cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 18-01-2017
Executado por Ultimate (administrador) em ULTIMATE-PC (20-01-2017 18:18:37)
Executando a partir de C:\Users\Ultimate\Downloads
Perfis Carregados: Ultimate (Perfis Disponíveis: Ultimate)
Platform: Windows 7 Ultimate (X64) Idioma: Português (Brasil)
Internet Explorer Versão 8 (Navegador padrão: Chrome)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registro (Whitelisted) ====================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2864016 2016-11-28] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2016-11-12] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-11-28] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-102420195-37096831-3797236631-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2881824 2017-01-18] (Valve Corporation)
HKU\S-1-5-21-102420195-37096831-3797236631-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8944344 2016-09-28] (Piriform Ltd)
HKU\S-1-5-21-102420195-37096831-3797236631-1000\...\Run: [uTorrent] => C:\Users\Ultimate\AppData\Roaming\uTorrent\uTorrent.exe [1979072 2016-12-27] (BitTorrent Inc.)
HKU\S-1-5-21-102420195-37096831-3797236631-1000\...\MountPoints2: {5c7065db-b506-11e6-8de9-806e6f6e6963} - D:\setup.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-11-28] (AVAST Software)
GroupPolicy: Restrição <======= ATENÇÃO

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\Parameters: [DhcpNameServer] 177.91.76.251 208.67.222.222
Tcpip\..\Interfaces\{483E5A0E-B345-4C47-8AD7-0CE7C65CB5B0}: [DhcpNameServer] 177.91.76.251 208.67.222.222
Tcpip\..\Interfaces\{98FC2265-8E2F-4D42-8A83-E83DD5AC57BB}: [DhcpNameServer] 177.91.76.251 208.67.222.222

Internet Explorer:
==================
HKU\S-1-5-21-102420195-37096831-3797236631-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pt-br/?ocid=iehp
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-11-28] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2016-12-28] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-11-28] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2016-12-28] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-13] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-13] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-13] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-13] (Microsoft Corporation)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-11-28]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-11-28]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Plugin: @microsoft.com/GENUINE -> disabled [Nenhum Arquivo]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Nenhum Arquivo]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-12-28] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com.br/
CHR StartupUrls: Default -> "hxxp://br.hao123.com/?tn=spark_inner_hp_02_speed_br","hxxp://www.google.com.br/","www.google.com","hxxp://isearch.omiga-plus.com/?type=hp&ts=1418074519&from=slbnew&uid=WDCXWD1600AAJS-75B4A0_WD-WMAT3030730207302","hxxp://www.google.com/","hxxp://isearch.omiga?type=hppppppppppppppppppp","hxxp://isearch.omiga-plus.com/?type=hp&ts=1422239014&from=cor&uid=WDCXWD5000BPVT-22HXZT3_WD-WX41EA1WKR79WKR79","hxxp://isearch.omiga-plus.com/?type=hppp&ts=1422239043&from=cor&uid=WDCXWD5000BPVT-22HXZT3_WD-WX41EA1WKR79WKR79","hxxp://br.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_bxi01_15_35¶m1=1¶m2=f%3D7%26b%3DChrome%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0D0CtD0E0AtC0CtD0AzytByB0E0FtA0FtN0D0Tzu0StCtAtAyBtN1L2XzutAtFtCtBtFyDtFtAtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2S0Azz0CyByEtC0D0EtGzy0CzztCtGyEtCtAzztG0ByBtAzztG0ByD0AyCtDtAtBtAyD0C0FyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzztD0BtDyCzyyE0BtG0A0Dzz0CtGyEtDtB0BtG0BtA0BtDtGtByDtAtByDzyyDzy0DyE0A0A2QtN0A0LzuyEtN1B2Z1V1T1S1NzuzyyEyE%26cr%3D518332864%26a%3Dwncy_bxi01_15_35%26os%3DWindows%2B7%2BProfessional","hxxps://br.search.yahoo.com/?type=639975&fr=yo-yhp-ch"
CHR Session Restore: Default -> está habilitado.
CHR Profile: C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default [2017-01-20]
CHR Extension: (Google Apresentações) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-11-28]
CHR Extension: (Google Docs) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-11-28]
CHR Extension: (Google Drive) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-11-28]
CHR Extension: (YouTube) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-11-28]
CHR Extension: (Avast SafePrice) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-11-29]
CHR Extension: (Planilhas do Google) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-11-28]
CHR Extension: (Documentos Google off-line) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-28]
CHR Extension: (AdBlock) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-12-29]
CHR Extension: (Galera Video News) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfcbekmjjphhabliifjaiidabpgnondo [2016-11-28]
CHR Extension: (Into The Mist) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgihmkgobaljfehcadcckdggpeojaadh [2016-11-28]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-18]
CHR Extension: (Gmail) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-11-28]
CHR Extension: (Chrome Media Router) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-15]
CHR Profile: C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-01-12]
CHR Extension: (Google Apresentações) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-11-28]
CHR Extension: (little owl) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\alopfckdopopebdogneaajhpajfbkane [2016-12-01]
CHR Extension: (Google Docs) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-11-28]
CHR Extension: (Google Drive) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-11-28]
CHR Extension: (YouTube) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-11-28]
CHR Extension: (Avast SafePrice) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-11-30]
CHR Extension: (Planilhas do Google) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-11-28]
CHR Extension: (Documentos Google off-line) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-01]
CHR Extension: (Avast Online Security) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-12-16]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-11-28]
CHR Extension: (Gmail) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-11-28]
CHR Extension: (Chrome Media Router) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-16]
CHR Profile: C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2 [2017-01-15]
CHR Extension: (Google Apresentações) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-01-02]
CHR Extension: (Google Docs) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-02]
CHR Extension: (Google Drive) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-02]
CHR Extension: (YouTube) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-02]
CHR Extension: (Avast SafePrice) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-01-02]
CHR Extension: (Planilhas do Google) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-01-02]
CHR Extension: (Documentos Google off-line) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-06]
CHR Extension: (AdBlock) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-01-02]
CHR Extension: (Avast Online Security) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-01-02]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-02]
CHR Extension: (Gmail) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-02]
CHR Extension: (Chrome Media Router) - C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-02]
CHR Profile: C:\Users\Ultimate\AppData\Local\Google\Chrome\User Data\System Profile [2017-01-02]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

==================== Serviços (Whitelisted) ====================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-11-28] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [223600 2016-11-28] (AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3699904 2016-12-28] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-11-28] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-11-28] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-11-28] (AVAST Software)
R3 aswNetNd6; C:\Windows\System32\DRIVERS\aswNetNd6.sys [28312 2016-11-28] (AVAST Software)
R1 aswNetSec; C:\Windows\system32\drivers\aswNetSec.sys [453192 2016-11-28] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-11-28] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-11-28] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-11-28] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-11-28] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-11-28] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-11-28] (AVAST Software)

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um Mês Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2017-01-20 18:18 - 2017-01-20 18:19 - 00019034 _____ C:\Users\Ultimate\Downloads\FRST.txt
2017-01-20 18:18 - 2017-01-20 18:18 - 00000000 ____D C:\FRST
2017-01-20 18:17 - 2017-01-20 18:17 - 02419712 _____ (Farbar) C:\Users\Ultimate\Downloads\FRST64.exe
2017-01-20 18:05 - 2017-01-20 18:08 - 00000000 ____D C:\Windows\system32\MRT
2017-01-20 18:05 - 2017-01-20 18:05 - 135657872 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-01-20 18:04 - 2016-06-25 14:03 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\EOSNotify.exe
2017-01-20 18:04 - 2015-03-19 01:07 - 05503416 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-01-20 18:04 - 2015-03-19 00:57 - 03963320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-01-20 18:04 - 2015-03-19 00:57 - 03908024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-01-20 18:04 - 2014-09-14 22:44 - 03195392 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-01-20 18:04 - 2013-03-19 03:54 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-01-20 18:04 - 2013-03-19 02:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-01-20 18:04 - 2013-03-19 01:19 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-01-20 18:04 - 2011-04-09 04:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2017-01-20 18:04 - 2011-04-09 03:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2017-01-20 18:00 - 2017-01-20 18:00 - 00013193 _____ C:\Users\Ultimate\Downloads\api-ms-win-crt-runtime-l1-1-0 (2).zip
2017-01-20 18:00 - 2016-08-10 13:01 - 00023232 _____ (Microsoft Corporation) C:\Users\Ultimate\Desktop\api-ms-win-crt-runtime-l1-1-0.dll
2017-01-20 17:57 - 2017-01-20 17:57 - 00003630 _____ C:\Users\Ultimate\Downloads\api-ms-win-crt-runtime-l1-1-0 (1).zip
2017-01-20 17:43 - 2012-06-02 20:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-01-20 17:43 - 2012-06-02 20:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-01-20 17:43 - 2012-06-02 20:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-01-20 17:43 - 2012-06-02 20:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-01-20 17:43 - 2012-06-02 20:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-01-20 17:43 - 2012-06-02 20:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-01-20 17:43 - 2012-06-02 20:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-01-20 17:42 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-01-20 17:42 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-01-20 17:40 - 2017-01-20 17:40 - 01034556 _____ C:\Users\Ultimate\Downloads\Windows6.1-KB2999226-x64.msu
2017-01-20 17:34 - 2016-08-10 13:01 - 00023232 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-01-20 17:33 - 2017-01-20 17:33 - 00003630 _____ C:\Users\Ultimate\Downloads\api-ms-win-crt-runtime-l1-1-0.zip
2017-01-20 17:23 - 2017-01-20 17:24 - 02729024 _____ (DLL-Files.com Client ) C:\Users\Ultimate\Downloads\clientsetup_d-0.exe
2017-01-20 14:19 - 2017-01-20 14:19 - 00000000 ___HD C:\Windows\msdownld.tmp
2017-01-20 14:16 - 2017-01-20 14:19 - 00000000 ____D C:\Program Files (x86)\PCSX2 1.4.0
2017-01-20 14:16 - 2017-01-20 14:16 - 00001935 _____ C:\Users\Public\Desktop\PCSX2 1.4.0.lnk
2017-01-20 14:16 - 2017-01-20 14:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2
2017-01-20 14:15 - 2017-01-20 14:16 - 17837152 _____ C:\Users\Ultimate\Downloads\pcsx2-1.4.0-setup.exe
2017-01-19 20:06 - 2017-01-20 17:55 - 00000000 ____D C:\Users\Ultimate\Desktop\Nova pasta
2017-01-13 20:22 - 2017-01-13 20:22 - 01020344 _____ C:\Users\Ultimate\Downloads\Dragon Ball Z - Super Butoden (F).zip
2017-01-12 00:33 - 2017-01-13 21:57 - 00000000 ____D C:\Users\Ultimate\Desktop\Questao de Tempo (2013) - wolverdonfilmes.com
2017-01-10 19:37 - 2017-01-10 19:38 - 03451827 _____ C:\Users\Ultimate\Downloads\Ultimate Mortal Kombat 3 (U).zip
2017-01-10 19:37 - 2017-01-10 19:37 - 00355387 _____ C:\Users\Ultimate\Downloads\Super Mario Kart (U) [!].zip
2017-01-10 19:23 - 2017-01-10 19:23 - 01182478 _____ C:\Users\Ultimate\Downloads\Super Bomberman 5 (J).zip
2017-01-10 19:22 - 2017-01-10 19:22 - 02557476 _____ C:\Users\Ultimate\Downloads\Donkey Kong Country (U) (V1.2) [!].zip
2017-01-10 19:20 - 2017-01-10 19:21 - 01362128 _____ ( ) C:\Users\Ultimate\Downloads\Super Bomberman 5.exe
2017-01-10 19:20 - 2017-01-10 19:20 - 01362128 _____ ( ) C:\Users\Ultimate\Downloads\Donkey Kong Country.exe
2017-01-10 18:51 - 2017-01-20 17:21 - 00000000 ____D C:\Users\Ultimate\Desktop\Nitendo
2017-01-10 18:48 - 2017-01-10 18:48 - 02004463 _____ C:\Users\Ultimate\Downloads\snes9x-1.53-win-x64.zip
2017-01-10 16:32 - 2017-01-10 16:32 - 02579552 _____ C:\Users\Ultimate\Downloads\Fatura_012017_APARECIDA_0174_MASTER_00080477810058 (1).PDF
2017-01-10 16:31 - 2017-01-10 16:31 - 02579552 _____ C:\Users\Ultimate\Downloads\Fatura_012017_APARECIDA_0174_MASTER_00080477810058.PDF
2017-01-08 00:09 - 2017-01-08 03:13 - 00000000 ____D C:\Users\Ultimate\Desktop\Atividade.Paranormal.Dimensao.Fantasma.2015.SEM.CORTES.720p.BluRay.DUBLADO-LiPEH
2017-01-07 17:26 - 2017-01-07 18:43 - 00000000 ____D C:\Users\Ultimate\Desktop\Mama (2013) 1080p Full Hd Dual Audio Pt Br Dublado
2017-01-07 17:14 - 2017-01-07 18:42 - 1428553766 ____R C:\Users\Ultimate\Desktop\Atividade paranormal 3 HD.mkv
2017-01-07 17:08 - 2017-01-07 17:08 - 00000000 ____D C:\Users\Ultimate\Desktop\Atividade.Paranormal.Marcados.Pelo.Mal.2014.720p-WOLVERDONFILMES.COM
2017-01-06 14:29 - 2017-01-06 14:29 - 00328753 _____ C:\Users\Ultimate\Downloads\legendas_tv_20160227121500000000.rar
2017-01-05 23:18 - 2017-01-05 23:19 - 00000000 ____D C:\Users\Ultimate\Desktop\Esquadrão Suicida 1080p (2016) Dual Áudio BluRay 5.1 -- By - Lucas Firmo
2017-01-05 23:17 - 2017-01-05 23:17 - 00000000 ____D C:\Users\Ultimate\Desktop\Assim Na Terra Como No Inferno (2014) BRrip 1080p Dublado - AndreTPF
2017-01-05 23:16 - 2017-01-05 23:16 - 00000000 ____D C:\Users\Ultimate\Desktop\O Homem nas Trevas 2016 Bluray 1080p Dublado - TPF
2017-01-05 23:14 - 2017-01-05 23:14 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2017-01-02 11:58 - 2017-01-02 11:58 - 00123449 _____ C:\Users\Ultimate\Downloads\Automotiva_DR_SP.pdf
2017-01-01 03:26 - 2017-01-19 19:13 - 00000000 ____D C:\Users\Ultimate\Desktop\The.Expanse.S01.720p.BluRay.x264-DEMAND[rartv]
2016-12-31 20:35 - 2016-12-31 20:35 - 01141807 _____ C:\Users\Ultimate\Desktop\clouds_milky_way_eclipse_light_68883_2560x1580.jpg
2016-12-31 20:31 - 2016-12-31 20:31 - 05422626 _____ C:\Users\Ultimate\Desktop\blocks_rainbow_3d_graphics_background_76559_6000x4000.jpg
2016-12-31 20:27 - 2017-01-03 22:56 - 00000000 ____D C:\Users\Ultimate\Desktop\Annabelle 2014 [1080p] WWW.BLUDV.COM
2016-12-31 12:40 - 2016-12-31 12:40 - 00000000 ____D C:\Users\Ultimate\Desktop\A Escolha (2016) 5.1 CH Dublado 720p (By-LuanHarper)
2016-12-30 00:35 - 2016-12-30 00:35 - 00000000 ____D C:\Users\Ultimate\Desktop\Inferno.2016.1080p.WEB-DL.DD5.1.H264-FGT
2016-12-28 16:24 - 2016-12-28 16:25 - 00000000 ____D C:\Users\Ultimate\Desktop\+
2016-12-28 15:52 - 2016-12-28 15:52 - 00000000 ____D C:\Windows\SysWOW64\Wat
2016-12-28 15:52 - 2016-12-28 15:52 - 00000000 ____D C:\Windows\system32\Wat
2016-12-27 11:13 - 2016-12-27 11:13 - 00564330 _____ C:\Users\Ultimate\Downloads\barueri_edital_cp012016.pdf

==================== Um Mês Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2017-01-20 18:12 - 2016-11-28 02:19 - 00000000 ____D C:\Program Files (x86)\Steam
2017-01-20 18:12 - 2016-11-28 02:18 - 00000000 ____D C:\Users\Ultimate\AppData\Roaming\uTorrent
2017-01-20 18:10 - 2009-07-14 03:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-01-20 18:10 - 2009-07-14 02:45 - 00433160 _____ C:\Windows\system32\FNTCACHE.DAT
2017-01-20 17:47 - 2009-07-14 02:45 - 00009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-01-20 17:47 - 2009-07-14 02:45 - 00009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-01-20 14:19 - 2016-11-30 22:09 - 00000000 ____D C:\Windows\SysWOW64\directx
2017-01-20 14:17 - 2016-11-30 19:51 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache
2017-01-20 14:17 - 2016-11-30 19:51 - 00000000 ____D C:\ProgramData\Package Cache
2017-01-19 20:03 - 2009-07-29 14:08 - 00705268 _____ C:\Windows\system32\prfh0416.dat
2017-01-19 20:03 - 2009-07-29 14:08 - 00147108 _____ C:\Windows\system32\prfc0416.dat
2017-01-19 20:03 - 2009-07-14 03:13 - 01633534 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-19 20:03 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\inf
2017-01-13 22:28 - 2016-11-28 03:16 - 00000000 ____D C:\Users\Todos os Usuários\regid.1991-06.com.microsoft
2017-01-13 22:28 - 2016-11-28 03:16 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-01-13 22:25 - 2016-11-28 02:31 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-01-12 17:32 - 2016-11-28 02:36 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2017-01-05 22:50 - 2016-11-29 14:33 - 00000000 ___SD C:\Users\Ultimate\AppData\LocalLow\Temp
2016-12-29 00:26 - 2009-07-14 01:20 - 00000000 __RSD C:\Windows\assembly
2016-12-28 15:53 - 2009-07-13 21:56 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll
2016-12-28 15:53 - 2009-07-13 21:52 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll
2016-12-28 15:53 - 2009-07-13 21:38 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2016-12-28 15:53 - 2009-07-13 21:36 - 00013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slwga.dll
2016-12-28 15:53 - 2009-07-13 21:24 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2016-12-22 18:13 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\system32\wdi
2016-12-21 19:49 - 2016-11-30 00:15 - 00000000 ____D C:\Users\Ultimate\AppData\Roaming\MPC-HC

Alguns arquivos em TEMP:
====================
C:\Users\Ultimate\AppData\Local\Temp\ICReinstall_Donkey Kong Country.exe


==================== Bamital & volsnap ======================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\system32\services.exe => O arquivo é assinado digitalmente
C:\Windows\system32\User32.dll
[2009-07-13 21:38] - [2016-12-28 15:53] - 1008640 ____A (Microsoft Corporation) 2C353B6CE0C8D03225CAA2AF33B68D79

C:\Windows\SysWOW64\User32.dll
[2009-07-13 21:24] - [2016-12-28 15:53] - 0833024 ____A (Microsoft Corporation) 861C4346F9281DC0380DE72C8D55D6BE

C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente

LastRegBack: 2017-01-13 16:07

==================== Fim de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité