04 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-07-16] (Lavasoft Limited)
Winsock: Catalog9 16 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-07-16] (Lavasoft Limited)
Winsock: Catalog9-x64 01 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-07-16] (Lavasoft Limited)
Winsock: Catalog9-x64 02 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-07-16] (Lavasoft Limited)
Winsock: Catalog9-x64 03 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-07-16] (Lavasoft Limited)
Winsock: Catalog9-x64 04 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-07-16] (Lavasoft Limited)
Winsock: Catalog9-x64 16 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-07-16] (Lavasoft Limited)
Hosts: Há mais de uma entrada no Hosts. Veja a seção Hosts do Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0E31F570-49BA-458B-8B67-3FE5BA5956FE}: [NameServer] 104.197.191.4
Tcpip\..\Interfaces\{11F35C2B-E42D-4760-A225-FBCE01DB4C16}: [NameServer] 104.197.191.4
Tcpip\..\Interfaces\{88718CEF-5AB4-46F3-9A02-95FAFD8B0C2E}: [NameServer] 104.197.191.4
Tcpip\..\Interfaces\{88718CEF-5AB4-46F3-9A02-95FAFD8B0C2E}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{9D09A85F-1509-4F37-A874-EDB6C9B012E6}: [NameServer] 104.197.191.4
Tcpip\..\Interfaces\{9D09A85F-1509-4F37-A874-EDB6C9B012E6}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{C3252508-083B-4F2A-9886-2811F7C337A0}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{CE9730F3-8B59-4AF3-8AF6-E630EF3B1343}: [NameServer] 104.197.191.4
Tcpip\..\Interfaces\{CE9730F3-8B59-4AF3-8AF6-E630EF3B1343}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{EAA8FFB4-4D28-46A4-8E61-6A7AD5C854B8}: [NameServer] 104.197.191.4

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yeabests.cc/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://br.hao123.com/?tn=sdkc_inner_hp_09_hao123_br&guid=9bb8524a0f0e37e9c8bb638a4232a319
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.oursurfing.com/web/?type=ds&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.oursurfing.com/web/?type=ds&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.oursurfing.com/?type=hp&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.oursurfing.com/?type=hp&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.oursurfing.com/web/?type=ds&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.oursurfing.com/web/?type=ds&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&q={searchTerms}
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yeabests.cc/
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=pt-BR&Src=MSE&Tid=000328B0&OHP=http%3A%2F%2Fsecurityresponse.symantec.com%2Favcenter%2Ffix%5Fhomepage&OSP=
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=pt-BR&Src=MSE&Tid=000328B0&OHP=http%3A%2F%2Fsecurityresponse.symantec.com%2Favcenter%2Ffix%5Fhomepage&OSP=
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=pt-BR&Src=MSE&Tid=000328B0&OHP=http%3A%2F%2Fsecurityresponse.symantec.com%2Favcenter%2Ffix%5Fhomepage&OSP=
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.oursurfing.com/web/?type=ds&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&q={searchTerms}
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://br.hao123.com/?tn=sdkc_inner_hp_09_hao123_br&guid=9bb8524a0f0e37e9c8bb638a4232a319
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.oursurfing.com/?type=hp&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\Software\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = hxxp://www.uol.com.br/
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.uol.com.br/
HKU\S-1-5-21-1277356225-661962986-2381428972-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.oursurfing.com/web/?type=ds&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&q={searchTerms}
URLSearchHook: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 - (Sem Nome) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - Nenhum Arquivo
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://search.iminent.com/?appId=5B68F911-736F-438C-8C2A-BDEE3786955F&ref=toolbox&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> BrowserMngrDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> OldSearch URL = hxxp://search.iminent.com/?appId=5B68F911-736F-438C-8C2A-BDEE3786955F&ref=toolbox&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {067979B1-B39A-4F38-9C6C-A24593C68313} URL = hxxp://www-searching.com/s.ashx?prd=opensearch&q={searchTerms}&s=G1Pzamobl3687,2a0eb4ba-1ccf-42be-a0ce-e7e8876b0f3a,
SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {1D39438F-4F38-48CB-854C-DEC182501A90} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=dig2&utm_campaign=install_ie&utm_content=ds&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&ts=1437773072&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=dig2&utm_campaign=install_ie&utm_content=ds&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&ts=1437773072&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=dig2&utm_campaign=install_ie&utm_content=ds&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&ts=1437773072&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {CC4D9256-79D7-4AAD-8BA9-D4404AE6AD4C} URL = hxxps://br.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {D4844172-3788-437D-89BB-D0AB5878F692} URL = hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=dig2&utm_campaign=install_ie&utm_content=ds&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&ts=1437773072&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {EFB990D6-7230-4E5A-8AF9-BD735F43537C} URL = hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=dig2&utm_campaign=install_ie&utm_content=ds&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&ts=1437773072&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {F2DABDCB-51CF-4411-86C8-840CA916D944} URL = hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=dig2&utm_campaign=install_ie&utm_content=ds&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&ts=1437773072&type=default&q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2015-12-22] (Oracle Corporation)
BHO: shopperz250120161400 -> {9DAD5043-33E9-4077-b42F-325EDE8A98B0} -> C:\Program Files\shopperz250120161400\Yfambyg64.dll [2016-01-25] ()
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-12-22] (Oracle Corporation)
BHO-x32: ssh2 Class -> {2E3C3651-B19C-4DD9-A979-901EC3E930AF} -> C:\Program Files (x86)\Scpad\scpsssh2.dll [2013-12-25] (Banco Bradesco S.A.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-22] (Oracle Corporation)
BHO-x32: shopperz250120161400 -> {9DAD5043-33E9-4077-b42F-325EDE8A98B0} -> C:\Program Files\shopperz250120161400\Yfambyg.dll [2016-01-25] ()
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540000} -> C:\Program Files (x86)\GbPlugin\gbieh.dll [2015-06-02] (Banco do Brasil)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-22] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> Sem Nome - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Nenhum Arquivo
Toolbar: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> Sem Nome - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Nenhum Arquivo
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - Nenhum Arquivo
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - Nenhum Arquivo
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)

FireFox:
========
FF ProfilePath: C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: yoursearching
FF Homepage: hxxp://br.hao123.com/?tn=sdkc_inner_hp_09_hao123_br&guid=9bb8524a0f0e37e9c8bb638a4232a319
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll [2016-01-21] ()
FF Plugin: @java.com/DTPlugin,version=10.76.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-12-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.76.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2015-12-22] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [Nenhum Arquivo]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> c:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-21] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Nenhum Arquivo]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> c:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=6.0.12.450 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll [2010-02-15] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll [2010-02-15] (RealNetworks, Inc.)
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [Nenhum Arquivo]
FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [Nenhum Arquivo]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\8\NP_wtapp.dll [2015-03-26] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1277356225-661962986-2381428972-1000: gastecnologia.com.br/sf/bb -> C:\Users\Debora\AppData\Local\GAS Tecnologia\GBBD\npsf_bb.dll [Nenhum Arquivo]
FF Plugin HKU\S-1-5-21-1277356225-661962986-2381428972-1000: gastecnologia.com.br/sf/cef64 -> C:\Users\Debora\AppData\Local\GAS Tecnologia\GBBD\npsf_cef_64.dll [Nenhum Arquivo]
FF SearchPlugin: C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\searchplugins\bing-.xml [2015-11-07]
FF SearchPlugin: C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\searchplugins\smod.xml [2016-01-25]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\SearchTheWeb.xml [2015-07-14]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yoursearching.xml [2016-01-27]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yoursites123.xml [2016-01-14]
FF Extension: AdPunisher - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\extensions\yaifwhyaihueeot@qnqbyzgxjqwjzyex.net [2015-09-03] [não assinado]
FF Extension: leethax.net extension - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\extensions\leethax@leethax.net.xpi [2015-11-18]
FF Extension: Default NewTab - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\extensions\default_newtabff@gmail.com [2016-01-14] [não assinado]
FF Extension: Bing Search - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\Extensions\bingsearch.full@microsoft.com [2015-10-23] [não assinado]
FF Extension: FFun2Saave - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\Extensions\L@f7n2S.org [2015-09-03] [não assinado]
FF Extension: Treasure Track - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\Extensions\{c713862d-0a3d-46bf-8460-d755ea4018a1}.xpi [2015-09-23] [não assinado]
FF Extension: New Tab by Yahoo - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\jid1-G80Ec8LLEbK5fQ@jetpack.xpi [2015-11-23] [não assinado]
FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06]
FF HKLM\...\Firefox\Extensions: [{3E4CD423-A6A2-4D6B-aBDD-0BEF52C389FF}] - C:\Program Files\shopperz250120161351\Firefox\{3E4CD423-A6A2-4D6B-aBDD-0BEF52C389FF}.xpi => não encontrado (a)
FF HKLM\...\Firefox\Extensions: [{9DAD5043-33E9-4077-b42F-325EDE8A98B0}] - C:\Program Files\shopperz250120161400\Firefox\{9DAD5043-33E9-4077-b42F-325EDE8A98B0}.xpi
FF Extension: shopperz250120161400 - C:\Program Files\shopperz250120161400\Firefox\{9DAD5043-33E9-4077-b42F-325EDE8A98B0}.xpi [2016-01-25] [não assinado]
FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\extensions\defsearchp@gmail.com => não encontrado (a)
FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\extensions\deskCutv2@gmail.com => não encontrado (a)
FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\extensions\default_newtabff@gmail.com
FF HKLM-x32\...\Firefox\Extensions: [{3E4CD423-A6A2-4D6B-aBDD-0BEF52C389FF}] - C:\Program Files\shopperz250120161351\Firefox\{3E4CD423-A6A2-4D6B-aBDD-0BEF52C389FF}.xpi => não encontrado (a)
FF HKLM-x32\...\Firefox\Extensions: [{9DAD5043-33E9-4077-b42F-325EDE8A98B0}] - C:\Program Files\shopperz250120161400\Firefox\{9DAD5043-33E9-4077-b42F-325EDE8A98B0}.xpi
FF HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\Firefox\Extensions: [addlyrics@addlyrics.net] - C:\Program Files (x86)\AddLyrics\FF => não encontrado (a)

Chrome:
=======
CHR HomePage: Profile 1 -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=pt-br
CHR StartupUrls: Profile 1 -> "hxxps://www.google.com.br/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8"
CHR Profile: C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-08]
CHR Extension: (YouTube) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-08]
CHR Extension: (Google Search) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-08]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-08]
CHR Extension: (Gmail) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-08]
CHR Profile: C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Drive) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-08]
CHR Extension: (YouTube) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-08]
CHR Extension: (Google Search) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-08]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-08]
CHR Extension: (Gmail) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-08]
CHR HKU\S-1-5-21-1277356225-661962986-2381428972-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1277356225-661962986-2381428972-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [jlcgehabolcakkjhgmgpkagpolbjlhfa] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eedgghdcpmmmilkmfpnklknlenbiolec] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08]

==================== Serviços (Whitelisted) ========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation)
S3 DA0A3FB4-A71F-4CC3-8152-36F557717930; C:\Program Files\shopperz250120161400\Dodgylu.exe [294256 2016-01-25] ()
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [347200 2015-03-26] (WildTangent)
R2 GbpSv; C:\Program Files (x86)\GbPlugin\gbpsv.exe [579896 2015-04-29] (GAS Tecnologia)
S2 GoogleChromeUpService; C:\ProgramData\service.exe [1734656 2016-01-11] () [Arquivo não assinado]
S2 GoogleChromeUpSvc; C:\ProgramData\Windows Update\svrupg.exe [2786816 2016-01-27] (TODO: ) [Arquivo não assinado]
S2 KMService; C:\windows\SysWOW64\srvany.exe [8192 2014-03-13] () [Arquivo não assinado]
S3 MatSvc; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [343856 2011-06-13] (Microsoft Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
S3 npggsvc; C:\windows\SysWOW64\GameMon.des [3473120 2015-08-10] (INCA Internet Co., Ltd.)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [Arquivo não assinado]
R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [Arquivo não assinado]
R2 scpVista; C:\Program Files (x86)\Scpad\scpVista.exe [360640 2013-12-24] (Banco Bradesco S.A.) [Arquivo não assinado]
R2 shopperz250120161400 Updater; C:\Program Files\shopperz250120161400\Lojtiuf.exe [159088 2016-01-25] ()
S2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.)
R2 TheCalendarService; C:\Program Files (x86)\CalendarTool\2.0.0.11189\CalendarServ.exe [141960 2015-12-25] ()
R2 TheDesktopWeatherService; C:\Program Files (x86)\WeatherTool\2.0.0.11150\WeatherService.exe [153552 2015-12-09] ()
S2 WdMan; C:\ProgramData\nWdMn\WdMan.exe [326656 2016-01-07] (TU-Funs LIMITED) [Arquivo não assinado]
R2 wucotusy; C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE\hnsgEEA4.tmp [416256 2016-01-25] () [Arquivo não assinado]
R2 zutuzuni; C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE\jnsgBC5C.tmp [307712 2016-01-25] () [Arquivo não assinado]
R2 zyzojupyzbt; C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE\knseAE56.tmp [186368 2016-02-01] () [Arquivo não assinado]

===================== Drivers (Whitelisted) ==========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R3 athr; C:\Windows\System32\DRIVERS\athrx.sys [2797056 2011-12-13] (Atheros Communications, Inc.) [Arquivo não assinado]
R1 cherimoya; C:\Windows\System32\drivers\cherimoya.sys [61336 2016-01-25] (Cherimoya Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 GBPRCM; C:\Program Files (x86)\GbPlugin\gbprcm64.sys [21720 2015-04-29] (GAS Tecnologia)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-07-06] (Windows (R) 2003 DDK 3790 provider)
S3 sdfhgdf; C:\Windows\System32\DRIVERS\sdfhgdf.sys [23208 2016-01-25] (Corporation) [Arquivo não assinado]
R2 SGDrv; C:\Windows\System32\DRIVERS\SGdrv64.sys [7680 2011-04-11] (Phoenix Technologies Ltd.)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [75512 2015-11-05] (VMware, Inc.)
R3 Warsaw_PP; C:\Program Files (x86)\GbPlugin\wsftprp64.sys [24792 2014-10-31] (GAS Tecnologia LTDA)
R1 {2381c708-437b-40af-a3fc-1f3bd1d5172d}Gw64; C:\Windows\System32\drivers\{2381c708-437b-40af-a3fc-1f3bd1d5172d}Gw64.sys [48784 2015-07-24] (StdLib)
R1 {7012eec1-4f37-42d4-a2cd-26727494d248}Gw64; C:\Windows\System32\drivers\{7012eec1-4f37-42d4-a2cd-26727494d248}Gw64.sys [48792 2014-10-13] (StdLib)
R1 {a6762132-8e80-4305-b1ba-2bec91757ac2}Gw64; C:\Windows\System32\drivers\{a6762132-8e80-4305-b1ba-2bec91757ac2}Gw64.sys [48792 2014-10-22] (StdLib)
R1 {e9bebce7-deb3-4ab9-896c-549739f208c5}Gw64; C:\Windows\System32\drivers\{e9bebce7-deb3-4ab9-896c-549739f208c5}Gw64.sys [48792 2014-10-06] (StdLib)
S3 AthBTPort; system32\DRIVERS\btath_flt.sys [X]
S1 bbbqxuzx; \??\C:\windows\system32\drivers\bbbqxuzx.sys [X]
S3 BTATH_A2DP; system32\drivers\btath_a2dp.sys [X]
S3 btath_avdt; system32\drivers\btath_avdt.sys [X]
S3 BTATH_BUS; system32\DRIVERS\btath_bus.sys [X]
S3 BTATH_HCRP; system32\DRIVERS\btath_hcrp.sys [X]
S3 BTATH_LWFLT; system32\DRIVERS\btath_lwflt.sys [X]
S3 BTATH_RCP; system32\DRIVERS\btath_rcp.sys [X]
S1 gbpddfac; system32\drivers\gbpddfac64.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S1 iSafeNetFilter; system32\drivers\iSafeNetFilter.sys [X]
S1 kkxkgham; \??\C:\windows\system32\drivers\kkxkgham.sys [X]
S3 SBIOSIO; \??\C:\Users\Debora\AppData\Local\Temp\__Samsung_Update\SBIOSIO64.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um Mês Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-02-02 10:11 - 2016-02-02 10:11 - 00042733 _____ C:\Users\Debora\Downloads\Shortcut.txt
2016-02-02 10:08 - 2016-02-02 10:11 - 00060577 _____ C:\Users\Debora\Downloads\Addition.txt
2016-02-02 10:05 - 2016-02-02 10:11 - 00037328 _____ C:\Users\Debora\Downloads\FRST.txt
2016-02-02 10:05 - 2016-02-02 10:11 - 00000000 ____D C:\FRST
2016-02-02 10:04 - 2016-02-02 10:04 - 02370560 _____ (Farbar) C:\Users\Debora\Downloads\FRST64.exe
2016-02-02 10:02 - 2016-02-02 10:03 - 00001684 _____ C:\Users\Debora\Desktop\Rkill.txt
2016-02-02 09:24 - 2016-02-02 09:24 - 00000000 ____D C:\Users\Debora\Documents\My Games
2016-02-02 09:24 - 2016-02-02 09:24 - 00000000 ____D C:\Users\Debora\AppData\Local\Pokemon Showdown
2016-02-02 09:18 - 2016-02-02 09:18 - 00002020 _____ C:\Users\Debora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokemon Showdown.lnk
2016-02-02 09:17 - 2016-02-02 09:24 - 00000000 ____D C:\Program Files (x86)\Pokemon Showdown
2016-02-02 09:14 - 2016-02-02 09:17 - 35241294 _____ C:\Users\Debora\Downloads\PokemonShowdownSetup.exe
2016-02-02 09:10 - 2016-02-02 09:10 - 00000000 ____D C:\Program Files (x86)\CalendarTool
2016-02-01 12:48 - 2016-02-01 12:48 - 00000000 ____D C:\Users\Debora\Downloads\Mod e jogo
2016-02-01 12:45 - 2016-01-31 12:33 - 102142456 ____N C:\Users\Debora\Downloads\Mod e jogo.zip
2016-02-01 12:30 - 2016-02-01 12:30 - 00000000 ____D C:\Users\Debora\.android
2016-02-01 12:29 - 2016-02-01 12:30 - 00000000 ____D C:\Users\Debora\AppData\Roaming\VMware
2016-02-01 12:27 - 2016-02-01 12:27 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Andy
2016-02-01 12:26 - 2016-02-01 12:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Andy
2016-02-01 12:25 - 2015-11-25 18:10 - 00934080 _____ (VMware, Inc.) C:\windows\system32\vnetlib64.dll
2016-02-01 12:25 - 2015-11-25 18:10 - 00392896 _____ (VMware, Inc.) C:\windows\SysWOW64\vmnat.exe
2016-02-01 12:25 - 2015-11-25 18:10 - 00358080 _____ (VMware, Inc.) C:\windows\SysWOW64\vmnetdhcp.exe
2016-02-01 12:25 - 2015-11-25 17:52 - 00026816 _____ (VMware, Inc.) C:\windows\system32\Drivers\vmnetuserif.sys
2016-02-01 12:25 - 2015-11-06 11:57 - 00057536 _____ (VMware, Inc.) C:\windows\system32\Drivers\hcmon.sys
2016-02-01 12:24 - 2016-02-01 12:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
2016-02-01 12:24 - 2016-02-01 12:24 - 00000000 ____D C:\Program Files\Common Files\VMware
2016-02-01 12:24 - 2015-11-25 18:10 - 00066752 _____ (VMware, Inc.) C:\windows\system32\Drivers\vmx86.sys
2016-02-01 12:24 - 2015-11-25 18:10 - 00033472 _____ (VMware, Inc.) C:\windows\system32\Drivers\VMkbd.sys
2016-02-01 12:24 - 2015-11-05 19:25 - 00075512 _____ (VMware, Inc.) C:\windows\system32\Drivers\vsock.sys
2016-02-01 12:24 - 2015-11-05 19:25 - 00068288 _____ (VMware, Inc.) C:\windows\system32\vsocklib.dll
2016-02-01 12:24 - 2015-11-05 19:25 - 00064192 _____ (VMware, Inc.) C:\windows\SysWOW64\vsocklib.dll
2016-02-01 12:23 - 2016-02-02 09:05 - 00000000 ____D C:\ProgramData\VMware
2016-02-01 12:18 - 2016-02-01 12:30 - 00000000 ____D C:\Users\Debora\Andy
2016-02-01 12:18 - 2016-02-01 12:21 - 00000000 ____D C:\Program Files\Andy
2016-02-01 12:18 - 2016-02-01 12:18 - 00000000 ____D C:\Program Files (x86)\VMware
2016-02-01 12:14 - 2016-02-01 12:18 - 00000000 ____D C:\Program Files\AndyOfflineInstaller46.2
2016-02-01 11:11 - 2016-02-01 12:06 - 434769152 _____ C:\Users\Debora\Downloads\Andy_v46.2_53_x64.exe
2016-01-29 10:53 - 2016-01-29 10:53 - 00000008 _____ C:\END
2016-01-27 10:11 - 2016-01-27 10:11 - 00000000 ____D C:\Users\Public\Documents\Tools
2016-01-27 10:03 - 2016-01-27 10:03 - 00000000 ____D C:\windows\system32\log
2016-01-27 09:54 - 2016-01-27 09:54 - 01736192 _____ C:\ProgramData\upgsvr.exe
2016-01-27 09:54 - 2016-01-27 09:54 - 00621568 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Debora\AppData\Roaming\libeay32.dll
2016-01-27 09:54 - 2016-01-27 09:54 - 00162304 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Debora\AppData\Roaming\ssleay32.dll
2016-01-27 09:54 - 2016-01-27 09:54 - 00000000 ____D C:\Users\Debora\AppData\Roaming\LightGate
2016-01-27 09:54 - 2015-12-10 08:39 - 01015808 _____ (d) C:\Users\Debora\AppData\Roaming\download.exe
2016-01-27 09:54 - 2015-12-04 13:14 - 01081344 _____ C:\Users\Debora\AppData\Roaming\LightGate.exe
2016-01-27 09:53 - 2016-02-02 09:07 - 00000000 ____D C:\ProgramData\WindowsMsg
2016-01-27 09:53 - 2016-02-02 09:07 - 00000000 ____D C:\Program Files (x86)\osTip
2016-01-27 09:53 - 2016-02-01 11:03 - 00000000 ____D C:\Users\Debora\AppData\Roaming\CalendarTool
2016-01-27 09:53 - 2016-01-27 10:36 - 00000000 ____D C:\Users\Debora\AppData\Local\Yeaplayer
2016-01-27 09:53 - 2016-01-27 09:50 - 02989680 _____ C:\Users\Debora\AppData\Roaming\8ec3f2c77d1f.exe
2016-01-27 09:53 - 2015-11-25 15:31 - 01100288 _____ C:\Users\Debora\AppData\Roaming\HomePage.exe
2016-01-27 09:53 - 2015-11-25 15:31 - 01100288 _____ C:\ProgramData\HomePage.exe
2016-01-27 09:52 - 2016-01-27 09:52 - 00000000 ____D C:\ProgramData\Windows Update
2016-01-27 09:52 - 2015-12-10 15:43 - 00600312 _____ C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe
2016-01-27 09:52 - 2015-11-14 21:06 - 02496403 _____ ( ) C:\Users\Debora\AppData\Roaming\yeaplayer_51447.exe
2016-01-27 09:51 - 2016-02-02 09:07 - 00009441 _____ C:\ProgramData\webad.xml
2016-01-27 09:51 - 2016-01-27 09:52 - 02786816 _____ (TODO: ) C:\Users\Debora\AppData\Roaming\svrupg.exe
2016-01-27 09:51 - 2016-01-27 09:51 - 00008643 _____ C:\Users\Debora\AppData\Roaming\webad.xml
2016-01-27 09:51 - 2016-01-27 09:51 - 00000000 ____D C:\Users\Debora\AppData\Local\Birds365
2016-01-27 09:51 - 2016-01-27 09:51 - 00000000 ____D C:\Users\Debora\AppData\Local\Birds
2016-01-27 09:51 - 2016-01-26 11:54 - 02415616 _____ C:\Users\Debora\AppData\Roaming\msiql.exe
2016-01-27 09:51 - 2016-01-26 11:54 - 02415616 _____ C:\ProgramData\msiql.exe
2016-01-27 09:51 - 2016-01-11 15:49 - 01734656 _____ C:\Users\Debora\AppData\Roaming\service.exe
2016-01-27 09:51 - 2016-01-11 15:49 - 01734656 _____ C:\ProgramData\service.exe
2016-01-27 09:51 - 2015-12-04 13:14 - 01081344 _____ C:\ProgramData\LightGate.exe
2016-01-27 09:48 - 2016-02-02 09:10 - 00000000 ____D C:\Users\Debora\AppData\Local\CleanBrowserApp
2016-01-27 09:45 - 2016-01-29 10:50 - 00000000 ____D C:\ProgramData\Tmp0x0x
2016-01-27 09:44 - 2016-01-27 10:38 - 00000000 ____D C:\Users\Debora\AppData\Local\gmsd_br_005010219
2016-01-27 09:44 - 2016-01-27 10:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP
2016-01-27 09:43 - 2016-01-27 09:48 - 00000000 ____D C:\Program Files (x86)\CleanBrowser
2016-01-26 13:57 - 2016-01-26 13:57 - 00001076 _____ C:\windows\run.vbs
2016-01-26 09:55 - 2016-02-02 09:09 - 00003226 _____ C:\windows\System32\Tasks\SidebarExecute
2016-01-25 18:31 - 2012-02-02 21:03 - 00267776 _____ (Microsoft Corporation) C:\windows\system32\ieaksie.dll
2016-01-25 18:31 - 2012-02-02 21:03 - 00227840 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieaksie.dll
2016-01-25 18:31 - 2012-02-02 21:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieakui.dll
2016-01-25 18:31 - 2012-02-02 21:03 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\ieakui.dll
2016-01-25 18:31 - 2012-02-02 21:03 - 00160256 _____ (Microsoft Corporation) C:\windows\system32\ieakeng.dll
2016-01-25 18:31 - 2012-02-02 21:03 - 00130560 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieakeng.dll
2016-01-25 18:31 - 2012-02-02 21:03 - 00114176 _____ (Microsoft Corporation) C:\windows\system32\admparse.dll
2016-01-25 18:31 - 2012-02-02 21:03 - 00101888 _____ (Microsoft Corporation) C:\windows\SysWOW64\admparse.dll
2016-01-25 18:31 - 2012-02-02 21:03 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\ie4uinit.exe
2016-01-25 18:31 - 2012-02-02 05:05 - 00174640 _____ (Symantec Corporation) C:\windows\system32\Drivers\SYMEVENT64x86.SYS
2016-01-25 18:31 - 2012-02-02 05:05 - 00007440 _____ C:\windows\system32\Drivers\SYMEVENT64x86.CAT
2016-01-25 18:31 - 2011-10-20 15:45 - 02791424 _____ (Atheros Communications, Inc.) C:\windows\system32\athrx.sys
2016-01-25 18:31 - 2011-10-12 05:53 - 07124304 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfc100ud.dll
2016-01-25 18:31 - 2011-10-12 05:53 - 07055696 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfc100d.dll
2016-01-25 18:31 - 2011-10-12 05:53 - 01505104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr100d.dll
2016-01-25 18:31 - 2011-10-12 05:53 - 00743760 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcp100d.dll
2016-01-25 18:31 - 2011-10-12 05:53 - 00105296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcm100ud.dll
2016-01-25 18:31 - 2011-10-12 05:53 - 00103760 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcm100d.dll
2016-01-25 18:31 - 2011-08-12 02:29 - 03053160 _____ (Realtek Semiconductor Corp.) C:\windows\system32\Drivers\RTKVHD64.sys
2016-01-25 18:31 - 2011-08-09 11:39 - 02504296 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtPgEx64.dll
2016-01-25 18:31 - 2011-08-04 04:12 - 00093288 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RCoInst64.dll
2016-01-25 18:31 - 2011-07-29 03:46 - 01827944 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkApi64.dll
2016-01-25 18:31 - 2011-07-27 13:55 - 02604376 _____ (Waves Audio Ltd.) C:\windows\system32\WavesGUILib.dll
2016-01-25 18:31 - 2011-07-27 13:55 - 02132824 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxAudioEQ.dll
2016-01-25 18:31 - 2011-07-22 08:35 - 01247848 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RTCOM64.dll
2016-01-25 18:31 - 2011-07-08 06:05 - 00603984 _____ (Knowles Acoustics ) C:\windows\system32\KAAPORT64.dll
2016-01-25 18:31 - 2011-07-06 03:16 - 00289704 _____ (Atheros) C:\windows\system32\Drivers\btfilter.sys
2016-01-25 18:31 - 2011-06-30 05:14 - 01560168 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RTSnMg64.cpl
2016-01-25 18:31 - 2011-06-27 03:45 - 03768152 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxAudioRealtek.dll
2016-01-25 18:31 - 2011-05-30 22:42 - 01756264 _____ (DTS) C:\windows\system32\DTSS2SpeakerDLL64.dll
2016-01-25 18:31 - 2011-05-30 22:42 - 01568360 _____ (DTS) C:\windows\system32\DTSS2HeadphoneDLL64.dll
2016-01-25 18:31 - 2011-05-30 22:42 - 01486952 _____ (DTS) C:\windows\system32\DTSBoostDLL64.dll
2016-01-25 18:31 - 2011-05-30 22:42 - 00728680 _____ (DTS) C:\windows\system32\DTSBassEnhancementDLL64.dll
2016-01-25 18:31 - 2011-05-30 22:42 - 00712296 _____ (DTS) C:\windows\system32\DTSSymmetryDLL64.dll
2016-01-25 18:31 - 2011-05-30 22:42 - 00693352 _____ (DTS) C:\windows\system32\DTSVoiceClarityDLL64.dll
2016-01-25 18:31 - 2011-05-30 22:42 - 00491112 _____ (DTS) C:\windows\system32\DTSNeoPCDLL64.dll
2016-01-25 18:31 - 2011-05-30 22:42 - 00432744 _____ (DTS) C:\windows\system32\DTSLimiterDLL64.dll
2016-01-25 18:31 - 2011-05-30 22:42 - 00428648 _____ (DTS) C:\windows\system32\DTSGainCompensatorDLL64.dll
2016-01-25 18:31 - 2011-05-30 22:42 - 00242792 _____ (DTS) C:\windows\system32\DTSLFXAPO64.dll
2016-01-25 18:31 - 2011-05-30 22:42 - 00242792 _____ (DTS) C:\windows\system32\DTSGFXAPO64.dll
2016-01-25 18:31 - 2011-05-30 22:42 - 00241768 _____ (DTS) C:\windows\system32\DTSGFXAPONS64.dll
2016-01-25 18:31 - 2011-05-17 04:55 - 00107552 _____ (Realtek Semiconductor Corporation) C:\windows\system32\RTNUninst64.dll
2016-01-25 18:31 - 2011-05-17 04:55 - 00074272 _____ C:\windows\system32\RtNicProp64.dll
2016-01-25 18:31 - 2011-05-13 02:58 - 00001204 _____ C:\windows\system32\Drivers\ramps_0x01020200_40.dfu
2016-01-25 18:31 - 2011-05-05 04:24 - 02085440 _____ (Fortemedia Corporation) C:\windows\system32\FMAPO64.dll
2016-01-25 18:31 - 2011-05-05 03:15 - 00220512 _____ (Synopsys, Inc.) C:\windows\system32\SFNHK64.dll
2016-01-25 18:31 - 2011-05-05 03:14 - 00081248 _____ (Synopsys, Inc.) C:\windows\system32\SFCOM64.dll
2016-01-25 18:31 - 2011-05-05 03:14 - 00078176 _____ (Synopsys, Inc.) C:\windows\system32\SFAPO64.dll
2016-01-25 18:31 - 2011-05-02 03:27 - 03308376 _____ (Dolby Laboratories) C:\windows\system32\R4EEP64A.dll
2016-01-25 18:31 - 2011-05-02 03:27 - 00426328 _____ (Dolby Laboratories) C:\windows\system32\R4EED64A.dll
2016-01-25 18:31 - 2011-05-02 03:27 - 00136024 _____ (Dolby Laboratories) C:\windows\system32\R4EEL64A.dll
2016-01-25 18:31 - 2011-05-02 03:27 - 00118104 _____ (Dolby Laboratories) C:\windows\system32\R4EEA64A.dll
2016-01-25 18:31 - 2011-05-02 03:27 - 00074072 _____ (Dolby Laboratories) C:\windows\system32\R4EEG64A.dll
2016-01-25 18:31 - 2011-04-29 06:14 - 00042484 _____ C:\windows\system32\Drivers\AthrBT_0x01020200.dfu
2016-01-25 18:31 - 2010-11-21 01:24 - 00412160 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2016-01-25 18:31 - 2010-11-18 00:49 - 00121744 _____ (Sony Corporation) C:\windows\system32\SFSS_APO.dll
2016-01-25 18:31 - 2010-11-07 20:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEP64A.dll
2016-01-25 18:31 - 2010-11-07 20:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RP3DHT64.dll
2016-01-25 18:31 - 2010-11-07 20:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RP3DAA64.dll
2016-01-25 18:31 - 2010-11-07 20:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEED64A.dll
2016-01-25 18:31 - 2010-11-07 20:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEL64A.dll
2016-01-25 18:31 - 2010-11-07 20:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEG64A.dll
2016-01-25 18:31 - 2010-11-03 07:31 - 00332392 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtlCPAPI64.dll
2016-01-25 18:31 - 2010-11-03 07:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkCfg64.dll
2016-01-25 18:31 - 2010-10-03 02:46 - 00341336 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxAudioAPO30.dll
2016-01-25 18:31 - 2010-09-26 22:34 - 00318808 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxAudioAPO20.dll
2016-01-25 18:31 - 2010-07-22 05:48 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\windows\SysWOW64\SFCOM.dll
2016-01-25 18:31 - 2010-07-22 05:37 - 00200800 _____ (Andrea Electronics Corporation) C:\windows\system32\AERTAC64.dll
2016-01-25 18:31 - 2010-05-06 06:34 - 00334680 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxVolumeSDAPO.dll
2016-01-25 18:31 - 2009-11-23 22:55 - 00518896 _____ (SRS Labs, Inc.) C:\windows\system32\SRSTSX64.dll
2016-01-25 18:31 - 2009-11-23 22:55 - 00211184 _____ (SRS Labs, Inc.) C:\windows\system32\SRSTSH64.dll
2016-01-25 18:31 - 2009-11-23 22:55 - 00198896 _____ (SRS Labs, Inc.) C:\windows\system32\SRSHP64.dll
2016-01-25 18:31 - 2009-11-23 22:55 - 00155888 _____ (SRS Labs, Inc.) C:\windows\system32\SRSWOW64.dll
2016-01-25 18:31 - 2009-11-17 07:12 - 00108960 _____ (Andrea Electronics Corporation) C:\windows\system32\AERTAR64.dll
2016-01-25 18:31 - 2009-07-13 23:39 - 00071168 _____ (Microsoft Corporation) C:\windows\system32\lpremove.exe
2016-01-25 18:31 - 2009-06-10 18:45 - 00000003 _____ C:\windows\system32\Drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf
2016-01-25 18:31 - 2008-11-08 20:09 - 00428544 _____ (Samsung Electronics) C:\windows\AutoReseal.exe
2016-01-25 18:31 - 2007-11-14 23:13 - 00423936 _____ (TODO: ) C:\windows\Reseal64.exe
2016-01-25 13:53 - 2016-01-26 09:57 - 00000000 ____D C:\Users\Debora\AppData\Roaming\systweak
2016-01-25 13:48 - 2016-01-25 13:48 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Real
2016-01-25 13:34 - 2016-02-02 09:30 - 00000000 ____D C:\Users\Debora\AppData\Roaming\WeatherTool
2016-01-25 13:34 - 2016-02-02 09:06 - 00000522 _____ C:\windows\Tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B}.job
2016-01-25 13:34 - 2016-01-25 13:34 - 00003624 _____ C:\windows\System32\Tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B}
2016-01-25 13:34 - 2016-01-25 13:34 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Baidu
2016-01-25 13:34 - 2016-01-25 13:34 - 00000000 ____D C:\ProgramData\baidu
2016-01-25 13:34 - 2016-01-25 13:34 - 00000000 ____D C:\Program Files (x86)\WeatherTool
2016-01-25 13:31 - 2016-01-25 13:32 - 00000000 ____D C:\Users\Debora\AppData\Local\Tempfolder
2016-01-25 13:31 - 2016-01-25 13:31 - 00000000 ____D C:\windows\system32\hagb
2016-01-25 13:31 - 2016-01-25 13:31 - 00000000 ____D C:\Users\Debora\AppData\Roaming\BhnobBuielka
2016-01-25 13:30 - 2016-01-25 13:30 - 00003342 _____ C:\windows\System32\Tasks\Jybgovbi
2016-01-25 13:30 - 2016-01-25 13:30 - 00000000 ____D C:\Program Files\shopperz250120161400
2016-01-25 11:32 - 2016-01-25 11:50 - 00000000 ____D C:\Users\Debora\AppData\Local\Internet
2016-01-25 10:52 - 2016-01-25 10:52 - 00000000 ____D C:\Users\Debora\AppData\Local\ElevatedDiagnostics
2016-01-25 10:37 - 2016-01-27 10:49 - 00003436 _____ C:\windows\System32\Tasks\IBUpd
2016-01-25 10:37 - 2016-01-25 10:37 - 00003248 _____ C:\windows\System32\Tasks\IBUpd2
2016-01-25 10:36 - 2016-01-25 10:36 - 00000000 ____D C:\Users\Debora\AppData\Local\BrowserAir
2016-01-25 10:33 - 2016-01-25 12:56 - 00023208 _____ (Corporation) C:\windows\system32\Drivers\sdfhgdf.sys
2016-01-25 10:33 - 2016-01-25 10:33 - 00000000 ____D C:\Program Files (x86)\ppt
2016-01-25 10:32 - 2016-01-25 10:29 - 00001012 _____ C:\windows\system32\Drivers\etc\hp.bak
2016-01-25 10:31 - 2016-02-02 09:50 - 00000000 ____D C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE
2016-01-25 10:29 - 2016-01-25 10:29 - 00003338 _____ C:\windows\System32\Tasks\Pomugoje
2016-01-25 10:29 - 2016-01-25 10:29 - 00000000 ____D C:\Users\Debora\AppData\LocalLow\Company
2016-01-25 10:29 - 2016-01-25 10:29 - 00000000 ____D C:\Users\Debora\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
2016-01-25 10:29 - 2016-01-25 10:29 - 00000000 ____D C:\uninst
2016-01-25 10:27 - 2016-01-29 11:41 - 00000000 ____D C:\Program Files\Sound+
2016-01-25 09:54 - 2016-01-25 10:29 - 00061336 _____ (Cherimoya Ltd) C:\windows\system32\Drivers\cherimoya.sys
2016-01-21 17:01 - 2016-01-21 17:01 - 00000000 ____D C:\Users\Debora\Downloads\Pack do tutorial - Zé Ruela Games 2015
2016-01-21 16:58 - 2016-01-21 17:00 - 12434322 _____ C:\Users\Debora\Downloads\Pack do tutorial - Zé Ruela Games 2015.rar
2016-01-21 16:41 - 2016-01-21 16:42 - 00000000 ____D C:\Users\Debora\Downloads\Terraria
2016-01-21 16:40 - 2016-01-21 16:41 - 101474421 _____ C:\Users\Debora\Downloads\Terraria.zip
2016-01-21 13:46 - 2016-01-21 16:38 - 416112128 _____ C:\Users\Debora\Downloads\minha intro.avi
2016-01-21 10:07 - 2016-01-29 11:15 - 00000000 ____D C:\Program Files (x86)\Picexa
2016-01-17 18:47 - 2016-01-17 18:48 - 18278658 _____ C:\Users\Debora\Downloads\Minecraft - Pocket Edition.apk
2016-01-17 14:03 - 2015-12-30 17:08 - 05572544 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2016-01-17 14:03 - 2015-12-30 17:05 - 01730496 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2016-01-17 14:03 - 2015-12-30 17:02 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2016-01-17 14:03 - 2015-12-30 17:02 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2016-01-17 14:03 - 2015-12-30 17:02 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2016-01-17 14:03 - 2015-12-30 17:01 - 01214464 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2016-01-17 14:03 - 2015-12-30 17:01 - 00344064 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2016-01-17 14:03 - 2015-12-30 17:00 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2016-01-17 14:03 - 2015-12-30 16:59 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2016-01-17 14:03 - 2015-12-30 16:59 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2016-01-17 14:03 - 2015-12-30 16:57 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2016-01-17 14:03 - 2015-12-30 16:57 - 00729600 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2016-01-17 14:03 - 2015-12-30 16:55 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2016-01-17 14:03 - 2015-12-30 16:55 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2016-01-17 14:03 - 2015-12-30 16:47 - 03993536 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2016-01-17 14:03 - 2015-12-30 16:47 - 03938240 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2016-01-17 14:03 - 2015-12-30 16:44 - 01311768 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2016-01-17 14:03 - 2015-12-30 16:41 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2016-01-17 14:03 - 2015-12-30 16:41 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2016-01-17 14:03 - 2015-12-30 16:41 - 00171520 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2016-01-17 14:03 - 2015-12-30 16:41 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2016-01-17 14:03 - 2015-12-30 16:40 - 00251392 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2016-01-17 14:03 - 2015-12-30 16:40 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2016-01-17 14:03 - 2015-12-30 16:39 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2016-01-17 14:03 - 2015-12-30 16:39 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2016-01-17 14:03 - 2015-12-30 16:38 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2016-01-17 14:03 - 2015-12-30 16:38 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2016-01-17 14:03 - 2015-12-30 15:43 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2016-01-17 14:03 - 2015-12-30 15:42 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2016-01-17 14:03 - 2015-12-30 15:41 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2016-01-17 14:03 - 2015-12-30 15:32 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2016-01-17 14:03 - 2015-12-30 15:30 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2016-01-17 14:02 - 2015-12-30 17:02 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2016-01-17 14:02 - 2015-12-30 17:02 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2016-01-17 14:02 - 2015-12-30 17:02 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2016-01-17 14:02 - 2015-12-30 17:01 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2016-01-17 14:02 - 2015-12-30 17:01 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2016-01-17 14:02 - 2015-12-30 16:57 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2016-01-17 14:02 - 2015-12-30 16:55 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:41 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2016-01-17 14:02 - 2015-12-30 16:41 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2016-01-17 14:02 - 2015-12-30 16:41 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2016-01-17 14:02 - 2015-12-30 16:41 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2016-01-17 14:02 - 2015-12-30 16:39 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2016-01-17 14:02 - 2015-12-30 16:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 15:50 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2016-01-17 14:02 - 2015-12-30 15:49 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2016-01-17 14:02 - 2015-12-30 15:44 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2016-01-17 14:02 - 2015-12-30 15:42 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2016-01-17 14:02 - 2015-12-30 15:32 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2016-01-17 14:02 - 2015-12-30 15:32 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2016-01-17 14:02 - 2015-12-30 15:32 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2016-01-17 14:02 - 2015-12-30 15:30 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 15:30 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 15:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-01-17 14:02 - 2015-12-30 15:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-01-17 14:01 - 2015-12-30 17:08 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2016-01-17 14:01 - 2015-12-30 17:08 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2016-01-17 14:01 - 2015-12-30 17:01 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2016-01-17 14:01 - 2015-12-30 17:01 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2016-01-17 14:01 - 2015-12-30 17:01 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2016-01-17 14:01 - 2015-12-30 16:59 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2016-01-17 14:01 - 2015-12-30 16:58 - 01461248 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2016-01-17 14:01 - 2015-12-30 16:58 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2016-01-17 14:01 - 2015-12-30 16:54 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2016-01-17 14:01 - 2015-12-30 15:57 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2016-01-17 14:01 - 2015-12-30 15:41 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2016-01-14 13:16 - 2016-01-20 14:18 - 00000001 _____ C:\windows\SysWOW64\br.html
2016-01-14 11:19 - 2016-01-21 10:05 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Picexa Viewer
2016-01-14 11:13 - 2016-01-14 11:15 - 00000000 ____D C:\windows\system32upd
2016-01-14 11:13 - 2016-01-14 11:14 - 00000000 ____D C:\ProgramData\nWdMn
2016-01-13 15:16 - 2015-12-23 21:13 - 00387784 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2016-01-13 15:16 - 2015-12-23 20:52 - 00341192 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2016-01-13 15:16 - 2015-12-12 16:54 - 25837568 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-01-13 15:16 - 2015-12-12 16:31 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2016-01-13 15:16 - 2015-12-12 16:30 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2016-01-13 15:16 - 2015-12-12 16:16 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2016-01-13 15:16 - 2015-12-12 16:15 - 02887168 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-01-13 15:16 - 2015-12-12 16:15 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2016-01-13 15:16 - 2015-12-12 16:15 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2016-01-13 15:16 - 2015-12-12 16:15 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2016-01-13 15:16 - 2015-12-12 16:14 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2016-01-13 15:16 - 2015-12-12 16:07 - 06051328 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-01-13 15:16 - 2015-12-12 16:07 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2016-01-13 15:16 - 2015-12-12 16:07 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2016-01-13 15:16 - 2015-12-12 16:03 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2016-01-13 15:16 - 2015-12-12 16:02 - 20367360 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-01-13 15:16 - 2015-12-12 16:02 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2016-01-13 15:16 - 2015-12-12 16:02 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2016-01-13 15:16 - 2015-12-12 16:02 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2016-01-13 15:16 - 2015-12-12 16:02 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2016-01-13 15:16 - 2015-12-12 15:55 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2016-01-13 15:16 - 2015-12-12 15:51 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2016-01-13 15:16 - 2015-12-12 15:49 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2016-01-13 15:16 - 2015-12-12 15:44 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2016-01-13 15:16 - 2015-12-12 15:40 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2016-01-13 15:16 - 2015-12-12 15:39 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2016-01-13 15:16 - 2015-12-12 15:37 - 00496640 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2016-01-13 15:16 - 2015-12-12 15:37 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2016-01-13 15:16 - 2015-12-12 15:37 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2016-01-13 15:16 - 2015-12-12 15:37 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2016-01-13 15:16 - 2015-12-12 15:36 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2016-01-13 15:16 - 2015-12-12 15:36 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2016-01-13 15:16 - 2015-12-12 15:35 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2016-01-13 15:16 - 2015-12-12 15:33 - 02280448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-01-13 15:16 - 2015-12-12 15:31 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2016-01-13 15:16 - 2015-12-12 15:30 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2016-01-13 15:16 - 2015-12-12 15:28 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2016-01-13 15:16 - 2015-12-12 15:27 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2016-01-13 15:16 - 2015-12-12 15:27 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2016-01-13 15:16 - 2015-12-12 15:27 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2016-01-13 15:16 - 2015-12-12 15:25 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2016-01-13 15:16 - 2015-12-12 15:23 - 00798208 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2016-01-13 15:16 - 2015-12-12 15:22 - 00718336 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2016-01-13 15:16 - 2015-12-12 15:21 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2016-01-13 15:16 - 2015-12-12 15:20 - 02123264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2016-01-13 15:16 - 2015-12-12 15:19 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2016-01-13 15:16 - 2015-12-12 15:18 - 14457856 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-01-13 15:16 - 2015-12-12 15:14 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-01-13 15:16 - 2015-12-12 15:12 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2016-01-13 15:16 - 2015-12-12 15:10 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2016-01-13 15:16 - 2015-12-12 15:10 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2016-01-13 15:16 - 2015-12-12 15:09 - 04610560 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-01-13 15:16 - 2015-12-12 15:08 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2016-01-13 15:16 - 2015-12-12 15:06 - 02487808 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-01-13 15:16 - 2015-12-12 15:02 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2016-01-13 15:16 - 2015-12-12 15:00 - 12856320 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-01-13 15:16 - 2015-12-12 15:00 - 02050560 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2016-01-13 15:16 - 2015-12-12 15:00 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2016-01-13 15:16 - 2015-12-12 15:00 - 00687104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2016-01-13 15:16 - 2015-12-12 14:54 - 01546752 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-01-13 15:16 - 2015-12-12 14:42 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2016-01-13 15:16 - 2015-12-12 14:41 - 02011136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-01-13 15:16 - 2015-12-12 14:38 - 01311744 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-01-13 15:16 - 2015-12-12 14:36 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2016-01-13 15:06 - 2015-11-13 21:09 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\mapistub.dll
2016-01-13 15:06 - 2015-11-13 21:09 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\mapi32.dll
2016-01-13 15:06 - 2015-11-13 21:08 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\fixmapi.exe
2016-01-13 15:06 - 2015-11-13 20:50 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mapistub.dll
2016-01-13 15:06 - 2015-11-13 20:50 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mapi32.dll
2016-01-13 15:06 - 2015-11-13 20:49 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\fixmapi.exe
2016-01-13 15:04 - 2015-12-11 16:57 - 01164800 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2016-01-13 15:04 - 2015-12-08 19:54 - 02285056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msmpeg2vdec.dll
2016-01-13 15:04 - 2015-12-08 19:54 - 01620992 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL
2016-01-13 15:04 - 2015-12-08 19:54 - 01568768 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVENCOD.DLL
2016-01-13 15:04 - 2015-12-08 19:54 - 01325056 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMSPDMOE.DLL
2016-01-13 15:04 - 2015-12-08 19:54 - 00902144 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMADMOD.DLL
2016-01-13 15:04 - 2015-12-08 19:54 - 00815616 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMADMOE.DLL
2016-01-13 15:04 - 2015-12-08 19:54 - 00740352 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmpmde.dll
2016-01-13 15:04 - 2015-12-08 19:54 - 00739328 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMSPDMOD.DLL
2016-01-13 15:04 - 2015-12-08 19:54 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVXENCD.DLL
2016-01-13 15:04 - 2015-12-08 19:54 - 00541184 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVSDECD.DLL
2016-01-13 15:04 - 2015-12-08 19:54 - 00358400 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVSENCD.DLL
2016-01-13 15:04 - 2015-12-08 19:54 - 00154112 _____ (Microsoft Corporation) C:\windows\SysWOW64\VIDRESZR.DLL
2016-01-13 15:04 - 2015-12-08 19:53 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2016-01-13 15:04 - 2015-12-08 19:53 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll
2016-01-13 15:04 - 2015-12-08 19:53 - 00970240 _____ (Microsoft Corporation) C:\windows\SysWOW64\msmpeg2adec.dll
2016-01-13 15:04 - 2015-12-08 19:53 - 00829952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSMPEG2ENC.DLL
2016-01-13 15:04 - 2015-12-08 19:53 - 00609280 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFWMAAEC.DLL
2016-01-13 15:04 - 2015-12-08 19:53 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll
2016-01-13 15:04 - 2015-12-08 19:53 - 00509952 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2016-01-13 15:04 - 2015-12-08 19:53 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll
2016-01-13 15:04 - 2015-12-08 19:53 - 00415744 _____ (Microsoft Corporation) C:\windows\SysWOW64\MP4SDECD.DLL
2016-01-13 15:04 - 2015-12-08 19:53 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll
2016-01-13 15:04 - 2015-12-08 19:53 - 00241152 _____ (Microsoft Corporation) C:\windows\SysWOW64\MPG4DECD.DLL
2016-01-13 15:04 - 2015-12-08 19:53 - 00241152 _____ (Microsoft Corporation) C:\windows\SysWOW64\MP43DECD.DLL
2016-01-13 15:04 - 2015-12-08 19:53 - 00206848 _____ (Microsoft Corporation) C:\windows\SysWOW64\RESAMPLEDMO.DLL
2016-01-13 15:04 - 2015-12-08 19:53 - 00206848 _____ (Microsoft Corporation) C:\windows\SysWOW64\qasf.dll
2016-01-13 15:04 - 2015-12-08 19:53 - 00193536 _____ (Microsoft Corporation) C:\windows\SysWOW64\ksproxy.ax
2016-01-13 15:04 - 2015-12-08 19:53 - 00153600 _____ (Microsoft Corporation) C:\windows\SysWOW64\COLORCNV.DLL
2016-01-13 15:04 - 2015-12-08 19:53 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2016-01-13 15:04 - 2015-12-08 19:53 - 00079872 _____ (Microsoft Corporation) C:\windows\SysWOW64\MP3DMOD.DLL
2016-01-13 15:04 - 2015-12-08 19:53 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\devenum.dll
2016-01-13 15:04 - 2015-12-08 19:53 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfvdsp.dll
2016-01-13 15:04 - 2015-12-08 19:53 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2016-01-13 15:04 - 2015-12-08 19:53 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2016-01-13 15:04 - 2015-12-08 19:53 - 00004608 _____ (Microsoft Corporation) C:\windows\SysWOW64\ksuser.dll
2016-01-13 15:04 - 2015-12-08 19:50 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 02777088 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 01955328 _____ (Microsoft Corporation) C:\windows\system32\WMVENCOD.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 01888768 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 01575424 _____ (Microsoft Corporation) C:\windows\system32\WMSPDMOE.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 01573888 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 01307136 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2adec.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 01232896 _____ (Microsoft Corporation) C:\windows\system32\WMADMOD.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 01160192 _____ (Microsoft Corporation) C:\windows\system32\MSMPEG2ENC.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 01153024 _____ (Microsoft Corporation) C:\windows\system32\WMADMOE.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 01026048 _____ (Microsoft Corporation) C:\windows\system32\wmpmde.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 01010688 _____ (Microsoft Corporation) C:\windows\system32\mcmde.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 00978944 _____ (Microsoft Corporation) C:\windows\system32\WMSPDMOD.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 00666112 _____ (Microsoft Corporation) C:\windows\system32\WMVSDECD.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 00653824 _____ (Microsoft Corporation) C:\windows\system32\MP4SDECD.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 00642048 _____ (Microsoft Corporation) C:\windows\system32\WMVXENCD.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 00632320 _____ (Microsoft Corporation) C:\windows\system32\evr.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 00624640 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 00484864 _____ (Microsoft Corporation) C:\windows\system32\MFWMAAEC.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 00447488 _____ (Microsoft Corporation) C:\windows\system32\WMVSENCD.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 00432128 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 00378880 _____ (Microsoft Corporation) C:\windows\system32\SysFxUI.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 00292352 _____ (Microsoft Corporation) C:\windows\system32\VIDRESZR.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 00254464 _____ (Microsoft Corporation) C:\windows\system32\qasf.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 00225792 _____ (Microsoft Corporation) C:\windows\system32\RESAMPLEDMO.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 00224768 _____ (Microsoft Corporation) C:\windows\system32\MPG4DECD.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 00223744 _____ (Microsoft Corporation) C:\windows\system32\MP43DECD.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 00189952 _____ (Microsoft Corporation) C:\windows\system32\COLORCNV.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\MP3DMOD.DLL
2016-01-13 15:04 - 2015-12-08 17:07 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\devenum.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\mfvdsp.dll
2016-01-13 15:04 - 2015-12-08 17:07 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2016-01-13 15:04 - 2015-12-08 17:07 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\ksuser.dll
2016-01-13 15:04 - 2015-12-08 17:06 - 00250880 _____ (Microsoft Corporation) C:\windows\system32\ksproxy.ax
2016-01-13 15:04 - 2015-12-08 17:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2016-01-13 15:04 - 2015-12-08 17:04 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2016-01-13 15:04 - 2015-12-08 16:54 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys
2016-01-13 15:04 - 2015-12-08 16:12 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys
2016-01-13 15:04 - 2015-12-08 16:11 - 00005632 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmkaud.sys
2016-01-13 15:04 - 2015-12-08 15:58 - 03211264 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2016-01-13 14:59 - 2015-12-08 19:53 - 00641536 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2016-01-13 14:59 - 2015-12-08 19:52 - 00312320 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2016-01-13 14:59 - 2015-12-08 17:07 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2016-01-13 14:59 - 2015-12-08 17:07 - 00405504 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2016-01-13 14:59 - 2015-11-16 23:11 - 00025024 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2016-01-13 14:59 - 2015-11-16 23:08 - 01381376 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2016-01-13 14:59 - 2015-11-16 23:08 - 00792064 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2016-01-13 14:59 - 2015-11-16 23:08 - 00705536 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2016-01-13 14:59 - 2015-11-16 23:08 - 00505856 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2016-01-13 14:59 - 2015-11-16 23:08 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2016-01-13 14:59 - 2015-11-16 18:17 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2016-01-10 21:34 - 2016-01-10 21:34 - 00049426 _____ C:\Users\Debora\Downloads\sophia silva 5759.pdf
2016-01-10 21:30 - 2016-01-10 21:30 - 00049445 _____ C:\Users\Debora\Downloads\laura silva 5758.pdf
2016-01-10 21:24 - 2016-01-10 21:24 - 00000000 ____D C:\ProgramData\Adobe
2016-01-06 14:16 - 2016-01-27 11:18 - 00000000 ____D C:\Riot Games
2016-01-04 12:22 - 2016-01-04 12:23 - 08972080 _____ C:\Users\Debora\Downloads\TX115_x64_660APS_C1.exe

==================== Um Mês Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-02-02 10:03 - 2013-09-22 18:34 - 00000902 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2016-02-02 09:57 - 2013-10-07 16:57 - 00000296 _____ C:\windows\Tasks\UpdaterEX.job
2016-02-02 09:53 - 2013-02-09 18:06 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Skype
2016-02-02 09:43 - 2014-03-31 15:43 - 00000304 _____ C:\windows\Tasks\PriceMeterUpdater.job
2016-02-02 09:23 - 2015-11-05 12:02 - 00001070 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-02 09:22 - 2015-11-05 12:02 - 00001066 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-02 09:22 - 2009-07-14 02:45 - 00028848 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-02-02 09:22 - 2009-07-14 02:45 - 00028848 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-02-02 09:17 - 2015-11-05 12:02 - 00004066 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-02-02 09:17 - 2015-11-05 12:02 - 00003814 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-02-02 09:11 - 2015-08-16 23:16 - 00002218 ____R C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-02 09:11 - 2015-08-16 23:16 - 00002189 ____R C:\Users\Public\Desktop\Google Chrome.lnk
2016-02-02 09:11 - 2015-06-19 13:51 - 00001167 ____R C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-02-02 09:06 - 2015-12-03 10:44 - 00000310 _____ C:\windows\Tasks\{5D559149-4358-4190-9CDA-25E643AA09DB}.job
2016-02-02 09:06 - 2015-08-03 12:27 - 00000660 _____ C:\windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job
2016-02-02 09:06 - 2015-07-24 19:24 - 00000912 _____ C:\windows\Tasks\globalUpdateUpdateTaskMachineCore.job
2016-02-02 09:05 - 2015-01-26 22:00 - 00000000 ____D C:\Program Files (x86)\GbPlugin
2016-02-02 09:05 - 2009-07-14 03:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-02-01 13:11 - 2015-09-22 12:21 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Andy
2016-02-01 12:30 - 2012-08-11 13:16 - 00000000 ____D C:\Users\Debora
2016-02-01 12:29 - 2015-07-24 19:24 - 00000916 _____ C:\windows\Tasks\globalUpdateUpdateTaskMachineUA.job
2016-02-01 12:24 - 2012-12-12 14:31 - 01662164 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2016-02-01 12:24 - 2012-02-02 20:59 - 00711650 _____ C:\windows\system32\prfh0416.dat
2016-02-01 12:24 - 2012-02-02 20:59 - 00149956 _____ C:\windows\system32\prfc0416.dat
2016-02-01 12:24 - 2009-07-14 01:20 - 00000000 ____D C:\windows\inf
2016-02-01 11:24 - 2015-08-06 20:24 - 00000266 _____ C:\windows\Tasks\{6A128791-4857-4484-9BB2-71D4C1257200}.job
2016-02-01 10:26 - 2012-09-13 23:27 - 00000000 ____D C:\Users\Debora\AppData\Local\CrashDumps
2016-02-01 09:24 - 2013-07-05 16:20 - 00003930 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{7F4467AA-F429-4B21-A5B8-97BCC51FEDEF}
2016-02-01 09:22 - 2009-07-14 03:13 - 01643790 _____ C:\windows\system32\PerfStringBackup.INI
2016-01-29 11:13 - 2014-05-12 22:35 - 00000000 ____D C:\windows\pss
2016-01-29 10:31 - 2012-10-15 00:09 - 00000000 ____D C:\Positivo
2016-01-29 10:27 - 2012-09-19 14:40 - 00000000 ____D C:\Users\Debora\AppData\LocalLow\Scpad
2016-01-29 10:17 - 2014-07-19 01:13 - 00000000 ____D C:\Users\Debora\AppData\Local\Adobe
2016-01-27 10:16 - 2015-09-25 09:33 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windroy
2016-01-27 10:16 - 2013-10-09 13:44 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
2016-01-27 10:03 - 2012-08-11 13:42 - 00001577 _____ C:\Users\Debora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-01-27 09:55 - 2009-07-14 02:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-01-27 09:51 - 2015-08-15 10:45 - 00000492 _____ C:\Users\Debora\Downloads\Desktop.lnk
2016-01-27 09:51 - 2009-07-14 03:09 - 00000000 ____D C:\windows\System32\Tasks\WPD
2016-01-25 18:33 - 2009-07-14 01:20 - 00000000 ____D C:\windows\SysWOW64\com
2016-01-25 18:33 - 2009-07-14 01:20 - 00000000 ____D C:\windows\system32\oobe
2016-01-25 18:33 - 2009-07-14 01:20 - 00000000 ____D C:\windows\system32\com
2016-01-25 18:05 - 2012-09-19 14:40 - 00000000 ____D C:\Program Files (x86)\Scpad
2016-01-25 18:05 - 2009-07-14 01:20 - 00000000 ____D C:\windows\registration
2016-01-25 16:47 - 2015-12-04 10:33 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Trove
2016-01-25 16:42 - 2015-12-09 08:59 - 00000000 ____D C:\ProgramData\7WdM7
2016-01-25 14:50 - 2013-02-19 21:42 - 00000000 ____D C:\Users\Debora\AppData\Roaming\AnySend
2016-01-25 14:50 - 2013-02-19 21:42 - 00000000 ____D C:\ProgramData\AnySend
2016-01-25 14:33 - 2015-08-09 18:45 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Steam
2016-01-25 14:33 - 2015-08-05 10:30 - 00000000 ____D C:\Users\Debora\AppData\Local\Steam
2016-01-25 13:31 - 2012-02-02 05:09 - 00357888 _____ (Microsoft Corporation) C:\windows\system32\dnsapi.dll
2016-01-25 13:31 - 2012-02-02 05:09 - 00270336 _____ (Microsoft Corporation) C:\windows\SysWOW64\dnsapi.dll
2016-01-25 12:40 - 2015-08-15 17:27 - 05116136 _____ C:\windows\system32\FNTCACHE.DAT
2016-01-25 12:38 - 2015-12-18 12:52 - 00539676 _____ C:\windows\ntbtlog.txt
2016-01-25 12:08 - 2013-12-15 14:14 - 00000433 _____ C:\windows\system32\Drivers\etc\hosts.ics
2016-01-21 16:53 - 2015-10-01 12:46 - 00000000 ____D C:\Users\Debora\Downloads\musicas
2016-01-21 16:40 - 2015-12-01 12:09 - 00000000 ____D C:\Users\Debora\Downloads\amv
2016-01-21 10:04 - 2013-09-22 18:34 - 00003840 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2016-01-21 10:04 - 2012-08-22 23:09 - 00796864 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-01-21 10:04 - 2012-08-22 23:09 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-01-21 10:03 - 2015-12-28 18:03 - 04499648 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe
2016-01-18 13:07 - 2016-01-01 20:28 - 00000000 ____D C:\Users\Debora\Downloads\TazerCraft Rig
2016-01-18 10:36 - 2015-12-22 16:09 - 00000000 ____D C:\Users\Debora\Downloads\page
2016-01-18 08:51 - 2013-03-15 23:49 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-01-18 08:51 - 2013-03-15 23:49 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-01-17 17:19 - 2015-11-12 22:01 - 00000000 ____D C:\Users\Debora\Downloads\illum
2016-01-17 13:51 - 2013-03-15 23:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-01-15 14:10 - 2015-12-04 16:47 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-01-15 09:10 - 2014-12-15 16:27 - 00000000 ____D C:\windows\system32\appraiser
2016-01-15 09:10 - 2014-05-13 00:09 - 00000000 ___SD C:\windows\system32\CompatTel
2016-01-14 17:54 - 2013-08-19 17:32 - 00000000 ____D C:\windows\system32\MRT
2016-01-14 17:54 - 2012-11-04 13:35 - 143671360 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-01-14 17:50 - 2009-07-14 00:34 - 00000606 _____ C:\windows\win.ini
2016-01-14 11:13 - 2015-09-24 11:49 - 00000074 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2016-01-06 14:17 - 2015-08-03 09:27 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Riot Games

==================== Arquivos na raiz de alguns diretórios =======

2015-07-29 23:07 - 2015-07-29 23:07 - 0000079 _____ () C:\Program Files (x86)\prefs.js
2016-01-27 09:53 - 2016-01-27 09:50 - 2989680 _____ () C:\Users\Debora\AppData\Roaming\8ec3f2c77d1f.exe
2016-01-27 09:54 - 2015-12-10 08:39 - 1015808 _____ (d) C:\Users\Debora\AppData\Roaming\download.exe
2016-01-27 09:53 - 2015-11-25 15:31 - 1100288 _____ () C:\Users\Debora\AppData\Roaming\HomePage.exe
2016-01-27 09:54 - 2016-01-27 09:54 - 0621568 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Debora\AppData\Roaming\libeay32.dll
2016-01-27 09:54 - 2015-12-04 13:14 - 1081344 _____ () C:\Users\Debora\AppData\Roaming\LightGate.exe
2005-10-31 17:12 - 2015-11-25 17:34 - 0032805 ____H () C:\Users\Debora\AppData\Roaming\logs.dat
2016-01-27 09:51 - 2016-01-26 11:54 - 2415616 _____ () C:\Users\Debora\AppData\Roaming\msiql.exe
2016-01-01 20:27 - 2016-01-01 20:27 - 0000132 _____ () C:\Users\Debora\AppData\Roaming\Preferências do Formato PNG do Adobe CS6
2016-01-27 09:51 - 2016-01-11 15:49 - 1734656 _____ () C:\Users\Debora\AppData\Roaming\service.exe
2016-01-27 09:54 - 2016-01-27 09:54 - 0162304 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Debora\AppData\Roaming\ssleay32.dll
2016-01-27 09:51 - 2016-01-27 09:52 - 2786816 _____ (TODO: ) C:\Users\Debora\AppData\Roaming\svrupg.exe
2016-01-27 09:51 - 2016-01-27 09:51 - 0008643 _____ () C:\Users\Debora\AppData\Roaming\webad.xml
2016-01-27 09:52 - 2015-11-14 21:06 - 2496403 _____ ( ) C:\Users\Debora\AppData\Roaming\yeaplayer_51447.exe
2015-11-18 08:33 - 2015-11-18 08:33 - 0000000 _____ () C:\Users\Debora\AppData\Local\{4C5BC80D-10E0-48BF-AA00-0AC70F7E6597}
2014-10-25 10:55 - 2014-10-25 10:55 - 0000020 _____ () C:\ProgramData\bc.ini
2014-01-15 03:15 - 2014-01-15 03:15 - 0167784 _____ (Baidu, Inc.) C:\ProgramData\FileSplitUpLoad.dll
2016-01-27 09:53 - 2015-11-25 15:31 - 1100288 _____ () C:\ProgramData\HomePage.exe
2016-01-27 09:51 - 2015-12-04 13:14 - 1081344 _____ () C:\ProgramData\LightGate.exe
2016-01-27 09:51 - 2016-01-26 11:54 - 2415616 _____ () C:\ProgramData\msiql.exe
2016-01-27 09:51 - 2016-01-11 15:49 - 1734656 _____ () C:\ProgramData\service.exe
2016-01-27 09:54 - 2016-01-27 09:54 - 1736192 _____ () C:\ProgramData\upgsvr.exe
2016-01-27 09:51 - 2016-02-02 09:07 - 0009441 _____ () C:\ProgramData\webad.xml
2016-01-27 09:52 - 2015-12-10 15:43 - 0600312 _____ () C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe
2012-02-02 06:09 - 2012-02-02 06:09 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2015-09-24 11:49 - 2016-01-14 11:13 - 0000074 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2012-02-02 06:00 - 2012-02-02 06:01 - 0000113 _____ () C:\ProgramData\{34FBC7C4-CD31-4D93-A428-0E524EAC4586}.log
2012-02-02 06:06 - 2012-02-02 06:06 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2012-02-02 06:01 - 2012-02-02 06:05 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log
2012-02-02 06:07 - 2012-02-02 06:09 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log

Arquivos para serem movidos ou deletados:
====================
C:\ProgramData\FileSplitUpLoad.dll
C:\ProgramData\HomePage.exe
C:\ProgramData\LightGate.exe
C:\ProgramData\msiql.exe
C:\ProgramData\service.exe
C:\ProgramData\upgsvr.exe
C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
C:\Windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job
C:\Windows\Tasks\{5D559149-4358-4190-9CDA-25E643AA09DB}.job
C:\Windows\Tasks\{6A128791-4857-4484-9BB2-71D4C1257200}.job


Alguns arquivos em TEMP:
====================
C:\Users\Debora\AppData\Local\Temp\tasklisten.exe


==================== Bamital & volsnap =================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente
C:\windows\explorer.exe => O arquivo é assinado digitalmente
C:\windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\windows\system32\services.exe => O arquivo é assinado digitalmente
C:\windows\system32\User32.dll => O arquivo é assinado digitalmente
C:\windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente
C:\windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
C:\windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente


LastRegBack: 2016-01-29 13:58

==================== Fim de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité