cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x86) Versão:17-02-2016
Executado por Msantos (administrador) em ANGEL-PC (20-02-2016 01:06:51)
Executando a partir de C:\Users\Msantos\Videos
Perfis Carregados: Msantos (Perfis Disponíveis: Angel & Msantos)
Platform: Microsoft Windows 7 Starter Service Pack 1 (X86) Idioma: Português (Brasil)
Internet Explorer Versão 11 (Navegador padrão: IE)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(Baidu Inc.) C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFasterSvc.exe
(Baidu, Inc.) C:\Program Files\Baidu Security\MoboMarket\1.3.7.5967\bassvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Baidu, Inc.) C:\Program Files\Baidu Security\Baidu Antivirus\5.4.3.133394.0\BavSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Baidu, Inc.) C:\Program Files\Baidu Security\Baidu Antivirus\5.4.3.133394.0\BHipsSvc.exe
(Positivo Informática) C:\Positivo\Deskmedia\DeskmediaService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(RealNetworks, Inc.) C:\Program Files\Online Games Manager\ogmservice.exe
(Baidu Inc.) C:\Program Files\Baidu Security\PC App Store\4.8.1.7002\PCAppStoreSvc.exe
(Banco Bradesco S.A.) C:\Program Files\Scpad\scpVista.exe
(Baidu Inc.) C:\Program Files\baidu\Baidu Browser43.22.1000.436.1\sparkservice.exe
() C:\Program Files\WajaNetEn\c82964e5aa800f187cedd562ef63248a.exe
(TU-Funs LIMITED) C:\ProgramData\QWdMQ\WdMan.exe
(Irrational Number Applications) C:\ProgramData\xAHBEqSJje\MCGtdxNIro.exe
() C:\ProgramData\Uixucsuf\1.0.7.1\emumeaem.exe
() C:\ProgramData\Uixucsuf\1.0.7.1\emumeaem.exe
(DotC United Inc) C:\Program Files\MPC AdCleaner\AdCleaner.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Baidu Inc.) C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFTray.exe
(Baidu, Inc.) C:\Program Files\Baidu Security\MoboMarket\1.3.7.5967\bastray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(DotC United Inc) C:\Program Files\MPC AdCleaner\AdxEngine.exe
(Positivo Informática) C:\Positivo\Deskmedia\GerenciadorLocal.exe
(Baidu Inc.) C:\Program Files\Baidu Security\PC App Store\4.8.1.7002\AppStoreDeskTool.exe
(Baidu, Inc.) C:\Program Files\Baidu Security\Baidu Antivirus\5.4.3.133394.0\BavTray.exe
() C:\ProgramData\SmartProtect\SmartProtect.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Positivo Informática S.A.) C:\Program Files\Positivo Informática\Positivo Experience\Positivo Experience\PositivoAplicativosService.exe
() C:\ProgramData\msiql.exe
(Positivo Informática) C:\Positivo\Deskmedia\Posibar\Posibar.exe
() C:\Program Files\Buscapé na Hora\BuscapeNaHora.exe
() C:\Program Files\SearchesToYesbnd\bugreport.exe
(Positivo Informática S.A.) C:\Program Files\Positivo Informática\Positivo Experience\Positivo Backup\PositivoSmartBackup.exe
(Positivo Informática S.A.) C:\Program Files\Positivo Informática\Positivo Experience\Positivo Áudio\AudioPower.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
() C:\Program Files\CalendarTool\2.0.0.11189\CalendarServ.exe
() C:\Program Files\CalendarTool\2.0.0.11189\calendar.exe
(program ) C:\Windows\TEMP\16029\MediaDownloaderSetup.exe
(Baidu Inc.) C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFasterSvc.exe
() C:\Program Files\baidu\Baidu Browser43.22.1000.436.1\spark.exe
() C:\Program Files\baidu\Baidu Browser43.22.1000.436.1\spark.exe
() C:\Program Files\baidu\Baidu Browser43.22.1000.436.1\spark.exe
() C:\Program Files\baidu\Baidu Browser43.22.1000.436.1\spark.exe
() C:\Program Files\baidu\Baidu Browser43.22.1000.436.1\spark.exe
() C:\Program Files\baidu\Baidu Browser43.22.1000.436.1\spark.exe
() C:\Program Files\baidu\Baidu Browser43.22.1000.436.1\spark.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
() C:\Program Files\baidu\Baidu Browser43.22.1000.436.1\spark.exe


==================== Registro (Whitelisted) ===========================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [Baidu PC Faster 4.0.0.0] => C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFTray.exe [2131648 2015-01-06] (Baidu Inc.)
HKLM\...\Run: [StartUpManagerPositivo] => C:\Program Files\Positivo Informática\Gerenciador de Inicialização Positivo\ManagerWindows.exe [171520 2012-03-01] ()
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7711264 2009-08-18] (Realtek Semiconductor)
HKLM\...\Run: [Deskmedia] => C:\Positivo\Deskmedia\GerenciadorLocal.exe [1042408 2015-09-28] (Positivo Informática)
HKLM\...\Run: [Baidu PCAppStore_AppStoreDeskTool] => C:\Program Files\Baidu Security\PC App Store\4.8.1.7002\AppStoreDeskTool.exe [634912 2014-09-01] (Baidu Inc.)
HKLM\...\Run: [Baidu Antivirus] => C:\Program Files\Baidu Security\Baidu Antivirus\5.4.3.133394.0\BavTray.exe [1997296 2015-06-13] (Baidu, Inc.)
HKLM\...\Run: [LightGate] => C:\ProgramData\LightGate.exe [1081344 2015-12-04] ()
HKLM\...\Run: [HomePageHelper] => C:\ProgramData\HomePage.exe [1100288 2015-11-25] ()
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\Run: [SmartProtect] => C:\ProgramData\SmartProtect\SmartProtect.exe [47896 2013-11-01] ()
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\Run: [Dropbox Update] => C:\Users\Msantos\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-20] (Dropbox, Inc.)
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\Run: [JavaMsantos] => regsvr32.exe /s "c:\ProgramData\Msantos\Msantosj.gif"
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\Run: [YeaInstaller] => C:\Users\Msantos\AppData\Local\Temp\457UT7I5X\OY2W1AKQQ.exe <===== ATENÇÃO
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\Run: [msiql] => C:\ProgramData\msiql.exe [2415616 2016-01-26] ()
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\Run: [taskhost] => rundll32.exe C:\ProgramData\WindowsMsg\675D131108D4FD145B0BFBC68A3E018A.dll Start /DEFAULT
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\Run: [Pritc] => c:\programdata\windows update\tmp\msdtc-.exe [2980352 2016-01-08] (VLOME)
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\MountPoints2: {5fdb1712-e99d-11e1-b571-c89cdc46d844} - E:\KODAK_Software_Downloader.exe
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\MountPoints2: {655dc9c4-da9a-11e2-a8ed-c83a35d753c9} - E:\iLinker.exe
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\MountPoints2: {d5e53d26-a496-11e2-a5cc-c83a35d753c9} - E:\AutoRun.exe
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\MountPoints2: {f69de47c-95ed-11e1-b469-c89cdc46d844} - E:\AutoRun.exe
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\MountPoints2: {f69de48a-95ed-11e1-b469-c89cdc46d844} - E:\AutoRun.exe
HKU\S-1-5-18\...\Run: [Pritc] => c:\programdata\windows update\tmp\msdtc-.exe [2980352 2016-01-08] (VLOME)
HKU\S-1-5-18\...\Run: [msiql] => c:\programdata\msiql.exe [2415616 2016-01-26] ()
SSODL: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Program Files\Scpad\scpLIB.dll (Banco Bradesco S.A.)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Msantos\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Msantos\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Msantos\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Msantos\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Msantos\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Msantos\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Msantos\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Msantos\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Nenhum Arquivo
ShellIconOverlayIdentifiers: [4SyncOverlay1] -> {2012DE06-50C0-48BD-ACDE-88F95D4CAD1F} => Nenhum Arquivo
ShellIconOverlayIdentifiers: [4SyncOverlay2] -> {C72C6188-BEF2-46E5-A89A-52F0ED75219E} => Nenhum Arquivo
ShellIconOverlayIdentifiers: [4SyncOverlay3] -> {C92F6BC2-AF61-4C0E-80E0-939B8282DDB7} => Nenhum Arquivo
ShellIconOverlayIdentifiers: [BaiduAntivirusIconLock] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CC} => C:\Program Files\Baidu Security\Baidu Antivirus\5.4.3.133394.0\BavShx.dll [2015-06-13] (Baidu, Inc.)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => Nenhum Arquivo
BootExecute: autocheck autochk * bddel.exe
CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO
CHR HKU\S-1-5-21-600554673-3371071739-3465117734-1001\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-31] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{3A12B5AC-4A27-48E6-87BA-5FAD72856B0D}: [DhcpNameServer] 172.16.0.1 8.8.8.8
Tcpip\..\Interfaces\{60090F8D-3724-448B-8C89-34CF51A03507}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = search.mpc.am
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = search.mpc.am
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.msn.com/1me10IE11PTBR/MSN_WCP
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://facebook.com.br/
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.msn.com/1me10IE11PTBR/MSN_WCP
HKU\S-1-5-21-600554673-3371071739-3465117734-1001\Software\Microsoft\Internet Explorer\Main,Start Page = search.mpc.am
SearchScopes: HKLM -> DefaultScope {FAABF890-DB2A-4539-9110-2E8E75CB7B80} URL = hxxp://www.bing.com/search?q={searchTerms}&form=POSTDF&pc=POS2&src=IE-SearchBox
SearchScopes: HKLM -> Backup.Old.DefaultScope {900653BC-C42A-4B13-8D29-2EAF2A1EE9CA}
SearchScopes: HKLM -> {FAABF890-DB2A-4539-9110-2E8E75CB7B80} URL = hxxp://www.bing.com/search?q={searchTerms}&form=POSTDF&pc=POS2&src=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-21-600554673-3371071739-3465117734-1001 -> Backup.Old.DefaultScope {FD2FBA27-95D9-4E52-AC8A-0BA448BC5D90}
SearchScopes: HKU\S-1-5-21-600554673-3371071739-3465117734-1001 -> {86c83f9e-48a4-4cd2-a763-64fea5df35f7} URL = hxxp://br.yhs4.search.yahoo.com/yhs/search?hspart=baixaki&hsimp=yhs-baixaki_br_installcore_02&type=y&p={searchTerms}
BHO: Buscape na Hora Plugin -> {051FB9EC-79EA-4F8E-9EC2-F1FF4462FB09} -> C:\Program Files\Buscapé\Buscapé na Hora\IE\BphBHO.dll [2012-12-06] (Buscapé Company)
BHO: ssh2 Class -> {2E3C3651-B19C-4DD9-A979-901EC3E930AF} -> C:\Program Files\Scpad\scpsssh2.dll [2012-10-24] (Banco Bradesco S.A.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
Toolbar: HKU\.DEFAULT -> Sem Nome - {EEE6C35B-6118-11DC-9C72-001320C79847} - Nenhum Arquivo
Toolbar: HKU\S-1-5-21-600554673-3371071739-3465117734-1001 -> Sem Nome - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Nenhum Arquivo
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll Nenhum Arquivo
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL [2008-02-27] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll Nenhum Arquivo
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
StartMenuInternet: IEXPLORE.EXE - C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE hxxp://www.mysites123.com/?type=sc&ts=1455657234&z=1b14ba8a193f0cf9869d7dcgcz4w0w2q1w4mfo9c1q&from=tt4u&uid=ST500DM002-1BD142_S2A0BXC5XXXXS2A0BXC5

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-11] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-21] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-16] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-600554673-3371071739-3465117734-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Msantos\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-600554673-3371071739-3465117734-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Msantos\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-02-20] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-600554673-3371071739-3465117734-1001: facebook.com/fbDesktopPlugin -> C:\Users\Msantos\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll [2013-03-07] (Facebook, Inc.)
FF HKLM\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: HP Smart Print - C:\Program Files\Hewlett-Packard\SmartPrint\QPExtension [2013-03-19] [não assinado]
FF HKLM\...\Firefox\Extensions: [speedanalysis02@SpeedAnalysis.com] - C:\Users\Msantos\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
FF Extension: Speed Analysis 2 - C:\Users\Msantos\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com [2013-09-27] [não assinado]
FF HKLM\...\Firefox\Extensions: [seesimilar02@SeeSimilar.com] - C:\Users\Msantos\AppData\Roaming\Mozilla\Extensions\seesimilar02@SeeSimilar.com
FF Extension: SeeSimilar02 - C:\Users\Msantos\AppData\Roaming\Mozilla\Extensions\seesimilar02@SeeSimilar.com [2013-09-27] [não assinado]
FF HKU\.DEFAULT\...\Firefox\Extensions: [{58931F90-7418-F91C-7D0E-6744BB523292}] - C:\Program Files\version09CheckMeUp\194.xpi => não encontrado (a)
FF HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\Firefox\Extensions: [speedanalysis02@SpeedAnalysis.com] - C:\Users\Msantos\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
FF HKU\S-1-5-21-600554673-3371071739-3465117734-1001\...\Firefox\Extensions: [seesimilar02@SeeSimilar.com] - C:\Users\Msantos\AppData\Roaming\Mozilla\Extensions\seesimilar02@SeeSimilar.com

Chrome:
=======
CHR Profile: C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-03]
CHR Extension: (Google Drive) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-12]
CHR Extension: (YouTube) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-05]
CHR Extension: (Google Search) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-12]
CHR Extension: (Google Docs Offline) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-04]
CHR Extension: (Gmail) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-03]
CHR Profile: C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Drive) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-12]
CHR Extension: (YouTube) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-12]
CHR Extension: (Google Search) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-12]
CHR Extension: (Print a Tree) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\dmibjfmphcpfoacbchialfobiohmhged [2014-01-01]
CHR Extension: (DealPly Shopping) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ejnmnhkgiphcaeefbaooconkceehicfi [2014-01-02] [UpdateUrl: hxxp://chromeupdate.dealply.com/updates.xml] <==== ATENÇÃO
CHR Extension: (Funmoods) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdloijijlkoblmigdofommgnheckmaki [2014-01-14] [UpdateUrl: hxxp://funmoods.com/public/download/chrome/update.xml] <==== ATENÇÃO
CHR Extension: (avast! Online Security) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-01-02]
CHR Extension: (Clock) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjocghlclkpgheifflemilcnblodjohg [2013-11-20]
CHR Extension: (Google Wallet) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-02]
CHR Extension: (Gmail) - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-17]
CHR HKLM\...\Chrome\Extension: [dmibjfmphcpfoacbchialfobiohmhged] - C:\Users\Msantos\AppData\Roaming\PRINTA~1\printatreeChrome.crx
CHR HKLM\...\Chrome\Extension: [ialdollnlgfogbjjlmjkdmjdmocdhfio] - C:\Program Files\DealPly\DealPly.crx
CHR HKLM\...\Chrome\Extension: [ieadcoanfjloocmfafkebdnfefmohngj] - C:\Program Files\BonanzaDeals\BonanzaDeals.crx
CHR HKLM\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx
CHR HKLM\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Users\Msantos\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx
CHR HKU\S-1-5-21-600554673-3371071739-3465117734-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dmibjfmphcpfoacbchialfobiohmhged] - C:\Users\Msantos\AppData\Roaming\PRINTA~1\printatreeChrome.crx
StartMenuInternet: Google Chrome - C:\Program Files\Google\Chrome\Application\chrome.exe hxxp://www.mysites123.com/?type=sc&ts=1455657234&z=1b14ba8a193f0cf9869d7dcgcz4w0w2q1w4mfo9c1q&from=tt4u&uid=ST500DM002-1BD142_S2A0BXC5XXXXS2A0BXC5

==================== Serviços (Whitelisted) ========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 AppManagerService; C:\Program Files\Positivo Informática\Positivo Experience\Positivo Experience\PositivoAplicativosService.exe [65304 2013-10-10] (Positivo Informática S.A.)
R2 BASSVC; C:\Program Files\Baidu Security\MoboMarket\1.3.7.5967\bassvc.exe [208928 2015-04-22] (Baidu, Inc.)
R2 BavSvc; C:\Program Files\Baidu Security\Baidu Antivirus\5.4.3.133394.0\BavSvc.exe [2572928 2015-06-13] (Baidu, Inc.)
S3 BdSandboxSrv; C:\Program Files\Baidu Security\Baidu Antivirus\5.4.3.133394.0\BdSandboxSrv.exe [216608 2015-01-08] (Baidu, Inc.)
R2 BHipsSvc; C:\Program Files\Baidu Security\Baidu Antivirus\5.4.3.133394.0\BHipsSvc.exe [531232 2015-06-13] (Baidu, Inc.)
R2 BPH Service; C:\Program Files\Buscapé na Hora\BuscapeNaHora.exe [336304 2014-07-22] ()
S3 BsrSvc; C:\Program Files\Baidu Security\Baidu Antivirus\5.4.3.133394.0\BavAdvTools\128B4BEC-5D89-43AD-BAA8-207084AA0E4F\tool\BsrSvc.exe [2797416 2014-07-23] (Baidu, Inc.)
R2 DeskmediaService; C:\Positivo\Deskmedia\DeskmediaService.exe [250344 2015-09-28] (Positivo Informática)
S2 ggbugreport; C:\Program Files\SearchesToYesbnd\bugreport.exe [1588408 2016-02-04] ()
S2 GoogleChromeUpService; C:\ProgramData\service.exe [1734656 2016-01-11] () [Arquivo não assinado]
S2 GoogleChromeUpSvc; C:\ProgramData\Windows Update\svrupg.exe [2786816 2016-02-16] (TODO: ) [Arquivo não assinado]
R2 MCGtdxNIro; C:\ProgramData\xAHBEqSJje\MCGtdxNIro.exe [3002360 2016-02-19] (Irrational Number Applications)
R2 ogmservice; C:\Program Files\Online Games Manager\ogmservice.exe [581568 2014-03-27] (RealNetworks, Inc.)
R2 PCAppStoreSvc_{PCAppStore_4.8.1.7002}; C:\Program Files\Baidu Security\PC App Store\4.8.1.7002\PCAppStoreSvc.exe [550944 2014-09-01] (Baidu Inc.)
R2 PCFasterSvc_{PCFaster_4.0.0.0}; C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFasterSvc.exe [1636336 2015-01-06] (Baidu Inc.) [Arquivo não assinado]
S3 PSafeSVC; C:\Program Files\PSafe\PSafesvc.exe [2578120 2013-11-21] (PSafe S/A)
S3 PSafeWD; C:\Program Files\PSafe\PSafeWD.exe [265416 2013-11-21] (PSafe S.A.)
R2 scpVista; C:\Program Files\Scpad\scpVista.exe [360624 2012-10-24] (Banco Bradesco S.A.)
R2 SparkSvc; C:\Program Files\baidu\Baidu Browser43.22.1000.436.1\sparkservice.exe [97080 2016-01-01] (Baidu Inc.)
R2 TheCalendarService; C:\Program Files\CalendarTool\2.0.0.11189\CalendarServ.exe [141960 2015-12-25] ()
R2 WajaNetEn Monitor; C:\Program Files\WajaNetEn\c82964e5aa800f187cedd562ef63248a.exe [2492928 2016-02-09] () [Arquivo não assinado]
R2 WdMan; C:\ProgramData\QWdMQ\WdMan.exe [794376 2016-02-16] (TU-Funs LIMITED)
R2 WifihlsUpdate; C:\Windows\System32\Aclhost.dll [414456 2011-07-07] ()
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 Winsere; C:\Program Files\Winsere\Winsere\Winsere.exe [302776 2016-02-03] ()
S3 eSafeSvc; C:\ProgramData\eSafe\eGdpSvc.exe [X]
S2 mnkf; c:\windows\mnkf.exe [X]
S2 nkf; c:\windows\nkf.exe [X]
S3 SparkUpdater; C:\Program Files\Baidu\SparkUpdate\Sparkupdate.exe [X]

===================== Drivers (Whitelisted) ==========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R1 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [60600 2013-10-31] (360.cn)
R1 360FileOem; C:\Windows\system32\drivers\360FileOem.sys [146304 2012-05-31] (360.cn) [Arquivo não assinado]
R0 360HookOem; C:\Windows\System32\drivers\360HookOEM.sys [54912 2012-05-31] (360安全中心) [Arquivo não assinado]
R1 360RegOem; C:\Windows\system32\drivers\360RegOem.sys [23168 2012-05-31] (360安全中心) [Arquivo não assinado]
R1 360SpOEM; C:\Windows\System32\drivers\360SpOEM.sys [64048 2012-08-21] (360安全中心)
R2 Acladapter; C:\Windows\system32\drivers\gamzexdetech.sys [124056 2011-07-07] ()
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [26112 2010-04-29] (Google Inc)
R3 BdApiUtil; C:\Program Files\Baidu Security\Baidu Antivirus\5.4.3.133394.0\BdApiUtil.sys [101448 2015-06-13] (Baidu, Inc.)
R3 bdark; C:\Windows\system32\drivers\bdark.sys [82376 2015-05-15] ()
R3 BdCameraProtect; C:\Program Files\Baidu Security\Baidu Antivirus\5.4.3.133394.0\BdCameraProtect.sys [21384 2015-06-13] (Baidu, Inc.)
S3 BdSandbox; C:\Windows\System32\drivers\BdSandbox.sys [194552 2015-01-08] (Baidu, Inc.)
R1 Bfilter; C:\Windows\System32\drivers\Bfilter.sys [51144 2015-06-13] (Baidu, Inc.)
R1 Bfmon; C:\Windows\System32\drivers\Bfmon.sys [31176 2015-06-13] (Baidu, Inc.)
R0 Bhbase; C:\Windows\System32\drivers\Bhbase.sys [74888 2015-06-13] (Baidu, Inc.)
R3 BHipsEx; C:\Windows\System32\drivers\BHipsEx.sys [138184 2015-06-13] (Baidu, Inc.)
R1 Bnbase; C:\Windows\System32\drivers\bnbasex.sys [75400 2015-06-13] (Baidu, Inc.)
R1 Bndef; C:\Windows\System32\drivers\bndef.sys [461192 2015-06-13] (Baidu, Inc.)
R3 BNmon; C:\Program Files\Baidu Security\Baidu Antivirus\5.4.3.133394.0\Bnmon.sys [84936 2015-06-13] (Baidu, Inc.)
R1 bphfilterdrv; C:\Windows\System32\drivers\bphfilterdrv.sys [37480 2014-06-20] (NetFilterSDK.com)
R1 Bprotect; C:\Windows\System32\drivers\Bprotect.sys [195528 2015-06-13] (Baidu, Inc.)
R1 BprotectEx; C:\Windows\System32\drivers\BprotectEx.sys [115008 2014-12-17] (Baidu, Inc.)
S4 bsrbc; C:\Windows\System32\drivers\bsrbc.sys [44736 2014-09-16] ()
R1 ndisrd; C:\Windows\System32\DRIVERS\ndisrd.sys [37408 2014-08-14] (NT Kernel Resources)
S3 PAC207; C:\Windows\System32\DRIVERS\PFC027.SYS [507136 2006-12-05] (PixArt Imaging Inc.)
R3 PCFApiUtil; C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFApiUtil.sys [119168 2014-06-30] (Baidu, Inc.)
R3 PositivoAudioDriverWdm; C:\Windows\System32\DRIVERS\pad.sys [52496 2011-08-11] ()
R0 MPCBase; System32\drivers\MPCBase.sys [X]
R1 MPCKpt; system32\DRIVERS\MPCKpt.sys [X]
S1 pfnfd_1_10_0_8; system32\drivers\pfnfd_1_10_0_8.sys [X]
S3 Spring; \??\C:\Program Files\Baidu Security\Baidu Antivirus\Spring.sys [X]
U0 sr; não ImagePath

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um Mês Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-02-20 00:52 - 2016-02-20 01:06 - 00000000 ____D C:\FRST
2016-02-19 23:06 - 2016-02-19 23:06 - 00000000 ____D C:\Program Files\CalendarTool
2016-02-19 23:05 - 2016-02-19 23:05 - 00000000 _____ C:\Windows\system32\ws.db
2016-02-19 22:32 - 2016-02-20 00:25 - 00000000 ____D C:\Users\Msantos\AppData\Roaming\CalendarTool
2016-02-19 20:54 - 2016-02-19 23:26 - 00000000 ____D C:\Program Files\JFileManager
2016-02-19 18:17 - 2016-02-19 18:18 - 00000000 ____D C:\Users\Todos os Usuários\xAHBEqSJje
2016-02-19 18:17 - 2016-02-19 18:18 - 00000000 ____D C:\ProgramData\xAHBEqSJje
2016-02-19 18:17 - 2016-02-19 18:17 - 00000000 ____D C:\Users\Todos os Usuários\WebShield
2016-02-19 18:17 - 2016-02-19 18:17 - 00000000 ____D C:\ProgramData\WebShield
2016-02-19 04:22 - 2016-02-19 04:22 - 00000000 ____D C:\Users\Msantos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-02-19 00:37 - 2016-02-19 23:04 - 00000000 ____D C:\Program Files\MPC AdCleaner
2016-02-19 00:37 - 2016-02-19 00:37 - 00000000 ____D C:\Users\Msantos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MPC AdCleaner
2016-02-18 21:44 - 2016-02-19 20:11 - 00000483 _____ C:\Users\Todos os Usuários\xcgui_debug.txt
2016-02-18 21:44 - 2016-02-19 20:11 - 00000483 _____ C:\ProgramData\xcgui_debug.txt
2016-02-18 20:03 - 2016-02-18 20:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WajaNetEn
2016-02-18 20:02 - 2016-02-18 20:03 - 00000000 ____D C:\Program Files\WajaNetEn
2016-02-18 20:01 - 2016-02-19 23:48 - 00000000 ____D C:\Program Files\MPC Cleaner
2016-02-17 23:06 - 2016-02-17 23:06 - 00631808 _____ C:\Windows\nkf.dat
2016-02-17 22:44 - 2016-02-19 23:14 - 00001852 ____R C:\Users\Msantos\Desktop\Yeabeats Browser.lnk
2016-02-16 21:02 - 2016-02-16 21:26 - 00000000 ____D C:\Users\Msantos\AppData\Local\WebShield
2016-02-16 19:55 - 2016-02-16 19:55 - 00000000 ____D C:\Program Files\OLBPre
2016-02-16 19:51 - 2016-02-16 21:42 - 00000000 ____D C:\Program Files\version09CheckMeUp
2016-02-16 19:34 - 2016-02-19 23:05 - 00000000 ____D C:\Users\Msantos\AppData\Roaming\LightGate
2016-02-16 19:28 - 2015-11-25 15:31 - 01100288 _____ C:\Users\Todos os Usuários\HomePage.exe
2016-02-16 19:28 - 2015-11-25 15:31 - 01100288 _____ C:\ProgramData\HomePage.exe
2016-02-16 19:20 - 2016-02-19 23:04 - 00000000 ____D C:\Users\Todos os Usuários\WindowsMsg
2016-02-16 19:20 - 2016-02-19 23:04 - 00000000 ____D C:\ProgramData\WindowsMsg
2016-02-16 19:20 - 2016-02-19 23:04 - 00000000 ____D C:\Program Files\osTip
2016-02-16 19:19 - 2016-02-16 19:20 - 00000000 ____D C:\Users\Public\Documents\Tools
2016-02-16 19:18 - 2016-02-16 19:19 - 00000000 ____D C:\Users\Todos os Usuários\Windows Update
2016-02-16 19:18 - 2016-02-16 19:19 - 00000000 ____D C:\ProgramData\Windows Update
2016-02-16 19:18 - 2016-02-16 19:18 - 00000000 ____D C:\Users\Public\Documents\Guid
2016-02-16 19:17 - 2016-02-19 23:06 - 00010365 _____ C:\Users\Todos os Usuários\webad.xml
2016-02-16 19:17 - 2016-02-19 23:06 - 00010365 _____ C:\ProgramData\webad.xml
2016-02-16 19:17 - 2015-12-10 15:43 - 00600312 _____ C:\Users\Todos os Usuários\YeaPlayer_br_IBD_Bundle.exe
2016-02-16 19:17 - 2015-12-10 15:43 - 00600312 _____ C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe
2016-02-16 19:17 - 2015-12-04 13:14 - 01081344 _____ C:\Users\Todos os Usuários\LightGate.exe
2016-02-16 19:17 - 2015-12-04 13:14 - 01081344 _____ C:\ProgramData\LightGate.exe
2016-02-16 19:16 - 2016-02-16 19:17 - 00000000 ____D C:\Users\Todos os Usuários\QWdMQ
2016-02-16 19:16 - 2016-02-16 19:17 - 00000000 ____D C:\ProgramData\QWdMQ
2016-02-16 19:16 - 2016-02-16 19:16 - 00000074 _____ C:\Users\Todos os Usuários\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2016-02-16 19:16 - 2016-02-16 19:16 - 00000074 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2016-02-16 19:16 - 2016-01-26 11:54 - 02415616 _____ C:\Users\Todos os Usuários\msiql.exe
2016-02-16 19:16 - 2016-01-26 11:54 - 02415616 _____ C:\ProgramData\msiql.exe
2016-02-16 19:14 - 2016-02-16 20:52 - 00000000 ____D C:\Users\Msantos\AppData\Roaming\mysites123
2016-02-16 19:14 - 2016-01-11 15:49 - 01734656 _____ C:\Users\Todos os Usuários\service.exe
2016-02-16 19:14 - 2016-01-11 15:49 - 01734656 _____ C:\Users\Msantos\AppData\Roaming\service.exe
2016-02-16 19:14 - 2016-01-11 15:49 - 01734656 _____ C:\ProgramData\service.exe
2016-02-16 19:08 - 2016-02-19 18:24 - 00000000 ____D C:\Users\Todos os Usuários\Uixucsuf
2016-02-16 19:08 - 2016-02-19 18:24 - 00000000 ____D C:\ProgramData\Uixucsuf
2016-02-16 19:00 - 2016-02-16 19:08 - 00000000 ____D C:\Users\Msantos\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-02-16 19:00 - 2016-02-16 19:00 - 00000000 ____D C:\Program Files\WinTaske
2016-02-16 19:00 - 2016-02-16 19:00 - 00000000 ____D C:\Program Files\Winsere
2016-02-16 19:00 - 2016-02-16 19:00 - 00000000 ____D C:\extensions
2016-02-16 18:59 - 2016-02-16 21:42 - 00000000 ____D C:\Program Files\SearchesToYesbnd
2016-02-16 18:58 - 2016-02-16 19:00 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-02-16 18:56 - 2016-02-16 18:56 - 00000000 ____D C:\Users\Msantos\AppData\Local\Setup Wizard
2016-02-11 13:44 - 2016-02-11 13:45 - 00000000 ___HD C:\$WINDOWS.~BT
2016-02-11 01:57 - 2016-01-22 04:13 - 03993536 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2016-02-11 01:57 - 2016-01-22 04:13 - 03938752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-02-11 01:57 - 2016-01-22 04:13 - 00138176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-02-11 01:57 - 2016-01-22 04:13 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-02-11 01:57 - 2016-01-22 04:09 - 01310232 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-02-11 01:57 - 2016-01-22 04:04 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2016-02-11 01:57 - 2016-01-22 04:04 - 00535040 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2016-02-11 01:57 - 2016-01-22 04:02 - 00872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-02-11 01:57 - 2016-01-22 04:02 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-02-11 01:57 - 2016-01-22 04:02 - 00293888 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-02-11 01:57 - 2016-01-22 04:02 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\msorcl32.dll
2016-02-11 01:57 - 2016-01-22 04:02 - 00114176 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-02-11 01:57 - 2016-01-22 03:59 - 00642560 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-02-11 01:56 - 2016-01-22 04:06 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-02-11 01:56 - 2016-01-22 04:06 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-02-11 01:56 - 2016-01-22 04:06 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-02-11 01:56 - 2016-01-22 04:06 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-02-11 01:56 - 2016-01-22 04:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-02-11 01:56 - 2016-01-22 04:06 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-02-11 01:56 - 2016-01-22 04:05 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-02-11 01:56 - 2016-01-22 04:05 - 00251392 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-02-11 01:56 - 2016-01-22 04:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-02-11 01:56 - 2016-01-22 04:02 - 01060864 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-02-11 01:56 - 2016-01-22 04:02 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-02-11 01:56 - 2016-01-22 04:02 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-02-11 01:56 - 2016-01-22 04:02 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-02-11 01:56 - 2016-01-22 04:02 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 03:07 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-02-11 01:56 - 2016-01-22 03:01 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-02-11 01:56 - 2016-01-22 03:00 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-02-11 01:56 - 2016-01-22 02:53 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-02-11 01:56 - 2016-01-22 02:53 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-02-11 01:56 - 2016-01-22 02:53 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-02-11 01:56 - 2016-01-22 02:51 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-02-11 01:56 - 2016-01-22 02:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-02-11 01:56 - 2016-01-22 02:51 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-02-11 01:56 - 2016-01-22 02:51 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-02-11 01:56 - 2016-01-22 02:51 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 02:51 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 02:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-02-11 01:56 - 2016-01-22 02:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-02-10 05:25 - 2016-01-22 18:10 - 00341200 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-02-10 05:25 - 2016-01-22 04:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-02-10 05:25 - 2016-01-22 03:55 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-02-10 05:25 - 2016-01-22 03:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-02-10 05:25 - 2016-01-22 03:52 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-02-10 05:25 - 2016-01-22 03:51 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-02-10 05:25 - 2016-01-22 03:51 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-02-10 05:25 - 2016-01-22 03:46 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-02-10 05:25 - 2016-01-22 03:43 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-02-10 05:25 - 2016-01-22 03:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-02-10 05:25 - 2016-01-22 03:38 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-02-10 05:25 - 2016-01-22 03:33 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-02-10 05:25 - 2016-01-22 03:25 - 00687104 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-02-10 05:25 - 2016-01-22 03:25 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-02-10 05:25 - 2016-01-22 03:02 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-02-10 05:24 - 2016-01-22 04:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-02-10 05:24 - 2016-01-22 04:02 - 00496640 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-02-10 05:24 - 2016-01-22 04:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-02-10 05:24 - 2016-01-22 04:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-02-10 05:24 - 2016-01-22 04:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-02-10 05:24 - 2016-01-22 03:51 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-02-10 05:24 - 2016-01-22 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-02-10 05:24 - 2016-01-22 03:35 - 04611072 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-02-10 05:24 - 2016-01-22 03:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-02-10 05:24 - 2016-01-22 03:34 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-02-10 05:24 - 2016-01-22 03:27 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-02-10 05:24 - 2016-01-22 03:24 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-02-10 05:24 - 2016-01-22 03:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-02-10 05:24 - 2016-01-22 03:07 - 02120704 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-02-10 05:22 - 2016-01-16 16:42 - 00022464 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-02-10 05:22 - 2016-01-16 16:34 - 00949760 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-02-10 05:22 - 2016-01-11 12:07 - 01198080 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-02-10 05:22 - 2016-01-11 12:07 - 00591360 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-02-10 05:22 - 2016-01-11 12:07 - 00544768 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-02-10 05:22 - 2016-01-11 12:07 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-02-10 05:22 - 2016-01-11 12:07 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-02-10 05:10 - 2016-01-16 16:36 - 01413632 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-02-10 05:07 - 2016-01-22 04:05 - 12877824 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-02-10 05:07 - 2016-01-22 04:00 - 01498624 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2016-02-10 05:07 - 2016-01-22 03:59 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-02-10 05:07 - 2016-01-22 03:12 - 02973184 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-02-10 05:06 - 2016-01-06 16:41 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2016-02-10 05:05 - 2016-01-07 15:47 - 02386944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-02-10 05:05 - 2016-01-07 15:35 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-02-10 05:02 - 2016-02-06 08:01 - 20366848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-02-10 05:02 - 2016-02-06 07:54 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-02-10 05:02 - 2016-02-06 07:43 - 02280448 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-02-10 05:02 - 2016-02-06 07:38 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-02-10 05:02 - 2016-02-06 07:16 - 12857856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-02-10 05:02 - 2016-02-06 06:54 - 01312256 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-02-10 05:01 - 2016-01-11 16:47 - 02956288 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2016-02-10 05:01 - 2016-01-11 16:47 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2016-02-10 05:01 - 2016-01-11 16:35 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2016-02-10 05:01 - 2016-01-11 16:17 - 02062848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-02-10 05:01 - 2016-01-11 16:14 - 00573440 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2016-02-10 05:01 - 2016-01-11 16:14 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2016-02-10 05:01 - 2016-01-11 16:14 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2016-02-10 05:01 - 2016-01-11 16:14 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2016-02-10 05:01 - 2016-01-11 16:14 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2016-02-10 05:01 - 2016-01-11 16:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2016-02-10 05:01 - 2016-01-11 16:14 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll

==================== Um Mês Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-02-20 01:05 - 2009-07-14 00:37 - 00000000 ____D C:\Windows\inf
2016-02-20 00:37 - 2013-09-26 03:59 - 00000300 _____ C:\Windows\Tasks\Printatree.job
2016-02-20 00:13 - 2015-06-20 17:00 - 00001038 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-600554673-3371071739-3465117734-1001UA.job
2016-02-20 00:03 - 2013-07-12 13:30 - 00000000 ____D C:\Users\Msantos\AppData\LocalLow\Scpad
2016-02-19 23:45 - 2012-03-29 12:51 - 00000000 ____D C:\Users\Msantos\AppData\Local\CrashDumps
2016-02-19 23:38 - 2014-08-21 00:44 - 00000000 ____D C:\Users\Todos os Usuários\BAVSvc_exe
2016-02-19 23:38 - 2014-08-21 00:44 - 00000000 ____D C:\ProgramData\BAVSvc_exe
2016-02-19 23:13 - 2013-12-19 19:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Baidu PC Faster
2016-02-19 23:13 - 2009-07-14 02:34 - 00016160 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-02-19 23:13 - 2009-07-14 02:34 - 00016160 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-02-19 23:12 - 2013-07-13 15:40 - 00002022 ____R C:\Users\Public\Desktop\Google Chrome.lnk
2016-02-19 23:06 - 2015-12-09 00:45 - 00002201 ____R C:\Users\Public\Desktop\Facebook.lnk
2016-02-19 23:06 - 2015-02-03 12:26 - 00002223 ____R C:\Users\Public\Desktop\Baidu Browser.lnk
2016-02-19 23:05 - 2013-03-19 13:47 - 00000000 ___HD C:\Users\Todos os Usuários\SmartProtect
2016-02-19 23:05 - 2013-03-19 13:47 - 00000000 ___HD C:\ProgramData\SmartProtect
2016-02-19 23:03 - 2012-12-31 17:06 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2016-02-19 23:03 - 2009-07-14 02:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-19 22:32 - 2012-09-19 02:56 - 00000936 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-600554673-3371071739-3465117734-1001UA.job
2016-02-19 20:09 - 2011-04-12 02:47 - 00026788 _____ C:\Windows\system32\prfh0416.dat
2016-02-19 20:09 - 2011-04-12 02:47 - 00013932 _____ C:\Windows\system32\prfc0416.dat
2016-02-19 20:09 - 2010-11-20 19:01 - 00784830 _____ C:\Windows\system32\PerfStringBackup.INI
2016-02-19 17:14 - 2011-12-15 11:10 - 00000000 ____D C:\Windows\Panther
2016-02-19 12:12 - 2015-06-20 17:00 - 00000986 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-600554673-3371071739-3465117734-1001Core.job
2016-02-19 11:10 - 2014-05-11 18:21 - 00000000 ___RD C:\Users\Msantos\Dropbox
2016-02-19 10:32 - 2012-09-19 02:56 - 00000914 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-600554673-3371071739-3465117734-1001Core.job
2016-02-19 04:24 - 2014-05-11 18:08 - 00000000 ____D C:\Users\Msantos\AppData\Roaming\Dropbox
2016-02-19 02:12 - 2015-11-30 00:16 - 00000000 ____D C:\Users\Msantos\Documents\Meus Arquivos
2016-02-19 01:02 - 2009-07-14 00:37 - 00000000 ____D C:\Windows\tracing
2016-02-18 12:33 - 2009-07-14 00:37 - 00000000 ____D C:\Windows\system32\NDF
2016-02-17 22:57 - 2012-03-29 12:28 - 00000000 ____D C:\Users\Msantos\AppData\Roaming\SoftGrid Client
2016-02-17 22:33 - 2009-07-14 02:53 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-02-17 12:00 - 2015-11-13 13:22 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-02-16 20:52 - 2012-03-28 14:03 - 00001389 _____ C:\Users\Msantos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-02-16 19:41 - 2009-07-14 02:46 - 00001515 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-02-16 19:14 - 2013-11-24 07:59 - 00000000 ____D C:\BaiduDownloads
2016-02-11 03:49 - 2012-03-30 10:01 - 00000902 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-02-11 03:09 - 2012-03-30 10:01 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-02-11 03:09 - 2012-03-30 10:01 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-02-11 03:02 - 2009-07-14 02:33 - 00451240 _____ C:\Windows\system32\FNTCACHE.DAT
2016-02-11 02:59 - 2015-01-14 09:26 - 00000000 ____D C:\Windows\system32\appraiser
2016-02-11 02:59 - 2014-04-30 04:02 - 00000000 ___SD C:\Windows\system32\CompatTel
2016-02-11 01:11 - 2015-11-29 20:47 - 00000000 ____D C:\Users\Msantos\AppData\Roaming\4shared Desktop
2016-02-10 13:54 - 2013-08-02 12:31 - 00000000 ____D C:\Users\Msantos\Downloads\Músicas
2016-02-10 13:47 - 2015-11-30 19:53 - 00000000 ___HD C:\Users\Msantos\Downloads\.4sh
2016-02-09 01:10 - 2014-06-08 11:59 - 00000000 ____D C:\Users\Msantos\Downloads\musicas novas
2016-02-01 22:22 - 2012-04-04 01:12 - 00000000 ____D C:\Users\Msantos\AppData\Local\ElevatedDiagnostics
2016-01-27 21:39 - 2012-09-13 13:08 - 00000000 ___RD C:\Users\Msantos\SkyDrive
2016-01-27 13:14 - 2015-12-09 19:08 - 00000099 _____ C:\Windows\Reimage.ini

==================== Arquivos na raiz de alguns diretórios =======

2015-05-08 21:57 - 2015-05-08 21:57 - 6103040 _____ () C:\Program Files\GUT1613.tmp
2015-12-22 21:10 - 2015-12-22 21:10 - 0000095 _____ () C:\Users\Msantos\AppData\Roaming\comec.bat
2015-12-22 21:10 - 2015-12-22 21:10 - 0805376 _____ () C:\Users\Msantos\AppData\Roaming\fugonff.dll
2014-05-17 19:22 - 2014-05-12 18:41 - 0261859 _____ () C:\Users\Msantos\AppData\Roaming\igfxtrayrc.mod
2014-05-17 19:22 - 2014-05-17 19:22 - 5693106 _____ () C:\Users\Msantos\AppData\Roaming\igfxtrayrc.zip
2014-05-17 19:22 - 2014-05-12 18:40 - 0426543 _____ () C:\Users\Msantos\AppData\Roaming\modgeral.mod
2014-05-17 19:22 - 2014-05-12 18:41 - 0235571 _____ () C:\Users\Msantos\AppData\Roaming\modoutlook.mod
2014-05-17 19:22 - 2014-05-12 18:41 - 3787307 _____ () C:\Users\Msantos\AppData\Roaming\modremoto.mod
2015-12-22 21:08 - 2015-12-22 21:08 - 0000006 _____ () C:\Users\Msantos\AppData\Roaming\NO.txt
2016-02-16 19:14 - 2016-01-11 15:49 - 1734656 _____ () C:\Users\Msantos\AppData\Roaming\service.exe
2013-09-27 23:20 - 2013-09-27 23:18 - 0030894 _____ () C:\Users\Msantos\AppData\Roaming\speedanalysis.ico
2012-04-29 00:55 - 2012-04-29 00:55 - 0020835 _____ () C:\Users\Msantos\AppData\Roaming\UserTile.png
2013-07-27 01:24 - 2014-02-09 00:46 - 0000201 _____ () C:\Users\Msantos\AppData\Roaming\WB.CFG
2013-07-19 15:24 - 2013-12-12 00:45 - 0000006 _____ () C:\Users\Msantos\AppData\Roaming\WBPU-TTL.DAT
2013-08-02 20:35 - 2013-09-24 05:52 - 0000119 _____ () C:\Users\Msantos\AppData\Local\ap_UA-24552437-8.txt
2013-08-02 20:34 - 2013-09-24 02:53 - 0000119 _____ () C:\Users\Msantos\AppData\Local\ap_UA-24552437-9.txt
2012-03-30 14:55 - 2012-03-30 14:55 - 0003584 _____ () C:\Users\Msantos\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-05-27 10:49 - 2012-06-12 04:19 - 0031470 _____ () C:\Users\Msantos\AppData\Local\funmoods.crx
2015-07-04 22:33 - 2015-07-04 22:33 - 0000036 _____ () C:\Users\Msantos\AppData\Local\housecall.guid.cache
2014-04-16 00:42 - 2014-06-21 05:20 - 0007609 _____ () C:\Users\Msantos\AppData\Local\Resmon.ResmonCfg
2013-03-19 13:46 - 2013-03-19 13:46 - 0000057 ____N () C:\ProgramData\Ament.ini
2015-01-30 00:36 - 2015-01-30 00:36 - 0014501 _____ () C:\ProgramData\Duplicaterecord.js
2013-11-22 09:40 - 2013-11-22 09:40 - 0170344 _____ (Baidu, Inc.) C:\ProgramData\FileSplitUpLoad.dll
2016-02-16 19:28 - 2015-11-25 15:31 - 1100288 _____ () C:\ProgramData\HomePage.exe
2016-02-16 19:17 - 2015-12-04 13:14 - 1081344 _____ () C:\ProgramData\LightGate.exe
2012-10-14 11:25 - 2013-10-22 11:38 - 0000868 ____N () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2016-02-16 19:16 - 2016-01-26 11:54 - 2415616 _____ () C:\ProgramData\msiql.exe
2016-02-16 19:14 - 2016-01-11 15:49 - 1734656 _____ () C:\ProgramData\service.exe
2016-02-16 19:17 - 2016-02-19 23:06 - 0010365 _____ () C:\ProgramData\webad.xml
2016-02-18 21:44 - 2016-02-19 20:11 - 0000483 _____ () C:\ProgramData\xcgui_debug.txt
2016-02-16 19:17 - 2015-12-10 15:43 - 0600312 _____ () C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe
2016-02-16 19:16 - 2016-02-16 19:16 - 0000074 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat

Arquivos para serem movidos ou deletados:
====================
C:\ProgramData\Duplicaterecord.js
C:\ProgramData\FileSplitUpLoad.dll
C:\ProgramData\HomePage.exe
C:\ProgramData\LightGate.exe
C:\ProgramData\msiql.exe
C:\ProgramData\service.exe
C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
C:\Users\Todos os Usuários\Duplicaterecord.js
C:\Users\Todos os Usuários\FileSplitUpLoad.dll
C:\Users\Todos os Usuários\HomePage.exe
C:\Users\Todos os Usuários\LightGate.exe
C:\Users\Todos os Usuários\msiql.exe
C:\Users\Todos os Usuários\service.exe
C:\Users\Todos os Usuários\YeaPlayer_br_IBD_Bundle.exe
C:\Users\Todos os Usuários\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat


Alguns arquivos em TEMP:
====================
C:\Users\Msantos\AppData\Local\Temp\FRST.exe


==================== Bamital & volsnap =================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\Windows\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\system32\services.exe => O arquivo é assinado digitalmente
C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente
C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente


LastRegBack: 2016-02-18 03:18

==================== Fim de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité