cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão:13-06-2016
Executado por Administrador (administrador) em DONAVAL_PC (14-06-2016 17:40:15)
Executando a partir de C:\Users\Administrador\Downloads
Perfis Carregados: Administrador (Perfis Disponíveis: Administrador)
Platform: Windows 7 Professional (X64) Idioma: Português (Brasil)
Internet Explorer Versão 8 (Navegador padrão: Chrome)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Desktop.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registro (Whitelisted) ===========================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8725248 2016-01-12] (Realtek Semiconductor)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [293872 2014-08-25] (Intel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
Winlogon\Notify\igfxcui: igfxdev.dll [X]

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{A719B6E5-771C-416A-A411-B9AEAD285175}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-220111350-2054966296-1305155763-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.atcomet.com/b/
SearchScopes: HKU\S-1-5-21-220111350-2054966296-1305155763-500 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO-x32: BitComet Helper -> {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} -> C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll [2013-11-29] (BitComet)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-30] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-30] (Oracle Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-13] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-13] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-13] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-13] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Administrador\AppData\Roaming\Mozilla\Firefox\Profiles\4l5ptcfx.default
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-30] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxps://www.google.com.br/
CHR StartupUrls: Default -> "","hxxp://search.conduit.com/?ctid=CT3318001&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP5FEAB1C1-69EA-4D24-AA05-28C1107F5F04&SSPV="
CHR Profile: C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Tradutor) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2016-03-09]
CHR Extension: (Google Apresentações) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-03-06]
CHR Extension: (Google Docs) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-03-06]
CHR Extension: (Google Drive) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-03-06]
CHR Extension: (YouTube) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-03-06]
CHR Extension: (Facebook) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\boeajhmfdjldchidhphikilcgdacljfm [2016-03-09]
CHR Extension: (Google Search) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-03-06]
CHR Extension: (Planilhas do Google) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-03-06]
CHR Extension: (Área de trabalho remota do Google Chrome) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2016-06-03]
CHR Extension: (Documentos Google off-line) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-18]
CHR Extension: (Endereço IP) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpnjjlbngpejmmhgcaagljaomgnginml [2016-03-09]
CHR Extension: (Google Play) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2016-03-09]
CHR Extension: (Google Maps) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2016-03-09]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-04]
CHR Extension: (Gmail) - C:\Users\Administrador\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-03-06]
CHR HKLM-x32\...\Chrome\Extension: [dhigneefebkcagnpnpbibganpmfgebnk] - hxxps://clients2.google.com/service/update2/crx

==================== Serviços (Whitelisted) ========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2013-11-29] (www.BitComet.com)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [28552 2016-04-26] (Hewlett-Packard Company)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344168 2016-01-12] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [Arquivo não assinado]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2120712 2016-05-13] (Electronic Arts)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2016-01-12] (REALiX(tm))
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [31144 2016-01-12] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [179456 2016-01-12] (Intel Corporation)
S3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [32936 2016-01-12] (Synaptics Incorporated)

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Três Meses Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-06-14 17:37 - 2016-06-14 17:37 - 00023126 _____ C:\Users\Administrador\Downloads\Addition.txt
2016-06-14 17:36 - 2016-06-14 17:40 - 00011595 _____ C:\Users\Administrador\Downloads\FRST.txt
2016-06-14 17:36 - 2016-06-14 17:40 - 00000000 ____D C:\FRST
2016-06-14 17:36 - 2016-06-14 17:36 - 02385920 _____ (Farbar) C:\Users\Administrador\Downloads\FRST64.exe
2016-06-14 17:33 - 2016-06-14 17:33 - 01034556 _____ C:\Users\Administrador\Downloads\Windows6.1-KB2999226-x64.msu
2016-06-14 17:29 - 2016-06-14 17:30 - 00000000 ____D C:\Users\Administrador\Downloads\Crash Twinsanity (v1.00)
2016-06-14 17:28 - 2016-06-14 17:29 - 00001939 _____ C:\Users\Public\Desktop\PCSX2 1.4.0.lnk
2016-06-14 17:28 - 2016-06-14 17:29 - 00000000 ___HD C:\Windows\msdownld.tmp
2016-06-14 17:28 - 2016-06-14 17:29 - 00000000 ____D C:\Windows\SysWOW64\directx
2016-06-14 17:28 - 2016-06-14 17:29 - 00000000 ____D C:\Program Files (x86)\PCSX2 1.4.0
2016-06-14 17:28 - 2016-06-14 17:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2
2016-06-14 17:06 - 2016-06-14 17:06 - 17837152 _____ C:\Users\Administrador\Downloads\pcsx2-1.4.0-setup.exe
2016-06-14 17:04 - 2016-06-14 17:23 - 999316774 _____ C:\Users\Administrador\Downloads\Crash Twinsanity (v1.00).7z
2016-05-19 21:26 - 2016-05-19 21:26 - 03014625 _____ C:\Users\Administrador\Downloads\forge-1.7.10-10.13.4.1558-1.7.10-universal.jar
2016-05-06 18:27 - 2016-05-06 18:28 - 00000000 ____D C:\Users\Administrador\AppData\Local\Mozilla
2016-05-06 18:27 - 2016-05-06 18:27 - 00000000 ____D C:\Users\Administrador\AppData\Roaming\Mozilla
2016-05-01 21:14 - 2016-05-01 21:42 - 00083968 _____ C:\Users\Administrador\Desktop\ESCALA FISIO JANEIRO-ABRIL (3).xls
2016-05-01 20:53 - 2016-05-01 20:53 - 00084992 _____ C:\Users\Administrador\Downloads\ESCALA FISIO JANEIRO-ABRIL (3).xls
2016-05-01 19:42 - 2016-05-01 19:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2016-05-01 19:42 - 2016-05-01 19:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Works
2016-05-01 19:41 - 2016-05-01 19:41 - 00000000 ____D C:\Windows\PCHEALTH
2016-05-01 19:41 - 2016-05-01 19:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio
2016-05-01 19:39 - 2016-05-01 19:42 - 00000000 ____D C:\Users\Todos os Usuários\Microsoft Help
2016-05-01 19:39 - 2016-05-01 19:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-05-01 19:39 - 2016-05-01 19:39 - 00000000 ____D C:\Users\Administrador\AppData\Local\Microsoft Help
2016-05-01 19:39 - 2016-05-01 19:39 - 00000000 ____D C:\Program Files\Microsoft Office
2016-05-01 19:39 - 2016-05-01 19:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8
2016-05-01 19:38 - 2016-05-01 19:38 - 00000000 __RHD C:\MSOCache
2016-05-01 19:18 - 2016-05-01 19:18 - 00084992 _____ C:\Users\Administrador\Downloads\ESCALA FISIO JANEIRO-ABRIL.xls
2016-05-01 19:18 - 2016-05-01 19:18 - 00084992 _____ C:\Users\Administrador\Downloads\ESCALA FISIO JANEIRO-ABRIL (2).xls
2016-05-01 19:18 - 2016-05-01 19:18 - 00084992 _____ C:\Users\Administrador\Downloads\ESCALA FISIO JANEIRO-ABRIL (1).xls
2016-05-01 18:36 - 2016-05-01 18:36 - 00106550 _____ C:\Users\Administrador\Downloads\BoletoImpresso_119743 (1).pdf
2016-05-01 18:34 - 2016-05-01 18:34 - 00106550 _____ C:\Users\Administrador\Downloads\BoletoImpresso_119743.pdf
2016-04-30 14:03 - 2016-06-05 15:12 - 00000000 ____D C:\Users\Administrador\AppData\Local\ElevatedDiagnostics
2016-04-30 08:56 - 2016-04-30 08:56 - 00000000 ____D C:\Users\Administrador\AppData\LocalLow\Oracle
2016-04-09 05:42 - 2016-04-30 08:57 - 00000000 ____D C:\Users\Administrador\.oracle_jre_usage
2016-04-09 05:42 - 2016-04-09 05:42 - 00000000 ____D C:\Users\Administrador\AppData\Roaming\Sun
2016-04-09 05:42 - 2016-04-09 05:42 - 00000000 ____D C:\Users\Administrador\AppData\LocalLow\Sun
2016-03-16 22:00 - 2016-06-14 17:28 - 00000000 ____D C:\Users\Administrador\AppData\Roaming\BitComet
2016-03-16 22:00 - 2016-03-16 22:00 - 10665336 _____ C:\Users\Administrador\Downloads\BitComet_1.40_x64_setup.exe
2016-03-16 22:00 - 2016-03-16 22:00 - 00000812 _____ C:\Users\Public\Desktop\BitComet.lnk
2016-03-16 22:00 - 2016-03-16 22:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet (64-bit)
2016-03-16 22:00 - 2016-03-16 22:00 - 00000000 ____D C:\Program Files\BitComet
2016-03-16 21:34 - 2016-03-16 21:34 - 00000000 ____D C:\Users\Todos os Usuários\Codemasters
2016-03-16 21:34 - 2016-03-16 21:34 - 00000000 ____D C:\Users\Administrador\Documents\My Games
2016-03-16 21:34 - 2016-03-16 21:34 - 00000000 ____D C:\ProgramData\Codemasters
2016-03-16 21:05 - 2016-03-16 21:05 - 00466456 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2016-03-16 21:05 - 2016-03-16 21:05 - 00444952 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2016-03-16 21:05 - 2016-03-16 21:05 - 00122904 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2016-03-16 21:05 - 2016-03-16 21:05 - 00109080 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2016-03-16 21:05 - 2016-03-16 21:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound
2016-03-16 21:05 - 2016-03-16 21:05 - 00000000 ____D C:\Program Files (x86)\OpenAL
2016-03-16 21:05 - 2016-03-16 21:05 - 00000000 ____D C:\Program Files (x86)\BRS
2016-03-16 21:05 - 2011-03-19 15:16 - 01417216 _____ (Blue Ripple Sound Limited) C:\Windows\SysWOW64\rapture3d_oal.dll
2016-03-16 21:05 - 2010-09-22 13:12 - 19087360 _____ (Intel Corporation / Blue Ripple Sound Limited) C:\Windows\SysWOW64\mkl_blueripple.dll
2016-03-16 21:00 - 2016-03-16 21:00 - 00000000 ____D C:\Users\Administrador\AppData\Roaming\Logitech
2016-03-16 21:00 - 2016-03-16 21:00 - 00000000 ____D C:\Users\Administrador\AppData\Roaming\Logishrd
2016-03-16 21:00 - 2016-03-16 21:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2016-03-16 21:00 - 2016-03-16 21:00 - 00000000 ____D C:\Program Files\Logitech
2016-03-16 21:00 - 2016-03-16 21:00 - 00000000 ____D C:\Program Files\Common Files\Logitech
2016-03-16 20:59 - 2016-03-16 21:00 - 16082320 _____ (Logitech Inc.) C:\Users\Administrador\Downloads\lgs510_x64.exe

==================== Três Meses Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-06-14 17:13 - 2016-01-12 01:42 - 00000902 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-06-14 17:05 - 2016-01-09 20:02 - 00001070 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-06-14 08:08 - 2009-07-14 01:45 - 00014528 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-06-14 08:08 - 2009-07-14 01:45 - 00014528 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-06-14 08:01 - 2016-03-06 18:11 - 00000000 __SHD C:\Users\Administrador\IntelGraphicsProfiles
2016-06-14 08:01 - 2016-01-09 20:02 - 00001066 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-06-14 08:01 - 2009-07-14 02:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-06-12 17:59 - 2016-03-06 19:17 - 00000364 _____ C:\Windows\Tasks\HPCeeScheduleForAdministrador.job
2016-06-12 00:17 - 2016-03-06 19:17 - 00003234 _____ C:\Windows\System32\Tasks\HPCeeScheduleForAdministrador
2016-06-09 19:31 - 2009-07-14 02:08 - 00032586 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-06-09 00:06 - 2016-01-09 20:03 - 00002193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-06-09 00:06 - 2016-01-09 20:03 - 00002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-05-22 21:44 - 2009-07-29 12:58 - 00709154 _____ C:\Windows\system32\prfh0416.dat
2016-05-22 21:44 - 2009-07-29 12:58 - 00150802 _____ C:\Windows\system32\prfc0416.dat
2016-05-22 21:44 - 2009-07-14 02:13 - 01650158 _____ C:\Windows\system32\PerfStringBackup.INI
2016-05-22 21:44 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\inf

==================== Arquivos na raiz de alguns diretórios =======

2016-02-27 13:45 - 2016-02-27 13:45 - 0000057 _____ () C:\ProgramData\Ament.ini
2016-01-12 01:28 - 2016-01-12 01:28 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Alguns arquivos em TEMP:
====================
C:\Users\Administrador\AppData\Local\Temp\bitcomet_mpcstar.exe
C:\Users\Administrador\AppData\Local\Temp\jre-8u91-windows-au.exe
C:\Users\DONAVAL\AppData\Local\Temp\jre-8u73-windows-au.exe


==================== Bamital & volsnap =================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\system32\services.exe => O arquivo é assinado digitalmente
C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente
C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente


LastRegBack: 2016-06-07 20:01

==================== Fim de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité