cjoint

Publicité


Publicité

Commentaire : http://cioint.com/?DHBns6ahL8r

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x86) Versão: 19-06-2016 01
Executado por casa (administrador) em CASA-PC (21-06-2016 12:31:29)
Executando a partir de C:\Users\casa\Downloads
Perfis Carregados: casa (Perfis Disponíveis: casa)
Platform: Microsoft Windows 7 Ultimate (X86) Idioma: Português (Brasil)
Internet Explorer Versão 8 (Navegador padrão: Chrome)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
() C:\Windows\System32\srvany.exe
(LogMeIn, Inc.) C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe
() C:\Windows\KMService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(© 2015 Microsoft Corporation) C:\Users\casa\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registro (Whitelisted) ===========================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [35696 2009-02-27] (Adobe Systems Incorporated)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [931200 2012-03-26] (Microsoft Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2841536 2016-02-23] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
HKLM\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [5565960 2016-06-08] (LogMeIn Inc.)
HKU\S-1-5-21-2281989020-2404267099-2285575676-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [52142720 2016-04-29] (Skype Technologies S.A.)
HKU\S-1-5-21-2281989020-2404267099-2285575676-1000\...\Run: [BingSvc] => C:\Users\casa\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-12-13] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-2281989020-2404267099-2285575676-1000\...\Run: [Chromium] => "c:\users\casa\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session --restore-last-session
HKU\S-1-5-21-2281989020-2404267099-2285575676-1000\...\Run: [uTorrent] => C:\Users\casa\AppData\Roaming\uTorrent\uTorrent.exe [2133504 2016-05-20] (BitTorrent Inc.)
HKU\S-1-5-21-2281989020-2404267099-2285575676-1000\Control Panel\Desktop\\SCRNSAVE.EXE ->
GroupPolicy: Restrição - Chrome <======= ATENÇÃO
CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\Parameters: [DhcpNameServer] 200.175.89.139 200.175.5.139 192.168.25.1
Tcpip\..\Interfaces\{6C3AFFF5-53B6-4058-B035-307C2A8D8962}: [NameServer] 208.67.222.222,208.67.220.220
Tcpip\..\Interfaces\{6C3AFFF5-53B6-4058-B035-307C2A8D8962}: [DhcpNameServer] 200.175.89.139 200.175.5.139 192.168.25.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://br.search.yahoo.com/yhs/web?hspart=elm&hsimp=yhs-001&type=hdr_s_16_21_orgnl¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dbr%26pa%3DHodor%26cd%3D2XzuyEtN2Y1L1QzuyB0AyBzytCzytD0FyBtDyB0E0EtC0AyBtN0D0Tzu0StCyCtCtDtN1L2XzutAtFtBtCtFtCtFtDtN1L1Czu1M1Q1CtByEtFtCtFtDtN1L1G1B1V1N2Y1L1Qzu2SyBtB0A0AyD0AtDtDtGtD0A0CzztGzzyCtBtCtGtDyDtD0EtGyEyDzzzyyC0DyC0EyEtC0A0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0Ezz0CtBtCyBzyyBtG0EyC0BzztGyE0C0EzztGzy0DtCyCtGyEyB0BzyyEyByEtDyCtAzy0A2QtN0A0LzuyE%26cr%3D1840906193%26a%3Dhdr_s_16_21_orgnl%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate
HKU\S-1-5-21-2281989020-2404267099-2285575676-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://br.search.yahoo.com/yhs/web?hspart=elm&hsimp=yhs-001&type=hdr_s_16_21_orgnl¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dbr%26pa%3DHodor%26cd%3D2XzuyEtN2Y1L1QzuyB0AyBzytCzytD0FyBtDyB0E0EtC0AyBtN0D0Tzu0StCyCtCtDtN1L2XzutAtFtBtCtFtCtFtDtN1L1Czu1M1Q1CtByEtFtCtFtDtN1L1G1B1V1N2Y1L1Qzu2SyBtB0A0AyD0AtDtDtGtD0A0CzztGzzyCtBtCtGtDyDtD0EtGyEyDzzzyyC0DyC0EyEtC0A0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0Ezz0CtBtCyBzyyBtG0EyC0BzztGyE0C0EzztGzy0DtCyCtGyEyB0BzyyEyByEtDyCtAzy0A2QtN0A0LzuyE%26cr%3D1840906193%26a%3Dhdr_s_16_21_orgnl%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate
HKU\S-1-5-21-2281989020-2404267099-2285575676-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://br.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_16_13¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0AyBzytCzytD0FyBtDyB0E0EtC0AyBtN0D0Tzu0StCyDyDtAtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyEtByD0E0DyDtCtBtGtBtA0F0FtGyBzyyEyBtGtDtCtByBtGzz0BtD0FtA0D0FyD0ByDyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0Ezz0CtBtCyBzyyBtG0EyC0BzztGyE0C0EzztGzy0DtCyCtGyEyB0BzyyEyByEtDyCtAzy0A2QtN0A0LzuyE%26cr%3D1457884450%26a%3Dwncy_ir_16_13%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsafld_16_10¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyDtDyEyCyD0DtDyDtB0Czzzz0EtC0AyBtN0D0Tzu0StCyDtBzztN1L2XzutAtFtCzytFtCtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCyDyCzz0Fzy0E0EtGyD0BtAtCtGyDtAyEzztGtA0DtA0BtG0CtCyBtBtByDzztBtCtAtA0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0Ezz0CtBtCyBzyyBtG0EyC0BzztGyE0C0EzztGzy0DtCyCtGyEyB0BzyyEyByEtDyCtAzy0A2QtN0A0LzuyE%26cr%3D409703449%26a%3Dwncy_adsafld_16_10%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsafld_16_10¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyDtDyEyCyD0DtDyDtB0Czzzz0EtC0AyBtN0D0Tzu0StCyDtBzztN1L2XzutAtFtCzytFtCtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCyDyCzz0Fzy0E0EtGyD0BtAtCtGyDtAyEzztGtA0DtA0BtG0CtCyBtBtByDzztBtCtAtA0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0Ezz0CtBtCyBzyyBtG0EyC0BzztGyE0C0EzztGzy0DtCyCtGyEyB0BzyyEyByEtDyCtAzy0A2QtN0A0LzuyE%26cr%3D409703449%26a%3Dwncy_adsafld_16_10%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_ir_16_13¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyB0AyBzytCzytD0FyBtDyB0E0EtC0AyBtN0D0Tzu0StCyDyDtAtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyEtByD0E0DyDtCtBtGtBtA0F0FtGyBzyyEyBtGtDtCtByBtGzz0BtD0FtA0D0FyD0ByDyE0D2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0Ezz0CtBtCyBzyyBtG0EyC0BzztGyE0C0EzztGzy0DtCyCtGyEyB0BzyyEyByEtDyCtAzy0A2QtN0A0LzuyE%26cr%3D1457884450%26a%3Dwncy_ir_16_13%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2281989020-2404267099-2285575676-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsafld_16_10¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyDtDyEyCyD0DtDyDtB0Czzzz0EtC0AyBtN0D0Tzu0StCyDtBzztN1L2XzutAtFtCzytFtCtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCyDyCzz0Fzy0E0EtGyD0BtAtCtGyDtAyEzztGtA0DtA0BtG0CtCyBtBtByDzztBtCtAtA0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0Ezz0CtBtCyBzyyBtG0EyC0BzztGyE0C0EzztGzy0DtCyCtGyEyB0BzyyEyByEtDyCtAzy0A2QtN0A0LzuyE%26cr%3D409703449%26a%3Dwncy_adsafld_16_10%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2281989020-2404267099-2285575676-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_adsafld_16_10¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzuyDtDyEyCyD0DtDyDtB0Czzzz0EtC0AyBtN0D0Tzu0StCyDtBzztN1L2XzutAtFtCzytFtCtFtDtN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyCyDyCzz0Fzy0E0EtGyD0BtAtCtGyDtAyEzztGtA0DtA0BtG0CtCyBtBtByDzztBtCtAtA0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0Ezz0CtBtCyBzyyBtG0EyC0BzztGyE0C0EzztGzy0DtCyCtGyEyB0BzyyEyByEtDyCtAzy0A2QtN0A0LzuyE%26cr%3D409703449%26a%3Dwncy_adsafld_16_10%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2281989020-2404267099-2285575676-1000 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxp://www.bing.com/search?FORM=SK216DF&PC=SK216&q={searchTerms}&src=IE-SearchBox
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27] (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-03-09] (Oracle Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-03-09] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32.dll [2008-03-25] ()
FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-03-09] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-03-09] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-10-13] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-10-13] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)

Chrome:
=======
CHR HomePage: Profile 1 -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=pt-br
CHR StartupUrls: Profile 1 -> "hxxps://www.google.com.br/?gws_rd=ssl","hxxp://www.istartsurf.com/?type=hp&ts=1433298055&z=dd078e717958b94b6b507c1g1zac6ceoct3b2edw4m&from=pcm&uid=WDCXWD5000AVVS-63M8B0_WD-WCAV9479228292282","hxxp://www.mystartsearch.com/?type=hppp&ts=1433648243&z=6f1f2d09fb8a772ca986083gazfc6c1q9z1beoczcm&from=cmi&uid=WDCXWD5000AVVS-63M8B0_WD-WCAV9479228292282","hxxp://www.istartsurf.com/?type=hp&ts=1442842590&z=5ca56cc47b443e86040acb5g8zaz9oab5z8o6zeg6m&from=cor&uid=WDCXWD5000AVVS-63M8B0_WD-WCAV9479228292282","hxxps://www.google.com/","hxxp://br.hao123.com/?tn=sdkw_inner_hp_09_hao123_br&guid=2214ebfeb4c143e8a0dde884067ac79b"
CHR Session Restore: Profile 1 -> está habilitado.
CHR Profile: C:\Users\casa\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-25]
CHR Extension: (Google Search) - C:\Users\casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-25]
CHR Extension: (MSN Homepage & Bing Search Engine) - C:\Users\casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2015-12-13]
CHR Extension: (AdBlock) - C:\Users\casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-02-15]
CHR Extension: (Skype) - C:\Users\casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-12-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-25]
CHR Extension: (Gmail) - C:\Users\casa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-25]
CHR Profile: C:\Users\casa\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Adblock Plus) - C:\Users\casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-06-01]
CHR Extension: (busca da palavra) - C:\Users\casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ggckablhhmjagmokplgnbamljajnhanm [2016-05-15]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\casa\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-02]
CHR HKLM\...\Chrome\Extension: [bahkljhhdeciiaodlkppoonappfnheoi] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [kofkpgiaknijknhajbhnghkodiccblkg] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]
CHR HKU\S-1-5-21-2281989020-2404267099-2285575676-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bahkljhhdeciiaodlkppoonappfnheoi] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2281989020-2404267099-2285575676-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2281989020-2404267099-2285575676-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [kofkpgiaknijknhajbhnghkodiccblkg] - hxxps://clients2.google.com/service/update2/crx

==================== Serviços (Whitelisted) ========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [929728 2016-02-23] (NVIDIA Corporation)
R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1898504 2016-06-08] (LogMeIn Inc.)
R2 KMService; C:\Windows\system32\srvany.exe [8192 2015-11-25] () [Arquivo não assinado]
R2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [405424 2016-06-07] (LogMeIn, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [11552 2012-03-26] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [214952 2012-03-26] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-02-23] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3052992 2016-02-23] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2176960 2016-02-23] (NVIDIA Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [110280 2013-11-29] (Qualcomm Atheros Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [171064 2012-03-20] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [13216 2009-07-16] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [25536 2016-02-23] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [42128 2015-12-18] (NVIDIA Corporation)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13368 2015-11-25] (SlimWare Utilities, Inc.)
R3 XDva534; \??\C:\Windows\system32\XDva534.sys [X]

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um Mês Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-06-21 12:29 - 2016-06-21 12:31 - 00029925 _____ C:\Users\casa\Downloads\Addition.txt
2016-06-21 12:28 - 2016-06-21 12:31 - 00020377 _____ C:\Users\casa\Downloads\FRST.txt
2016-06-21 12:28 - 2016-06-21 12:31 - 00000000 ____D C:\FRST
2016-06-21 12:28 - 2016-06-21 12:28 - 01738240 _____ (Farbar) C:\Users\casa\Downloads\FRST.exe
2016-06-21 12:22 - 2016-06-21 12:23 - 03781536 _____ (DLL-Files.com Client ) C:\Users\casa\Downloads\clientsetup_zip-1.exe
2016-06-21 12:21 - 2016-06-21 12:21 - 00001889 _____ C:\Users\Public\Desktop\PCSX2 1.4.0.lnk
2016-06-21 12:21 - 2016-06-21 12:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2
2016-06-21 12:21 - 2016-06-21 12:21 - 00000000 ____D C:\Program Files\PCSX2 1.4.0
2016-06-21 12:19 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2016-06-21 12:19 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2016-06-21 12:19 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2016-06-21 12:19 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2016-06-21 12:19 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2016-06-21 12:19 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2016-06-21 12:19 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2016-06-21 12:19 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2016-06-21 12:19 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2016-06-21 12:19 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2016-06-21 12:19 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2016-06-21 12:19 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2016-06-21 12:19 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2016-06-21 12:19 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2016-06-21 12:19 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2016-06-21 12:19 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2016-06-21 12:19 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2016-06-21 12:19 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2016-06-21 12:19 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2016-06-21 12:19 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2016-06-21 12:19 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2016-06-21 12:19 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2016-06-21 12:19 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2016-06-21 12:19 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2016-06-21 12:19 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2016-06-21 12:19 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2016-06-21 12:19 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2016-06-21 12:19 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2016-06-21 12:19 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2016-06-21 12:19 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2016-06-21 12:19 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2016-06-21 12:19 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2016-06-21 12:19 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2016-06-21 12:19 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2016-06-21 12:19 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2016-06-21 12:19 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2016-06-21 12:19 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2016-06-21 12:19 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2016-06-21 12:19 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2016-06-21 12:19 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2016-06-21 12:19 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2016-06-21 12:19 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2016-06-21 12:19 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2016-06-21 12:19 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2016-06-21 12:19 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2016-06-21 12:19 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2016-06-21 12:19 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2016-06-21 12:19 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2016-06-21 12:19 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2016-06-21 12:19 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2016-06-21 12:19 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2016-06-21 12:19 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2016-06-21 12:19 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2016-06-21 12:19 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2016-06-21 12:19 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2016-06-21 12:19 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2016-06-21 12:19 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2016-06-21 12:19 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2016-06-21 12:19 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2016-06-21 12:19 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2016-06-21 12:19 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2016-06-21 12:19 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2016-06-21 12:19 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2016-06-21 12:19 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2016-06-21 12:19 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2016-06-21 12:19 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2016-06-21 12:19 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2016-06-21 12:19 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2016-06-21 12:19 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2016-06-21 12:19 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2016-06-21 12:19 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2016-06-21 12:19 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2016-06-21 12:19 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2016-06-21 12:19 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2016-06-21 12:19 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2016-06-21 12:19 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2016-06-21 12:19 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2016-06-21 12:19 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2016-06-21 12:19 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2016-06-21 12:19 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2016-06-21 12:19 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2016-06-21 12:19 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2016-06-21 12:19 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2016-06-21 12:15 - 2016-06-21 12:21 - 00000000 ___HD C:\Windows\msdownld.tmp
2016-06-21 12:15 - 2016-06-21 12:21 - 00000000 ____D C:\Windows\system32\directx
2016-06-21 12:10 - 2016-06-21 12:13 - 17837152 _____ C:\Users\casa\Downloads\pcsx2-1.4.0-setup.exe
2016-06-21 12:08 - 2016-06-21 12:10 - 21406927 _____ C:\Users\casa\Downloads\Todas As Bios.rar
2016-06-19 08:48 - 2016-06-19 08:48 - 00036547 _____ C:\Users\casa\Downloads\X-RayMod_v044.zip
2016-06-19 08:48 - 2016-06-19 08:48 - 00036547 _____ C:\Users\casa\Downloads\X-RayMod_v044 (1).zip
2016-06-18 03:01 - 2016-06-18 03:01 - 00001056 _____ C:\Users\casa\Desktop\fotos celular deva - Atalho.lnk
2016-06-08 22:06 - 2016-06-08 22:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2016-06-08 22:06 - 2016-06-08 22:06 - 00000000 ____D C:\Program Files\LogMeIn Hamachi
2016-05-29 17:02 - 2016-05-29 17:02 - 00000000 ____D C:\Users\casa\AppData\Local\CEF
2016-05-29 17:00 - 2016-06-18 02:59 - 00000000 ____D C:\Users\casa\AppData\Roaming\TS3Client
2016-05-29 16:59 - 2016-05-29 16:59 - 00001124 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2016-05-29 16:59 - 2016-05-29 16:59 - 00001086 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
2016-05-29 16:59 - 2016-05-29 16:59 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2016-05-29 16:54 - 2016-05-29 16:58 - 29439032 _____ (TeamSpeak Systems GmbH) C:\Users\casa\Downloads\TeamSpeak3-Client-win32-3.0.19.1.exe
2016-05-22 04:41 - 2016-05-22 04:43 - 21683184 _____ (Mirillis Ltd.) C:\Users\casa\Downloads\action_1_30_0_setup.exe

==================== Um Mês Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-06-21 12:15 - 2015-12-09 15:36 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache
2016-06-21 12:15 - 2015-12-09 15:36 - 00000000 ____D C:\ProgramData\Package Cache
2016-06-21 12:15 - 2015-11-25 10:19 - 00001058 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-06-21 10:19 - 2015-12-13 10:38 - 00000000 ____D C:\Users\casa\AppData\Roaming\Skype
2016-06-21 03:10 - 2016-03-26 08:30 - 00001837 _____ C:\Users\casa\Desktop\Luz da Escuridão.lnk
2016-06-20 23:15 - 2015-11-25 10:19 - 00001054 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-06-20 21:51 - 2009-07-14 01:34 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-06-20 21:51 - 2009-07-14 01:34 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-06-20 21:37 - 2015-12-25 09:43 - 00000220 _____ C:\Windows\Tasks\AutoKMSDaily.job
2016-06-20 21:36 - 2015-11-25 10:11 - 00077824 _____ C:\Windows\KMSEmulator.exe
2016-06-20 20:12 - 2016-03-11 00:34 - 00000000 ____D C:\Users\casa\AppData\Roaming\.minecraft
2016-06-20 12:48 - 2016-05-09 16:17 - 00000000 ____D C:\Users\casa\Desktop\devair musicas
2016-06-19 23:34 - 2016-04-17 02:22 - 00000000 ____D C:\Users\casa\AppData\Roaming\uTorrent
2016-06-19 23:34 - 2016-03-11 00:32 - 00000000 ____D C:\Users\casa\AppData\Local\LogMeIn Hamachi
2016-06-19 21:36 - 2015-11-25 10:11 - 00000214 _____ C:\Windows\Tasks\AutoKMS.job
2016-06-19 21:35 - 2015-11-25 11:20 - 00000000 ____D C:\Users\Todos os Usuários\NVIDIA
2016-06-19 21:35 - 2015-11-25 11:20 - 00000000 ____D C:\ProgramData\NVIDIA
2016-06-19 21:35 - 2009-07-14 01:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-06-18 12:41 - 2015-11-25 10:01 - 00000000 ____D C:\Users\casa\AppData\Roaming\vlc
2016-06-18 12:40 - 2016-05-04 23:33 - 00000000 ____D C:\Users\casa\Desktop\celular devair
2016-06-18 03:28 - 2016-03-26 16:54 - 00000000 ____D C:\Users\casa\Desktop\Super Nintendo
2016-06-18 01:43 - 2016-05-16 08:11 - 00000000 ____D C:\Users\casa\Desktop\Skillet
2016-06-16 12:25 - 2016-04-18 00:14 - 00000000 ____D C:\Program Files\Grand Chase History
2016-06-16 03:51 - 2016-04-17 02:23 - 00000000 ___SD C:\Users\casa\AppData\LocalLow\Temp
2016-06-15 17:40 - 2015-11-25 10:24 - 00400040 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-06-14 16:45 - 2009-07-14 01:53 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-06-12 13:34 - 2016-04-01 18:14 - 00000000 ____D C:\Users\casa\AppData\Local\CrashDumps
2016-06-08 23:41 - 2015-11-25 14:51 - 00704982 _____ C:\Windows\system32\prfh0416.dat
2016-06-08 23:41 - 2015-11-25 14:51 - 00146668 _____ C:\Windows\system32\prfc0416.dat
2016-06-08 23:41 - 2015-11-25 09:49 - 01633428 _____ C:\Windows\system32\PerfStringBackup.INI
2016-06-08 23:41 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\inf
2016-06-08 10:56 - 2016-03-11 00:32 - 00027040 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys
2016-06-06 22:18 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\system32\NDF
2016-06-06 10:22 - 2015-11-25 21:14 - 00000000 ____D C:\Users\casa\AppData\Local\ElevatedDiagnostics
2016-05-30 00:25 - 2016-03-08 02:56 - 00000000 ____D C:\Users\casa\AppData\Roaming\WarThunder
2016-05-30 00:09 - 2016-05-11 11:09 - 00000137 _____ C:\Users\casa\AppData\Roaming\WB.CFG
2016-05-30 00:09 - 2015-11-25 13:22 - 00001056 __RSH C:\Users\Todos os Usuários\ntuser.pol
2016-05-30 00:09 - 2015-11-25 13:22 - 00001056 __RSH C:\ProgramData\ntuser.pol
2016-05-26 22:02 - 2015-12-13 10:37 - 00000000 ___RD C:\Program Files\Skype
2016-05-26 06:56 - 2015-12-13 10:37 - 00000000 ____D C:\Users\Todos os Usuários\Skype
2016-05-26 06:56 - 2015-12-13 10:37 - 00000000 ____D C:\ProgramData\Skype
2016-05-26 05:50 - 2015-11-25 09:43 - 00000000 ____D C:\Users\casa
2016-05-23 10:44 - 2016-04-18 00:27 - 00074752 _____ () C:\SiKernel.dll
2016-05-23 10:44 - 2016-04-18 00:27 - 00028672 _____ () C:\SiInterpreteour.dll

==================== Arquivos na raiz de alguns diretórios =======

2016-05-11 11:09 - 2016-05-30 00:09 - 0000137 _____ () C:\Users\casa\AppData\Roaming\WB.CFG

Alguns arquivos em TEMP:
====================
C:\Users\casa\AppData\Local\Temp\BingBarSetup-Partner.exe
C:\Users\casa\AppData\Local\Temp\BingSvc.exe
C:\Users\casa\AppData\Local\Temp\BSvcProcessor.exe
C:\Users\casa\AppData\Local\Temp\BSvcUpdater.exe
C:\Users\casa\AppData\Local\Temp\CardiographiesRegilding.dll
C:\Users\casa\AppData\Local\Temp\HokiestRedevelop.dll
C:\Users\casa\AppData\Local\Temp\ICReinstall_Minecraft_1_8_7_Completo_Atualizado.exe
C:\Users\casa\AppData\Local\Temp\ICReinstall_Minecraft_1_8_7_Pirata_Completo_PH_Downs.exe
C:\Users\casa\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\casa\AppData\Local\Temp\nvStInst.exe
C:\Users\casa\AppData\Local\Temp\SkypeSetup.exe
C:\Users\casa\AppData\Local\Temp\utils.dll
C:\Users\casa\AppData\Local\Temp\vcredist_2015_Update_1_x86.exe
C:\Users\casa\AppData\Local\Temp\_inst1.exe
C:\Users\casa\AppData\Local\Temp\_inst2.exe
C:\Users\casa\AppData\Local\Temp\_inst3.exe
C:\Users\casa\AppData\Local\Temp\_inst4.exe
C:\Users\casa\AppData\Local\Temp\_inst5.exe


==================== Bamital & volsnap =================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\Windows\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\system32\services.exe => O arquivo é assinado digitalmente
C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente
C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente


LastRegBack: 2016-06-09 02:39

==================== Fim de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité