cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x86) Versão:21-02-2016 01
Executado por pessoal (administrador) em PESSOAL-PC (22-02-2016 22:41:56)
Executando a partir de C:\Users\pessoal\Desktop
Perfis Carregados: pessoal (Perfis Disponíveis: pessoal)
Platform: Microsoft Windows 7 Professional (X86) Idioma: Português (Brasil)
Internet Explorer Versão 8 (Navegador padrão: Chrome)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(IObit) C:\Program Files\IObit\Advanced SystemCare\ASCService.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(GAS Tecnologia) C:\Program Files\GbPlugin\GbpSv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(GAS Tecnologia) C:\Program Files\GbPlugin\GbpSv.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare\Monitor.exe
(Newzie) C:\Users\pessoal\AppData\Roaming\alFSVWJB\winhlp32.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
() C:\ProgramData\msiql.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(UpAurora.COM) C:\Users\pessoal\AppData\Roaming\UpAuroraBrowser\Installer\UpAuroraKernelService.exe
() C:\Users\pessoal\AppData\Roaming\XBox\XBLive.exe
() C:\ProgramData\WindowsMsg\osmsg.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer.exe
(Newzie) C:\Users\pessoal\AppData\Roaming\alFSVWJB\winhlp32.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(TODO: ) C:\Users\pessoal\Documents\ovkkf.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\tv_w32.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(IObit) C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe
(Oracle Corporation) C:\Program Files\Java\jre1.8.0_66\bin\jp2launcher.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
() C:\Program Files\CalendarTool\2.0.0.11189\CalendarServ.exe
() C:\Program Files\CalendarTool\2.0.0.11189\calendar.exe
(IObit) C:\Program Files\IObit\Advanced SystemCare\ASCTray.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe
(TODO: ) C:\Users\pessoal\Documents\oikln.exe
() C:\Program Files\CalendarTool\2.0.0.11189\CrashReport.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registro (Whitelisted) ===========================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [10082920 2011-05-31] (Realtek Semiconductor)
HKLM\...\Run: [avast5] => C:\Program Files\Alwil Software\Avast5\avastUI.exe [2837864 2010-06-28] (AVAST Software)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-26] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-12-03] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM\...\Run: [winhlp32.exe] => C:\Users\pessoal\AppData\Roaming\alFSVWJB\winhlp32.exe [227328 2009-07-13] (Newzie)
Winlogon\Notify\ GbPluginCef: C:\Program Files\GbPlugin\gbiehCef.dll [2015-09-01] (Caixa Economica Federal)
HKLM\...\Policies\Explorer\Run: [2387058] => C:\ProgramData\msiwnql.exe [229888 2009-07-13] (PortableApps.com)
HKLM\...\Policies\Explorer\Run: [1991300243] => C:\ProgramData\mszgunir.exe [290304 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [934353930] => C:\ProgramData\msmhsofk.exe [290816 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [1552537398] => C:\ProgramData\msvau.exe [282112 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [104611188] => C:\ProgramData\mswsfm.exe [229888 2009-07-13] (PortableApps.com)
HKLM\...\Policies\Explorer\Run: [1245168569] => C:\ProgramData\mszopdn.exe [269824 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [1396067854] => C:\ProgramData\msfrtjr.exe [284672 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [1070971067] => C:\ProgramData\mschwya.exe [267776 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [254392593] => C:\ProgramData\msireqxo.exe [222208 2009-07-13] (© XTreme ©)
HKLM\...\Policies\Explorer\Run: [765775954] => C:\ProgramData\msnvuefo.exe [222208 2009-07-13] (© XTreme ©)
HKLM\...\Policies\Explorer\Run: [688756006] => C:\ProgramData\msaesgn.exe [223232 2009-07-13] (© XTreme ©)
HKLM\...\Policies\Explorer\Run: [890539750] => C:\ProgramData\mskhbua.exe [294912 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [1175518101] => C:\ProgramData\mshfg.exe [239616 2009-07-13] (Incorporate)
HKLM\...\Policies\Explorer\Run: [1276654741] => C:\ProgramData\msanldgu.exe [294912 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [1021399794] => C:\ProgramData\mspsjpjb.exe [282624 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [140309669] => C:\ProgramData\msbvvrdaj.exe [239616 2009-07-13] (Incorporate)
HKLM\...\Policies\Explorer\Run: [1060425607] => C:\ProgramData\mseuc.exe [269824 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [1566368384] => C:\ProgramData\msbjjqxm.exe [269824 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [309348965] => C:\ProgramData\msirjrlqa.exe [294912 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [1183914492] => C:\ProgramData\msqck.exe [267776 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [1320603425] => C:\ProgramData\msuurdq.exe [108544 2009-07-13] (Nokia Corporation and/or its subsidiary(-ies))
HKLM\...\Policies\Explorer\Run: [490528167] => C:\ProgramData\msfhoiviv.exe [108544 2009-07-13] (Nokia Corporation and/or its subsidiary(-ies))
HKLM\...\Policies\Explorer\Run: [1395454648] => C:\ProgramData\msqcobx.exe [107520 2009-07-13] (Nokia Corporation and/or its subsidiary(-ies))
HKLM\...\Policies\Explorer\Run: [1597020259] => C:\ProgramData\msarlvecs.exe [109056 2009-07-13] (Nokia Corporation and/or its subsidiary(-ies))
HKLM\...\Policies\Explorer\Run: [1840359701] => C:\ProgramData\msrztkegx.exe [294912 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [968115562] => C:\ProgramData\msblj.exe [109056 2009-07-13] (Nokia Corporation and/or its subsidiary(-ies))
HKLM\...\Policies\Explorer\Run: [650028419] => C:\ProgramData\msarx.exe [258560 2009-07-13] (The Code::Blocks Team)
HKLM\...\Policies\Explorer\Run: [2048487651] => C:\ProgramData\mssgt.exe [258560 2009-07-13] (The Code::Blocks Team)
HKLM\...\Policies\Explorer\Run: [494377809] => C:\ProgramData\mszcp.exe [218624 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [814077404] => C:\ProgramData\msixzbir.exe [230912 2009-07-13] (medical bag)
HKLM\...\Policies\Explorer\Run: [1077217615] => C:\ProgramData\msrnjv.exe [237568 2009-07-13] (medical bag)
HKLM\...\Policies\Explorer\Run: [1507541035] => C:\ProgramData\msduibuw.exe [238592 2009-07-13] (Incorporate)
HKLM\...\Policies\Explorer\Run: [1699565410] => C:\ProgramData\msihlz.exe [238592 2009-07-13] (Incorporate)
HKLM\...\Policies\Explorer\Run: [243821027] => C:\ProgramData\mspfn.exe [218112 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [1801872187] => C:\ProgramData\msmxsvi.exe [231936 2009-07-13] (medical bag)
HKLM\...\Policies\Explorer\Run: [137847306] => C:\ProgramData\mskweavf.exe [231936 2009-07-13] (medical bag)
HKLM\...\Policies\Explorer\Run: [116513985] => C:\ProgramData\msufgj.exe [230912 2009-07-13] (medical bag)
HKLM\...\Policies\Explorer\Run: [1144796724] => C:\ProgramData\msfmpvfli.exe [206848 2009-07-13] (MyBrains inc)
HKLM\...\Policies\Explorer\Run: [1718167835] => C:\ProgramData\msudvc.exe [205312 2009-07-13] (MyBrains inc)
HKLM\...\Policies\Explorer\Run: [1886196052] => C:\ProgramData\msmvyvcyx.exe [206848 2009-07-13] (MyBrains inc)
HKLM\...\Policies\Explorer\Run: [156295044] => C:\ProgramData\msbkdb.exe [205312 2009-07-13] (MyBrains inc)
HKLM\...\Policies\Explorer\Run: [53725507] => C:\ProgramData\mszyiut.exe [207360 2009-07-13] (MyBrains inc)
HKLM\...\Policies\Explorer\Run: [744133456] => C:\ProgramData\msevdp.exe [218112 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [461900327] => C:\ProgramData\mshsbjq.exe [219648 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [1786105603] => C:\ProgramData\msbljvbs.exe [219136 2009-07-13] ()
HKLM\...\Policies\Explorer\Run: [832538017] => C:\ProgramData\msbqp.exe [102400 2009-07-13] (AnVir Software)
HKLM\...\Policies\Explorer\Run: [1928829774] => C:\ProgramData\msgmpyrpc.exe [103936 2009-07-13] (AnVir Software)
HKLM\...\Policies\Explorer\Run: [787206877] => C:\ProgramData\msvzsccax.exe [104448 2009-07-13] (AnVir Software)
HKLM\...\Policies\Explorer\Run: [57113651] => C:\ProgramData\msetbzu.exe [229888 2009-07-13] (PortableApps.com)
HKLM\...\Policies\Explorer\Run: [152136678] => C:\ProgramData\mstdjcnt.exe [229888 2009-07-13] (PortableApps.com)
HKLM\...\Policies\Explorer: [TaskbarNoNotification] 1
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [winhlp32.exe] => C:\Users\pessoal\AppData\Roaming\alFSVWJB\winhlp32.exe [227328 2009-07-13] (Newzie)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6628056 2016-01-15] (Piriform Ltd)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [wibem6za] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18709272\wibem6za.exe [275968 2016-02-13] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [w1m1z1m6a1] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1870912372\wibemz1a1q.exe [81408 2016-02-21] (AnVir Software)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [wibem613z9a121] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18709272\wibe3a81211.exe [81920 2016-02-21] (AnVir Software)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [Kdj4SdfdaS01] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-183161771\KdjSadfS4d01.exe [276480 2016-02-13] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [wibem6za121] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18709272\wibem6za121.exe [278016 2016-02-13] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [Kdj4SdaS01] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18161771\KdjSaS4d01.exe [81408 2016-02-21] (AnVir Software)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [w1m1z1aam6a1a] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1870912372\wibemaaz1a1qa.exe [276992 2016-02-13] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [w1ibem6a1] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18709272\wibe31aaaaq.exe [210944 2016-02-19] (medical bag)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [w1m1z1am6a1] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1870912372\wibemaz1a1q.exe [279040 2016-02-13] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [osmsg] => C:\ProgramData\WindowsMsg\osmsg.exe [2036224 2016-02-09] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [msiql] => C:\ProgramData\msiql.exe [2415616 2016-01-26] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [12_23-dst] => C:\Windows\gpxrxoiwfhap.exe [622592 2016-02-17] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [senewsys32] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-186345671\senewsys32.exe [189952 2016-02-20] (MyBrains inc)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [senzwbsys32] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1363345871\senewzbys32.exe [223232 2016-02-19] (Incorporate)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [syszwbsys32] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-13633145871\sysewzbys32.exe [189952 2016-02-20] (MyBrains inc)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [sysazwbsays32] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-13633451\sysaewazbys32.exe [224256 2016-02-19] (Incorporate)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [sysazwb6says32] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-136633451\sysae6w6azbys32.exe [192512 2016-02-20] (MyBrains inc)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [sysanitesys2132] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1232612551\sysanitesy2132.exe [189440 2016-02-20] (MyBrains inc)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [sysanitesays2132s] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-123268151\sysaniteasy2132s.exe [190464 2016-02-20] (MyBrains inc)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Run: [sysanf132s] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-12326151\sysanifsy2132s.exe [191488 2016-02-20] (MyBrains inc)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [w1m1z1aam6a1a] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1870912372\wibemaaz1a1qa.exe [276992 2016-02-13] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [wibem6za] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18709272\wibem6za.exe [275968 2016-02-13] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [wibem6za121] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18709272\wibem6za121.exe [278016 2016-02-13] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [Kdj4SdfdaS01] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-183161771\KdjSadfS4d01.exe [276480 2016-02-13] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [wibem613z9a121] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18709272\wibe3a81211.exe [81920 2016-02-21] (AnVir Software)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [w1m1z1am6a1] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1870912372\wibemaz1a1q.exe [279040 2016-02-13] ()
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [Kdj4SdaS01] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18161771\KdjSaS4d01.exe [81408 2016-02-21] (AnVir Software)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [w1m1z1m6a1] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1870912372\wibemz1a1q.exe [81408 2016-02-21] (AnVir Software)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [sysanf132s] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-12326151\sysanifsy2132s.exe [191488 2016-02-20] (MyBrains inc)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [sysazwb6says32] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-136633451\sysae6w6azbys32.exe [192512 2016-02-20] (MyBrains inc)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [sysanitesays2132s] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-123268151\sysaniteasy2132s.exe [190464 2016-02-20] (MyBrains inc)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [senewsys32] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-186345671\senewsys32.exe [189952 2016-02-20] (MyBrains inc)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [w1ibem6a1] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-18709272\wibe31aaaaq.exe [210944 2016-02-19] (medical bag)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [syszwbsys32] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-13633145871\sysewzbys32.exe [189952 2016-02-20] (MyBrains inc)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [senzwbsys32] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1363345871\senewzbys32.exe [223232 2016-02-19] (Incorporate)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [sysanitesys2132] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-1232612551\sysanitesy2132.exe [189440 2016-02-20] (MyBrains inc)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\RunOnce: [sysazwbsays32] => C:\RECYCLER\S-1-5-21-0243556031-888888379-781862338-13633451\sysaewazbys32.exe [224256 2016-02-19] (Incorporate)
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Policies\Explorer: [TaskbarNoNotification] 1
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\...\Policies\Explorer: [HideSCAHealth] 1
ShellExecuteHooks: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399003} - C:\Program Files\GbPlugin\gbiehcef.dll [1867432 2015-09-01] (Caixa Economica Federal)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2009-02-09] (Autodesk, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+bufcn.html [2016-02-21] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+bufcn.png [2016-02-21] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+bufcn.txt [2016-02-21] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+cbjwl.html [2016-02-19] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+cbjwl.png [2016-02-19] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+cbjwl.txt [2016-02-19] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+fdlic.html [2016-02-18] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+fdlic.png [2016-02-18] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+fdlic.txt [2016-02-18] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+fmehi.html [2016-02-21] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+fmehi.png [2016-02-21] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+fmehi.txt [2016-02-21] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+hqovs.html [2016-02-22] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+hqovs.png [2016-02-22] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+hqovs.txt [2016-02-22] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+kogva.html [2016-02-19] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+kogva.png [2016-02-19] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+kogva.txt [2016-02-19] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+rmbjh.html [2016-02-20] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+rmbjh.png [2016-02-20] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+rmbjh.txt [2016-02-20] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+wsscw.html [2016-02-17] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+wsscw.png [2016-02-17] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+wsscw.txt [2016-02-17] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+yexgr.html [2016-02-20] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+yexgr.png [2016-02-20] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+yexgr.txt [2016-02-20] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+yicto.html [2016-02-22] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+yicto.png [2016-02-22] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+yicto.txt [2016-02-22] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+bufcn.html [2016-02-21] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+bufcn.png [2016-02-21] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+bufcn.txt [2016-02-21] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+cbjwl.html [2016-02-19] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+cbjwl.png [2016-02-19] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+cbjwl.txt [2016-02-19] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+fdlic.html [2016-02-18] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+fdlic.png [2016-02-18] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+fdlic.txt [2016-02-18] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+fmehi.html [2016-02-21] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+fmehi.png [2016-02-21] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+fmehi.txt [2016-02-21] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+hqovs.html [2016-02-22] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+hqovs.png [2016-02-22] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+hqovs.txt [2016-02-22] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+kogva.html [2016-02-19] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+kogva.png [2016-02-19] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+kogva.txt [2016-02-19] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+rmbjh.html [2016-02-20] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+rmbjh.png [2016-02-20] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+rmbjh.txt [2016-02-20] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+wsscw.html [2016-02-17] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+wsscw.png [2016-02-17] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+wsscw.txt [2016-02-17] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+yexgr.html [2016-02-20] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+yexgr.png [2016-02-20] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+yexgr.txt [2016-02-20] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+yicto.html [2016-02-22] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+yicto.png [2016-02-22] ()
Startup: C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Recovery+yicto.txt [2016-02-22] ()
GroupPolicy: Restrição - Chrome <======= ATENÇÃO
CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

ProxyEnable: [.DEFAULT] => Proxy está habilitado.
ProxyServer: [.DEFAULT] => http=127.0.0.1:53173;https=127.0.0.1:53173;
AutoConfigURL: [.DEFAULT] => http=127.0.0.1:53173;https=127.0.0.1:53173;
Winsock: Catalog5 07 C:\ProgramData\System32\SafeGuard32.dll [1536952 2015-12-25] ()
Hosts: Há mais de uma entrada no Hosts. Veja a seção Hosts do Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{843EACEB-1D29-452A-A663-9E8933987636}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restrição <======= ATENÇÃO
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://nav.brotlab.net?uid={b37569a5fc6c44c08d2cee323f1b05a7}&r=eg
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-4267091593-3674064722-2955824580-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.globasearch.com/?serie=211&b=3&installkey=Evny2fubLNBiM5IIIswD
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4267091593-3674064722-2955824580-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=Evny2fubLNBiM5IIIswD&b=3&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4267091593-3674064722-2955824580-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.globasearch.com/?serie=211&installkey=Evny2fubLNBiM5IIIswD&b=3&q={searchTerms}
SearchScopes: HKU\S-1-5-21-4267091593-3674064722-2955824580-1000 -> {C4A7CA3D-5DFE-49A8-914E-91EA6CE79C30} URL = hxxps://br.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
BHO: Sem Nome -> {73A5650C-C783-49F9-84C5-A1834D8D16CF} -> Nenhum Arquivo
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2015-12-31] (Oracle Corporation)
BHO: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540003} -> C:\Program Files\GbPlugin\gbiehcef.dll [2015-09-01] (Caixa Economica Federal)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-31] (Oracle Corporation)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E0186C22-E62C-4247-897F-BDA400A8C350} hxxp://jddomingos5.ddns-intelbras.com.br:8182/webrec.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2006-10-26] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-10] ()
FF Plugin: @DVR/npmedia-intelbras,version=3.1.0.4 -> C:\Program Files\webrec\WEB30\HDCVI\WebPlugin\npmedia.dll [2015-02-04] ()
FF Plugin: @DVR/npTimeGrid-intelbras,version=3.1.0.4 -> C:\Program Files\webrec\WEB30\HDCVI\WebPlugin\npTimeGrid.dll [2015-02-04] (Unauthorized copy)
FF Plugin: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-31] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-31] (Oracle Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-08-17] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-08-17] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-06] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4267091593-3674064722-2955824580-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\pessoal\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies ApS)
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+bufcn.html [2016-02-21]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+bufcn.png [2016-02-21]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+bufcn.txt [2016-02-21]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+cbjwl.html [2016-02-19]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+cbjwl.png [2016-02-19]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+cbjwl.txt [2016-02-19]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+fdlic.html [2016-02-18]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+fdlic.png [2016-02-18]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+fdlic.txt [2016-02-18]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+fmehi.html [2016-02-21]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+fmehi.png [2016-02-21]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+fmehi.txt [2016-02-21]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+hqovs.html [2016-02-22]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+hqovs.png [2016-02-22]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+hqovs.txt [2016-02-22]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+kogva.html [2016-02-19]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+kogva.png [2016-02-19]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+kogva.txt [2016-02-19]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+rmbjh.html [2016-02-20]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+rmbjh.png [2016-02-20]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+rmbjh.txt [2016-02-20]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+wsscw.html [2016-02-17]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+wsscw.png [2016-02-17]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+wsscw.txt [2016-02-17]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+yexgr.html [2016-02-20]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+yexgr.png [2016-02-20]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+yexgr.txt [2016-02-20]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+yicto.html [2016-02-22]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+yicto.png [2016-02-22]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\searchplugins\Recovery+yicto.txt [2016-02-22]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\7071285EEB18.xml [2015-12-15]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+bufcn.html [2016-02-21]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+bufcn.png [2016-02-21]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+bufcn.txt [2016-02-21]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+cbjwl.html [2016-02-19]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+cbjwl.png [2016-02-19]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+cbjwl.txt [2016-02-19]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+fdlic.html [2016-02-18]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+fdlic.png [2016-02-18]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+fdlic.txt [2016-02-18]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+fmehi.html [2016-02-21]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+fmehi.png [2016-02-21]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+fmehi.txt [2016-02-21]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+hqovs.html [2016-02-22]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+hqovs.png [2016-02-22]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+hqovs.txt [2016-02-22]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+kogva.html [2016-02-19]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+kogva.png [2016-02-19]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+kogva.txt [2016-02-19]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+rmbjh.html [2016-02-20]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+rmbjh.png [2016-02-20]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+rmbjh.txt [2016-02-20]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+wsscw.html [2016-02-17]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+wsscw.png [2016-02-17]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+wsscw.txt [2016-02-17]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+yexgr.html [2016-02-20]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+yexgr.png [2016-02-20]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+yexgr.txt [2016-02-20]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+yicto.html [2016-02-22]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+yicto.png [2016-02-22]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\Recovery+yicto.txt [2016-02-22]
FF SearchPlugin: C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\searchplugins\yahoo-ysp.xml [2015-12-31]
FF Extension: FirefixTab - C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\Extensions\1455213442_xpi [2016-02-22] [não assinado]
FF Extension: Get The Results Hub - C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\Extensions\{2c610837-6a36-4f5c-aa6e-6f008805941c}.xpi [2015-11-20] [não assinado]
FF Extension: Money Viking - C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\Extensions\{809ef5b6-4119-4781-b39b-c70793c04d47}.xpi [2015-11-20] [não assinado]
FF Extension: Oasis Space 1.0.1 - C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\p4ttlmt2.default\Extensions\{f5230593-67d7-4f19-bcdc-c4f29bcc8e74}.xpi [2015-12-22] [não assinado]
FF Extension: Get The Results Hub - C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{2c610837-6a36-4f5c-aa6e-6f008805941c}.xpi [2015-11-20] [não assinado]
FF Extension: Money Viking - C:\Users\pessoal\AppData\Roaming\Mozilla\Firefox\Profiles\41A66E7E5EE1\Extensions\{809ef5b6-4119-4781-b39b-c70793c04d47}.xpi [2015-11-20] [não assinado]
FF Extension: New Tab by Yahoo - C:\Program Files\Mozilla Firefox\browser\extensions\jid1-G80Ec8LLEbK5fQ@jetpack.xpi [2015-11-23] [não assinado]
StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome:
=======
CHR StartupUrls: Default -> "hxxps://www.google.com.br/?gws_rd=cr&ei=E_86UtqhK4v49gT9qYGoCw","hxxp://www.istartpageing.com/?type=hp&ts=1450961581&z=0112ab6777f41bf09a2f3dag2z6w2e8t5qbgew4bft&from=cmi&uid=SAMSUNGXHD322HJ_S1RLJ50S641325","hxxp://www.istartpageing.com/?type=hp&ts=1450986685&z=fb01cca5066c5334edebe2dgdz3wee3t8bbq9qet0c&from=cmi&uid=SAMSUNGXHD322HJ_S1RLJ50S641325","hxxp://www.palikan.com/?f=7&a=bfp_cmi_16_06&cd=2XzuyEtN2Y1L1QzutDtDyEtD0AyBtCyE0BtAyD0D0F0BzytBtN0D0Tzu0StCyDtDtAtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyCtAzytA0AyEyEtAtGyBzytC0DtG0F0E0EyBtGtCzz0AyEtG0A0A0BtCyEyE0CyC0D0ByByB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0F0B0F0A0E0C0FtG0ByDtAtAtGyE0FzztCtGzzyByCtBtGzztCtDyB0AyCyEtBtA0FtA0C2QtN0A0LzuyE&cr=676702899&ir="
CHR Profile: C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (PasswordBox - Log in with 1-Click) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajgnnllmjadopdlmpplonojbfogkjlcl [2016-02-22]
CHR Extension: (Adguard Ad Blocker) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2016-02-22]
CHR Extension: (Mouse Drag) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Default\Extensions\eddldcghfdhmdcfmjolaefkjglmeobpf [2016-02-22]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-22]
CHR Profile: C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Apresentações) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-22]
CHR Extension: (Google Docs) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-22]
CHR Extension: (Google Drive) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-22]
CHR Extension: (Adguard Ad Blocker) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2016-02-22]
CHR Extension: (YouTube) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-22]
CHR Extension: (Google Search) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-22]
CHR Extension: (Tonematrix) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\enpfehkomaakbncdddjkoffacajcglha [2016-02-22]
CHR Extension: (Planilhas do Google) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-22]
CHR Extension: (Causality Games) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\femoooemgmjaebeodbbikbkmhlafenpl [2016-02-22]
CHR Extension: (Screencastify (Screen Video Recorder)) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mmeijimgabbpbgpdklnllpncmdofkcpn [2016-02-22]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-22]
CHR Extension: (Portal 2D) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\noeojpcnabfdkncikfpepcpcldcfmpeb [2016-02-22]
CHR Extension: (GBBD Caixa Economica Federal) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pbcaplhfkihhldmlbjhgajdeghjdbffi [2016-02-22]
CHR Extension: (Gmail) - C:\Users\pessoal\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-22]
CHR HKLM\...\Chrome\Extension: [eedgghdcpmmmilkmfpnklknlenbiolec] - hxxps://clients2.google.com/service/update2/crx

Opera:
=======
OPR Extension: (Get The Results Hub) - C:\Users\pessoal\AppData\Roaming\Opera Software\Opera Stable\Extensions\bglklhfdcmljdeccibbjcdcbmljbmmdp [2016-02-22]
OPR Extension: (Money Viking) - C:\Users\pessoal\AppData\Roaming\Opera Software\Opera Stable\Extensions\gkkggbkmanplombgcjkadbheeflajlim [2016-02-22]
OPR Extension: (Oasis Space) - C:\Users\pessoal\AppData\Roaming\Opera Software\Opera Stable\Extensions\kioegjfcfkfjgenleelmadfdbnlkcgma [2016-02-22]

==================== Serviços (Whitelisted) ========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 AdvancedSystemCareService9; C:\Program Files\IObit\Advanced SystemCare\ASCService.exe [446240 2016-01-05] (IObit)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2010-06-28] (AVAST Software)
R3 avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2010-06-28] (AVAST Software)
R3 avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2010-06-28] (AVAST Software)
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2015-11-11] (Macrovision Europe Ltd.) [Arquivo não assinado]
R2 GbpSv; C:\Program Files\GbPlugin\GbpSv.exe [587576 2015-08-13] (GAS Tecnologia)
S2 GoogleChromeUpService; C:\ProgramData\upgsvr.exe [1762304 2015-11-16] (TODO: <公司名>) [Arquivo não assinado]
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2945312 2016-01-14] (IObit)
S3 npggsvc; C:\Windows\system32\GameMon.des [3520872 2015-09-22] (INCA Internet Co., Ltd.)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [6348560 2015-10-29] (TeamViewer GmbH)
R2 TheCalendarService; C:\Program Files\CalendarTool\2.0.0.11189\CalendarServ.exe [141960 2015-12-25] ()
R2 UpAurora Kernel Service; C:\Users\pessoal\AppData\Roaming\UpAuroraBrowser\Installer\UpAuroraKernelService.exe [184880 2015-12-03] (UpAurora.COM)
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Corporation)
R2 XBox; C:\Users\pessoal\AppData\Roaming\XBox\XBLive.exe [7142328 2015-12-08] ()

===================== Drivers (Whitelisted) ==========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 aswFsBlk; C:\Windows\system32\Drivers\aswFsBlk.sys [17744 2010-06-28] (ALWIL Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [50256 2010-06-28] (ALWIL Software)
R1 aswRdr; C:\Windows\system32\Drivers\aswRdr.sys [23376 2010-06-28] (ALWIL Software)
R1 aswSP; C:\Windows\system32\Drivers\aswSP.sys [165456 2010-06-28] (ALWIL Software)
R1 aswTdi; C:\Windows\system32\Drivers\aswTdi.sys [46672 2010-06-28] (ALWIL Software)
R1 bsdriver; C:\Windows\system32\drivers\bsdriver.sys [30104 2016-02-11] ()
R3 DFX11_1; C:\Windows\System32\drivers\dfx11_1.sys [24424 2012-12-13] (Windows (R) Win 7 DDK provider)
R0 GbpKm; C:\Windows\System32\drivers\GbpKm.sys [49496 2015-09-03] (GAS Tecnologia)
R1 ndisrd; C:\Windows\System32\DRIVERS\gbpndisrdn.sys [29400 2015-12-08] (GAS Tecnologia)
S1 asfilterdrv; system32\drivers\asfilterdrv.sys [X]
S1 {f5230593-67d7-4f19-bcdc-c4f29bcc8e74}Gw; system32\drivers\{f5230593-67d7-4f19-bcdc-c4f29bcc8e74}Gw.sys [X]

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um Mês Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-02-22 22:41 - 2016-02-22 22:42 - 00050513 _____ C:\Users\pessoal\Desktop\FRST.txt
2016-02-22 22:41 - 2016-02-22 22:41 - 00000000 ____D C:\FRST
2016-02-22 22:40 - 2016-02-22 22:40 - 01722368 _____ (Farbar) C:\Users\pessoal\Desktop\FRST.exe
2016-02-22 21:54 - 2016-02-22 21:54 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\oikln.exe
2016-02-22 21:53 - 2016-02-22 21:53 - 00007479 _____ C:\Users\Public\Recovery+hqovs.html
2016-02-22 21:53 - 2016-02-22 21:53 - 00007479 _____ C:\Users\Public\Downloads\Recovery+hqovs.html
2016-02-22 21:53 - 2016-02-22 21:53 - 00007479 _____ C:\Users\pessoal\Recovery+hqovs.html
2016-02-22 21:53 - 2016-02-22 21:53 - 00007479 _____ C:\Users\pessoal\Downloads\Recovery+hqovs.html
2016-02-22 21:53 - 2016-02-22 21:53 - 00007479 _____ C:\Users\pessoal\Documents\Recovery+hqovs.html
2016-02-22 21:53 - 2016-02-22 21:53 - 00002152 _____ C:\Users\Public\Recovery+hqovs.txt
2016-02-22 21:53 - 2016-02-22 21:53 - 00002152 _____ C:\Users\Public\Downloads\Recovery+hqovs.txt
2016-02-22 21:53 - 2016-02-22 21:53 - 00002152 _____ C:\Users\pessoal\Recovery+hqovs.txt
2016-02-22 21:53 - 2016-02-22 21:53 - 00002152 _____ C:\Users\pessoal\Downloads\Recovery+hqovs.txt
2016-02-22 21:53 - 2016-02-22 21:53 - 00002152 _____ C:\Users\pessoal\Documents\Recovery+hqovs.txt
2016-02-22 21:52 - 2016-02-22 21:53 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+hqovs.html
2016-02-22 21:52 - 2016-02-22 21:53 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+hqovs.txt
2016-02-22 21:52 - 2016-02-22 21:52 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Recovery+hqovs.html
2016-02-22 21:52 - 2016-02-22 21:52 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+hqovs.html
2016-02-22 21:52 - 2016-02-22 21:52 - 00007479 _____ C:\Users\pessoal\AppData\Recovery+hqovs.html
2016-02-22 21:52 - 2016-02-22 21:52 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Recovery+hqovs.txt
2016-02-22 21:52 - 2016-02-22 21:52 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+hqovs.txt
2016-02-22 21:52 - 2016-02-22 21:52 - 00002152 _____ C:\Users\pessoal\AppData\Recovery+hqovs.txt
2016-02-22 21:51 - 2016-02-22 21:51 - 00007479 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+hqovs.html
2016-02-22 21:51 - 2016-02-22 21:51 - 00002152 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:54 - 00007479 _____ C:\Users\Default\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:54 - 00002152 _____ C:\Users\Default\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:52 - 00007479 _____ C:\Users\pessoal\AppData\Local\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:52 - 00002152 _____ C:\Users\pessoal\AppData\Local\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Usuário Padrão\Downloads\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Usuário Padrão\Documents\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Usuário Padrão\Desktop\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default\Downloads\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default\Documents\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default\Desktop\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default\AppData\Roaming\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default\AppData\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default\AppData\Local\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default User\Downloads\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default User\Documents\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default User\Desktop\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default User\AppData\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Default User\AppData\Local\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Convidado\AppData\Roaming\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00007479 _____ C:\Users\Convidado\AppData\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Usuário Padrão\Downloads\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Usuário Padrão\Documents\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Usuário Padrão\Desktop\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default\Downloads\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default\Documents\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default\Desktop\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default\AppData\Roaming\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default\AppData\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default\AppData\Local\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default User\Downloads\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default User\Documents\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default User\Desktop\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default User\AppData\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Default User\AppData\Local\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Convidado\AppData\Roaming\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00002152 _____ C:\Users\Convidado\AppData\Recovery+hqovs.txt
2016-02-22 21:46 - 2016-02-22 21:46 - 00000000 ____D C:\Program Files\CalendarTool
2016-02-22 21:45 - 2016-02-22 21:54 - 00007479 _____ C:\Users\Todos os Usuários\Recovery+hqovs.html
2016-02-22 21:45 - 2016-02-22 21:54 - 00007479 _____ C:\Users\Recovery+hqovs.html
2016-02-22 21:45 - 2016-02-22 21:54 - 00007479 _____ C:\ProgramData\Recovery+hqovs.html
2016-02-22 21:45 - 2016-02-22 21:54 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+hqovs.html
2016-02-22 21:45 - 2016-02-22 21:54 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+hqovs.html
2016-02-22 21:45 - 2016-02-22 21:54 - 00002152 _____ C:\Users\Todos os Usuários\Recovery+hqovs.txt
2016-02-22 21:45 - 2016-02-22 21:54 - 00002152 _____ C:\Users\Recovery+hqovs.txt
2016-02-22 21:45 - 2016-02-22 21:54 - 00002152 _____ C:\ProgramData\Recovery+hqovs.txt
2016-02-22 21:45 - 2016-02-22 21:54 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+hqovs.txt
2016-02-22 21:45 - 2016-02-22 21:54 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+hqovs.txt
2016-02-22 21:45 - 2016-02-22 21:53 - 00007479 _____ C:\Users\Public\Documents\Recovery+hqovs.html
2016-02-22 21:45 - 2016-02-22 21:53 - 00002152 _____ C:\Users\Public\Documents\Recovery+hqovs.txt
2016-02-22 21:45 - 2016-02-22 21:45 - 00007479 _____ C:\Users\Administrador\Recovery+hqovs.html
2016-02-22 21:45 - 2016-02-22 21:45 - 00007479 _____ C:\Users\Administrador\AppData\Roaming\Recovery+hqovs.html
2016-02-22 21:45 - 2016-02-22 21:45 - 00007479 _____ C:\Users\Administrador\AppData\Recovery+hqovs.html
2016-02-22 21:45 - 2016-02-22 21:45 - 00002152 _____ C:\Users\Administrador\Recovery+hqovs.txt
2016-02-22 21:45 - 2016-02-22 21:45 - 00002152 _____ C:\Users\Administrador\AppData\Roaming\Recovery+hqovs.txt
2016-02-22 21:45 - 2016-02-22 21:45 - 00002152 _____ C:\Users\Administrador\AppData\Recovery+hqovs.txt
2016-02-22 21:41 - 2016-02-22 21:41 - 00007479 _____ C:\Program Files\Recovery+hqovs.html
2016-02-22 21:41 - 2016-02-22 21:41 - 00002152 _____ C:\Program Files\Recovery+hqovs.txt
2016-02-22 21:37 - 2016-02-22 21:37 - 00000254 _____ C:\Users\pessoal\Documents\recover_file_oojtnkoii.txt
2016-02-22 21:36 - 2016-02-22 21:36 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\ovkkf.exe
2016-02-22 10:14 - 2016-02-22 10:14 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\ywyxd.exe
2016-02-22 10:13 - 2016-02-22 10:13 - 00007479 _____ C:\Users\Public\Recovery+yicto.html
2016-02-22 10:13 - 2016-02-22 10:13 - 00007479 _____ C:\Users\Public\Downloads\Recovery+yicto.html
2016-02-22 10:13 - 2016-02-22 10:13 - 00007479 _____ C:\Users\pessoal\Recovery+yicto.html
2016-02-22 10:13 - 2016-02-22 10:13 - 00007479 _____ C:\Users\pessoal\Downloads\Recovery+yicto.html
2016-02-22 10:13 - 2016-02-22 10:13 - 00007479 _____ C:\Users\pessoal\Documents\Recovery+yicto.html
2016-02-22 10:13 - 2016-02-22 10:13 - 00002152 _____ C:\Users\Public\Recovery+yicto.txt
2016-02-22 10:13 - 2016-02-22 10:13 - 00002152 _____ C:\Users\Public\Downloads\Recovery+yicto.txt
2016-02-22 10:13 - 2016-02-22 10:13 - 00002152 _____ C:\Users\pessoal\Recovery+yicto.txt
2016-02-22 10:13 - 2016-02-22 10:13 - 00002152 _____ C:\Users\pessoal\Downloads\Recovery+yicto.txt
2016-02-22 10:13 - 2016-02-22 10:13 - 00002152 _____ C:\Users\pessoal\Documents\Recovery+yicto.txt
2016-02-22 10:12 - 2016-02-22 10:13 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yicto.html
2016-02-22 10:12 - 2016-02-22 10:13 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yicto.txt
2016-02-22 10:12 - 2016-02-22 10:12 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Recovery+yicto.html
2016-02-22 10:12 - 2016-02-22 10:12 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yicto.html
2016-02-22 10:12 - 2016-02-22 10:12 - 00007479 _____ C:\Users\pessoal\AppData\Recovery+yicto.html
2016-02-22 10:12 - 2016-02-22 10:12 - 00007479 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+yicto.html
2016-02-22 10:12 - 2016-02-22 10:12 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Recovery+yicto.txt
2016-02-22 10:12 - 2016-02-22 10:12 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yicto.txt
2016-02-22 10:12 - 2016-02-22 10:12 - 00002152 _____ C:\Users\pessoal\AppData\Recovery+yicto.txt
2016-02-22 10:12 - 2016-02-22 10:12 - 00002152 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+yicto.txt
2016-02-22 10:08 - 2016-02-22 10:12 - 00007479 _____ C:\Users\pessoal\AppData\Local\Recovery+yicto.html
2016-02-22 10:08 - 2016-02-22 10:12 - 00002152 _____ C:\Users\pessoal\AppData\Local\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:14 - 00007479 _____ C:\Users\Default\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:14 - 00002152 _____ C:\Users\Default\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:13 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:13 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Usuário Padrão\Downloads\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Usuário Padrão\Documents\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Usuário Padrão\Desktop\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default\Downloads\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default\Documents\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default\Desktop\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default\AppData\Roaming\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default\AppData\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default\AppData\Local\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default User\Downloads\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default User\Documents\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default User\Desktop\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default User\AppData\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Default User\AppData\Local\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Convidado\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Convidado\AppData\Roaming\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00007479 _____ C:\Users\Convidado\AppData\Recovery+yicto.html
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Usuário Padrão\Downloads\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Usuário Padrão\Documents\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Usuário Padrão\Desktop\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default\Downloads\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default\Documents\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default\Desktop\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default\AppData\Roaming\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default\AppData\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default\AppData\Local\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default User\Downloads\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default User\Documents\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default User\Desktop\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default User\AppData\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Default User\AppData\Local\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Convidado\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Convidado\AppData\Roaming\Recovery+yicto.txt
2016-02-22 10:07 - 2016-02-22 10:07 - 00002152 _____ C:\Users\Convidado\AppData\Recovery+yicto.txt
2016-02-22 10:06 - 2016-02-22 10:14 - 00007479 _____ C:\Users\Todos os Usuários\Recovery+yicto.html
2016-02-22 10:06 - 2016-02-22 10:14 - 00007479 _____ C:\Users\Recovery+yicto.html
2016-02-22 10:06 - 2016-02-22 10:14 - 00007479 _____ C:\ProgramData\Recovery+yicto.html
2016-02-22 10:06 - 2016-02-22 10:14 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+yicto.html
2016-02-22 10:06 - 2016-02-22 10:14 - 00002152 _____ C:\Users\Todos os Usuários\Recovery+yicto.txt
2016-02-22 10:06 - 2016-02-22 10:14 - 00002152 _____ C:\Users\Recovery+yicto.txt
2016-02-22 10:06 - 2016-02-22 10:14 - 00002152 _____ C:\ProgramData\Recovery+yicto.txt
2016-02-22 10:06 - 2016-02-22 10:14 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+yicto.txt
2016-02-22 10:06 - 2016-02-22 10:13 - 00007479 _____ C:\Users\Public\Documents\Recovery+yicto.html
2016-02-22 10:06 - 2016-02-22 10:13 - 00002152 _____ C:\Users\Public\Documents\Recovery+yicto.txt
2016-02-22 10:06 - 2016-02-22 10:06 - 00007479 _____ C:\Users\Administrador\Recovery+yicto.html
2016-02-22 10:06 - 2016-02-22 10:06 - 00007479 _____ C:\Users\Administrador\AppData\Roaming\Recovery+yicto.html
2016-02-22 10:06 - 2016-02-22 10:06 - 00007479 _____ C:\Users\Administrador\AppData\Recovery+yicto.html
2016-02-22 10:06 - 2016-02-22 10:06 - 00002152 _____ C:\Users\Administrador\Recovery+yicto.txt
2016-02-22 10:06 - 2016-02-22 10:06 - 00002152 _____ C:\Users\Administrador\AppData\Roaming\Recovery+yicto.txt
2016-02-22 10:06 - 2016-02-22 10:06 - 00002152 _____ C:\Users\Administrador\AppData\Recovery+yicto.txt
2016-02-22 10:05 - 2016-02-22 10:05 - 00007479 _____ C:\Program Files\Recovery+yicto.html
2016-02-22 10:05 - 2016-02-22 10:05 - 00002152 _____ C:\Program Files\Recovery+yicto.txt
2016-02-22 09:53 - 2016-02-22 09:53 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\nxfto.exe
2016-02-22 09:53 - 2016-02-22 09:53 - 00000254 _____ C:\Users\pessoal\Documents\recover_file_yloxufyww.txt
2016-02-21 23:12 - 2016-02-21 23:12 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\gcqvv.exe
2016-02-21 23:11 - 2016-02-21 23:11 - 00007479 _____ C:\Users\Public\Recovery+fmehi.html
2016-02-21 23:11 - 2016-02-21 23:11 - 00007479 _____ C:\Users\Public\Downloads\Recovery+fmehi.html
2016-02-21 23:11 - 2016-02-21 23:11 - 00007479 _____ C:\Users\pessoal\Recovery+fmehi.html
2016-02-21 23:11 - 2016-02-21 23:11 - 00007479 _____ C:\Users\pessoal\Downloads\Recovery+fmehi.html
2016-02-21 23:11 - 2016-02-21 23:11 - 00007479 _____ C:\Users\pessoal\Documents\Recovery+fmehi.html
2016-02-21 23:11 - 2016-02-21 23:11 - 00002152 _____ C:\Users\Public\Recovery+fmehi.txt
2016-02-21 23:11 - 2016-02-21 23:11 - 00002152 _____ C:\Users\Public\Downloads\Recovery+fmehi.txt
2016-02-21 23:11 - 2016-02-21 23:11 - 00002152 _____ C:\Users\pessoal\Recovery+fmehi.txt
2016-02-21 23:11 - 2016-02-21 23:11 - 00002152 _____ C:\Users\pessoal\Downloads\Recovery+fmehi.txt
2016-02-21 23:11 - 2016-02-21 23:11 - 00002152 _____ C:\Users\pessoal\Documents\Recovery+fmehi.txt
2016-02-21 23:10 - 2016-02-21 23:10 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Recovery+fmehi.html
2016-02-21 23:10 - 2016-02-21 23:10 - 00007479 _____ C:\Users\pessoal\AppData\Recovery+fmehi.html
2016-02-21 23:10 - 2016-02-21 23:10 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Recovery+fmehi.txt
2016-02-21 23:10 - 2016-02-21 23:10 - 00002152 _____ C:\Users\pessoal\AppData\Recovery+fmehi.txt
2016-02-21 23:09 - 2016-02-21 23:11 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fmehi.html
2016-02-21 23:09 - 2016-02-21 23:11 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fmehi.txt
2016-02-21 23:09 - 2016-02-21 23:09 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fmehi.html
2016-02-21 23:09 - 2016-02-21 23:09 - 00007479 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+fmehi.html
2016-02-21 23:09 - 2016-02-21 23:09 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fmehi.txt
2016-02-21 23:09 - 2016-02-21 23:09 - 00002152 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:12 - 00007479 _____ C:\Users\Todos os Usuários\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:12 - 00007479 _____ C:\Users\Default\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:12 - 00007479 _____ C:\ProgramData\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:12 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:12 - 00002152 _____ C:\Users\Todos os Usuários\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:12 - 00002152 _____ C:\Users\Default\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:12 - 00002152 _____ C:\ProgramData\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:12 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:11 - 00007479 _____ C:\Users\Public\Documents\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:11 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:11 - 00002152 _____ C:\Users\Public\Documents\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:11 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:10 - 00007479 _____ C:\Users\pessoal\AppData\Local\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:10 - 00002152 _____ C:\Users\pessoal\AppData\Local\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Usuário Padrão\Downloads\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Usuário Padrão\Documents\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Usuário Padrão\Desktop\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default\Downloads\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default\Documents\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default\Desktop\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default\AppData\Roaming\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default\AppData\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default\AppData\Local\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default User\Downloads\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default User\Documents\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default User\Desktop\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default User\AppData\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Default User\AppData\Local\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Convidado\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Convidado\AppData\Roaming\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00007479 _____ C:\Users\Convidado\AppData\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Usuário Padrão\Downloads\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Usuário Padrão\Documents\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Usuário Padrão\Desktop\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default\Downloads\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default\Documents\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default\Desktop\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default\AppData\Roaming\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default\AppData\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default\AppData\Local\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default User\Downloads\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default User\Documents\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default User\Desktop\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default User\AppData\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Default User\AppData\Local\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Convidado\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Convidado\AppData\Roaming\Recovery+fmehi.txt
2016-02-21 23:04 - 2016-02-21 23:04 - 00002152 _____ C:\Users\Convidado\AppData\Recovery+fmehi.txt
2016-02-21 23:03 - 2016-02-21 23:12 - 00007479 _____ C:\Users\Recovery+fmehi.html
2016-02-21 23:03 - 2016-02-21 23:12 - 00002152 _____ C:\Users\Recovery+fmehi.txt
2016-02-21 23:03 - 2016-02-21 23:03 - 00007479 _____ C:\Users\Administrador\Recovery+fmehi.html
2016-02-21 23:03 - 2016-02-21 23:03 - 00007479 _____ C:\Users\Administrador\AppData\Roaming\Recovery+fmehi.html
2016-02-21 23:03 - 2016-02-21 23:03 - 00007479 _____ C:\Users\Administrador\AppData\Recovery+fmehi.html
2016-02-21 23:03 - 2016-02-21 23:03 - 00002152 _____ C:\Users\Administrador\Recovery+fmehi.txt
2016-02-21 23:03 - 2016-02-21 23:03 - 00002152 _____ C:\Users\Administrador\AppData\Roaming\Recovery+fmehi.txt
2016-02-21 23:03 - 2016-02-21 23:03 - 00002152 _____ C:\Users\Administrador\AppData\Recovery+fmehi.txt
2016-02-21 23:02 - 2016-02-21 23:02 - 00007479 _____ C:\Program Files\Recovery+fmehi.html
2016-02-21 23:02 - 2016-02-21 23:02 - 00002152 _____ C:\Program Files\Recovery+fmehi.txt
2016-02-21 22:58 - 2016-02-21 22:58 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\tpmgv.exe
2016-02-21 22:58 - 2016-02-21 22:58 - 00000254 _____ C:\Users\pessoal\Documents\recover_file_ojfpoqgbn.txt
2016-02-21 13:44 - 2016-02-21 13:44 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\byykp.exe
2016-02-21 13:43 - 2016-02-21 13:43 - 00007479 _____ C:\Users\Public\Recovery+bufcn.html
2016-02-21 13:43 - 2016-02-21 13:43 - 00007479 _____ C:\Users\Public\Downloads\Recovery+bufcn.html
2016-02-21 13:43 - 2016-02-21 13:43 - 00007479 _____ C:\Users\pessoal\Recovery+bufcn.html
2016-02-21 13:43 - 2016-02-21 13:43 - 00007479 _____ C:\Users\pessoal\Downloads\Recovery+bufcn.html
2016-02-21 13:43 - 2016-02-21 13:43 - 00007479 _____ C:\Users\pessoal\Documents\Recovery+bufcn.html
2016-02-21 13:43 - 2016-02-21 13:43 - 00002152 _____ C:\Users\Public\Recovery+bufcn.txt
2016-02-21 13:43 - 2016-02-21 13:43 - 00002152 _____ C:\Users\Public\Downloads\Recovery+bufcn.txt
2016-02-21 13:43 - 2016-02-21 13:43 - 00002152 _____ C:\Users\pessoal\Recovery+bufcn.txt
2016-02-21 13:43 - 2016-02-21 13:43 - 00002152 _____ C:\Users\pessoal\Downloads\Recovery+bufcn.txt
2016-02-21 13:43 - 2016-02-21 13:43 - 00002152 _____ C:\Users\pessoal\Documents\Recovery+bufcn.txt
2016-02-21 13:42 - 2016-02-21 13:43 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+bufcn.html
2016-02-21 13:42 - 2016-02-21 13:43 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+bufcn.txt
2016-02-21 13:42 - 2016-02-21 13:42 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Recovery+bufcn.html
2016-02-21 13:42 - 2016-02-21 13:42 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+bufcn.html
2016-02-21 13:42 - 2016-02-21 13:42 - 00007479 _____ C:\Users\pessoal\AppData\Recovery+bufcn.html
2016-02-21 13:42 - 2016-02-21 13:42 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Recovery+bufcn.txt
2016-02-21 13:42 - 2016-02-21 13:42 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+bufcn.txt
2016-02-21 13:42 - 2016-02-21 13:42 - 00002152 _____ C:\Users\pessoal\AppData\Recovery+bufcn.txt
2016-02-21 13:41 - 2016-02-21 13:41 - 00007479 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+bufcn.html
2016-02-21 13:41 - 2016-02-21 13:41 - 00002152 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+bufcn.txt
2016-02-21 13:38 - 2016-02-22 21:53 - 00000000 ____D C:\Users\Public\Documents\Guid
2016-02-21 13:35 - 2016-02-21 13:43 - 00007479 _____ C:\Users\Default\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:43 - 00002152 _____ C:\Users\Default\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:42 - 00007479 _____ C:\Users\pessoal\AppData\Local\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:42 - 00002152 _____ C:\Users\pessoal\AppData\Local\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Usuário Padrão\Downloads\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Usuário Padrão\Documents\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Usuário Padrão\Desktop\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default\Downloads\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default\Documents\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default\Desktop\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default\AppData\Roaming\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default\AppData\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default\AppData\Local\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default User\Downloads\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default User\Documents\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default User\Desktop\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default User\AppData\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Default User\AppData\Local\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Convidado\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Convidado\AppData\Roaming\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00007479 _____ C:\Users\Convidado\AppData\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Usuário Padrão\Downloads\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Usuário Padrão\Documents\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Usuário Padrão\Desktop\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default\Downloads\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default\Documents\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default\Desktop\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default\AppData\Roaming\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default\AppData\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default\AppData\Local\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default User\Downloads\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default User\Documents\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default User\Desktop\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default User\AppData\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Default User\AppData\Local\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Convidado\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Convidado\AppData\Roaming\Recovery+bufcn.txt
2016-02-21 13:35 - 2016-02-21 13:35 - 00002152 _____ C:\Users\Convidado\AppData\Recovery+bufcn.txt
2016-02-21 13:34 - 2016-02-21 13:43 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+bufcn.html
2016-02-21 13:34 - 2016-02-21 13:43 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+bufcn.txt
2016-02-21 13:33 - 2016-02-21 13:43 - 00007479 _____ C:\Users\Todos os Usuários\Recovery+bufcn.html
2016-02-21 13:33 - 2016-02-21 13:43 - 00007479 _____ C:\Users\Recovery+bufcn.html
2016-02-21 13:33 - 2016-02-21 13:43 - 00007479 _____ C:\Users\Public\Documents\Recovery+bufcn.html
2016-02-21 13:33 - 2016-02-21 13:43 - 00007479 _____ C:\ProgramData\Recovery+bufcn.html
2016-02-21 13:33 - 2016-02-21 13:43 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+bufcn.html
2016-02-21 13:33 - 2016-02-21 13:43 - 00002152 _____ C:\Users\Todos os Usuários\Recovery+bufcn.txt
2016-02-21 13:33 - 2016-02-21 13:43 - 00002152 _____ C:\Users\Recovery+bufcn.txt
2016-02-21 13:33 - 2016-02-21 13:43 - 00002152 _____ C:\Users\Public\Documents\Recovery+bufcn.txt
2016-02-21 13:33 - 2016-02-21 13:43 - 00002152 _____ C:\ProgramData\Recovery+bufcn.txt
2016-02-21 13:33 - 2016-02-21 13:43 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+bufcn.txt
2016-02-21 13:33 - 2016-02-21 13:33 - 00007479 _____ C:\Users\Administrador\Recovery+bufcn.html
2016-02-21 13:33 - 2016-02-21 13:33 - 00007479 _____ C:\Users\Administrador\AppData\Roaming\Recovery+bufcn.html
2016-02-21 13:33 - 2016-02-21 13:33 - 00007479 _____ C:\Users\Administrador\AppData\Recovery+bufcn.html
2016-02-21 13:33 - 2016-02-21 13:33 - 00002152 _____ C:\Users\Administrador\Recovery+bufcn.txt
2016-02-21 13:33 - 2016-02-21 13:33 - 00002152 _____ C:\Users\Administrador\AppData\Roaming\Recovery+bufcn.txt
2016-02-21 13:33 - 2016-02-21 13:33 - 00002152 _____ C:\Users\Administrador\AppData\Recovery+bufcn.txt
2016-02-21 13:32 - 2016-02-21 13:32 - 00007479 _____ C:\Program Files\Recovery+bufcn.html
2016-02-21 13:32 - 2016-02-21 13:32 - 00002152 _____ C:\Program Files\Recovery+bufcn.txt
2016-02-21 13:31 - 2016-02-21 13:31 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\tuqxr.exe
2016-02-21 13:31 - 2016-02-21 13:31 - 00000254 _____ C:\Users\pessoal\Documents\recover_file_jtmnxqcac.txt
2016-02-20 23:27 - 2016-02-20 23:27 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\cuxxn.exe
2016-02-20 23:26 - 2016-02-20 23:26 - 00007479 _____ C:\Users\Public\Recovery+rmbjh.html
2016-02-20 23:26 - 2016-02-20 23:26 - 00007479 _____ C:\Users\Public\Downloads\Recovery+rmbjh.html
2016-02-20 23:26 - 2016-02-20 23:26 - 00007479 _____ C:\Users\pessoal\Recovery+rmbjh.html
2016-02-20 23:26 - 2016-02-20 23:26 - 00007479 _____ C:\Users\pessoal\Downloads\Recovery+rmbjh.html
2016-02-20 23:26 - 2016-02-20 23:26 - 00007479 _____ C:\Users\pessoal\Documents\Recovery+rmbjh.html
2016-02-20 23:26 - 2016-02-20 23:26 - 00002152 _____ C:\Users\Public\Recovery+rmbjh.txt
2016-02-20 23:26 - 2016-02-20 23:26 - 00002152 _____ C:\Users\Public\Downloads\Recovery+rmbjh.txt
2016-02-20 23:26 - 2016-02-20 23:26 - 00002152 _____ C:\Users\pessoal\Recovery+rmbjh.txt
2016-02-20 23:26 - 2016-02-20 23:26 - 00002152 _____ C:\Users\pessoal\Downloads\Recovery+rmbjh.txt
2016-02-20 23:26 - 2016-02-20 23:26 - 00002152 _____ C:\Users\pessoal\Documents\Recovery+rmbjh.txt
2016-02-20 23:25 - 2016-02-20 23:26 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+rmbjh.html
2016-02-20 23:25 - 2016-02-20 23:26 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+rmbjh.txt
2016-02-20 23:25 - 2016-02-20 23:25 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Recovery+rmbjh.html
2016-02-20 23:25 - 2016-02-20 23:25 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+rmbjh.html
2016-02-20 23:25 - 2016-02-20 23:25 - 00007479 _____ C:\Users\pessoal\AppData\Recovery+rmbjh.html
2016-02-20 23:25 - 2016-02-20 23:25 - 00007479 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+rmbjh.html
2016-02-20 23:25 - 2016-02-20 23:25 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Recovery+rmbjh.txt
2016-02-20 23:25 - 2016-02-20 23:25 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+rmbjh.txt
2016-02-20 23:25 - 2016-02-20 23:25 - 00002152 _____ C:\Users\pessoal\AppData\Recovery+rmbjh.txt
2016-02-20 23:25 - 2016-02-20 23:25 - 00002152 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:27 - 00007479 _____ C:\Users\Default\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:27 - 00002152 _____ C:\Users\Default\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:25 - 00007479 _____ C:\Users\pessoal\AppData\Local\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:25 - 00002152 _____ C:\Users\pessoal\AppData\Local\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Usuário Padrão\Downloads\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Usuário Padrão\Documents\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Usuário Padrão\Desktop\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default\Downloads\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default\Documents\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default\Desktop\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default\AppData\Roaming\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default\AppData\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default\AppData\Local\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default User\Downloads\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default User\Documents\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default User\Desktop\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default User\AppData\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Default User\AppData\Local\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Convidado\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Convidado\AppData\Roaming\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00007479 _____ C:\Users\Convidado\AppData\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Usuário Padrão\Downloads\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Usuário Padrão\Documents\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Usuário Padrão\Desktop\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default\Downloads\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default\Documents\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default\Desktop\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default\AppData\Roaming\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default\AppData\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default\AppData\Local\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default User\Downloads\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default User\Documents\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default User\Desktop\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default User\AppData\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Default User\AppData\Local\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Convidado\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Convidado\AppData\Roaming\Recovery+rmbjh.txt
2016-02-20 23:22 - 2016-02-20 23:22 - 00002152 _____ C:\Users\Convidado\AppData\Recovery+rmbjh.txt
2016-02-20 23:21 - 2016-02-20 23:27 - 00007479 _____ C:\Users\Todos os Usuários\Recovery+rmbjh.html
2016-02-20 23:21 - 2016-02-20 23:27 - 00007479 _____ C:\Users\Recovery+rmbjh.html
2016-02-20 23:21 - 2016-02-20 23:27 - 00007479 _____ C:\ProgramData\Recovery+rmbjh.html
2016-02-20 23:21 - 2016-02-20 23:27 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+rmbjh.html
2016-02-20 23:21 - 2016-02-20 23:27 - 00002152 _____ C:\Users\Todos os Usuários\Recovery+rmbjh.txt
2016-02-20 23:21 - 2016-02-20 23:27 - 00002152 _____ C:\Users\Recovery+rmbjh.txt
2016-02-20 23:21 - 2016-02-20 23:27 - 00002152 _____ C:\ProgramData\Recovery+rmbjh.txt
2016-02-20 23:21 - 2016-02-20 23:27 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+rmbjh.txt
2016-02-20 23:21 - 2016-02-20 23:26 - 00007479 _____ C:\Users\Public\Documents\Recovery+rmbjh.html
2016-02-20 23:21 - 2016-02-20 23:26 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+rmbjh.html
2016-02-20 23:21 - 2016-02-20 23:26 - 00002152 _____ C:\Users\Public\Documents\Recovery+rmbjh.txt
2016-02-20 23:21 - 2016-02-20 23:26 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+rmbjh.txt
2016-02-20 23:21 - 2016-02-20 23:21 - 00007479 _____ C:\Users\Administrador\Recovery+rmbjh.html
2016-02-20 23:21 - 2016-02-20 23:21 - 00007479 _____ C:\Users\Administrador\AppData\Roaming\Recovery+rmbjh.html
2016-02-20 23:21 - 2016-02-20 23:21 - 00007479 _____ C:\Users\Administrador\AppData\Recovery+rmbjh.html
2016-02-20 23:21 - 2016-02-20 23:21 - 00002152 _____ C:\Users\Administrador\Recovery+rmbjh.txt
2016-02-20 23:21 - 2016-02-20 23:21 - 00002152 _____ C:\Users\Administrador\AppData\Roaming\Recovery+rmbjh.txt
2016-02-20 23:21 - 2016-02-20 23:21 - 00002152 _____ C:\Users\Administrador\AppData\Recovery+rmbjh.txt
2016-02-20 23:19 - 2016-02-20 23:19 - 00007479 _____ C:\Program Files\Recovery+rmbjh.html
2016-02-20 23:19 - 2016-02-20 23:19 - 00002152 _____ C:\Program Files\Recovery+rmbjh.txt
2016-02-20 23:18 - 2016-02-20 23:18 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\prxii.exe
2016-02-20 23:18 - 2016-02-20 23:18 - 00000254 _____ C:\Users\pessoal\Documents\recover_file_hhjqpissr.txt
2016-02-20 23:08 - 2016-02-20 23:08 - 01511424 _____ C:\Users\pessoal\Downloads\adwcleaner_5.035.exe
2016-02-20 16:09 - 2016-02-20 16:09 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\ibvpa.exe
2016-02-20 16:07 - 2016-02-20 16:07 - 00007479 _____ C:\Users\Public\Recovery+yexgr.html
2016-02-20 16:07 - 2016-02-20 16:07 - 00007479 _____ C:\Users\Public\Downloads\Recovery+yexgr.html
2016-02-20 16:07 - 2016-02-20 16:07 - 00007479 _____ C:\Users\pessoal\Recovery+yexgr.html
2016-02-20 16:07 - 2016-02-20 16:07 - 00007479 _____ C:\Users\pessoal\Downloads\Recovery+yexgr.html
2016-02-20 16:07 - 2016-02-20 16:07 - 00007479 _____ C:\Users\pessoal\Documents\Recovery+yexgr.html
2016-02-20 16:07 - 2016-02-20 16:07 - 00002152 _____ C:\Users\Public\Recovery+yexgr.txt
2016-02-20 16:07 - 2016-02-20 16:07 - 00002152 _____ C:\Users\Public\Downloads\Recovery+yexgr.txt
2016-02-20 16:07 - 2016-02-20 16:07 - 00002152 _____ C:\Users\pessoal\Recovery+yexgr.txt
2016-02-20 16:07 - 2016-02-20 16:07 - 00002152 _____ C:\Users\pessoal\Downloads\Recovery+yexgr.txt
2016-02-20 16:07 - 2016-02-20 16:07 - 00002152 _____ C:\Users\pessoal\Documents\Recovery+yexgr.txt
2016-02-20 16:05 - 2016-02-20 16:05 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Recovery+yexgr.html
2016-02-20 16:05 - 2016-02-20 16:05 - 00007479 _____ C:\Users\pessoal\AppData\Recovery+yexgr.html
2016-02-20 16:05 - 2016-02-20 16:05 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Recovery+yexgr.txt
2016-02-20 16:05 - 2016-02-20 16:05 - 00002152 _____ C:\Users\pessoal\AppData\Recovery+yexgr.txt
2016-02-20 16:04 - 2016-02-20 16:07 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yexgr.html
2016-02-20 16:04 - 2016-02-20 16:07 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yexgr.txt
2016-02-20 16:04 - 2016-02-20 16:04 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yexgr.html
2016-02-20 16:04 - 2016-02-20 16:04 - 00007479 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+yexgr.html
2016-02-20 16:04 - 2016-02-20 16:04 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yexgr.txt
2016-02-20 16:04 - 2016-02-20 16:04 - 00002152 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 16:09 - 00007479 _____ C:\Users\Default\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 16:09 - 00002152 _____ C:\Users\Default\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 16:05 - 00007479 _____ C:\Users\pessoal\AppData\Local\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 16:05 - 00002152 _____ C:\Users\pessoal\AppData\Local\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Usuário Padrão\Downloads\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Usuário Padrão\Documents\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Usuário Padrão\Desktop\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default\Downloads\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default\Documents\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default\Desktop\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default\AppData\Roaming\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default\AppData\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default User\Downloads\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default User\Documents\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default User\Desktop\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default User\AppData\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Usuário Padrão\Downloads\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Usuário Padrão\Documents\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Usuário Padrão\Desktop\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default\Downloads\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default\Documents\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default\Desktop\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default\AppData\Roaming\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default\AppData\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default User\Downloads\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default User\Documents\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default User\Desktop\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+yexgr.txt
2016-02-20 15:59 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default User\AppData\Recovery+yexgr.txt
2016-02-20 15:58 - 2016-02-20 16:08 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+yexgr.html
2016-02-20 15:58 - 2016-02-20 16:08 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+yexgr.txt
2016-02-20 15:58 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+yexgr.html
2016-02-20 15:58 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default\AppData\Local\Recovery+yexgr.html
2016-02-20 15:58 - 2016-02-20 15:59 - 00007479 _____ C:\Users\Default User\AppData\Local\Recovery+yexgr.html
2016-02-20 15:58 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+yexgr.txt
2016-02-20 15:58 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default\AppData\Local\Recovery+yexgr.txt
2016-02-20 15:58 - 2016-02-20 15:59 - 00002152 _____ C:\Users\Default User\AppData\Local\Recovery+yexgr.txt
2016-02-20 15:58 - 2016-02-20 15:58 - 00007479 _____ C:\Users\Convidado\Recovery+yexgr.html
2016-02-20 15:58 - 2016-02-20 15:58 - 00007479 _____ C:\Users\Convidado\AppData\Roaming\Recovery+yexgr.html
2016-02-20 15:58 - 2016-02-20 15:58 - 00007479 _____ C:\Users\Convidado\AppData\Recovery+yexgr.html
2016-02-20 15:58 - 2016-02-20 15:58 - 00002152 _____ C:\Users\Convidado\Recovery+yexgr.txt
2016-02-20 15:58 - 2016-02-20 15:58 - 00002152 _____ C:\Users\Convidado\AppData\Roaming\Recovery+yexgr.txt
2016-02-20 15:58 - 2016-02-20 15:58 - 00002152 _____ C:\Users\Convidado\AppData\Recovery+yexgr.txt
2016-02-20 15:57 - 2016-02-20 16:09 - 00007479 _____ C:\Users\Todos os Usuários\Recovery+yexgr.html
2016-02-20 15:57 - 2016-02-20 16:09 - 00007479 _____ C:\Users\Recovery+yexgr.html
2016-02-20 15:57 - 2016-02-20 16:09 - 00007479 _____ C:\ProgramData\Recovery+yexgr.html
2016-02-20 15:57 - 2016-02-20 16:09 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+yexgr.html
2016-02-20 15:57 - 2016-02-20 16:09 - 00002152 _____ C:\Users\Todos os Usuários\Recovery+yexgr.txt
2016-02-20 15:57 - 2016-02-20 16:09 - 00002152 _____ C:\Users\Recovery+yexgr.txt
2016-02-20 15:57 - 2016-02-20 16:09 - 00002152 _____ C:\ProgramData\Recovery+yexgr.txt
2016-02-20 15:57 - 2016-02-20 16:09 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+yexgr.txt
2016-02-20 15:57 - 2016-02-20 16:07 - 00007479 _____ C:\Users\Public\Documents\Recovery+yexgr.html
2016-02-20 15:57 - 2016-02-20 16:07 - 00002152 _____ C:\Users\Public\Documents\Recovery+yexgr.txt
2016-02-20 15:57 - 2016-02-20 15:57 - 00007479 _____ C:\Users\Administrador\Recovery+yexgr.html
2016-02-20 15:57 - 2016-02-20 15:57 - 00007479 _____ C:\Users\Administrador\AppData\Roaming\Recovery+yexgr.html
2016-02-20 15:57 - 2016-02-20 15:57 - 00007479 _____ C:\Users\Administrador\AppData\Recovery+yexgr.html
2016-02-20 15:57 - 2016-02-20 15:57 - 00002152 _____ C:\Users\Administrador\Recovery+yexgr.txt
2016-02-20 15:57 - 2016-02-20 15:57 - 00002152 _____ C:\Users\Administrador\AppData\Roaming\Recovery+yexgr.txt
2016-02-20 15:57 - 2016-02-20 15:57 - 00002152 _____ C:\Users\Administrador\AppData\Recovery+yexgr.txt
2016-02-20 15:50 - 2016-02-20 15:50 - 00007479 _____ C:\Program Files\Recovery+yexgr.html
2016-02-20 15:50 - 2016-02-20 15:50 - 00002152 _____ C:\Program Files\Recovery+yexgr.txt
2016-02-20 15:47 - 2016-02-20 15:47 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\uxcbu.exe
2016-02-20 15:47 - 2016-02-20 15:47 - 00000254 _____ C:\Users\pessoal\Documents\recover_file_xdjwlbpkk.txt
2016-02-19 21:41 - 2016-02-19 21:41 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\xjhhn.exe
2016-02-19 21:40 - 2016-02-19 21:40 - 00007479 _____ C:\Users\Public\Recovery+cbjwl.html
2016-02-19 21:40 - 2016-02-19 21:40 - 00007479 _____ C:\Users\Public\Downloads\Recovery+cbjwl.html
2016-02-19 21:40 - 2016-02-19 21:40 - 00007479 _____ C:\Users\pessoal\Recovery+cbjwl.html
2016-02-19 21:40 - 2016-02-19 21:40 - 00007479 _____ C:\Users\pessoal\Downloads\Recovery+cbjwl.html
2016-02-19 21:40 - 2016-02-19 21:40 - 00007479 _____ C:\Users\pessoal\Documents\Recovery+cbjwl.html
2016-02-19 21:40 - 2016-02-19 21:40 - 00002152 _____ C:\Users\Public\Recovery+cbjwl.txt
2016-02-19 21:40 - 2016-02-19 21:40 - 00002152 _____ C:\Users\Public\Downloads\Recovery+cbjwl.txt
2016-02-19 21:40 - 2016-02-19 21:40 - 00002152 _____ C:\Users\pessoal\Recovery+cbjwl.txt
2016-02-19 21:40 - 2016-02-19 21:40 - 00002152 _____ C:\Users\pessoal\Downloads\Recovery+cbjwl.txt
2016-02-19 21:40 - 2016-02-19 21:40 - 00002152 _____ C:\Users\pessoal\Documents\Recovery+cbjwl.txt
2016-02-19 21:39 - 2016-02-19 21:40 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+cbjwl.html
2016-02-19 21:39 - 2016-02-19 21:40 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+cbjwl.txt
2016-02-19 21:39 - 2016-02-19 21:39 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Recovery+cbjwl.html
2016-02-19 21:39 - 2016-02-19 21:39 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+cbjwl.html
2016-02-19 21:39 - 2016-02-19 21:39 - 00007479 _____ C:\Users\pessoal\AppData\Recovery+cbjwl.html
2016-02-19 21:39 - 2016-02-19 21:39 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Recovery+cbjwl.txt
2016-02-19 21:39 - 2016-02-19 21:39 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+cbjwl.txt
2016-02-19 21:39 - 2016-02-19 21:39 - 00002152 _____ C:\Users\pessoal\AppData\Recovery+cbjwl.txt
2016-02-19 21:38 - 2016-02-19 21:38 - 00007479 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+cbjwl.html
2016-02-19 21:38 - 2016-02-19 21:38 - 00002152 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:40 - 00007479 _____ C:\Users\Default\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:40 - 00002152 _____ C:\Users\Default\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:39 - 00007479 _____ C:\Users\pessoal\AppData\Local\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:39 - 00002152 _____ C:\Users\pessoal\AppData\Local\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Usuário Padrão\Downloads\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Usuário Padrão\Documents\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Usuário Padrão\Desktop\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default\Downloads\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default\Documents\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default\Desktop\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default\AppData\Roaming\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default\AppData\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default\AppData\Local\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default User\Downloads\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default User\Documents\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default User\Desktop\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default User\AppData\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Default User\AppData\Local\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Convidado\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Convidado\AppData\Roaming\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00007479 _____ C:\Users\Convidado\AppData\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Usuário Padrão\Downloads\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Usuário Padrão\Documents\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Usuário Padrão\Desktop\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default\Downloads\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default\Documents\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default\Desktop\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default\AppData\Roaming\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default\AppData\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default\AppData\Local\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default User\Downloads\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default User\Documents\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default User\Desktop\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default User\AppData\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Default User\AppData\Local\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Convidado\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Convidado\AppData\Roaming\Recovery+cbjwl.txt
2016-02-19 21:34 - 2016-02-19 21:34 - 00002152 _____ C:\Users\Convidado\AppData\Recovery+cbjwl.txt
2016-02-19 21:33 - 2016-02-19 21:40 - 00007479 _____ C:\Users\Todos os Usuários\Recovery+cbjwl.html
2016-02-19 21:33 - 2016-02-19 21:40 - 00007479 _____ C:\Users\Public\Documents\Recovery+cbjwl.html
2016-02-19 21:33 - 2016-02-19 21:40 - 00007479 _____ C:\ProgramData\Recovery+cbjwl.html
2016-02-19 21:33 - 2016-02-19 21:40 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+cbjwl.html
2016-02-19 21:33 - 2016-02-19 21:40 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+cbjwl.html
2016-02-19 21:33 - 2016-02-19 21:40 - 00002152 _____ C:\Users\Todos os Usuários\Recovery+cbjwl.txt
2016-02-19 21:33 - 2016-02-19 21:40 - 00002152 _____ C:\Users\Public\Documents\Recovery+cbjwl.txt
2016-02-19 21:33 - 2016-02-19 21:40 - 00002152 _____ C:\ProgramData\Recovery+cbjwl.txt
2016-02-19 21:33 - 2016-02-19 21:40 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+cbjwl.txt
2016-02-19 21:33 - 2016-02-19 21:40 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+cbjwl.txt
2016-02-19 21:33 - 2016-02-19 21:33 - 00007479 _____ C:\Users\Administrador\Recovery+cbjwl.html
2016-02-19 21:33 - 2016-02-19 21:33 - 00007479 _____ C:\Users\Administrador\AppData\Roaming\Recovery+cbjwl.html
2016-02-19 21:33 - 2016-02-19 21:33 - 00007479 _____ C:\Users\Administrador\AppData\Recovery+cbjwl.html
2016-02-19 21:33 - 2016-02-19 21:33 - 00002152 _____ C:\Users\Administrador\Recovery+cbjwl.txt
2016-02-19 21:33 - 2016-02-19 21:33 - 00002152 _____ C:\Users\Administrador\AppData\Roaming\Recovery+cbjwl.txt
2016-02-19 21:33 - 2016-02-19 21:33 - 00002152 _____ C:\Users\Administrador\AppData\Recovery+cbjwl.txt
2016-02-19 21:32 - 2016-02-19 21:40 - 00007479 _____ C:\Users\Recovery+cbjwl.html
2016-02-19 21:32 - 2016-02-19 21:40 - 00002152 _____ C:\Users\Recovery+cbjwl.txt
2016-02-19 21:27 - 2016-02-19 21:27 - 00007479 _____ C:\Program Files\Recovery+cbjwl.html
2016-02-19 21:27 - 2016-02-19 21:27 - 00002152 _____ C:\Program Files\Recovery+cbjwl.txt
2016-02-19 21:22 - 2016-02-19 21:22 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\xniet.exe
2016-02-19 21:22 - 2016-02-19 21:22 - 00000254 _____ C:\Users\pessoal\Documents\recover_file_vxrarhuca.txt
2016-02-19 09:37 - 2016-02-19 09:37 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\yintd.exe
2016-02-19 09:36 - 2016-02-19 09:36 - 00007479 _____ C:\Users\Public\Recovery+kogva.html
2016-02-19 09:36 - 2016-02-19 09:36 - 00007479 _____ C:\Users\Public\Downloads\Recovery+kogva.html
2016-02-19 09:36 - 2016-02-19 09:36 - 00007479 _____ C:\Users\pessoal\Recovery+kogva.html
2016-02-19 09:36 - 2016-02-19 09:36 - 00007479 _____ C:\Users\pessoal\Downloads\Recovery+kogva.html
2016-02-19 09:36 - 2016-02-19 09:36 - 00007479 _____ C:\Users\pessoal\Documents\Recovery+kogva.html
2016-02-19 09:36 - 2016-02-19 09:36 - 00002152 _____ C:\Users\Public\Recovery+kogva.txt
2016-02-19 09:36 - 2016-02-19 09:36 - 00002152 _____ C:\Users\Public\Downloads\Recovery+kogva.txt
2016-02-19 09:36 - 2016-02-19 09:36 - 00002152 _____ C:\Users\pessoal\Recovery+kogva.txt
2016-02-19 09:36 - 2016-02-19 09:36 - 00002152 _____ C:\Users\pessoal\Downloads\Recovery+kogva.txt
2016-02-19 09:36 - 2016-02-19 09:36 - 00002152 _____ C:\Users\pessoal\Documents\Recovery+kogva.txt
2016-02-19 09:35 - 2016-02-19 09:36 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+kogva.html
2016-02-19 09:35 - 2016-02-19 09:36 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+kogva.txt
2016-02-19 09:35 - 2016-02-19 09:35 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Recovery+kogva.html
2016-02-19 09:35 - 2016-02-19 09:35 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+kogva.html
2016-02-19 09:35 - 2016-02-19 09:35 - 00007479 _____ C:\Users\pessoal\AppData\Recovery+kogva.html
2016-02-19 09:35 - 2016-02-19 09:35 - 00007479 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+kogva.html
2016-02-19 09:35 - 2016-02-19 09:35 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Recovery+kogva.txt
2016-02-19 09:35 - 2016-02-19 09:35 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+kogva.txt
2016-02-19 09:35 - 2016-02-19 09:35 - 00002152 _____ C:\Users\pessoal\AppData\Recovery+kogva.txt
2016-02-19 09:35 - 2016-02-19 09:35 - 00002152 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:37 - 00007479 _____ C:\Users\Default\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:37 - 00002152 _____ C:\Users\Default\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:35 - 00007479 _____ C:\Users\pessoal\AppData\Local\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:35 - 00002152 _____ C:\Users\pessoal\AppData\Local\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Usuário Padrão\Downloads\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Usuário Padrão\Documents\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Usuário Padrão\Desktop\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default\Downloads\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default\Documents\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default\Desktop\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default\AppData\Roaming\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default\AppData\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default User\Downloads\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default User\Documents\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default User\Desktop\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default User\AppData\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Usuário Padrão\Downloads\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Usuário Padrão\Documents\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Usuário Padrão\Desktop\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default\Downloads\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default\Documents\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default\Desktop\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default\AppData\Roaming\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default\AppData\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default User\Downloads\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default User\Documents\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default User\Desktop\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+kogva.txt
2016-02-19 09:32 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default User\AppData\Recovery+kogva.txt
2016-02-19 09:31 - 2016-02-19 09:37 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+kogva.html
2016-02-19 09:31 - 2016-02-19 09:37 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+kogva.txt
2016-02-19 09:31 - 2016-02-19 09:36 - 00007479 _____ C:\Users\Public\Documents\Recovery+kogva.html
2016-02-19 09:31 - 2016-02-19 09:36 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+kogva.html
2016-02-19 09:31 - 2016-02-19 09:36 - 00002152 _____ C:\Users\Public\Documents\Recovery+kogva.txt
2016-02-19 09:31 - 2016-02-19 09:36 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+kogva.txt
2016-02-19 09:31 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+kogva.html
2016-02-19 09:31 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default\AppData\Local\Recovery+kogva.html
2016-02-19 09:31 - 2016-02-19 09:32 - 00007479 _____ C:\Users\Default User\AppData\Local\Recovery+kogva.html
2016-02-19 09:31 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+kogva.txt
2016-02-19 09:31 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default\AppData\Local\Recovery+kogva.txt
2016-02-19 09:31 - 2016-02-19 09:32 - 00002152 _____ C:\Users\Default User\AppData\Local\Recovery+kogva.txt
2016-02-19 09:31 - 2016-02-19 09:31 - 00007479 _____ C:\Users\Convidado\Recovery+kogva.html
2016-02-19 09:31 - 2016-02-19 09:31 - 00007479 _____ C:\Users\Convidado\AppData\Roaming\Recovery+kogva.html
2016-02-19 09:31 - 2016-02-19 09:31 - 00007479 _____ C:\Users\Convidado\AppData\Recovery+kogva.html
2016-02-19 09:31 - 2016-02-19 09:31 - 00002152 _____ C:\Users\Convidado\Recovery+kogva.txt
2016-02-19 09:31 - 2016-02-19 09:31 - 00002152 _____ C:\Users\Convidado\AppData\Roaming\Recovery+kogva.txt
2016-02-19 09:31 - 2016-02-19 09:31 - 00002152 _____ C:\Users\Convidado\AppData\Recovery+kogva.txt
2016-02-19 09:30 - 2016-02-19 09:37 - 00007479 _____ C:\Users\Todos os Usuários\Recovery+kogva.html
2016-02-19 09:30 - 2016-02-19 09:37 - 00007479 _____ C:\Users\Recovery+kogva.html
2016-02-19 09:30 - 2016-02-19 09:37 - 00007479 _____ C:\ProgramData\Recovery+kogva.html
2016-02-19 09:30 - 2016-02-19 09:37 - 00002152 _____ C:\Users\Todos os Usuários\Recovery+kogva.txt
2016-02-19 09:30 - 2016-02-19 09:37 - 00002152 _____ C:\Users\Recovery+kogva.txt
2016-02-19 09:30 - 2016-02-19 09:37 - 00002152 _____ C:\ProgramData\Recovery+kogva.txt
2016-02-19 09:30 - 2016-02-19 09:30 - 00007479 _____ C:\Users\Administrador\Recovery+kogva.html
2016-02-19 09:30 - 2016-02-19 09:30 - 00007479 _____ C:\Users\Administrador\AppData\Roaming\Recovery+kogva.html
2016-02-19 09:30 - 2016-02-19 09:30 - 00007479 _____ C:\Users\Administrador\AppData\Recovery+kogva.html
2016-02-19 09:30 - 2016-02-19 09:30 - 00002152 _____ C:\Users\Administrador\Recovery+kogva.txt
2016-02-19 09:30 - 2016-02-19 09:30 - 00002152 _____ C:\Users\Administrador\AppData\Roaming\Recovery+kogva.txt
2016-02-19 09:30 - 2016-02-19 09:30 - 00002152 _____ C:\Users\Administrador\AppData\Recovery+kogva.txt
2016-02-19 09:28 - 2016-02-19 09:28 - 00007479 _____ C:\Program Files\Recovery+kogva.html
2016-02-19 09:28 - 2016-02-19 09:28 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\yydnp.exe
2016-02-19 09:28 - 2016-02-19 09:28 - 00002152 _____ C:\Program Files\Recovery+kogva.txt
2016-02-19 09:28 - 2016-02-19 09:28 - 00000254 _____ C:\Users\pessoal\Documents\recover_file_jhhnnppxh.txt
2016-02-18 08:56 - 2016-02-18 08:56 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\ivvra.exe
2016-02-18 08:55 - 2016-02-18 08:55 - 00007479 _____ C:\Users\Public\Recovery+fdlic.html
2016-02-18 08:55 - 2016-02-18 08:55 - 00007479 _____ C:\Users\Public\Downloads\Recovery+fdlic.html
2016-02-18 08:55 - 2016-02-18 08:55 - 00007479 _____ C:\Users\pessoal\Recovery+fdlic.html
2016-02-18 08:55 - 2016-02-18 08:55 - 00007479 _____ C:\Users\pessoal\Downloads\Recovery+fdlic.html
2016-02-18 08:55 - 2016-02-18 08:55 - 00007479 _____ C:\Users\pessoal\Documents\Recovery+fdlic.html
2016-02-18 08:55 - 2016-02-18 08:55 - 00002152 _____ C:\Users\Public\Recovery+fdlic.txt
2016-02-18 08:55 - 2016-02-18 08:55 - 00002152 _____ C:\Users\Public\Downloads\Recovery+fdlic.txt
2016-02-18 08:55 - 2016-02-18 08:55 - 00002152 _____ C:\Users\pessoal\Recovery+fdlic.txt
2016-02-18 08:55 - 2016-02-18 08:55 - 00002152 _____ C:\Users\pessoal\Downloads\Recovery+fdlic.txt
2016-02-18 08:55 - 2016-02-18 08:55 - 00002152 _____ C:\Users\pessoal\Documents\Recovery+fdlic.txt
2016-02-18 08:54 - 2016-02-18 08:55 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fdlic.html
2016-02-18 08:54 - 2016-02-18 08:55 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fdlic.txt
2016-02-18 08:54 - 2016-02-18 08:54 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Recovery+fdlic.html
2016-02-18 08:54 - 2016-02-18 08:54 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fdlic.html
2016-02-18 08:54 - 2016-02-18 08:54 - 00007479 _____ C:\Users\pessoal\AppData\Recovery+fdlic.html
2016-02-18 08:54 - 2016-02-18 08:54 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Recovery+fdlic.txt
2016-02-18 08:54 - 2016-02-18 08:54 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fdlic.txt
2016-02-18 08:54 - 2016-02-18 08:54 - 00002152 _____ C:\Users\pessoal\AppData\Recovery+fdlic.txt
2016-02-18 08:53 - 2016-02-18 08:53 - 00007479 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+fdlic.html
2016-02-18 08:53 - 2016-02-18 08:53 - 00002152 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:56 - 00007479 _____ C:\Users\Default\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:56 - 00002152 _____ C:\Users\Default\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:54 - 00007479 _____ C:\Users\pessoal\AppData\Local\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:54 - 00002152 _____ C:\Users\pessoal\AppData\Local\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Usuário Padrão\Downloads\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Usuário Padrão\Documents\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Usuário Padrão\Desktop\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default\Downloads\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default\Documents\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default\Desktop\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default\AppData\Roaming\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default\AppData\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default User\Downloads\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default User\Documents\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default User\Desktop\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default User\AppData\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Usuário Padrão\Downloads\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Usuário Padrão\Documents\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Usuário Padrão\Desktop\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default\Downloads\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default\Documents\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default\Desktop\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default\AppData\Roaming\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default\AppData\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default User\Downloads\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default User\Documents\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default User\Desktop\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+fdlic.txt
2016-02-18 08:50 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default User\AppData\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:56 - 00007479 _____ C:\Users\Todos os Usuários\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:56 - 00007479 _____ C:\ProgramData\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:56 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:56 - 00002152 _____ C:\Users\Todos os Usuários\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:56 - 00002152 _____ C:\ProgramData\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:56 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:55 - 00007479 _____ C:\Users\Public\Documents\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:55 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:55 - 00002152 _____ C:\Users\Public\Documents\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:55 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default\AppData\Local\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:50 - 00007479 _____ C:\Users\Default User\AppData\Local\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default\AppData\Local\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:50 - 00002152 _____ C:\Users\Default User\AppData\Local\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:49 - 00007479 _____ C:\Users\Convidado\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:49 - 00007479 _____ C:\Users\Convidado\AppData\Roaming\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:49 - 00007479 _____ C:\Users\Convidado\AppData\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:49 - 00007479 _____ C:\Users\Administrador\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:49 - 00007479 _____ C:\Users\Administrador\AppData\Roaming\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:49 - 00007479 _____ C:\Users\Administrador\AppData\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:49 - 00002152 _____ C:\Users\Convidado\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:49 - 00002152 _____ C:\Users\Convidado\AppData\Roaming\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:49 - 00002152 _____ C:\Users\Convidado\AppData\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:49 - 00002152 _____ C:\Users\Administrador\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:49 - 00002152 _____ C:\Users\Administrador\AppData\Roaming\Recovery+fdlic.txt
2016-02-18 08:49 - 2016-02-18 08:49 - 00002152 _____ C:\Users\Administrador\AppData\Recovery+fdlic.txt
2016-02-18 08:48 - 2016-02-18 08:56 - 00007479 _____ C:\Users\Recovery+fdlic.html
2016-02-18 08:48 - 2016-02-18 08:56 - 00002152 _____ C:\Users\Recovery+fdlic.txt
2016-02-18 08:47 - 2016-02-18 08:47 - 00007479 _____ C:\Program Files\Recovery+fdlic.html
2016-02-18 08:47 - 2016-02-18 08:47 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\qgkhn.exe
2016-02-18 08:47 - 2016-02-18 08:47 - 00002152 _____ C:\Program Files\Recovery+fdlic.txt
2016-02-18 08:47 - 2016-02-18 08:47 - 00000254 _____ C:\Users\pessoal\Documents\recover_file_iwbhltsco.txt
2016-02-17 11:44 - 2016-02-17 11:44 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\nivts.exe
2016-02-17 11:43 - 2016-02-17 11:43 - 00007479 _____ C:\Users\Public\Recovery+wsscw.html
2016-02-17 11:43 - 2016-02-17 11:43 - 00007479 _____ C:\Users\Public\Downloads\Recovery+wsscw.html
2016-02-17 11:43 - 2016-02-17 11:43 - 00007479 _____ C:\Users\pessoal\Recovery+wsscw.html
2016-02-17 11:43 - 2016-02-17 11:43 - 00007479 _____ C:\Users\pessoal\Downloads\Recovery+wsscw.html
2016-02-17 11:43 - 2016-02-17 11:43 - 00002152 _____ C:\Users\Public\Recovery+wsscw.txt
2016-02-17 11:43 - 2016-02-17 11:43 - 00002152 _____ C:\Users\Public\Downloads\Recovery+wsscw.txt
2016-02-17 11:43 - 2016-02-17 11:43 - 00002152 _____ C:\Users\pessoal\Recovery+wsscw.txt
2016-02-17 11:43 - 2016-02-17 11:43 - 00002152 _____ C:\Users\pessoal\Downloads\Recovery+wsscw.txt
2016-02-17 11:42 - 2016-02-17 11:43 - 00007479 _____ C:\Users\pessoal\Documents\Recovery+wsscw.html
2016-02-17 11:42 - 2016-02-17 11:43 - 00002152 _____ C:\Users\pessoal\Documents\Recovery+wsscw.txt
2016-02-17 11:14 - 2016-02-17 11:15 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Recovery+wsscw.html
2016-02-17 11:14 - 2016-02-17 11:15 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Recovery+wsscw.txt
2016-02-17 11:14 - 2016-02-17 11:14 - 00007479 _____ C:\Users\pessoal\AppData\Recovery+wsscw.html
2016-02-17 11:14 - 2016-02-17 11:14 - 00002152 _____ C:\Users\pessoal\AppData\Recovery+wsscw.txt
2016-02-17 11:10 - 2016-02-17 11:43 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+wsscw.html
2016-02-17 11:10 - 2016-02-17 11:43 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+wsscw.txt
2016-02-17 11:09 - 2016-02-17 11:10 - 00007479 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+wsscw.html
2016-02-17 11:09 - 2016-02-17 11:10 - 00002152 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+wsscw.txt
2016-02-17 11:09 - 2016-02-17 11:09 - 00007479 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+wsscw.html
2016-02-17 11:09 - 2016-02-17 11:09 - 00002152 _____ C:\Users\pessoal\AppData\LocalLow\Recovery+wsscw.txt
2016-02-17 10:59 - 2016-02-17 11:14 - 00007479 _____ C:\Users\pessoal\AppData\Local\Recovery+wsscw.html
2016-02-17 10:59 - 2016-02-17 11:14 - 00002152 _____ C:\Users\pessoal\AppData\Local\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 11:43 - 00007479 _____ C:\Users\Default\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 11:43 - 00002152 _____ C:\Users\Default\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Usuário Padrão\Downloads\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Usuário Padrão\Documents\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Usuário Padrão\Desktop\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default\Downloads\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default\Documents\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default\Desktop\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default\AppData\Roaming\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default\AppData\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default\AppData\Local\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default User\Downloads\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default User\Documents\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default User\Desktop\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default User\AppData\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Default User\AppData\Local\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Convidado\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Convidado\AppData\Roaming\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00007479 _____ C:\Users\Convidado\AppData\Recovery+wsscw.html
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Usuário Padrão\Downloads\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Usuário Padrão\Documents\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Usuário Padrão\Desktop\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Usuário Padrão\AppData\Local\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default\Downloads\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default\Documents\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default\Desktop\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default\AppData\Roaming\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default\AppData\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default\AppData\Local\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default User\Downloads\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default User\Documents\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default User\Desktop\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default User\AppData\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Default User\AppData\Local\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Convidado\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Convidado\AppData\Roaming\Recovery+wsscw.txt
2016-02-17 10:58 - 2016-02-17 10:58 - 00002152 _____ C:\Users\Convidado\AppData\Recovery+wsscw.txt
2016-02-17 10:57 - 2016-02-17 11:43 - 00007479 _____ C:\Users\Public\Documents\Recovery+wsscw.html
2016-02-17 10:57 - 2016-02-17 11:43 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+wsscw.html
2016-02-17 10:57 - 2016-02-17 11:43 - 00007479 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+wsscw.html
2016-02-17 10:57 - 2016-02-17 11:43 - 00002152 _____ C:\Users\Public\Documents\Recovery+wsscw.txt
2016-02-17 10:57 - 2016-02-17 11:43 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Recovery+wsscw.txt
2016-02-17 10:57 - 2016-02-17 11:43 - 00002152 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recovery+wsscw.txt
2016-02-17 10:56 - 2016-02-17 11:43 - 00007479 _____ C:\Users\Todos os Usuários\Recovery+wsscw.html
2016-02-17 10:56 - 2016-02-17 11:43 - 00007479 _____ C:\Users\Recovery+wsscw.html
2016-02-17 10:56 - 2016-02-17 11:43 - 00007479 _____ C:\ProgramData\Recovery+wsscw.html
2016-02-17 10:56 - 2016-02-17 11:43 - 00002152 _____ C:\Users\Todos os Usuários\Recovery+wsscw.txt
2016-02-17 10:56 - 2016-02-17 11:43 - 00002152 _____ C:\Users\Recovery+wsscw.txt
2016-02-17 10:56 - 2016-02-17 11:43 - 00002152 _____ C:\ProgramData\Recovery+wsscw.txt
2016-02-17 10:56 - 2016-02-17 10:56 - 00007479 _____ C:\Users\Administrador\Recovery+wsscw.html
2016-02-17 10:56 - 2016-02-17 10:56 - 00007479 _____ C:\Users\Administrador\AppData\Roaming\Recovery+wsscw.html
2016-02-17 10:56 - 2016-02-17 10:56 - 00007479 _____ C:\Users\Administrador\AppData\Recovery+wsscw.html
2016-02-17 10:56 - 2016-02-17 10:56 - 00002152 _____ C:\Users\Administrador\Recovery+wsscw.txt
2016-02-17 10:56 - 2016-02-17 10:56 - 00002152 _____ C:\Users\Administrador\AppData\Roaming\Recovery+wsscw.txt
2016-02-17 10:56 - 2016-02-17 10:56 - 00002152 _____ C:\Users\Administrador\AppData\Recovery+wsscw.txt
2016-02-17 10:41 - 2016-02-17 10:41 - 00007479 _____ C:\Program Files\Recovery+wsscw.html
2016-02-17 10:41 - 2016-02-17 10:41 - 00002152 _____ C:\Program Files\Recovery+wsscw.txt
2016-02-17 10:40 - 2016-02-17 10:40 - 00005632 ____H (TODO: ) C:\Users\pessoal\Documents\mdryq.exe
2016-02-17 10:40 - 2016-02-17 10:40 - 00000254 _____ C:\Users\pessoal\Documents\recover_file_jvqanewul.txt
2016-02-17 10:39 - 2016-02-17 10:39 - 00622592 ____H C:\Windows\gpxrxoiwfhap.exe
2016-02-17 05:20 - 2016-02-17 09:15 - 00000230 _____ C:\Windows\Tasks\osTip.job
2016-02-15 23:41 - 2016-02-15 23:41 - 00000631 _____ C:\istartpageing.xml
2016-02-15 23:09 - 2016-02-22 21:35 - 00010365 _____ C:\Users\Todos os Usuários\webad.xml
2016-02-15 23:09 - 2016-02-22 21:35 - 00010365 _____ C:\ProgramData\webad.xml
2016-02-15 22:54 - 2016-02-22 21:52 - 00000000 ____D C:\Users\pessoal\Desktop\Limpesa
2016-02-15 22:33 - 2016-02-22 21:52 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\ProductData
2016-02-15 22:33 - 2016-02-22 21:51 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\IObit
2016-02-15 22:33 - 2016-02-22 21:51 - 00000000 ____D C:\Users\pessoal\AppData\LocalLow\IObit
2016-02-15 22:33 - 2016-02-22 21:46 - 00000000 ____D C:\Users\Todos os Usuários\ProductData
2016-02-15 22:33 - 2016-02-22 21:46 - 00000000 ____D C:\Users\Todos os Usuários\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98}
2016-02-15 22:33 - 2016-02-22 21:46 - 00000000 ____D C:\ProgramData\ProductData
2016-02-15 22:33 - 2016-02-22 21:46 - 00000000 ____D C:\ProgramData\{FD6F83C0-EC70-4581-8361-C70CD1AA4B98}
2016-02-15 22:33 - 2016-02-22 21:45 - 00000000 ____D C:\Users\Todos os Usuários\IObit
2016-02-15 22:33 - 2016-02-22 21:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller
2016-02-15 22:33 - 2016-02-22 21:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare
2016-02-15 22:33 - 2016-02-22 21:45 - 00000000 ____D C:\ProgramData\IObit
2016-02-15 22:33 - 2016-02-15 22:39 - 00000000 ____D C:\Program Files\Common Files\IObit
2016-02-15 22:33 - 2016-02-15 22:33 - 00002110 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk
2016-02-15 22:33 - 2016-02-15 22:33 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2016-02-15 22:33 - 2016-02-15 22:33 - 00000000 ____D C:\Program Files\IObit
2016-02-15 22:24 - 2016-02-15 22:24 - 00000000 ____D C:\Program Files\CCleaner
2016-02-15 22:22 - 2016-02-22 21:45 - 00000000 ____D C:\Users\Todos os Usuários\Auslogics
2016-02-15 22:22 - 2016-02-22 21:45 - 00000000 ____D C:\ProgramData\Auslogics
2016-02-15 22:20 - 2016-02-22 21:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
2016-02-15 22:20 - 2016-02-15 22:20 - 00000000 ____D C:\Program Files\Auslogics
2016-02-15 22:06 - 2016-02-15 22:06 - 44466176 ____H (Kutre joni motor) C:\Users\pessoal\aajjxivv.exe
2016-02-15 12:14 - 2016-02-15 12:14 - 00000000 ____D C:\Windows\Sun
2016-02-14 11:46 - 2016-02-14 11:46 - 00000000 _____ C:\Windows\kernel32.dll
2016-02-13 00:27 - 2016-02-22 21:35 - 00000352 ____H C:\Windows\Tasks\alFSVWJB.job
2016-02-12 18:20 - 2016-02-14 15:06 - 00009441 _____ C:\Users\pessoal\AppData\Roaming\webad.xml
2016-02-12 12:01 - 2016-02-14 12:01 - 00000098 _____ C:\Users\pessoal\AppData\Roaming\WB.CFG
2016-02-11 23:02 - 2016-02-22 21:52 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\QyjxiiEfedje
2016-02-11 23:02 - 2016-02-22 21:51 - 00000000 ____D C:\Users\pessoal\AppData\Local\Tempfolder
2016-02-11 23:02 - 2016-02-20 22:50 - 00000000 ____D C:\Program Files\shopperz120220160129
2016-02-11 23:02 - 2016-02-11 23:02 - 00030104 _____ () C:\Windows\system32\Drivers\bsdriver.sys
2016-02-11 23:02 - 2016-02-11 23:02 - 00000000 ____D C:\Windows\system32\nopw
2016-02-11 20:33 - 2016-02-11 23:02 - 00049408 _____ (Cherimoya Ltd) C:\Windows\system32\Drivers\cherimoya.sys
2016-02-11 16:19 - 2016-01-26 10:54 - 02415616 _____ C:\Users\pessoal\AppData\Roaming\msiql.exe
2016-02-11 15:12 - 2016-02-22 21:46 - 00000000 ____D C:\Users\Todos os Usuários\WindowsMsg
2016-02-11 15:12 - 2016-02-22 21:46 - 00000000 ____D C:\ProgramData\WindowsMsg
2016-02-11 15:04 - 2016-02-11 15:04 - 00000000 ____D C:\Program Files\VideoLAN
2016-02-11 15:01 - 2016-02-11 15:00 - 00001495 _____ C:\Windows\system32\Drivers\etc\hp.bak
2016-02-11 14:59 - 2016-02-22 21:51 - 00000000 ____D C:\Users\pessoal\AppData\LocalLow\Company
2016-02-11 14:59 - 2016-02-22 21:45 - 00000000 ____D C:\uninst
2016-02-11 10:38 - 2016-02-22 21:51 - 00000000 ____D C:\Users\pessoal\AppData\LocalLow\uTorrent
2016-02-09 23:18 - 2016-02-22 21:53 - 00000000 ____D C:\Users\pessoal\Downloads\Sony Vegas Pro 13.0 build 310 (64 bit) (patch KHG) [ChingLiu]
2016-02-09 10:05 - 2016-02-22 21:53 - 00000000 ____D C:\Users\pessoal\Downloads\Haywyre - Two Fold Pt 2
2016-02-08 21:15 - 2016-02-08 21:15 - 00002651 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2016-02-07 21:56 - 2016-02-22 21:53 - 00000000 ____D C:\Users\Public\Documents\Tools
2016-02-06 20:29 - 2016-02-22 21:51 - 00000000 ___SD C:\Users\pessoal\AppData\LocalLow\Temp
2016-02-06 19:46 - 2016-02-22 21:52 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2016-02-06 18:47 - 2016-02-22 21:53 - 00000000 ____D C:\Users\pessoal\Downloads\Tony Hawk's Project 8 [PSP] [ENGLISH]
2016-02-06 18:28 - 2016-02-22 21:46 - 00000000 ____D C:\Users\Todos os Usuários\Windows Update
2016-02-06 18:28 - 2016-02-22 21:46 - 00000000 ____D C:\ProgramData\Windows Update
2016-02-06 18:27 - 2016-01-26 11:54 - 02415616 _____ C:\Users\Todos os Usuários\msiql.exe
2016-02-06 18:27 - 2016-01-26 11:54 - 02415616 _____ C:\ProgramData\msiql.exe

==================== Um Mês Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-02-22 22:30 - 2015-11-11 22:56 - 00001058 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-22 22:08 - 2015-11-17 11:49 - 00000902 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-02-22 21:53 - 2015-12-23 13:29 - 00000000 ____D C:\Users\pessoal\Downloads\The Last - Naruto the Movie (BDRip 1080p FLAC 5.1) [rich_jc]
2016-02-22 21:53 - 2015-12-22 19:16 - 00000000 ____D C:\Users\Public\Documents\Baidu
2016-02-22 21:53 - 2015-12-16 16:48 - 00000000 ____D C:\Users\pessoal\Desktop\Victor
2016-02-22 21:53 - 2015-12-15 16:43 - 00000000 ____D C:\Users\pessoal\Downloads\Ela Dança, Eu Danço 5 (2015) BRrip Blu-Ray 1080p 5.1 Ch Dublado - AndreTPF
2016-02-22 21:53 - 2015-12-15 16:41 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-02-22 21:53 - 2015-11-20 13:39 - 00000000 ____D C:\Users\pessoal\Downloads\Instalador_Client_Elsword_5.0923.52
2016-02-22 21:53 - 2015-11-18 17:22 - 00000000 ____D C:\Users\pessoal\Tracing
2016-02-22 21:53 - 2015-11-04 19:52 - 00000000 ____D C:\Users\pessoal\Downloads\Call Of Duty Black Ops 3 Compatibility Pack + TU 01 www.soparaxbox360.com
2016-02-22 21:53 - 2015-10-23 12:29 - 00000000 ____D C:\Users\pessoal
2016-02-22 21:53 - 2009-07-14 04:49 - 00000000 ___RD C:\Users\Public\Recorded TV
2016-02-22 21:53 - 2009-07-13 23:37 - 00000000 __RHD C:\Users\Public\Libraries
2016-02-22 21:52 - 2016-01-22 09:34 - 00000000 ____D C:\Users\pessoal\Desktop\CATALAGO ESQUADRIAS
2016-02-22 21:52 - 2016-01-14 11:20 - 00000000 ____D C:\Users\pessoal\Desktop\ORÇAMENTOS
2016-02-22 21:52 - 2016-01-09 09:55 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\NVIDIA
2016-02-22 21:52 - 2016-01-08 17:04 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicativos do Google Chrome
2016-02-22 21:52 - 2016-01-04 15:24 - 00000000 ____D C:\Users\pessoal\Desktop\FOTOS VENDAS
2016-02-22 21:52 - 2015-12-31 14:10 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Sun
2016-02-22 21:52 - 2015-12-31 14:00 - 00000000 ____D C:\Users\pessoal\Desktop\Portas
2016-02-22 21:52 - 2015-12-31 09:48 - 00000000 ____D C:\Users\pessoal\Desktop\CAD
2016-02-22 21:52 - 2015-12-25 12:26 - 00000000 ____D C:\Users\pessoal\Desktop\MATEUS
2016-02-22 21:52 - 2015-12-25 11:01 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\XBox
2016-02-22 21:52 - 2015-12-24 18:06 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\ZHP
2016-02-22 21:52 - 2015-12-22 18:42 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\UpAuroraBrowser
2016-02-22 21:52 - 2015-12-22 13:37 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2016-02-22 21:52 - 2015-12-21 15:25 - 00000000 ____D C:\Users\pessoal\Desktop\TRABALHO DE MADEIRA
2016-02-22 21:52 - 2015-12-16 16:46 - 00000000 ____D C:\Users\pessoal\Desktop\Arquivos Word
2016-02-22 21:52 - 2015-12-08 17:18 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\TeamViewer
2016-02-22 21:52 - 2015-12-03 19:22 - 00000000 ____D C:\Users\pessoal\Desktop\HORAS COMPLEMENTARES
2016-02-22 21:52 - 2015-12-03 18:34 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WebPlugin
2016-02-22 21:52 - 2015-11-24 21:02 - 00000000 ____D C:\Users\pessoal\Desktop\Jogos
2016-02-22 21:52 - 2015-11-20 23:44 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Opera Software
2016-02-22 21:52 - 2015-11-17 19:42 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Skype
2016-02-22 21:52 - 2015-11-17 18:22 - 00000000 ____D C:\Users\pessoal\Desktop\projeto TCC
2016-02-22 21:52 - 2015-11-17 14:38 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\MPC-HC
2016-02-22 21:52 - 2015-11-16 22:01 - 00000000 ____D C:\Users\pessoal\Desktop\Ryan
2016-02-22 21:52 - 2015-11-15 14:41 - 00000000 ____D C:\Users\pessoal\Desktop\FACCAMP
2016-02-22 21:52 - 2015-11-14 22:25 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Unity
2016-02-22 21:52 - 2015-11-14 18:11 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\uTorrent
2016-02-22 21:52 - 2015-11-14 18:04 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Horizon
2016-02-22 21:52 - 2015-11-11 19:32 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\WinRAR
2016-02-22 21:52 - 2015-11-11 19:20 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Mozilla
2016-02-22 21:52 - 2015-10-25 16:44 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\X Codec Pack 2.7.0 Xmas Edition
2016-02-22 21:52 - 2015-10-25 16:44 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-02-22 21:51 - 2016-01-08 18:10 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\LightGate
2016-02-22 21:51 - 2015-12-31 14:10 - 00000000 ____D C:\Users\pessoal\AppData\LocalLow\Sun
2016-02-22 21:51 - 2015-12-31 14:04 - 00000000 ____D C:\Users\pessoal\AppData\LocalLow\Oracle
2016-02-22 21:51 - 2015-12-22 18:47 - 00000000 ____D C:\Users\pessoal\AppData\Local\Yeaplayer
2016-02-22 21:51 - 2015-12-08 20:37 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\AdbDriverInstaller
2016-02-22 21:51 - 2015-12-08 17:20 - 00000000 ____D C:\Users\pessoal\AppData\Local\TeamViewer
2016-02-22 21:51 - 2015-11-20 23:44 - 00000000 ____D C:\Users\pessoal\AppData\Local\Opera Software
2016-02-22 21:51 - 2015-11-17 19:42 - 00000000 ____D C:\Users\pessoal\AppData\Local\Skype
2016-02-22 21:51 - 2015-11-17 13:49 - 00000000 ____D C:\Users\pessoal\AppData\Local\Steam
2016-02-22 21:51 - 2015-11-17 12:55 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Macromedia
2016-02-22 21:51 - 2015-11-15 13:01 - 00000000 ____D C:\Users\pessoal\AppData\Local\PDFCreator
2016-02-22 21:51 - 2015-11-14 22:21 - 00000000 ____D C:\Users\pessoal\AppData\LocalLow\Unity
2016-02-22 21:51 - 2015-11-14 22:21 - 00000000 ____D C:\Users\pessoal\AppData\Local\Unity
2016-02-22 21:51 - 2015-11-11 19:41 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Autodesk
2016-02-22 21:51 - 2015-11-11 19:20 - 00000000 ____D C:\Users\pessoal\AppData\Local\Mozilla
2016-02-22 21:51 - 2015-11-11 19:19 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Adobe
2016-02-22 21:51 - 2015-11-11 19:19 - 00000000 ____D C:\Users\pessoal\AppData\LocalLow\Adobe
2016-02-22 21:51 - 2015-10-25 16:26 - 00000000 ____D C:\Users\pessoal\AppData\Local\Microsoft Help
2016-02-22 21:51 - 2015-10-23 12:29 - 00000000 ____D C:\Users\pessoal\AppData\Roaming\Media Center Programs
2016-02-22 21:51 - 2015-10-23 12:29 - 00000000 ____D C:\Users\pessoal\AppData\Local\VirtualStore
2016-02-22 21:51 - 2009-07-13 20:41 - 00000000 __SHD C:\Users\pessoal\AppData\Roaming\alFSVWJB
2016-02-22 21:49 - 2015-11-17 12:55 - 00000000 ____D C:\Users\pessoal\AppData\Local\Macromedia
2016-02-22 21:49 - 2015-11-11 22:56 - 00000000 ____D C:\Users\pessoal\AppData\Local\Google
2016-02-22 21:46 - 2015-12-31 14:10 - 00000000 ____D C:\Users\pessoal\.oracle_jre_usage
2016-02-22 21:46 - 2015-12-31 14:09 - 00000000 ____D C:\Users\Todos os Usuários\Oracle
2016-02-22 21:46 - 2015-12-31 14:09 - 00000000 ____D C:\ProgramData\Oracle
2016-02-22 21:46 - 2015-12-25 11:37 - 00000000 ____D C:\Users\Todos os Usuários\System32
2016-02-22 21:46 - 2015-12-25 11:37 - 00000000 ____D C:\ProgramData\System32
2016-02-22 21:46 - 2015-12-19 04:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2016-02-22 21:46 - 2015-12-14 12:13 - 00000000 ____D C:\Users\pessoal\.android
2016-02-22 21:46 - 2015-12-08 14:04 - 00000000 ____D C:\Users\Todos os Usuários\Temp
2016-02-22 21:46 - 2015-12-08 14:04 - 00000000 ____D C:\ProgramData\Temp
2016-02-22 21:46 - 2015-11-22 13:29 - 00000000 ____D C:\Users\pessoal\AppData\Local\DFX
2016-02-22 21:46 - 2015-11-22 13:28 - 00000000 ____D C:\Users\Convidado\AppData\Roaming\vlc
2016-02-22 21:46 - 2015-11-17 19:41 - 00000000 ____D C:\Users\Todos os Usuários\Skype
2016-02-22 21:46 - 2015-11-17 19:41 - 00000000 ____D C:\ProgramData\Skype
2016-02-22 21:46 - 2015-11-17 13:49 - 00000000 ____D C:\Users\pessoal\AppData\Local\CEF
2016-02-22 21:46 - 2015-11-15 13:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2016-02-22 21:46 - 2015-11-14 18:04 - 00000000 ____D C:\Users\pessoal\AppData\Local\Daring_Development_Inc
2016-02-22 21:46 - 2015-11-14 18:04 - 00000000 ____D C:\Users\pessoal\AppData\Local\Daring Development
2016-02-22 21:46 - 2015-11-11 19:41 - 00000000 ____D C:\Users\pessoal\AppData\Local\Autodesk
2016-02-22 21:46 - 2015-11-11 19:19 - 00000000 ____D C:\Users\pessoal\AppData\Local\Adobe
2016-02-22 21:46 - 2015-10-25 16:46 - 00000000 ____D C:\Users\Todos os Usuários\Mozilla
2016-02-22 21:46 - 2015-10-25 16:46 - 00000000 ____D C:\ProgramData\Mozilla
2016-02-22 21:46 - 2015-10-25 16:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-02-22 21:46 - 2015-10-25 16:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2016-02-22 21:46 - 2015-10-25 16:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-02-22 21:46 - 2015-10-25 16:26 - 00000000 ____D C:\Users\Todos os Usuários\Microsoft Help
2016-02-22 21:46 - 2015-10-25 15:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-02-22 21:46 - 2015-10-25 15:35 - 00000000 ____D C:\Users\Todos os Usuários\NVIDIA
2016-02-22 21:46 - 2015-10-25 15:35 - 00000000 ____D C:\ProgramData\NVIDIA
2016-02-22 21:46 - 2015-10-25 15:34 - 00000000 ____D C:\Users\Todos os Usuários\NVIDIA Corporation
2016-02-22 21:46 - 2015-10-25 15:34 - 00000000 ____D C:\Users\pessoal\AppData\Local\ElevatedDiagnostics
2016-02-22 21:46 - 2015-10-25 15:34 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-02-22 21:46 - 2015-10-23 12:33 - 01517030 _____ C:\Windows\system32\PerfStringBackup.INI
2016-02-22 21:46 - 2009-07-29 15:38 - 00663606 _____ C:\Windows\system32\prfh0416.dat
2016-02-22 21:46 - 2009-07-29 15:38 - 00127896 _____ C:\Windows\system32\prfc0416.dat
2016-02-22 21:46 - 2009-07-14 04:49 - 00000000 ____D C:\Users\Usuário Padrão\AppData\Roaming\Media Center Programs
2016-02-22 21:46 - 2009-07-14 04:49 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2016-02-22 21:46 - 2009-07-14 04:49 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs
2016-02-22 21:46 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\inf
2016-02-22 21:45 - 2015-12-31 14:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-02-22 21:45 - 2015-12-22 13:37 - 00000000 ____D C:\FFOutput
2016-02-22 21:45 - 2015-12-08 20:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Android Device USB driver
2016-02-22 21:45 - 2015-12-08 14:04 - 00000000 ____D C:\Users\Todos os Usuários\GbPlugin
2016-02-22 21:45 - 2015-12-08 14:04 - 00000000 ____D C:\Users\Todos os Usuários\GAS Tecnologia
2016-02-22 21:45 - 2015-12-08 14:04 - 00000000 ____D C:\ProgramData\GbPlugin
2016-02-22 21:45 - 2015-12-08 14:04 - 00000000 ____D C:\ProgramData\GAS Tecnologia
2016-02-22 21:45 - 2015-11-22 13:29 - 00000000 ____D C:\Users\Todos os Usuários\DFX
2016-02-22 21:45 - 2015-11-22 13:29 - 00000000 ____D C:\ProgramData\DFX
2016-02-22 21:45 - 2015-11-22 13:28 - 00000000 ____D C:\Users\Administrador\AppData\Roaming\vlc
2016-02-22 21:45 - 2015-11-22 13:28 - 00000000 ____D C:\Users\Administrador
2016-02-22 21:45 - 2015-11-22 13:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DFX Audio Enhancer
2016-02-22 21:45 - 2015-11-17 11:49 - 00000000 ____D C:\Users\Todos os Usuários\McAfee
2016-02-22 21:45 - 2015-11-17 11:49 - 00000000 ____D C:\ProgramData\McAfee
2016-02-22 21:45 - 2015-11-11 19:44 - 00000000 ____D C:\Users\Todos os Usuários\FLEXnet
2016-02-22 21:45 - 2015-11-11 19:44 - 00000000 ____D C:\ProgramData\FLEXnet
2016-02-22 21:45 - 2015-11-11 19:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2016-02-22 21:45 - 2015-11-11 19:41 - 00000000 ____D C:\Users\Todos os Usuários\Autodesk
2016-02-22 21:45 - 2015-11-11 19:41 - 00000000 ____D C:\ProgramData\Autodesk
2016-02-22 21:45 - 2015-11-11 19:34 - 00000000 ____D C:\Autodesk
2016-02-22 21:45 - 2015-10-25 16:46 - 00000000 ____D C:\Users\Todos os Usuários\Adobe
2016-02-22 21:45 - 2015-10-25 16:46 - 00000000 ____D C:\ProgramData\Adobe
2016-02-22 21:45 - 2015-10-25 16:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-02-22 21:45 - 2015-10-25 16:27 - 00000000 ____D C:\Users\Todos os Usuários\Alwil Software
2016-02-22 21:45 - 2015-10-25 16:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
2016-02-22 21:45 - 2015-10-25 16:27 - 00000000 ____D C:\ProgramData\Alwil Software
2016-02-22 21:45 - 2015-10-25 16:26 - 00000000 __RHD C:\MSOCache
2016-02-22 21:45 - 2009-07-14 01:52 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-02-22 21:45 - 2009-07-13 23:37 - 00000000 ____D C:\PerfLogs
2016-02-22 21:41 - 2015-11-24 21:21 - 00000000 ____D C:\AdwCleaner
2016-02-22 21:41 - 2015-10-25 15:59 - 00000000 ____D C:\ative
2016-02-22 21:35 - 2015-11-11 22:56 - 00001054 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-22 21:34 - 2009-07-14 01:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-02-21 18:06 - 2009-07-14 01:34 - 00009600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-02-21 18:06 - 2009-07-14 01:34 - 00009600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-02-21 13:42 - 2009-07-14 01:46 - 00001515 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-02-20 16:03 - 2015-11-11 23:05 - 00002192 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-15 22:37 - 2015-10-23 18:15 - 00000000 ____D C:\Windows\Panther
2016-02-15 22:31 - 2015-12-08 17:18 - 00000000 ____D C:\Program Files\TeamViewer
2016-02-13 16:50 - 2009-07-14 01:53 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-02-12 10:59 - 2015-11-20 23:53 - 00001206 __RSH C:\Users\Todos os Usuários\ntuser.pol
2016-02-12 10:59 - 2015-11-20 23:53 - 00001206 __RSH C:\ProgramData\ntuser.pol
2016-02-11 22:44 - 2015-10-25 16:46 - 00001835 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-02-11 22:44 - 2015-10-23 12:30 - 00001393 _____ C:\Users\pessoal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-02-10 11:08 - 2015-11-17 11:49 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-02-10 11:08 - 2015-11-17 11:49 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-02-09 10:06 - 2015-11-17 13:36 - 00000000 ____D C:\Program Files\Common Files\Steam

==================== Arquivos na raiz de alguns diretórios =======

2016-02-21 13:32 - 2016-02-21 13:32 - 0007479 _____ () C:\Program Files\Recovery+bufcn.html
2016-02-21 13:32 - 2016-02-21 13:32 - 0087456 _____ () C:\Program Files\Recovery+bufcn.png
2016-02-21 13:32 - 2016-02-21 13:32 - 0002152 _____ () C:\Program Files\Recovery+bufcn.txt
2016-02-19 21:27 - 2016-02-19 21:27 - 0007479 _____ () C:\Program Files\Recovery+cbjwl.html
2016-02-19 21:27 - 2016-02-19 21:27 - 0087456 _____ () C:\Program Files\Recovery+cbjwl.png
2016-02-19 21:27 - 2016-02-19 21:27 - 0002152 _____ () C:\Program Files\Recovery+cbjwl.txt
2016-02-18 08:47 - 2016-02-18 08:47 - 0007479 _____ () C:\Program Files\Recovery+fdlic.html
2016-02-18 08:47 - 2016-02-18 08:47 - 0087456 _____ () C:\Program Files\Recovery+fdlic.png
2016-02-18 08:47 - 2016-02-18 08:47 - 0002152 _____ () C:\Program Files\Recovery+fdlic.txt
2016-02-21 23:02 - 2016-02-21 23:02 - 0007479 _____ () C:\Program Files\Recovery+fmehi.html
2016-02-21 23:02 - 2016-02-21 23:02 - 0087456 _____ () C:\Program Files\Recovery+fmehi.png
2016-02-21 23:02 - 2016-02-21 23:02 - 0002152 _____ () C:\Program Files\Recovery+fmehi.txt
2016-02-22 21:41 - 2016-02-22 21:41 - 0007479 _____ () C:\Program Files\Recovery+hqovs.html
2016-02-22 21:41 - 2016-02-22 21:41 - 0087456 _____ () C:\Program Files\Recovery+hqovs.png
2016-02-22 21:41 - 2016-02-22 21:41 - 0002152 _____ () C:\Program Files\Recovery+hqovs.txt
2016-02-19 09:28 - 2016-02-19 09:28 - 0007479 _____ () C:\Program Files\Recovery+kogva.html
2016-02-19 09:28 - 2016-02-19 09:28 - 0087456 _____ () C:\Program Files\Recovery+kogva.png
2016-02-19 09:28 - 2016-02-19 09:28 - 0002152 _____ () C:\Program Files\Recovery+kogva.txt
2016-02-20 23:19 - 2016-02-20 23:19 - 0007479 _____ () C:\Program Files\Recovery+rmbjh.html
2016-02-20 23:19 - 2016-02-20 23:19 - 0087456 _____ () C:\Program Files\Recovery+rmbjh.png
2016-02-20 23:19 - 2016-02-20 23:19 - 0002152 _____ () C:\Program Files\Recovery+rmbjh.txt
2016-02-17 10:41 - 2016-02-17 10:41 - 0007479 _____ () C:\Program Files\Recovery+wsscw.html
2016-02-17 10:41 - 2016-02-17 10:41 - 0087456 _____ () C:\Program Files\Recovery+wsscw.png
2016-02-17 10:41 - 2016-02-17 10:41 - 0002152 _____ () C:\Program Files\Recovery+wsscw.txt
2016-02-20 15:50 - 2016-02-20 15:50 - 0007479 _____ () C:\Program Files\Recovery+yexgr.html
2016-02-20 15:50 - 2016-02-20 15:50 - 0087456 _____ () C:\Program Files\Recovery+yexgr.png
2016-02-20 15:50 - 2016-02-20 15:50 - 0002152 _____ () C:\Program Files\Recovery+yexgr.txt
2016-02-22 10:05 - 2016-02-22 10:05 - 0007479 _____ () C:\Program Files\Recovery+yicto.html
2016-02-22 10:05 - 2016-02-22 10:05 - 0087456 _____ () C:\Program Files\Recovery+yicto.png
2016-02-22 10:05 - 2016-02-22 10:05 - 0002152 _____ () C:\Program Files\Recovery+yicto.txt
2016-02-11 16:19 - 2016-01-26 10:54 - 2415616 _____ () C:\Users\pessoal\AppData\Roaming\msiql.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0229888 ___SH (PortableApps.com) C:\Users\pessoal\AppData\Roaming\msiwnql.exe
2016-02-21 13:42 - 2016-02-21 13:42 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+bufcn.html
2016-02-21 13:42 - 2016-02-21 13:42 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+bufcn.png
2016-02-21 13:42 - 2016-02-21 13:42 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+bufcn.txt
2016-02-19 21:39 - 2016-02-19 21:39 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+cbjwl.html
2016-02-19 21:39 - 2016-02-19 21:39 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+cbjwl.png
2016-02-19 21:39 - 2016-02-19 21:39 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+cbjwl.txt
2016-02-18 08:54 - 2016-02-18 08:54 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+fdlic.html
2016-02-18 08:54 - 2016-02-18 08:54 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+fdlic.png
2016-02-18 08:54 - 2016-02-18 08:54 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+fdlic.txt
2016-02-21 23:10 - 2016-02-21 23:10 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+fmehi.html
2016-02-21 23:10 - 2016-02-21 23:10 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+fmehi.png
2016-02-21 23:10 - 2016-02-21 23:10 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+fmehi.txt
2016-02-22 21:52 - 2016-02-22 21:52 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+hqovs.html
2016-02-22 21:52 - 2016-02-22 21:52 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+hqovs.png
2016-02-22 21:52 - 2016-02-22 21:52 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+hqovs.txt
2016-02-19 09:35 - 2016-02-19 09:35 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+kogva.html
2016-02-19 09:35 - 2016-02-19 09:35 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+kogva.png
2016-02-19 09:35 - 2016-02-19 09:35 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+kogva.txt
2016-02-20 23:25 - 2016-02-20 23:25 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+rmbjh.html
2016-02-20 23:25 - 2016-02-20 23:25 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+rmbjh.png
2016-02-20 23:25 - 2016-02-20 23:25 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+rmbjh.txt
2016-02-17 11:14 - 2016-02-17 11:15 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+wsscw.html
2016-02-17 11:14 - 2016-02-17 11:15 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+wsscw.png
2016-02-17 11:14 - 2016-02-17 11:15 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+wsscw.txt
2016-02-20 16:05 - 2016-02-20 16:05 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+yexgr.html
2016-02-20 16:05 - 2016-02-20 16:05 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+yexgr.png
2016-02-20 16:05 - 2016-02-20 16:05 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+yexgr.txt
2016-02-22 10:12 - 2016-02-22 10:12 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+yicto.html
2016-02-22 10:12 - 2016-02-22 10:12 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+yicto.png
2016-02-22 10:12 - 2016-02-22 10:12 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Recovery+yicto.txt
2015-12-24 18:35 - 2015-12-23 06:13 - 4524576 _____ (${COMPANY_NAME}) C:\Users\pessoal\AppData\Roaming\Setup.exe
2015-12-25 10:59 - 2015-12-25 06:18 - 4540096 _____ (${COMPANY_NAME}) C:\Users\pessoal\AppData\Roaming\setup.exe@ver=1.0.0.0
2016-02-12 12:01 - 2016-02-14 12:01 - 0000098 _____ () C:\Users\pessoal\AppData\Roaming\WB.CFG
2016-02-12 18:20 - 2016-02-14 15:06 - 0009441 _____ () C:\Users\pessoal\AppData\Roaming\webad.xml
2016-02-12 09:07 - 2016-02-17 11:14 - 0001024 _____ () C:\Users\pessoal\AppData\Roaming\xcgui_debug.txt.mp3
2016-02-21 13:42 - 2016-02-21 13:42 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+bufcn.html
2016-02-21 13:42 - 2016-02-21 13:42 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+bufcn.png
2016-02-21 13:42 - 2016-02-21 13:42 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+bufcn.txt
2016-02-19 21:39 - 2016-02-19 21:39 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+cbjwl.html
2016-02-19 21:39 - 2016-02-19 21:39 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+cbjwl.png
2016-02-19 21:39 - 2016-02-19 21:39 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+cbjwl.txt
2016-02-18 08:54 - 2016-02-18 08:54 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+fdlic.html
2016-02-18 08:54 - 2016-02-18 08:54 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+fdlic.png
2016-02-18 08:54 - 2016-02-18 08:54 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+fdlic.txt
2016-02-21 23:09 - 2016-02-21 23:09 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+fmehi.html
2016-02-21 23:09 - 2016-02-21 23:09 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+fmehi.png
2016-02-21 23:09 - 2016-02-21 23:09 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+fmehi.txt
2016-02-22 21:52 - 2016-02-22 21:52 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+hqovs.html
2016-02-22 21:52 - 2016-02-22 21:52 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+hqovs.png
2016-02-22 21:52 - 2016-02-22 21:52 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+hqovs.txt
2016-02-19 09:35 - 2016-02-19 09:35 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+kogva.html
2016-02-19 09:35 - 2016-02-19 09:35 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+kogva.png
2016-02-19 09:35 - 2016-02-19 09:35 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+kogva.txt
2016-02-20 23:25 - 2016-02-20 23:25 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+rmbjh.html
2016-02-20 23:25 - 2016-02-20 23:25 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+rmbjh.png
2016-02-20 23:25 - 2016-02-20 23:25 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+rmbjh.txt
2016-02-17 11:10 - 2016-02-17 11:10 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+wsscw.html
2016-02-17 11:10 - 2016-02-17 11:10 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+wsscw.png
2016-02-17 11:10 - 2016-02-17 11:10 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+wsscw.txt
2016-02-20 16:04 - 2016-02-20 16:04 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+yexgr.html
2016-02-20 16:04 - 2016-02-20 16:04 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+yexgr.png
2016-02-20 16:04 - 2016-02-20 16:04 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+yexgr.txt
2016-02-22 10:12 - 2016-02-22 10:12 - 0007479 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+yicto.html
2016-02-22 10:12 - 2016-02-22 10:12 - 0087456 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+yicto.png
2016-02-22 10:12 - 2016-02-22 10:12 - 0002152 _____ () C:\Users\pessoal\AppData\Roaming\Microsoft\Recovery+yicto.txt
2016-02-21 13:35 - 2016-02-21 13:42 - 0007479 _____ () C:\Users\pessoal\AppData\Local\Recovery+bufcn.html
2016-02-21 13:35 - 2016-02-21 13:42 - 0087456 _____ () C:\Users\pessoal\AppData\Local\Recovery+bufcn.png
2016-02-21 13:35 - 2016-02-21 13:42 - 0002152 _____ () C:\Users\pessoal\AppData\Local\Recovery+bufcn.txt
2016-02-19 21:34 - 2016-02-19 21:39 - 0007479 _____ () C:\Users\pessoal\AppData\Local\Recovery+cbjwl.html
2016-02-19 21:34 - 2016-02-19 21:39 - 0087456 _____ () C:\Users\pessoal\AppData\Local\Recovery+cbjwl.png
2016-02-19 21:34 - 2016-02-19 21:39 - 0002152 _____ () C:\Users\pessoal\AppData\Local\Recovery+cbjwl.txt
2016-02-18 08:50 - 2016-02-18 08:54 - 0007479 _____ () C:\Users\pessoal\AppData\Local\Recovery+fdlic.html
2016-02-18 08:50 - 2016-02-18 08:54 - 0087456 _____ () C:\Users\pessoal\AppData\Local\Recovery+fdlic.png
2016-02-18 08:50 - 2016-02-18 08:54 - 0002152 _____ () C:\Users\pessoal\AppData\Local\Recovery+fdlic.txt
2016-02-21 23:04 - 2016-02-21 23:10 - 0007479 _____ () C:\Users\pessoal\AppData\Local\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:10 - 0087456 _____ () C:\Users\pessoal\AppData\Local\Recovery+fmehi.png
2016-02-21 23:04 - 2016-02-21 23:10 - 0002152 _____ () C:\Users\pessoal\AppData\Local\Recovery+fmehi.txt
2016-02-22 21:46 - 2016-02-22 21:52 - 0007479 _____ () C:\Users\pessoal\AppData\Local\Recovery+hqovs.html
2016-02-22 21:46 - 2016-02-22 21:52 - 0087456 _____ () C:\Users\pessoal\AppData\Local\Recovery+hqovs.png
2016-02-22 21:46 - 2016-02-22 21:52 - 0002152 _____ () C:\Users\pessoal\AppData\Local\Recovery+hqovs.txt
2016-02-19 09:32 - 2016-02-19 09:35 - 0007479 _____ () C:\Users\pessoal\AppData\Local\Recovery+kogva.html
2016-02-19 09:32 - 2016-02-19 09:35 - 0087456 _____ () C:\Users\pessoal\AppData\Local\Recovery+kogva.png
2016-02-19 09:32 - 2016-02-19 09:35 - 0002152 _____ () C:\Users\pessoal\AppData\Local\Recovery+kogva.txt
2016-02-20 23:22 - 2016-02-20 23:25 - 0007479 _____ () C:\Users\pessoal\AppData\Local\Recovery+rmbjh.html
2016-02-20 23:22 - 2016-02-20 23:25 - 0087456 _____ () C:\Users\pessoal\AppData\Local\Recovery+rmbjh.png
2016-02-20 23:22 - 2016-02-20 23:25 - 0002152 _____ () C:\Users\pessoal\AppData\Local\Recovery+rmbjh.txt
2016-02-17 10:59 - 2016-02-17 11:14 - 0007479 _____ () C:\Users\pessoal\AppData\Local\Recovery+wsscw.html
2016-02-17 10:59 - 2016-02-17 11:14 - 0087456 _____ () C:\Users\pessoal\AppData\Local\Recovery+wsscw.png
2016-02-17 10:59 - 2016-02-17 11:14 - 0002152 _____ () C:\Users\pessoal\AppData\Local\Recovery+wsscw.txt
2016-02-20 15:59 - 2016-02-20 16:05 - 0007479 _____ () C:\Users\pessoal\AppData\Local\Recovery+yexgr.html
2016-02-20 15:59 - 2016-02-20 16:05 - 0087456 _____ () C:\Users\pessoal\AppData\Local\Recovery+yexgr.png
2016-02-20 15:59 - 2016-02-20 16:05 - 0002152 _____ () C:\Users\pessoal\AppData\Local\Recovery+yexgr.txt
2016-02-22 10:08 - 2016-02-22 10:12 - 0007479 _____ () C:\Users\pessoal\AppData\Local\Recovery+yicto.html
2016-02-22 10:08 - 2016-02-22 10:12 - 0087456 _____ () C:\Users\pessoal\AppData\Local\Recovery+yicto.png
2016-02-22 10:08 - 2016-02-22 10:12 - 0002152 _____ () C:\Users\pessoal\AppData\Local\Recovery+yicto.txt
2009-07-13 20:31 - 2009-07-13 22:14 - 0223232 ___SH (© XTreme ©) C:\ProgramData\msaesgn.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0294912 ___SH () C:\ProgramData\msanldgu.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0109056 ___SH (Nokia Corporation and/or its subsidiary(-ies)) C:\ProgramData\msarlvecs.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0258560 ___SH (The Code::Blocks Team) C:\ProgramData\msarx.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0269824 ___SH () C:\ProgramData\msbjjqxm.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0205312 ___SH (MyBrains inc) C:\ProgramData\msbkdb.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0109056 ___SH (Nokia Corporation and/or its subsidiary(-ies)) C:\ProgramData\msblj.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0219136 ___SH () C:\ProgramData\msbljvbs.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0102400 ___SH (AnVir Software) C:\ProgramData\msbqp.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0239616 ___SH (Incorporate) C:\ProgramData\msbvvrdaj.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0267776 ___SH () C:\ProgramData\mschwya.exe
2015-12-29 08:51 - 2016-01-07 14:34 - 2417664 _____ () C:\ProgramData\msdtc.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0238592 ___SH (Incorporate) C:\ProgramData\msduibuw.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0229888 ___SH (PortableApps.com) C:\ProgramData\msetbzu.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0269824 ___SH () C:\ProgramData\mseuc.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0218112 ___SH () C:\ProgramData\msevdp.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0108544 ___SH (Nokia Corporation and/or its subsidiary(-ies)) C:\ProgramData\msfhoiviv.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0206848 ___SH (MyBrains inc) C:\ProgramData\msfmpvfli.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0284672 ___SH () C:\ProgramData\msfrtjr.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0103936 ___SH (AnVir Software) C:\ProgramData\msgmpyrpc.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0239616 ___SH (Incorporate) C:\ProgramData\mshfg.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0219648 ___SH () C:\ProgramData\mshsbjq.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0238592 ___SH (Incorporate) C:\ProgramData\msihlz.exe
2016-02-06 18:27 - 2016-01-26 11:54 - 2415616 _____ () C:\ProgramData\msiql.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0222208 ___SH (© XTreme ©) C:\ProgramData\msireqxo.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0294912 ___SH () C:\ProgramData\msirjrlqa.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0229888 ___SH (PortableApps.com) C:\ProgramData\msiwnql.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0230912 ___SH (medical bag) C:\ProgramData\msixzbir.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0294912 ___SH () C:\ProgramData\mskhbua.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0231936 ___SH (medical bag) C:\ProgramData\mskweavf.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0290816 ___SH () C:\ProgramData\msmhsofk.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0206848 ___SH (MyBrains inc) C:\ProgramData\msmvyvcyx.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0231936 ___SH (medical bag) C:\ProgramData\msmxsvi.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0222208 ___SH (© XTreme ©) C:\ProgramData\msnvuefo.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0218112 ___SH () C:\ProgramData\mspfn.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0282624 ___SH () C:\ProgramData\mspsjpjb.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0267776 ___SH () C:\ProgramData\msqck.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0107520 ___SH (Nokia Corporation and/or its subsidiary(-ies)) C:\ProgramData\msqcobx.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0237568 ___SH (medical bag) C:\ProgramData\msrnjv.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0294912 ___SH () C:\ProgramData\msrztkegx.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0258560 ___SH (The Code::Blocks Team) C:\ProgramData\mssgt.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0229888 ___SH (PortableApps.com) C:\ProgramData\mstdjcnt.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0205312 ___SH (MyBrains inc) C:\ProgramData\msudvc.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0230912 ___SH (medical bag) C:\ProgramData\msufgj.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0108544 ___SH (Nokia Corporation and/or its subsidiary(-ies)) C:\ProgramData\msuurdq.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0282112 ___SH () C:\ProgramData\msvau.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0104448 ___SH (AnVir Software) C:\ProgramData\msvzsccax.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0229888 ___SH (PortableApps.com) C:\ProgramData\mswsfm.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0218624 ___SH () C:\ProgramData\mszcp.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0290304 ___SH () C:\ProgramData\mszgunir.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0269824 ___SH () C:\ProgramData\mszopdn.exe
2009-07-13 20:31 - 2009-07-13 22:14 - 0207360 ___SH (MyBrains inc) C:\ProgramData\mszyiut.exe
2016-02-21 13:33 - 2016-02-21 13:43 - 0007479 _____ () C:\ProgramData\Recovery+bufcn.html
2016-02-21 13:33 - 2016-02-21 13:43 - 0087456 _____ () C:\ProgramData\Recovery+bufcn.png
2016-02-21 13:33 - 2016-02-21 13:43 - 0002152 _____ () C:\ProgramData\Recovery+bufcn.txt
2016-02-19 21:33 - 2016-02-19 21:40 - 0007479 _____ () C:\ProgramData\Recovery+cbjwl.html
2016-02-19 21:33 - 2016-02-19 21:40 - 0087456 _____ () C:\ProgramData\Recovery+cbjwl.png
2016-02-19 21:33 - 2016-02-19 21:40 - 0002152 _____ () C:\ProgramData\Recovery+cbjwl.txt
2016-02-18 08:49 - 2016-02-18 08:56 - 0007479 _____ () C:\ProgramData\Recovery+fdlic.html
2016-02-18 08:49 - 2016-02-18 08:56 - 0087456 _____ () C:\ProgramData\Recovery+fdlic.png
2016-02-18 08:49 - 2016-02-18 08:56 - 0002152 _____ () C:\ProgramData\Recovery+fdlic.txt
2016-02-21 23:04 - 2016-02-21 23:12 - 0007479 _____ () C:\ProgramData\Recovery+fmehi.html
2016-02-21 23:04 - 2016-02-21 23:12 - 0087456 _____ () C:\ProgramData\Recovery+fmehi.png
2016-02-21 23:04 - 2016-02-21 23:12 - 0002152 _____ () C:\ProgramData\Recovery+fmehi.txt
2016-02-22 21:45 - 2016-02-22 21:54 - 0007479 _____ () C:\ProgramData\Recovery+hqovs.html
2016-02-22 21:45 - 2016-02-22 21:54 - 0087456 _____ () C:\ProgramData\Recovery+hqovs.png
2016-02-22 21:45 - 2016-02-22 21:54 - 0002152 _____ () C:\ProgramData\Recovery+hqovs.txt
2016-02-19 09:30 - 2016-02-19 09:37 - 0007479 _____ () C:\ProgramData\Recovery+kogva.html
2016-02-19 09:30 - 2016-02-19 09:37 - 0087456 _____ () C:\ProgramData\Recovery+kogva.png
2016-02-19 09:30 - 2016-02-19 09:37 - 0002152 _____ () C:\ProgramData\Recovery+kogva.txt
2016-02-20 23:21 - 2016-02-20 23:27 - 0007479 _____ () C:\ProgramData\Recovery+rmbjh.html
2016-02-20 23:21 - 2016-02-20 23:27 - 0087456 _____ () C:\ProgramData\Recovery+rmbjh.png
2016-02-20 23:21 - 2016-02-20 23:27 - 0002152 _____ () C:\ProgramData\Recovery+rmbjh.txt
2016-02-17 10:56 - 2016-02-17 11:43 - 0007479 _____ () C:\ProgramData\Recovery+wsscw.html
2016-02-17 10:56 - 2016-02-17 11:43 - 0087456 _____ () C:\ProgramData\Recovery+wsscw.png
2016-02-17 10:56 - 2016-02-17 11:43 - 0002152 _____ () C:\ProgramData\Recovery+wsscw.txt
2016-02-20 15:57 - 2016-02-20 16:09 - 0007479 _____ () C:\ProgramData\Recovery+yexgr.html
2016-02-20 15:57 - 2016-02-20 16:09 - 0087456 _____ () C:\ProgramData\Recovery+yexgr.png
2016-02-20 15:57 - 2016-02-20 16:09 - 0002152 _____ () C:\ProgramData\Recovery+yexgr.txt
2016-02-22 10:06 - 2016-02-22 10:14 - 0007479 _____ () C:\ProgramData\Recovery+yicto.html
2016-02-22 10:06 - 2016-02-22 10:14 - 0087456 _____ () C:\ProgramData\Recovery+yicto.png
2016-02-22 10:06 - 2016-02-22 10:14 - 0002152 _____ () C:\ProgramData\Recovery+yicto.txt
2016-01-08 18:11 - 2015-04-28 11:05 - 0001149 _____ () C:\ProgramData\tops.exe
2015-12-22 19:09 - 2015-12-17 13:31 - 2245032 _____ (UpAurora.COM) C:\ProgramData\UpAurora_1.0.0.3034__101br.exe
2015-12-22 18:44 - 2015-11-16 07:01 - 1762304 _____ (TODO: <公司名>) C:\ProgramData\upgsvr.exe
2016-02-15 23:09 - 2016-02-22 21:35 - 0010365 _____ () C:\ProgramData\webad.xml
2016-01-07 18:37 - 2016-02-17 10:58 - 0000864 _____ () C:\ProgramData\xcgui_debug.txt.mp3
2015-12-22 19:12 - 2015-12-10 15:43 - 0600312 _____ () C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe

Arquivos para serem movidos ou deletados:
====================
C:\ProgramData\msaesgn.exe
C:\ProgramData\msanldgu.exe
C:\ProgramData\msarlvecs.exe
C:\ProgramData\msarx.exe
C:\ProgramData\msbjjqxm.exe
C:\ProgramData\msbkdb.exe
C:\ProgramData\msblj.exe
C:\ProgramData\msbljvbs.exe
C:\ProgramData\msbqp.exe
C:\ProgramData\msbvvrdaj.exe
C:\ProgramData\mschwya.exe
C:\ProgramData\msdtc.exe
C:\ProgramData\msduibuw.exe
C:\ProgramData\msetbzu.exe
C:\ProgramData\mseuc.exe
C:\ProgramData\msevdp.exe
C:\ProgramData\msfhoiviv.exe
C:\ProgramData\msfmpvfli.exe
C:\ProgramData\msfrtjr.exe
C:\ProgramData\msgmpyrpc.exe
C:\ProgramData\mshfg.exe
C:\ProgramData\mshsbjq.exe
C:\ProgramData\msihlz.exe
C:\ProgramData\msiql.exe
C:\ProgramData\msireqxo.exe
C:\ProgramData\msirjrlqa.exe
C:\ProgramData\msiwnql.exe
C:\ProgramData\msixzbir.exe
C:\ProgramData\mskhbua.exe
C:\ProgramData\mskweavf.exe
C:\ProgramData\msmhsofk.exe
C:\ProgramData\msmvyvcyx.exe
C:\ProgramData\msmxsvi.exe
C:\ProgramData\msnvuefo.exe
C:\ProgramData\mspfn.exe
C:\ProgramData\mspsjpjb.exe
C:\ProgramData\msqck.exe
C:\ProgramData\msqcobx.exe
C:\ProgramData\msrnjv.exe
C:\ProgramData\msrztkegx.exe
C:\ProgramData\mssgt.exe
C:\ProgramData\mstdjcnt.exe
C:\ProgramData\msudvc.exe
C:\ProgramData\msufgj.exe
C:\ProgramData\msuurdq.exe
C:\ProgramData\msvau.exe
C:\ProgramData\msvzsccax.exe
C:\ProgramData\mswsfm.exe
C:\ProgramData\mszcp.exe
C:\ProgramData\mszgunir.exe
C:\ProgramData\mszopdn.exe
C:\ProgramData\mszyiut.exe
C:\ProgramData\tops.exe
C:\ProgramData\UpAurora_1.0.0.3034__101br.exe
C:\ProgramData\upgsvr.exe
C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe
C:\Users\pessoal\aajjxivv.exe
C:\Users\Todos os Usuários\msaesgn.exe
C:\Users\Todos os Usuários\msanldgu.exe
C:\Users\Todos os Usuários\msarlvecs.exe
C:\Users\Todos os Usuários\msarx.exe
C:\Users\Todos os Usuários\msbjjqxm.exe
C:\Users\Todos os Usuários\msbkdb.exe
C:\Users\Todos os Usuários\msblj.exe
C:\Users\Todos os Usuários\msbljvbs.exe
C:\Users\Todos os Usuários\msbqp.exe
C:\Users\Todos os Usuários\msbvvrdaj.exe
C:\Users\Todos os Usuários\mschwya.exe
C:\Users\Todos os Usuários\msdtc.exe
C:\Users\Todos os Usuários\msduibuw.exe
C:\Users\Todos os Usuários\msetbzu.exe
C:\Users\Todos os Usuários\mseuc.exe
C:\Users\Todos os Usuários\msevdp.exe
C:\Users\Todos os Usuários\msfhoiviv.exe
C:\Users\Todos os Usuários\msfmpvfli.exe
C:\Users\Todos os Usuários\msfrtjr.exe
C:\Users\Todos os Usuários\msgmpyrpc.exe
C:\Users\Todos os Usuários\mshfg.exe
C:\Users\Todos os Usuários\mshsbjq.exe
C:\Users\Todos os Usuários\msihlz.exe
C:\Users\Todos os Usuários\msiql.exe
C:\Users\Todos os Usuários\msireqxo.exe
C:\Users\Todos os Usuários\msirjrlqa.exe
C:\Users\Todos os Usuários\msiwnql.exe
C:\Users\Todos os Usuários\msixzbir.exe
C:\Users\Todos os Usuários\mskhbua.exe
C:\Users\Todos os Usuários\mskweavf.exe
C:\Users\Todos os Usuários\msmhsofk.exe
C:\Users\Todos os Usuários\msmvyvcyx.exe
C:\Users\Todos os Usuários\msmxsvi.exe
C:\Users\Todos os Usuários\msnvuefo.exe
C:\Users\Todos os Usuários\mspfn.exe
C:\Users\Todos os Usuários\mspsjpjb.exe
C:\Users\Todos os Usuários\msqck.exe
C:\Users\Todos os Usuários\msqcobx.exe
C:\Users\Todos os Usuários\msrnjv.exe
C:\Users\Todos os Usuários\msrztkegx.exe
C:\Users\Todos os Usuários\mssgt.exe
C:\Users\Todos os Usuários\mstdjcnt.exe
C:\Users\Todos os Usuários\msudvc.exe
C:\Users\Todos os Usuários\msufgj.exe
C:\Users\Todos os Usuários\msuurdq.exe
C:\Users\Todos os Usuários\msvau.exe
C:\Users\Todos os Usuários\msvzsccax.exe
C:\Users\Todos os Usuários\mswsfm.exe
C:\Users\Todos os Usuários\mszcp.exe
C:\Users\Todos os Usuários\mszgunir.exe
C:\Users\Todos os Usuários\mszopdn.exe
C:\Users\Todos os Usuários\mszyiut.exe
C:\Users\Todos os Usuários\tops.exe
C:\Users\Todos os Usuários\UpAurora_1.0.0.3034__101br.exe
C:\Users\Todos os Usuários\upgsvr.exe
C:\Users\Todos os Usuários\YeaPlayer_br_IBD_Bundle.exe


Alguns arquivos em TEMP:
====================
C:\Users\pessoal\AppData\Local\Temp\101.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\1557.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\21A1.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\26F5.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\283.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\284.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\2976.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\3BAD.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\4C72.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\5823.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\70F6.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\749E.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\79C4.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\818A.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\92BE.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\9AA4.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\A07D.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\A7C3.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\A7CD.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\ADE5.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\B300.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\B8D5.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\B95.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\C3A5.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\C6D8.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\C6E7.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\CA49.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\CD3B.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\CE37.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\CFFA.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\D17A.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\D3A9.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\DA6D.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\EBDE.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\F2DC.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\FC7.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\FF09.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\FF18.tmp.exe
C:\Users\pessoal\AppData\Local\Temp\fsdAD6E.exe
C:\Users\pessoal\AppData\Local\Temp\KB00583225.exe
C:\Users\pessoal\AppData\Local\Temp\KB00584317.exe
C:\Users\pessoal\AppData\Local\Temp\KB00592803.exe
C:\Users\pessoal\AppData\Local\Temp\KB00828037.exe
C:\Users\pessoal\AppData\Local\Temp\KB00828396.exe
C:\Users\pessoal\AppData\Local\Temp\KB00844729.exe
C:\Users\pessoal\AppData\Local\Temp\KB00848489.exe
C:\Users\pessoal\AppData\Local\Temp\KB00849924.exe
C:\Users\pessoal\AppData\Local\Temp\KB00898206.exe
C:\Users\pessoal\AppData\Local\Temp\KB00918611.exe
C:\Users\pessoal\AppData\Local\Temp\KB00934945.exe
C:\Users\pessoal\AppData\Local\Temp\KB00947425.exe
C:\Users\pessoal\AppData\Local\Temp\sqlite3.dll


Alguns com tamanho de zero byte arquivos/pastas:
==========================
C:\Windows\kernel32.dll

==================== Bamital & volsnap =================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\Windows\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\system32\services.exe => O arquivo é assinado digitalmente
C:\Windows\system32\User32.dll
[2009-07-13 20:24] - [2009-07-13 22:16] - 0811520 ____A (Microsoft Corporation) 8626F0C30D4E3564FFDD25C90F4426F1

C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente


LastRegBack: 2016-02-18 17:32

==================== Fim de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité