cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão:09-05-2016
Executado por Rodrigo (administrador) em SLIPKNOT (10-05-2016 22:37:19)
Executando a partir de C:\Users\Rodrigo\Downloads\Ferramentas para Desinfeção
Perfis Carregados: Rodrigo (Perfis Disponíveis: Rodrigo & adevi & MSSQL$SQLEXPRESS & ReportServer$SQLEXPRESS & MSSQLFDLauncher$SQLEXPRESS)
Platform: Windows 10 Pro Versão 1511 (X64) Idioma: Português (Brasil)
Internet Explorer Versão 11 (Navegador padrão: Edge)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Ransomware\MBAMService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
(Ralink) C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corporation) C:\Windows\System32\vmms.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
(VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Ransomware\mbarw.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.30.3\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registro (Whitelisted) ===========================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [SMSERIAL] => C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe [1702400 2009-10-26] (Motorola Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1796056 2014-08-19] (NVIDIA Corporation)
HKLM\...\Run: [BoxSync] => C:\Program Files\Box\Box Sync\BoxSync.exe [5970456 2015-12-15] (Box, Inc.)
HKLM-x32\...\Run: [X-G510] => C:\Program Files (x86)\Genius\X-G510\mousehid.exe
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [23248560 2016-04-08] (Dropbox, Inc.)
HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [104128 2015-10-18] (VMware, Inc.)
HKLM-x32\...\Run: [GamingKeyboard] => C:\Program Files (x86)\SHARKOON Skiller\GameMon.exe [1803264 2012-06-07] (Game Inc.)
HKU\S-1-5-21-354422575-759729991-2597353769-1002\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8698584 2016-04-15] (Piriform Ltd)
ShellIconOverlayIdentifiers: [ BoxSyncFileLocked] -> {2a607da5-abe8-358e-a881-c0f5faf2d3a5} => C:\WINDOWS\system32\mscoree.dll [2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncFileLockedByOther] -> {f7d2951f-0b6b-346c-99ec-69cffc30a364} => C:\WINDOWS\system32\mscoree.dll [2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncNotSynced] -> {5ea95e3d-3e46-3812-b03c-49785fa67d41} => C:\WINDOWS\system32\mscoree.dll [2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncProblem] -> {a88b7184-bfa1-3d14-8efb-2225df9699bc} => C:\WINDOWS\system32\mscoree.dll [2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncSynced] -> {c89f9943-8f58-3eca-bd55-a658f53b2f48} => C:\WINDOWS\system32\mscoree.dll [2015-10-30] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-04-25] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-04-25] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-04-25] (Google)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-04-08] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Malwarebytes Anti-Ransomware.lnk [2016-03-31]
ShortcutTarget: Malwarebytes Anti-Ransomware.lnk -> C:\Program Files\Malwarebytes\Anti-Ransomware\mbarw.exe (Malwarebytes)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk [2016-03-24]
ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
Startup: C:\Users\Rodrigo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Stardock ObjectDock.lnk [2016-04-01]
ShortcutTarget: Stardock ObjectDock.lnk -> C:\Program Files (x86)\Stardock\ObjectDock Plus\ObjectDock.exe (Stardock)

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\Parameters: [DhcpNameServer] 201.82.0.64 201.82.0.52 201.6.4.116
Tcpip\..\Interfaces\{3b41bdb0-4b44-4b90-a466-395d6d4b008d}: [DhcpNameServer] 201.82.0.64 201.82.0.52 201.6.4.116
ManualProxies:

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-354422575-759729991-2597353769-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-07-14] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-07-14] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2016-01-16] (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2013-10-22] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2016-01-16] (Oracle Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Rodrigo\AppData\Roaming\Mozilla\Firefox\Profiles\wpu1hpqr.default
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @EDVR/WebClient -> C:\windows\system32\WebClient\npwebclient.dll [Nenhum Arquivo]
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 -> C:\WINDOWS\SysWOW64\npDeployJava1.dll [2016-01-16] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2016-01-16] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-01-29] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-01-29] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-354422575-759729991-2597353769-1002: sony.com/MediaGoDetector -> C:\Program Files (x86)\Sony\Media Go\npMediaGoDetector.dll [2014-07-10] (Sony Network Entertainment International LLC)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\buscape.xml [2015-08-15]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mercadolivre.xml [2015-08-15]
FF Extension: RightToClick - C:\Users\Rodrigo\AppData\Roaming\Mozilla\Firefox\Profiles\wpu1hpqr.default\extensions\{cd617375-6743-4ee8-bac4-fbf10f35729e}.xpi [2016-02-13]
FF Extension: NoScript - C:\Users\Rodrigo\AppData\Roaming\Mozilla\Firefox\Profiles\wpu1hpqr.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-02-13]
FF Extension: Video DownloadHelper - C:\Users\Rodrigo\AppData\Roaming\Mozilla\Firefox\Profiles\wpu1hpqr.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-02-13]
FF Extension: Evernote Web Clipper - C:\Users\Rodrigo\AppData\Roaming\Mozilla\Firefox\Profiles\wpu1hpqr.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}.xpi [2016-02-13]

Chrome:
=======
CHR HomePage: Profile 1 -> hxxp://www.positivoinformatica.com.br/
CHR Profile: C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (MeasureIt!) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aonjhmdcgbgikgjapjckfkefpphjpgma [2015-10-28]
CHR Extension: (Google Drive) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (Web Developer) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbameneiokkgbdmiekhjnmfkcnldhhm [2015-03-07]
CHR Extension: (ColorZilla) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhlhnicpbhignbdhedgjhgdocnmhomnp [2015-06-27]
CHR Extension: (YouTube) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Firebug Lite for Google Chrome™) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmagokdooijbeehmkpknfglimnifench [2015-09-18]
CHR Extension: (Webug) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjbeipenlpoeifpkjhgakejmikdhlhcj [2015-12-22]
CHR Extension: (Rastreador de Pacotes dos Correios) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnlegggomkoaacenefdcdddgcgjhjmfg [2015-10-28]
CHR Extension: (Google Search) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-28]
CHR Extension: (jQuery Debugger) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbhhnnnpaeobfddmlalhnehgclcmjimi [2015-08-22]
CHR Extension: (Full Page Screen Capture) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdpohaocaechififmbbbbbknoalclacl [2015-08-09]
CHR Extension: (Área de trabalho remota do Google Chrome) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2015-11-04]
CHR Extension: (CSSViewer) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggfgijbpiheegefliciemofobhmofgce [2015-03-07]
CHR Extension: (Documentos Google off-line) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (SEO e Analise web) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlngmmdolgbdnnimbmblfhhndibdipaf [2015-10-28]
CHR Extension: (Eye Dropper) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmdcmlfkchdmnmnmheododdhjedfccka [2015-03-07]
CHR Extension: (Lingualy - Practice a Language) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\iilcekgoelpgecpjnnoikhbleipnjdhf [2015-05-01]
CHR Extension: (PHPHOST.ORG) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\khkimiladblfhhmefghkpkoikghmdddf [2015-10-28]
CHR Extension: (Black Black Chrome Theme Blue Highlight) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfpkblfdnephakmjpldlhjpcblifmojn [2015-08-31]
CHR Extension: (JSIDE Marlies offline JS/jQuery Development) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjmfllniihogiogcejndmejblamojcpe [2015-08-31]
CHR Extension: (PHP Console) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfhmhhlpfleoednkpnnnkolmclajemef [2015-11-27]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-28]
CHR Extension: (Chrome Apps & Extensions Developer Tool) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohmmkhmmmpcnpikjeljgnaoabkaalbgc [2015-09-18]
CHR Extension: (Gmail) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Profile: C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Apresentações) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-09]
CHR Extension: (Google Docs) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-09]
CHR Extension: (Google Drive) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-09]
CHR Extension: (Web Developer) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bfbameneiokkgbdmiekhjnmfkcnldhhm [2016-01-09]
CHR Extension: (YouTube) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-09]
CHR Extension: (Firebug Lite for Google Chrome™) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\bmagokdooijbeehmkpknfglimnifench [2016-05-07]
CHR Extension: (Adblock Plus) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-08]
CHR Extension: (Webug) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjbeipenlpoeifpkjhgakejmikdhlhcj [2016-03-16]
CHR Extension: (Google Search) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-09]
CHR Extension: (Full Page Screen Capture) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fdpohaocaechififmbbbbbknoalclacl [2016-05-10]
CHR Extension: (Planilhas do Google) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-09]
CHR Extension: (CSSViewer) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ggfgijbpiheegefliciemofobhmofgce [2016-05-07]
CHR Extension: (Documentos Google off-line) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-14]
CHR Extension: (Desprotetor de Links) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\imcbnnnoghiihopefblgehihofbfbmei [2016-04-23]
CHR Extension: (PHPHOST.ORG) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\khkimiladblfhhmefghkpkoikghmdddf [2016-01-09]
CHR Extension: (DriveTunes) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\labgcacinobdnkfndodfkfeabbjckbnj [2016-05-07]
CHR Extension: (Baixou Agora) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nbfjpmeddmamejnmmppjlfglfhcjbbai [2016-01-13]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-01]
CHR Extension: (ColorPick Eyedropper) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ohcpnigalekghcmgcdcenkpelffpdolg [2016-02-22]
CHR Extension: (Evernote Web Clipper) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2016-04-13]
CHR Extension: (Gmail) - C:\Users\Rodrigo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-09]
CHR HKU\S-1-5-21-354422575-759729991-2597353769-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ihenkjeihefokohmemphikjnjbmegdik] - "C:\Program Files (x86)\Sony\Media Go\MediaGoDetector.crx"
CHR HKLM-x32\...\Chrome\Extension: [nbfjpmeddmamejnmmppjlfglfhcjbbai] - hxxps://clients2.google.com/service/update2/crx

==================== Serviços (Whitelisted) ========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S4 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [32144 2015-12-01] (Box, Inc.)
S4 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [406288 2014-06-23] (BlueStack Systems, Inc.)
S4 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-06-23] (BlueStack Systems, Inc.)
S4 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [774928 2014-06-23] (BlueStack Systems, Inc.)
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2016-03-07] (Microsoft Corporation)
S4 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-01-27] (Dropbox, Inc.)
S4 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-01-27] (Dropbox, Inc.)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2013-08-22] (Microsoft Corporation) [Arquivo não assinado]
R2 MB3Service; C:\Program Files\Malwarebytes\Anti-Ransomware\MBAMService.exe [3141088 2016-03-23] (Malwarebytes)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)
S3 MSSQL$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [190904 2012-06-12] (Microsoft Corporation)
S3 MSSQLFDLauncher$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\fdlauncher.exe [49752 2012-02-11] (Microsoft Corporation)
S4 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [32568 2014-04-09] (The OpenVPN Project)
S4 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2016-03-06] (Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [75136 2015-10-02] ()
S4 PSI_SVC_2; c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe [277360 2013-09-13] (arvato digital services llc)
U2 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [1863680 2012-07-06] (Ralink) [Arquivo não assinado]
S3 ReportServer$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSRS11.SQLEXPRESS\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2348472 2012-06-12] (Microsoft Corporation)
S4 SQLAgent$SQLEXPRESS; C:\Program Files\Microsoft SQL Server\MSSQL11.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [608696 2012-06-12] (Microsoft Corporation)
S4 SWGVCSvc; C:\Program Files\Dell SonicWALL\Global VPN Client\SWGVCSvc.exe [336616 2013-12-03] (Dell SonicWALL, Inc.)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [Arquivo não assinado]
S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6942480 2016-03-02] (TeamViewer GmbH)
S2 uvnc_service; C:\Program Files (x86)\uvnc bvba\UltraVNC\WinVNC.exe [1970256 2016-01-24] (UltraVNC)
S3 vmcompute; C:\Windows\system32\vmcompute.exe [1142272 2016-03-07] (Microsoft Corporation)
R2 vmms; C:\Windows\system32\vmms.exe [14384128 2016-03-07] (Microsoft Corporation)
S4 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [12465856 2015-10-18] ()
S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-04] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R1 badriver; C:\Windows\System32\drivers\badriver.sys [67560 2014-11-04] (Windows (R) Win 7 DDK provider)
S2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [123152 2014-06-23] (BlueStack Systems)
S3 CEDRIVER60; C:\Program Files (x86)\Cheat Engine 6.5\dbk64.sys [54272 2013-08-11] () [Arquivo não assinado]
S3 DFX11_1; C:\Windows\system32\drivers\dfx11_1x64.sys [28008 2012-12-13] (Windows (R) Win 7 DDK provider)
R1 DNE; C:\Windows\system32\DRIVERS\dnelwf64.sys [133456 2013-10-03] (Citrix Systems, Inc.)
R3 farflt; C:\WINDOWS\system32\drivers\farflt.sys [59776 2016-05-10] (Malwarebytes)
R3 GameKB; C:\Windows\system32\drivers\GameKB.sys [27648 2012-05-11] ()
S3 ggsomc; C:\Windows\System32\drivers\ggsomc.sys [30424 2015-03-14] (Sony Mobile Communications)
R1 ISODrive; C:\Program Files (x86)\UltraISO\drivers\ISODrv64.sys [115448 2013-11-21] (EZB Systems, Inc.)
S3 lunparser; C:\Windows\System32\drivers\lunparser.sys [22528 2016-03-07] (Microsoft Corporation)
R2 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [140672 2016-03-10] (Malwarebytes)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-05-10] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation)
S3 passthruparser; C:\Windows\System32\drivers\passthruparser.sys [23552 2016-03-07] (Microsoft Corporation)
S3 pcip; C:\Windows\System32\drivers\pcip.sys [44544 2016-03-07] (Microsoft Corporation)
S3 pvhdparser; C:\Windows\System32\drivers\pvhdparser.sys [50176 2016-03-07] (Microsoft Corporation)
S4 RsFx0200; C:\Windows\System32\DRIVERS\RsFx0200.sys [334936 2012-02-11] (Microsoft Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek )
R3 seehcri; C:\Windows\System32\drivers\seehcri.sys [34032 2014-01-30] (Sony Ericsson Mobile Communications)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)
R3 smserial; C:\Windows\system32\DRIVERS\smserial.sys [1202688 2009-10-26] (Motorola Inc.)
R2 SWIPsec; C:\WINDOWS\system32\Drivers\SWIPsec.sys [110064 2013-12-03] (Dell SonicWALL, Inc.)
R3 Synth3dVsp; C:\Windows\System32\drivers\synth3dvsp.sys [101888 2016-03-07] (Microsoft Corporation)
S3 vhdparser; C:\Windows\System32\drivers\vhdparser.sys [26624 2016-03-07] (Microsoft Corporation)
R2 VMparport; C:\WINDOWS\system32\drivers\VMparport.sys [31936 2015-10-18] (VMware, Inc.)
R2 VMSP; C:\Windows\System32\drivers\vmswitch.sys [976384 2016-03-07] (Microsoft Corporation)
R0 vmsproxy; C:\Windows\System32\drivers\vmsproxy.sys [22016 2016-03-07] (Microsoft Corporation)
S3 VMSVSF; C:\Windows\System32\drivers\vmswitch.sys [976384 2016-03-07] (Microsoft Corporation)
S3 VMSVSP; C:\Windows\System32\drivers\vmswitch.sys [976384 2016-03-07] (Microsoft Corporation)
R0 vsock; C:\Windows\System32\drivers\vsock.sys [75512 2015-10-18] (VMware, Inc.)
R2 vstor2-mntapi20-shared; C:\Windows\SysWow64\drivers\vstor2-mntapi20-shared.sys [34520 2015-07-09] (VMware, Inc.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
S3 WinNat; C:\Windows\System32\drivers\winnat.sys [350720 2016-03-07] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um Mês Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-05-10 22:37 - 2016-05-10 22:37 - 00000000 ____D C:\FRST
2016-05-10 22:30 - 2016-05-10 22:30 - 00000882 _____ C:\Users\Rodrigo\Desktop\JRT.txt
2016-05-10 21:59 - 2016-05-10 22:15 - 00000000 ____D C:\AdwCleaner
2016-05-10 21:56 - 2016-05-10 21:56 - 00172060 _____ C:\Users\Rodrigo\Desktop\ZHPDiag.txt
2016-05-10 21:43 - 2016-05-10 21:58 - 00000000 ____D C:\Users\Rodrigo\AppData\Roaming\ZHP
2016-05-10 21:43 - 2016-05-10 21:43 - 00000905 _____ C:\Users\Rodrigo\Desktop\ZHPDiag.lnk
2016-05-10 21:42 - 2016-05-10 22:37 - 00000000 ____D C:\Users\Rodrigo\Downloads\Ferramentas para Desinfeção
2016-05-09 22:12 - 2016-05-09 22:12 - 00005048 _____ C:\Users\Rodrigo\Downloads\Game.of.Thrones.S06E03.1080p.HDTV.x264-G2G.DUAL-RK (2)[www.b2s-share.com].torrent
2016-05-09 19:48 - 2016-05-09 19:49 - 00017280 _____ C:\Users\Rodrigo\Desktop\Projeto.sublime-workspace
2016-05-09 19:48 - 2016-05-09 19:48 - 00015115 _____ C:\Users\Rodrigo\Desktop\Projeto2.sublime-workspace
2016-05-09 19:48 - 2016-05-09 19:48 - 00000095 _____ C:\Users\Rodrigo\Desktop\Projeto2.sublime-project
2016-05-09 19:48 - 2016-05-09 19:48 - 00000094 _____ C:\Users\Rodrigo\Desktop\Projeto.sublime-project
2016-05-09 19:37 - 2016-05-09 19:37 - 00000000 ____D C:\Users\Rodrigo\Downloads\hallooou-HTML5-responsive-template_v1.2
2016-05-09 19:37 - 2016-05-09 19:37 - 00000000 ____D C:\Users\Rodrigo\Downloads\Director-free
2016-05-09 19:37 - 2016-05-09 19:37 - 00000000 ____D C:\Users\Rodrigo\Downloads\AdminLTE-2.3.0
2016-05-09 19:33 - 2016-05-09 19:33 - 04540457 _____ C:\Users\Rodrigo\Downloads\Director-free.zip
2016-05-09 19:31 - 2016-05-09 19:31 - 12051244 _____ C:\Users\Rodrigo\Downloads\hallooou-HTML5-responsive-template_v1.2.zip
2016-05-09 19:23 - 2016-05-09 19:24 - 06871892 _____ C:\Users\Rodrigo\Downloads\AdminLTE-2.3.0.zip
2016-05-08 17:05 - 2016-05-08 17:06 - 00001514 _____ C:\Users\Rodrigo\Desktop\Crysis2.exe - Atalho.lnk
2016-05-08 16:50 - 2013-08-11 19:00 - 00054272 _____ C:\Users\Rodrigo\Desktop\dbk64 - Copia.sys
2016-05-08 16:49 - 2013-08-11 19:00 - 00054272 _____ C:\Users\Rodrigo\Desktop\dbk64.sys
2016-05-08 16:48 - 2016-05-08 16:48 - 00023913 _____ C:\Users\Rodrigo\Downloads\dbk64.rar
2016-05-08 16:42 - 2016-05-08 16:42 - 00000064 _____ C:\Users\Rodrigo\Desktop\hex.txt
2016-05-08 16:35 - 2016-05-08 16:36 - 04661445 _____ (Dark Byte ) C:\Users\Rodrigo\Downloads\CheatEngine561 (1).exe
2016-05-08 16:32 - 2016-05-08 16:32 - 04661445 _____ (Dark Byte ) C:\Users\Rodrigo\Downloads\CheatEngine561.exe
2016-05-08 16:12 - 2016-05-08 16:13 - 00000000 ____D C:\Users\Rodrigo\Downloads\CheatEngine561src (1)
2016-05-08 16:10 - 2016-05-08 16:11 - 04739910 _____ C:\Users\Rodrigo\Downloads\CheatEngine561src (1).rar
2016-05-08 16:02 - 2016-05-08 16:02 - 04739910 _____ C:\Users\Rodrigo\Downloads\CheatEngine561src.rar
2016-05-08 15:52 - 2016-05-08 15:52 - 00002056 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine Brasil.lnk
2016-05-08 15:52 - 2016-05-08 15:52 - 00002044 _____ C:\Users\Public\Desktop\Cheat Engine Brasil.lnk
2016-05-08 15:52 - 2016-05-08 15:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine
2016-05-08 15:52 - 2016-05-08 15:52 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.5
2016-05-08 15:51 - 2016-05-08 15:51 - 00000000 ____D C:\Users\Rodrigo\Downloads\Setup.CE.v6.5_32Bit.(x86)
2016-05-08 15:43 - 2016-05-08 15:48 - 14428017 _____ C:\Users\Rodrigo\Downloads\Setup.CE.v6.5_32Bit.(x86).zip
2016-05-07 13:32 - 2016-05-07 13:35 - 00000000 ____D C:\Program Files\Speccy
2016-05-07 13:32 - 2016-05-07 13:32 - 00000837 _____ C:\Users\Public\Desktop\Speccy.lnk
2016-05-07 13:32 - 2016-05-07 13:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2016-05-07 13:31 - 2016-05-07 13:34 - 00000000 ____D C:\Program Files\CCleaner
2016-05-07 13:31 - 2016-05-07 13:31 - 00002860 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-05-07 13:31 - 2016-05-07 13:31 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-05-07 13:31 - 2016-05-07 13:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-05-07 13:28 - 2016-05-07 13:28 - 00020630 _____ C:\Users\Rodrigo\Downloads\CCleaner.Professional.Plus.5.17.5590[www.b2s-share.com].torrent
2016-05-07 01:12 - 2016-05-07 01:12 - 00018466 _____ C:\Users\Rodrigo\Downloads\Deadpool.2016.BDRip Dual by WaGoZ[www.b2s-share.com].torrent
2016-05-07 00:17 - 2016-05-07 00:39 - 00000000 ____D C:\Users\Rodrigo\AppData\Roaming\Windows Update
2016-05-07 00:17 - 2016-05-07 00:17 - 00003420 _____ C:\WINDOWS\System32\Tasks\Windows Update Logon
2016-05-07 00:06 - 2016-05-07 00:29 - 60279237 _____ C:\Users\Rodrigo\Desktop\0WebDesignerNo.2292014.pdf
2016-05-07 00:05 - 2016-05-07 00:06 - 03928338 _____ C:\Users\Rodrigo\Desktop\1782169296_Bottin.pdf
2016-05-06 23:58 - 2016-05-06 23:59 - 27381033 _____ C:\Users\Rodrigo\Desktop\The_Hacker_Playbook.pdf
2016-05-06 19:03 - 2016-05-06 19:03 - 00033256 _____ C:\Users\Rodrigo\Downloads\Gotham.S02E18.1080p.WEB-DL.DD5.1.H.264-NTb-DUAL.HDMAN[www.b2s-share.com].torrent
2016-05-05 23:57 - 2016-05-05 23:57 - 01710680 _____ C:\Users\Rodrigo\Downloads\SetupVCD5500.exe
2016-05-05 23:30 - 2016-05-05 23:30 - 00176858 _____ C:\Users\Rodrigo\Downloads\CORELDRAW.GRAPHICS.SUITE.X8.MULTI.RETAIL_By.WEBMASTER.iso[www.b2s-share.com].torrent
2016-05-05 22:21 - 2016-05-05 22:21 - 00019978 _____ C:\Users\Rodrigo\Downloads\CorelDRAWGraphicsSuiteX8Installer_pt64Bit.rar[www.b2s-share.com].torrent
2016-05-02 23:42 - 2016-05-02 23:42 - 00002847 _____ C:\Users\Rodrigo\Downloads\Game.of.Thrones.S06E02.1080p.HDTV.DD5.1.X264-G2G.DUAL-RK[www.b2s-share.com].torrent
2016-05-01 23:44 - 2016-05-01 23:44 - 00039011 _____ C:\Users\Rodrigo\Downloads\Gotham.S02E17.WEB-DL.XviD.Dual-MaC[www.b2s-share.com].torrent
2016-04-29 18:36 - 2016-04-29 19:06 - 00000000 ____D C:\Users\Rodrigo\Documents\ros-bot_2.02_early_access
2016-04-29 18:36 - 2016-04-29 18:36 - 00000000 ____D C:\Users\Rodrigo\Downloads\ros-bot_2.02_early_access
2016-04-29 18:36 - 2016-04-29 18:36 - 00000000 ____D C:\Users\Rodrigo\Documents\RoS-BoT
2016-04-29 18:35 - 2016-04-29 18:36 - 03581320 _____ C:\Users\Rodrigo\Downloads\ros-bot_2.02_early_access.zip
2016-04-26 21:36 - 2016-04-26 21:36 - 00000000 ____D C:\Users\Rodrigo\Downloads\ros-bot_2.01d (1)
2016-04-26 21:35 - 2016-04-26 21:35 - 03645612 _____ C:\Users\Rodrigo\Downloads\ros-bot_2.01d (1).zip
2016-04-26 21:11 - 2016-04-26 21:11 - 00015460 _____ C:\Users\Rodrigo\Downloads\Game.of.Thrones.S06E01.HDTV.x264-AVS.DUAL-HORRO[www.b2s-share.com].torrent
2016-04-25 23:38 - 2016-04-25 23:38 - 00038971 _____ C:\Users\Rodrigo\Downloads\Gotham.S02E16.WEB-DL.XviD.Dual-MaC[www.b2s-share.com].torrent
2016-04-25 23:21 - 2016-04-25 23:21 - 00018104 _____ C:\Users\Rodrigo\Downloads\Gotham.S02E16.1080p.WEB-DL.DD5.1.H.264-NTb.DUAL-NEOROSE[www.b2s-share.com].torrent
2016-04-21 01:49 - 2016-04-21 01:49 - 50449456 _____ (Microsoft Corporation) C:\Users\Rodrigo\Downloads\dotNetFx40_Full_x86_x64.exe
2016-04-21 01:37 - 2016-04-21 01:37 - 00000000 ____D C:\Users\Rodrigo\Documents\ros-bot_2.01d
2016-04-21 01:05 - 2016-04-21 01:29 - 00000000 ____D C:\Users\Rodrigo\Documents\RoS-BoT_old
2016-04-21 01:03 - 2016-04-21 01:03 - 13767776 _____ (Microsoft Corporation) C:\Users\Rodrigo\Downloads\vc_redist.x86.exe
2016-04-21 01:03 - 2016-04-21 01:03 - 00000000 ____D C:\Users\Rodrigo\Downloads\ros-bot_2.01d
2016-04-21 01:02 - 2016-04-21 01:02 - 03645612 _____ C:\Users\Rodrigo\Downloads\ros-bot_2.01d.zip
2016-04-19 23:17 - 2016-04-19 23:17 - 00001112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk
2016-04-19 23:15 - 2016-04-19 23:15 - 09688248 _____ (TeamViewer GmbH) C:\Users\Rodrigo\Downloads\TeamViewer_Setup.exe
2016-04-19 23:15 - 2016-04-19 23:15 - 06871216 _____ (TeamViewer) C:\Users\Rodrigo\Downloads\TeamViewerQS.exe
2016-04-19 00:28 - 2016-04-19 00:28 - 00272713 _____ C:\Users\Rodrigo\Desktop\Em branco.psd
2016-04-18 20:34 - 2016-04-18 20:34 - 00040957 _____ C:\Users\Rodrigo\Downloads\arrowdoodles-brushes.rar
2016-04-18 20:19 - 2016-04-21 00:05 - 00000000 ____D C:\Users\Rodrigo\Desktop\Cubo Mágico
2016-04-18 19:35 - 2016-04-19 00:28 - 00277922 _____ C:\Users\Rodrigo\Desktop\CUBO VETOR.psd
2016-04-16 23:20 - 2016-04-16 23:20 - 00915336 _____ (Magical Jelly Bean ) C:\Users\Rodrigo\Downloads\KeyFinderInstaller.exe
2016-04-16 23:20 - 2016-04-16 23:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyFinder
2016-04-16 23:20 - 2016-04-16 23:20 - 00000000 ____D C:\Program Files (x86)\Magical Jelly Bean
2016-04-16 23:15 - 2016-04-16 23:15 - 00007680 _____ C:\Users\Rodrigo\Downloads\loadhive.exe
2016-04-16 22:22 - 2016-04-16 22:22 - 00000000 ____D C:\Users\Rodrigo\Downloads\produkey-x64
2016-04-16 18:54 - 2016-04-16 18:54 - 00000000 ____D C:\Users\Rodrigo\Downloads\pen driver bootavel
2016-04-16 18:53 - 2016-04-16 18:53 - 00702777 _____ C:\Users\Rodrigo\Downloads\pen driver bootavel.rar
2016-04-16 18:38 - 2016-04-16 18:38 - 00098304 _____ (Hewlett-Packard Company) C:\Users\Rodrigo\Downloads\HPUSBDisk-2.2.3.exe
2016-04-16 18:34 - 2016-04-16 18:34 - 10587224 _____ C:\Users\Rodrigo\Downloads\BIOS_Acer_1.20_A_A.zip
2016-04-16 18:34 - 2016-04-16 18:34 - 00000000 ____D C:\Users\Rodrigo\Downloads\BIOS_Acer_1.20_A_A
2016-04-16 17:56 - 2016-04-16 17:55 - 00049871 _____ C:\Users\Rodrigo\Desktop\drivers.html
2016-04-16 16:02 - 2016-04-16 16:02 - 03014656 _____ C:\Users\Rodrigo\Desktop\Norton.Ghost.11.5.Corporate.DOS.Boot.CD.iso
2016-04-16 13:56 - 2016-04-16 13:56 - 00368318 _____ C:\Users\Rodrigo\Downloads\IdeaPatch.jar
2016-04-16 13:55 - 2016-04-16 13:55 - 00000000 ____D C:\Users\Rodrigo\AppData\Roaming\JetBrains
2016-04-16 13:54 - 2016-04-16 13:54 - 00000000 ____D C:\Users\Rodrigo\.PhpStorm2016.1
2016-04-16 13:52 - 2016-04-16 13:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JetBrains
2016-04-16 13:52 - 2016-04-16 13:52 - 00000000 ____D C:\Program Files (x86)\JetBrains
2016-04-16 13:48 - 2016-04-16 13:51 - 174316232 _____ C:\Users\Rodrigo\Downloads\PhpStorm-2016.1.exe
2016-04-16 00:44 - 2016-04-16 00:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-04-14 23:23 - 2016-04-14 23:23 - 00265235 _____ C:\Users\Rodrigo\Downloads\ajax-gif-loading-animations.rar
2016-04-14 23:23 - 2016-04-14 23:23 - 00000000 ____D C:\Users\Rodrigo\Downloads\ajax-gif-loading-animations
2016-04-13 20:07 - 2016-04-13 20:07 - 00142607 _____ C:\Users\Rodrigo\Downloads\Gotham.S02E15.1080p.WEB-DL.DD5.1.H.264-NTb.Dual.AndersonDJ.torrent
2016-04-13 19:16 - 2016-03-29 07:20 - 07474016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-04-13 19:16 - 2016-03-29 07:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-13 19:16 - 2016-03-29 07:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-04-13 19:16 - 2016-03-29 06:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-04-13 19:16 - 2016-03-29 05:41 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-04-13 19:16 - 2016-03-29 05:06 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-04-13 19:16 - 2016-03-29 05:01 - 00541304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-04-13 19:16 - 2016-03-29 04:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-04-13 19:16 - 2016-03-29 04:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-04-13 19:16 - 2016-03-29 04:46 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-04-13 19:16 - 2016-03-29 04:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-04-13 19:16 - 2016-03-29 04:19 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-04-13 19:16 - 2016-03-29 04:15 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-04-13 19:16 - 2016-03-29 04:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-04-13 19:16 - 2016-03-29 04:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-04-13 19:16 - 2016-03-29 04:10 - 01388544 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-04-13 19:16 - 2016-03-29 04:07 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-04-13 19:16 - 2016-03-29 04:02 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-04-13 19:16 - 2016-03-29 03:42 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-04-13 19:16 - 2016-03-29 03:37 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-04-13 19:16 - 2016-03-29 03:32 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-04-13 19:16 - 2016-03-29 03:31 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-04-13 19:16 - 2016-03-29 03:26 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-04-13 19:16 - 2016-03-29 03:05 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-04-13 19:16 - 2016-03-29 03:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-04-13 19:16 - 2016-03-29 03:02 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-04-13 19:16 - 2016-03-29 02:51 - 22378496 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-04-13 19:16 - 2016-03-29 02:41 - 24602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-04-13 19:16 - 2016-03-29 02:41 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-04-13 19:16 - 2016-03-29 02:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-04-13 19:16 - 2016-03-29 02:38 - 18673664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-04-13 19:16 - 2016-03-29 02:37 - 19340800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-04-13 19:15 - 2016-03-29 04:15 - 01714688 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-04-13 19:15 - 2016-03-29 04:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-04-13 19:15 - 2016-03-29 03:37 - 01444352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-04-13 19:15 - 2016-03-29 03:37 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-04-13 19:15 - 2016-03-29 03:01 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-04-13 19:15 - 2016-03-29 02:56 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-04-13 19:14 - 2016-04-02 00:14 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-04-13 19:14 - 2016-04-02 00:09 - 01832448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-04-13 19:14 - 2016-04-02 00:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-04-13 19:14 - 2016-03-29 06:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-04-13 19:14 - 2016-03-29 06:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-04-13 19:14 - 2016-03-29 06:11 - 00605440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-04-13 19:14 - 2016-03-29 05:02 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-04-13 19:14 - 2016-03-29 04:34 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-04-13 19:14 - 2016-03-29 04:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-04-13 19:14 - 2016-03-29 04:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-04-13 19:14 - 2016-03-29 04:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-04-13 19:14 - 2016-03-29 03:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-04-13 19:14 - 2016-03-29 03:31 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-04-13 19:14 - 2016-03-29 03:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-04-13 19:14 - 2016-03-29 03:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-04-13 19:14 - 2016-03-29 03:19 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-04-13 19:14 - 2016-03-29 02:58 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-04-13 19:14 - 2016-03-29 02:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-04-13 19:14 - 2016-03-29 02:51 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-04-13 19:14 - 2016-03-29 02:49 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-04-13 19:14 - 2016-03-29 02:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-04-13 19:14 - 2016-03-29 02:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-04-13 19:14 - 2016-03-29 02:27 - 07836160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-04-13 19:14 - 2016-03-29 02:27 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-04-13 19:13 - 2016-04-02 01:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-04-13 19:13 - 2016-04-02 00:26 - 00630272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-04-13 19:13 - 2016-04-02 00:21 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-04-13 19:13 - 2016-04-02 00:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-04-13 19:13 - 2016-04-02 00:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-04-13 19:13 - 2016-04-02 00:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-04-13 19:13 - 2016-04-02 00:07 - 03575296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2016-04-13 19:13 - 2016-04-02 00:07 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-04-13 19:13 - 2016-03-29 07:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-04-13 19:13 - 2016-03-29 07:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-04-13 19:13 - 2016-03-29 07:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-04-13 19:13 - 2016-03-29 07:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-04-13 19:13 - 2016-03-29 07:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-04-13 19:13 - 2016-03-29 06:28 - 00696664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-04-13 19:13 - 2016-03-29 06:17 - 00300104 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-04-13 19:13 - 2016-03-29 06:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-04-13 19:13 - 2016-03-29 05:44 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-04-13 19:13 - 2016-03-29 05:32 - 00253088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-04-13 19:13 - 2016-03-29 05:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-04-13 19:13 - 2016-03-29 04:39 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-04-13 19:13 - 2016-03-29 04:38 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-04-13 19:13 - 2016-03-29 04:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-04-13 19:13 - 2016-03-29 04:28 - 00460288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-04-13 19:13 - 2016-03-29 04:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-04-13 19:13 - 2016-03-29 04:23 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-04-13 19:13 - 2016-03-29 04:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
2016-04-13 19:13 - 2016-03-29 04:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-04-13 19:13 - 2016-03-29 04:16 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-04-13 19:13 - 2016-03-29 04:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-04-13 19:13 - 2016-03-29 04:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-04-13 19:13 - 2016-03-29 04:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-04-13 19:13 - 2016-03-29 04:12 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-04-13 19:13 - 2016-03-29 04:11 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-04-13 19:13 - 2016-03-29 04:10 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-04-13 19:13 - 2016-03-29 04:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2016-04-13 19:13 - 2016-03-29 04:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-04-13 19:13 - 2016-03-29 04:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-04-13 19:13 - 2016-03-29 04:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2016-04-13 19:13 - 2016-03-29 04:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-04-13 19:13 - 2016-03-29 03:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-04-13 19:13 - 2016-03-29 03:56 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-04-13 19:13 - 2016-03-29 03:56 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-04-13 19:13 - 2016-03-29 03:48 - 00346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-04-13 19:13 - 2016-03-29 03:44 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-04-13 19:13 - 2016-03-29 03:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
2016-04-13 19:13 - 2016-03-29 03:39 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-04-13 19:13 - 2016-03-29 03:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-04-13 19:13 - 2016-03-29 03:35 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-04-13 19:13 - 2016-03-29 03:34 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-04-13 19:13 - 2016-03-29 03:34 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-04-13 19:13 - 2016-03-29 03:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-04-13 19:13 - 2016-03-29 03:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-04-13 19:13 - 2016-03-29 03:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-04-13 19:13 - 2016-03-29 03:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
2016-04-13 19:13 - 2016-03-29 03:05 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-04-13 19:13 - 2016-03-29 03:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-04-13 19:13 - 2016-03-29 02:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-04-13 19:13 - 2016-03-29 02:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-04-13 19:13 - 2016-03-29 02:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-04-13 19:13 - 2016-03-29 02:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2016-04-13 19:12 - 2016-04-02 01:10 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2016-04-13 19:12 - 2016-04-02 00:29 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-04-13 19:12 - 2016-03-29 07:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2016-04-13 19:12 - 2016-03-29 07:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-04-13 19:12 - 2016-03-29 06:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2016-04-13 19:12 - 2016-03-29 06:25 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
2016-04-13 19:12 - 2016-03-29 06:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-04-13 19:12 - 2016-03-29 06:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2016-04-13 19:12 - 2016-03-29 05:44 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-04-13 19:12 - 2016-03-29 05:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-04-13 19:12 - 2016-03-29 05:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-04-13 19:12 - 2016-03-29 05:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2016-04-13 19:12 - 2016-03-29 05:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-04-13 19:12 - 2016-03-29 04:57 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-04-13 19:12 - 2016-03-29 04:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-04-13 19:12 - 2016-03-29 04:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-04-13 19:12 - 2016-03-29 04:42 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-04-13 19:12 - 2016-03-29 04:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2016-04-13 19:12 - 2016-03-29 04:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-04-13 19:12 - 2016-03-29 04:26 - 00169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-04-13 19:12 - 2016-03-29 04:23 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-04-13 19:12 - 2016-03-29 04:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2016-04-13 19:12 - 2016-03-29 04:17 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-04-13 19:12 - 2016-03-29 04:17 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-04-13 19:12 - 2016-03-29 04:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-04-13 19:12 - 2016-03-29 04:11 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-04-13 19:12 - 2016-03-29 04:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2016-04-13 19:12 - 2016-03-29 04:06 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-04-13 19:12 - 2016-03-29 03:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2016-04-13 19:12 - 2016-03-29 03:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-04-13 19:12 - 2016-03-29 03:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-04-13 19:12 - 2016-03-29 03:38 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-04-13 19:12 - 2016-03-29 03:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-04-13 19:12 - 2016-03-29 03:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2016-04-13 19:12 - 2016-03-29 03:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2016-04-13 19:12 - 2016-03-29 03:32 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-04-13 19:12 - 2016-03-29 03:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2016-04-13 19:12 - 2016-03-29 03:29 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-04-13 19:12 - 2016-03-29 03:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-04-13 19:12 - 2016-03-29 03:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2016-04-13 19:12 - 2016-03-29 03:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-04-13 19:12 - 2016-03-29 03:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
2016-04-13 19:12 - 2016-03-29 03:22 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-04-13 19:12 - 2016-03-29 03:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2016-04-13 19:12 - 2016-03-29 03:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2016-04-13 19:12 - 2016-03-29 03:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2016-04-13 19:12 - 2016-03-29 03:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-04-13 19:12 - 2016-03-29 02:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2016-04-13 19:11 - 2016-04-02 01:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
2016-04-13 19:11 - 2016-04-02 01:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-04-13 19:11 - 2016-04-02 00:29 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-04-13 19:11 - 2016-03-29 07:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-04-13 19:11 - 2016-03-29 07:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2016-04-13 19:11 - 2016-03-29 07:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-04-13 19:11 - 2016-03-29 06:28 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-04-13 19:11 - 2016-03-29 06:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-04-13 19:11 - 2016-03-29 06:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2016-04-13 19:11 - 2016-03-29 06:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
2016-04-13 19:11 - 2016-03-29 06:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
2016-04-13 19:11 - 2016-03-29 06:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
2016-04-13 19:11 - 2016-03-29 05:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
2016-04-13 19:11 - 2016-03-29 05:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
2016-04-13 19:11 - 2016-03-29 05:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
2016-04-13 19:11 - 2016-03-29 05:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
2016-04-13 19:11 - 2016-03-29 05:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-04-13 19:11 - 2016-03-29 04:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
2016-04-13 19:11 - 2016-03-29 04:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2016-04-13 19:11 - 2016-03-29 04:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2016-04-13 19:11 - 2016-03-29 04:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2016-04-13 19:11 - 2016-03-29 04:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2016-04-13 19:11 - 2016-03-29 04:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-04-13 19:11 - 2016-03-29 04:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-04-13 19:11 - 2016-03-29 04:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
2016-04-13 19:11 - 2016-03-29 04:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-04-13 19:11 - 2016-03-29 03:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2016-04-13 19:11 - 2016-03-29 03:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2016-04-13 19:11 - 2016-03-29 03:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2016-04-13 19:11 - 2016-03-29 03:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2016-04-13 19:11 - 2016-03-29 03:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2016-04-13 19:11 - 2016-03-29 03:32 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2016-04-13 19:11 - 2016-03-29 03:31 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-04-13 19:11 - 2016-03-29 03:06 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2016-04-13 19:11 - 2016-03-29 03:04 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-04-13 19:11 - 2016-03-29 02:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
2016-04-13 19:10 - 2016-04-02 00:30 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-04-13 19:10 - 2016-04-02 00:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2016-04-13 19:10 - 2016-04-02 00:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2016-04-13 19:10 - 2016-04-02 00:23 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-04-13 19:10 - 2016-04-02 00:23 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-04-13 19:10 - 2016-04-02 00:03 - 04774912 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-04-13 19:10 - 2016-03-29 06:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-04-13 19:10 - 2016-03-29 05:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-04-13 19:10 - 2016-03-29 05:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
2016-04-13 19:10 - 2016-03-29 05:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
2016-04-13 19:10 - 2016-03-29 04:59 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wnvapi.dll
2016-04-13 19:10 - 2016-03-29 04:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2016-04-13 19:10 - 2016-03-29 04:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
2016-04-13 19:10 - 2016-03-29 04:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-04-13 19:10 - 2016-03-29 04:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2016-04-13 19:10 - 2016-03-29 04:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-04-13 19:10 - 2016-03-29 04:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
2016-04-13 19:10 - 2016-03-29 04:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2016-04-13 19:10 - 2016-03-29 04:49 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2016-04-13 19:10 - 2016-03-29 04:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2016-04-13 19:10 - 2016-03-29 04:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
2016-04-13 19:10 - 2016-03-29 04:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
2016-04-13 19:10 - 2016-03-29 04:34 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-04-13 19:10 - 2016-03-29 04:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2016-04-13 19:10 - 2016-03-29 04:33 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wnv.sys
2016-04-13 19:10 - 2016-03-29 04:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2016-04-13 19:10 - 2016-03-29 04:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 19:10 - 2016-03-29 04:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
2016-04-13 19:10 - 2016-03-29 04:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2016-04-13 19:10 - 2016-03-29 04:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
2016-04-13 19:10 - 2016-03-29 03:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2016-04-13 19:10 - 2016-03-29 03:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2016-04-13 19:10 - 2016-03-29 03:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-04-13 19:10 - 2016-03-29 03:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
2016-04-13 19:10 - 2016-03-29 03:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-04-13 19:10 - 2016-03-29 03:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2016-04-13 19:10 - 2016-03-29 03:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2016-04-13 19:10 - 2016-03-29 03:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2016-04-13 19:10 - 2016-03-29 03:05 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-04-13 19:10 - 2016-03-29 03:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2016-04-13 19:10 - 2016-03-29 02:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2016-04-13 19:10 - 2016-03-29 02:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2016-04-13 19:10 - 2016-03-29 02:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2016-04-13 19:10 - 2016-03-29 02:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2016-04-13 19:10 - 2016-03-29 02:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
2016-04-13 19:09 - 2016-04-02 00:08 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-04-13 19:09 - 2016-03-29 05:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-04-13 19:09 - 2016-03-29 05:07 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-04-13 19:09 - 2016-03-29 05:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2016-04-13 19:09 - 2016-03-29 05:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
2016-04-13 19:09 - 2016-03-29 05:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2016-04-13 19:09 - 2016-03-29 05:00 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-04-13 19:09 - 2016-03-29 04:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-04-13 19:09 - 2016-03-29 04:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2016-04-13 19:09 - 2016-03-29 04:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-04-13 19:09 - 2016-03-29 04:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-04-13 19:09 - 2016-03-29 04:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
2016-04-13 19:09 - 2016-03-29 04:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2016-04-13 19:09 - 2016-03-29 04:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
2016-04-13 19:09 - 2016-03-29 04:50 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-04-13 19:09 - 2016-03-29 04:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-04-13 19:09 - 2016-03-29 04:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2016-04-13 19:09 - 2016-03-29 04:32 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-04-13 19:09 - 2016-03-29 04:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-04-13 19:09 - 2016-03-29 04:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2016-04-13 19:09 - 2016-03-29 04:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
2016-04-13 19:09 - 2016-03-29 04:11 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-04-13 19:09 - 2016-03-29 04:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2016-04-13 19:09 - 2016-03-29 04:09 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-04-13 19:09 - 2016-03-29 04:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2016-04-13 19:09 - 2016-03-29 04:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-04-13 19:09 - 2016-03-29 04:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2016-04-13 19:09 - 2016-03-29 04:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
2016-04-13 19:09 - 2016-03-29 04:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-04-13 19:09 - 2016-03-29 04:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2016-04-13 19:09 - 2016-03-29 03:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-04-13 19:09 - 2016-03-29 03:34 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-04-13 19:09 - 2016-03-29 03:27 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-04-13 19:09 - 2016-03-29 03:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-04-13 19:09 - 2016-03-29 03:00 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-04-13 19:09 - 2016-03-29 02:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2016-04-11 21:39 - 2016-04-11 21:39 - 00060680 _____ C:\Users\Rodrigo\Desktop\Tables - Ace Admin.pdf
2016-04-11 21:01 - 2016-04-11 21:01 - 00000000 ____D C:\Users\Rodrigo\Downloads\startmin-master
2016-04-11 21:00 - 2016-04-11 21:01 - 00702049 _____ C:\Users\Rodrigo\Downloads\startmin-master.zip
2016-04-11 20:53 - 2016-04-11 20:53 - 00033403 _____ C:\Users\Rodrigo\Downloads\hJ6U0WphRy.zip
2016-04-11 20:53 - 2016-04-11 20:53 - 00000000 ____D C:\Users\Rodrigo\Downloads\hJ6U0WphRy
2016-04-11 20:50 - 2016-04-11 20:50 - 00000000 ____D C:\Users\Rodrigo\Downloads\Bootstrap-Admin-Theme-3-master
2016-04-11 20:49 - 2016-04-11 20:49 - 08759443 _____ C:\Users\Rodrigo\Downloads\Bootstrap-3-Admin-Theme-master.zip
2016-04-11 20:49 - 2016-04-11 20:49 - 00000000 ____D C:\Users\Rodrigo\Downloads\Bootstrap-3-Admin-Theme-master
2016-04-11 20:48 - 2016-04-11 20:48 - 04108682 _____ C:\Users\Rodrigo\Downloads\Bootstrap-Admin-Theme-3-master.zip
2016-04-11 20:45 - 2016-04-11 20:45 - 00000000 ____D C:\Users\Rodrigo\Downloads\admin-bootstrap
2016-04-11 20:44 - 2016-04-11 20:44 - 00287786 _____ C:\Users\Rodrigo\Downloads\admin-bootstrap.zip

==================== Um Mês Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-05-10 22:37 - 2015-03-07 10:25 - 00001094 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-10 22:32 - 2015-10-30 04:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-05-10 22:27 - 2015-03-07 11:40 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-05-10 22:26 - 2015-10-30 04:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-05-10 22:25 - 2016-03-07 21:06 - 02300160 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-05-10 22:25 - 2015-10-30 16:11 - 00953782 _____ C:\WINDOWS\system32\prfh0416.dat
2016-05-10 22:25 - 2015-10-30 16:11 - 00224092 _____ C:\WINDOWS\system32\prfc0416.dat
2016-05-10 22:25 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-05-10 22:25 - 2015-10-30 04:21 - 00000000 ____D C:\WINDOWS\INF
2016-05-10 22:19 - 2016-03-28 18:52 - 00059776 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2016-05-10 22:19 - 2016-01-27 21:37 - 00001036 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2016-05-10 22:19 - 2015-03-07 10:25 - 00001090 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-10 22:18 - 2016-03-07 21:31 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-05-10 22:18 - 2016-03-07 21:05 - 00000000 ____D C:\Users\Todos os Usuários\NVIDIA
2016-05-10 22:18 - 2016-03-07 21:05 - 00000000 ____D C:\ProgramData\NVIDIA
2016-05-10 22:18 - 2015-10-30 03:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2016-05-10 22:18 - 2015-08-22 23:57 - 00000000 ____D C:\Users\Todos os Usuários\VMware
2016-05-10 22:18 - 2015-08-22 23:57 - 00000000 ____D C:\ProgramData\VMware
2016-05-10 21:57 - 2015-08-08 11:33 - 00000000 ____D C:\Users\Rodrigo\AppData\Local\CrashDumps
2016-05-10 21:48 - 2015-03-07 10:46 - 00000000 ____D C:\temp
2016-05-10 21:42 - 2016-01-27 21:37 - 00001040 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2016-05-10 21:32 - 2015-03-07 10:25 - 00004152 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-05-10 21:32 - 2015-03-07 10:25 - 00003920 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-05-10 21:14 - 2015-03-07 09:56 - 00004170 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{86C61BC5-3AEB-4157-9278-323038FF07A5}
2016-05-10 21:03 - 2015-04-19 18:36 - 00000000 ____D C:\Users\Rodrigo\AppData\Roaming\BitTorrent
2016-05-10 21:03 - 2015-03-07 11:34 - 00000000 ____D C:\Users\Rodrigo\AppData\Roaming\Media Player Classic
2016-05-08 16:44 - 2016-03-07 21:08 - 00000000 ____D C:\Users\Rodrigo
2016-05-07 13:41 - 2016-04-07 19:13 - 00000000 ____D C:\WINDOWS\Minidump
2016-05-07 13:41 - 2016-03-07 21:02 - 00000000 ___DC C:\WINDOWS\Panther
2016-05-07 13:41 - 2015-06-12 01:18 - 00000000 ____D C:\Users\Rodrigo\AppData\Roaming\TeamViewer
2016-05-07 13:11 - 2015-10-30 04:24 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2016-05-07 01:05 - 2015-07-12 22:13 - 00000000 ____D C:\Users\Rodrigo\AppData\Roaming\Notepad++
2016-05-06 19:00 - 2016-01-27 21:40 - 00000000 ___RD C:\Users\Rodrigo\Dropbox
2016-05-05 00:46 - 2015-04-04 15:28 - 00000000 ____D C:\Users\Rodrigo\AppData\Local\Battle.net
2016-05-02 19:33 - 2016-03-24 21:35 - 00002270 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-05-02 19:32 - 2015-03-07 09:51 - 00000000 ____D C:\Users\Rodrigo\AppData\Local\Packages
2016-04-27 19:32 - 2015-04-12 08:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-04-22 04:57 - 2014-06-14 23:48 - 00453288 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-04-21 01:58 - 2016-03-07 21:02 - 00477480 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-04-21 01:04 - 2015-03-07 11:25 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache
2016-04-21 01:04 - 2015-03-07 11:25 - 00000000 ____D C:\ProgramData\Package Cache
2016-04-20 15:28 - 2016-01-12 12:24 - 00000000 ____D C:\Users\adevi\AppData\Local\CrashDumps
2016-04-20 15:28 - 2015-12-30 00:34 - 00000000 ____D C:\Users\adevi\AppData\Local\Packages
2016-04-19 23:17 - 2015-06-12 01:18 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-04-19 00:29 - 2015-03-08 20:03 - 00000000 ____D C:\Users\Rodrigo\AppData\LocalLow\Adobe
2016-04-19 00:29 - 2015-03-08 20:00 - 00000000 ____D C:\Users\Rodrigo\AppData\Local\Adobe
2016-04-19 00:29 - 2015-03-07 10:55 - 00000000 ____D C:\Users\Todos os Usuários\Adobe
2016-04-19 00:29 - 2015-03-07 10:55 - 00000000 ____D C:\ProgramData\Adobe
2016-04-19 00:29 - 2015-03-07 09:51 - 00000000 ____D C:\Users\Rodrigo\AppData\Roaming\Adobe
2016-04-18 20:26 - 2016-03-19 19:45 - 00000000 ___RD C:\Users\Rodrigo\Desktop\-
2016-04-16 13:54 - 2015-10-15 19:50 - 00000000 ____D C:\Users\Rodrigo\.oracle_jre_usage
2016-04-16 10:58 - 2015-07-30 00:54 - 00000000 ____D C:\Users\Rodrigo\AppData\Local\Publishers
2016-04-16 00:44 - 2016-01-27 21:37 - 00000000 ____D C:\Program Files (x86)\Dropbox
2016-04-16 00:44 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\rescache
2016-04-14 22:30 - 2015-06-23 22:30 - 00000000 ____D C:\Users\Rodrigo\AppData\Local\ElevatedDiagnostics
2016-04-13 22:43 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-04-13 22:43 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-04-13 22:43 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-04-13 22:43 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-04-13 19:57 - 2014-06-14 23:43 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-13 19:40 - 2014-06-14 23:43 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-11 21:23 - 2015-12-13 15:17 - 00000000 ____D C:\Meus Sites

==================== Arquivos na raiz de alguns diretórios =======

2015-05-08 23:53 - 2015-05-18 23:10 - 0099384 _____ () C:\Users\Rodrigo\AppData\Roaming\inst.exe
2015-05-08 23:53 - 2015-05-18 23:10 - 0007859 _____ () C:\Users\Rodrigo\AppData\Roaming\pcouffin.cat
2015-05-08 23:53 - 2015-05-18 23:10 - 0001167 _____ () C:\Users\Rodrigo\AppData\Roaming\pcouffin.inf
2015-05-08 23:53 - 2015-05-18 23:10 - 0000033 _____ () C:\Users\Rodrigo\AppData\Roaming\pcouffin.log
2015-05-08 23:53 - 2015-05-18 23:10 - 0082816 _____ (VSO Software) C:\Users\Rodrigo\AppData\Roaming\pcouffin.sys
2015-08-02 12:14 - 2015-08-03 23:48 - 0000096 _____ () C:\Users\Rodrigo\AppData\Roaming\version2.xml
2015-05-08 23:55 - 2015-05-08 23:56 - 0000668 _____ () C:\Users\Rodrigo\AppData\Roaming\vso_ts_preview.xml
2015-03-14 22:16 - 2015-03-14 22:16 - 28579392 _____ (Sony Mobile Communications ) C:\Users\Rodrigo\AppData\Local\pcc.exe
2015-03-14 15:17 - 2015-11-04 00:11 - 0000600 _____ () C:\Users\Rodrigo\AppData\Local\PUTTY.RND
2016-01-11 18:11 - 2016-01-11 18:11 - 0007606 _____ () C:\Users\Rodrigo\AppData\Local\Resmon.ResmonCfg
2015-05-23 10:41 - 2015-05-23 10:41 - 0000057 _____ () C:\ProgramData\Ament.ini

Alguns arquivos em TEMP:
====================
C:\Users\Rodrigo\AppData\Local\Temp\libeay32.dll
C:\Users\Rodrigo\AppData\Local\Temp\msvcr120.dll
C:\Users\Rodrigo\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\WINDOWS\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\wininit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\explorer.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\svchost.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\services.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\User32.dll => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\User32.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\userinit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\WINDOWS\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\WINDOWS\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
C:\WINDOWS\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente


LastRegBack: 2016-05-07 01:23

==================== Fim de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité