Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão:27-01-2016 Executado por Debora (administrador) em NOTE (02-02-2016 10:11:22) Executando a partir de C:\Users\Debora\Downloads Perfis Carregados: Debora (Perfis Disponíveis: Debora) Platform: Windows 7 Home Premium Service Pack 1 (X64) Idioma: Português (Brasil) Internet Explorer Versão 11 (Navegador padrão: Chrome) Modo da Inicialização: Normal Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (GAS Tecnologia) C:\Program Files (x86)\GbPlugin\gbpsv.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe (Banco Bradesco S.A.) C:\Program Files (x86)\Scpad\scpVista.exe () C:\Program Files\shopperz250120161400\Lojtiuf.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe () C:\Program Files (x86)\WeatherTool\2.0.0.11150\WeatherService.exe (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe () C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE\hnsgEEA4.tmp () C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE\jnsgBC5C.tmp () C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE\knseAE56.tmp (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (GAS Tecnologia) C:\Program Files (x86)\GbPlugin\gbpsv.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (ShenZhen Enode Techology co,.Ltd) C:\Program Files (x86)\WeatherTool\2.0.0.11150\weather.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe () C:\Program Files\Andy\HandyAndy.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe () C:\Program Files (x86)\CalendarTool\2.0.0.11189\CalendarServ.exe () C:\Program Files (x86)\CalendarTool\2.0.0.11189\calendar.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Program Files (x86)\Pokemon Showdown\pokemonshowdown.exe () C:\Program Files (x86)\Pokemon Showdown\pokemonshowdown.exe () C:\Program Files (x86)\Pokemon Showdown\pokemonshowdown.exe () C:\Program Files (x86)\Pokemon Showdown\pokemonshowdown.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registro (Whitelisted) =========================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM-x32\...\Run: [fst_br_103] => [X] HKLM-x32\...\Run: [gmsd_br_005010218] => [X] HKLM-x32\...\Run: [rec_en_77] => [X] HKLM-x32\...\Run: [LightGate] => c:\programdata\lightgate.exe [1081344 2015-12-04] () HKLM-x32\...\Run: [HomePageHelper] => c:\programdata\homepage.exe [1100288 2015-11-25] () HKLM\...\Winlogon: [Userinit] wscript C:\windows\run.vbs, Winlogon\Notify\ GbPluginBb: C:\Program Files (x86)\GbPlugin\gbieh.dll [2015-06-02] (Banco do Brasil) HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\Run: [msiql] => c:\programdata\msiql.exe [2415616 2016-01-26] () HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\Run: [taskhost] => rundll32.exe C:\ProgramData\WindowsMsg\A3FB110AD80824E309242083833A556D.dll Start /DEFAULT HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {1f87cb15-fb97-11e1-a001-e81132b3beff} - F:\AutoRun.exe HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {752b0a4a-0115-11e2-8032-e81132b3beff} - F:\AutoRun.exe HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {99949252-5221-11e3-8eb5-e81132b3befe} - F:\iLinker.exe HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {a0fdee8b-8187-11e5-8899-ec0747cc5307} - F:\LGAutoRun.exe HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {bb1fa51a-6502-11e3-bb98-e81132b3befe} - F:\AutoRun.exe HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {c6e67129-043c-11e2-b313-e81132b3beff} - F:\AutoRun.exe HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {e6c95d5d-f2ee-11e1-8377-e81132b3beff} - F:\AutoRun.exe HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\MountPoints2: {e6c95d6f-f2ee-11e1-8377-e81132b3beff} - F:\AutoRun.exe SSODL-x32: CompIBBrd - {A3717295-941D-416F-9384-ED1736729F1C} - C:\Program Files (x86)\Scpad\scpLIB.dll (Banco Bradesco S.A.) ShellExecuteHooks-x32: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399F83} - C:\Program Files (x86)\GbPlugin\gbieh.dll [1889664 2015-06-02] (Banco do Brasil) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HandyAndy.lnk [2016-02-01] ShortcutTarget: HandyAndy.lnk -> C:\Program Files\Andy\HandyAndy.exe () GroupPolicy: Restrição - Chrome <======= ATENÇÃO CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Winsock: Catalog9 01 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-07-16] (Lavasoft Limited) Winsock: Catalog9 02 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-07-16] (Lavasoft Limited) Winsock: Catalog9 03 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-07-16] (Lavasoft Limited) Winsock: Catalog9 04 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-07-16] (Lavasoft Limited) Winsock: Catalog9 16 C:\windows\SysWOW64\LavasoftTcpService.dll [342016 2015-07-16] (Lavasoft Limited) Winsock: Catalog9-x64 01 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-07-16] (Lavasoft Limited) Winsock: Catalog9-x64 02 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-07-16] (Lavasoft Limited) Winsock: Catalog9-x64 03 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-07-16] (Lavasoft Limited) Winsock: Catalog9-x64 04 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-07-16] (Lavasoft Limited) Winsock: Catalog9-x64 16 C:\windows\system32\LavasoftTcpService64.dll [422400 2015-07-16] (Lavasoft Limited) Hosts: Há mais de uma entrada no Hosts. Veja a seção Hosts do Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{0E31F570-49BA-458B-8B67-3FE5BA5956FE}: [NameServer] 104.197.191.4 Tcpip\..\Interfaces\{11F35C2B-E42D-4760-A225-FBCE01DB4C16}: [NameServer] 104.197.191.4 Tcpip\..\Interfaces\{88718CEF-5AB4-46F3-9A02-95FAFD8B0C2E}: [NameServer] 104.197.191.4 Tcpip\..\Interfaces\{88718CEF-5AB4-46F3-9A02-95FAFD8B0C2E}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{9D09A85F-1509-4F37-A874-EDB6C9B012E6}: [NameServer] 104.197.191.4 Tcpip\..\Interfaces\{9D09A85F-1509-4F37-A874-EDB6C9B012E6}: [DhcpNameServer] 192.168.42.129 Tcpip\..\Interfaces\{C3252508-083B-4F2A-9886-2811F7C337A0}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{CE9730F3-8B59-4AF3-8AF6-E630EF3B1343}: [NameServer] 104.197.191.4 Tcpip\..\Interfaces\{CE9730F3-8B59-4AF3-8AF6-E630EF3B1343}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{EAA8FFB4-4D28-46A4-8E61-6A7AD5C854B8}: [NameServer] 104.197.191.4 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yeabests.cc/ HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://br.hao123.com/?tn=sdkc_inner_hp_09_hao123_br&guid=9bb8524a0f0e37e9c8bb638a4232a319 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.oursurfing.com/web/?type=ds&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.oursurfing.com/web/?type=ds&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.oursurfing.com/?type=hp&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.oursurfing.com/?type=hp&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.oursurfing.com/web/?type=ds&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.oursurfing.com/web/?type=ds&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&q={searchTerms} HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yeabests.cc/ HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=pt-BR&Src=MSE&Tid=000328B0&OHP=http%3A%2F%2Fsecurityresponse.symantec.com%2Favcenter%2Ffix%5Fhomepage&OSP= HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=pt-BR&Src=MSE&Tid=000328B0&OHP=http%3A%2F%2Fsecurityresponse.symantec.com%2Favcenter%2Ffix%5Fhomepage&OSP= HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSSE HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=pt-BR&Src=MSE&Tid=000328B0&OHP=http%3A%2F%2Fsecurityresponse.symantec.com%2Favcenter%2Ffix%5Fhomepage&OSP= HKU\S-1-5-21-1277356225-661962986-2381428972-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.oursurfing.com/web/?type=ds&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&q={searchTerms} HKU\S-1-5-21-1277356225-661962986-2381428972-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://br.hao123.com/?tn=sdkc_inner_hp_09_hao123_br&guid=9bb8524a0f0e37e9c8bb638a4232a319 HKU\S-1-5-21-1277356225-661962986-2381428972-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.oursurfing.com/?type=hp&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX HKU\S-1-5-21-1277356225-661962986-2381428972-1000\Software\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = hxxp://www.uol.com.br/ HKU\S-1-5-21-1277356225-661962986-2381428972-1000\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://www.uol.com.br/ HKU\S-1-5-21-1277356225-661962986-2381428972-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.oursurfing.com/web/?type=ds&ts=1437772982&z=c55910760c8931d5f2db01ag6z8camfm1mbobtaqbm&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&q={searchTerms} URLSearchHook: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 - (Sem Nome) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - Nenhum Arquivo SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SMSTDF&pc=MASM&src=IE-SearchBox SearchScopes: HKLM-x32 -> {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://search.iminent.com/?appId=5B68F911-736F-438C-8C2A-BDEE3786955F&ref=toolbox&q={searchTerms} SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> BrowserMngrDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> OldSearch URL = hxxp://search.iminent.com/?appId=5B68F911-736F-438C-8C2A-BDEE3786955F&ref=toolbox&q={searchTerms} SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {067979B1-B39A-4F38-9C6C-A24593C68313} URL = hxxp://www-searching.com/s.ashx?prd=opensearch&q={searchTerms}&s=G1Pzamobl3687,2a0eb4ba-1ccf-42be-a0ce-e7e8876b0f3a, SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {1D39438F-4F38-48CB-854C-DEC182501A90} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {460C3D19-B3D4-4964-A550-77D263B0CCCB} URL = hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=dig2&utm_campaign=install_ie&utm_content=ds&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&ts=1437773072&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=dig2&utm_campaign=install_ie&utm_content=ds&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&ts=1437773072&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=dig2&utm_campaign=install_ie&utm_content=ds&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&ts=1437773072&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {CC4D9256-79D7-4AAD-8BA9-D4404AE6AD4C} URL = hxxps://br.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {D4844172-3788-437D-89BB-D0AB5878F692} URL = hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=dig2&utm_campaign=install_ie&utm_content=ds&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&ts=1437773072&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {EFB990D6-7230-4E5A-8AF9-BD735F43537C} URL = hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=dig2&utm_campaign=install_ie&utm_content=ds&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&ts=1437773072&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> {F2DABDCB-51CF-4411-86C8-840CA916D944} URL = hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=dig2&utm_campaign=install_ie&utm_content=ds&from=dig2&uid=HitachiXHTS547550A9E384_J2150050E9Z4JDE9Z4JDX&ts=1437773072&type=default&q={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2015-12-22] (Oracle Corporation) BHO: shopperz250120161400 -> {9DAD5043-33E9-4077-b42F-325EDE8A98B0} -> C:\Program Files\shopperz250120161400\Yfambyg64.dll [2016-01-25] () BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-12-22] (Oracle Corporation) BHO-x32: ssh2 Class -> {2E3C3651-B19C-4DD9-A979-901EC3E930AF} -> C:\Program Files (x86)\Scpad\scpsssh2.dll [2013-12-25] (Banco Bradesco S.A.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-22] (Oracle Corporation) BHO-x32: shopperz250120161400 -> {9DAD5043-33E9-4077-b42F-325EDE8A98B0} -> C:\Program Files\shopperz250120161400\Yfambyg.dll [2016-01-25] () BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540000} -> C:\Program Files (x86)\GbPlugin\gbieh.dll [2015-06-02] (Banco do Brasil) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-22] (Oracle Corporation) Toolbar: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> Sem Nome - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Nenhum Arquivo Toolbar: HKU\S-1-5-21-1277356225-661962986-2381428972-1000 -> Sem Nome - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Nenhum Arquivo Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - Nenhum Arquivo Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - Nenhum Arquivo Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices) Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices) Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices) Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices) FireFox: ======== FF ProfilePath: C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default FF NewTab: chrome://quick_start/content/index.html FF DefaultSearchEngine: yoursearching FF Homepage: hxxp://br.hao123.com/?tn=sdkc_inner_hp_09_hao123_br&guid=9bb8524a0f0e37e9c8bb638a4232a319 FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll [2016-01-21] () FF Plugin: @java.com/DTPlugin,version=10.76.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-12-22] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.76.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2015-12-22] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Nenhum Arquivo] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> c:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll [2016-01-21] () FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-22] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-22] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [Nenhum Arquivo] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> c:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @real.com/nppl3260;version=6.0.12.450 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll [2010-02-15] (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpjplug;version=6.0.12.448 -> C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll [2010-02-15] (RealNetworks, Inc.) FF Plugin-x32: @staging.google.com/globalUpdate Update;version=10 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [Nenhum Arquivo] FF Plugin-x32: @staging.google.com/globalUpdate Update;version=4 -> C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npglobalupdateUpdate4.dll [Nenhum Arquivo] FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\8\NP_wtapp.dll [2015-03-26] () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1277356225-661962986-2381428972-1000: gastecnologia.com.br/sf/bb -> C:\Users\Debora\AppData\Local\GAS Tecnologia\GBBD\npsf_bb.dll [Nenhum Arquivo] FF Plugin HKU\S-1-5-21-1277356225-661962986-2381428972-1000: gastecnologia.com.br/sf/cef64 -> C:\Users\Debora\AppData\Local\GAS Tecnologia\GBBD\npsf_cef_64.dll [Nenhum Arquivo] FF SearchPlugin: C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\searchplugins\bing-.xml [2015-11-07] FF SearchPlugin: C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\searchplugins\smod.xml [2016-01-25] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\SearchTheWeb.xml [2015-07-14] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yoursearching.xml [2016-01-27] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yoursites123.xml [2016-01-14] FF Extension: AdPunisher - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\extensions\yaifwhyaihueeot@qnqbyzgxjqwjzyex.net [2015-09-03] [não assinado] FF Extension: leethax.net extension - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\extensions\leethax@leethax.net.xpi [2015-11-18] FF Extension: Default NewTab - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\extensions\default_newtabff@gmail.com [2016-01-14] [não assinado] FF Extension: Bing Search - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\Extensions\bingsearch.full@microsoft.com [2015-10-23] [não assinado] FF Extension: FFun2Saave - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\Extensions\L@f7n2S.org [2015-09-03] [não assinado] FF Extension: Treasure Track - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\Extensions\{c713862d-0a3d-46bf-8460-d755ea4018a1}.xpi [2015-09-23] [não assinado] FF Extension: New Tab by Yahoo - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\jid1-G80Ec8LLEbK5fQ@jetpack.xpi [2015-11-23] [não assinado] FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-01-06] FF HKLM\...\Firefox\Extensions: [{3E4CD423-A6A2-4D6B-aBDD-0BEF52C389FF}] - C:\Program Files\shopperz250120161351\Firefox\{3E4CD423-A6A2-4D6B-aBDD-0BEF52C389FF}.xpi => não encontrado (a) FF HKLM\...\Firefox\Extensions: [{9DAD5043-33E9-4077-b42F-325EDE8A98B0}] - C:\Program Files\shopperz250120161400\Firefox\{9DAD5043-33E9-4077-b42F-325EDE8A98B0}.xpi FF Extension: shopperz250120161400 - C:\Program Files\shopperz250120161400\Firefox\{9DAD5043-33E9-4077-b42F-325EDE8A98B0}.xpi [2016-01-25] [não assinado] FF HKLM-x32\...\Firefox\Extensions: [defsearchp@gmail.com] - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\extensions\defsearchp@gmail.com => não encontrado (a) FF HKLM-x32\...\Firefox\Extensions: [deskCutv2@gmail.com] - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\extensions\deskCutv2@gmail.com => não encontrado (a) FF HKLM-x32\...\Firefox\Extensions: [default_newtabff@gmail.com] - C:\Users\Debora\AppData\Roaming\Mozilla\Firefox\Profiles\5q6gph5w.default\extensions\default_newtabff@gmail.com FF HKLM-x32\...\Firefox\Extensions: [{3E4CD423-A6A2-4D6B-aBDD-0BEF52C389FF}] - C:\Program Files\shopperz250120161351\Firefox\{3E4CD423-A6A2-4D6B-aBDD-0BEF52C389FF}.xpi => não encontrado (a) FF HKLM-x32\...\Firefox\Extensions: [{9DAD5043-33E9-4077-b42F-325EDE8A98B0}] - C:\Program Files\shopperz250120161400\Firefox\{9DAD5043-33E9-4077-b42F-325EDE8A98B0}.xpi FF HKU\S-1-5-21-1277356225-661962986-2381428972-1000\...\Firefox\Extensions: [addlyrics@addlyrics.net] - C:\Program Files (x86)\AddLyrics\FF => não encontrado (a) Chrome: ======= CHR HomePage: Profile 1 -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=pt-br CHR StartupUrls: Profile 1 -> "hxxps://www.google.com.br/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8" CHR Profile: C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-08] CHR Extension: (YouTube) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-08] CHR Extension: (Google Search) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-08] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-08] CHR Extension: (Gmail) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-08] CHR Profile: C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Drive) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-08] CHR Extension: (YouTube) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-08] CHR Extension: (Google Search) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-08] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-08] CHR Extension: (Gmail) - C:\Users\Debora\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-08] CHR HKU\S-1-5-21-1277356225-661962986-2381428972-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-1277356225-661962986-2381428972-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [jlcgehabolcakkjhgmgpkagpolbjlhfa] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [eedgghdcpmmmilkmfpnklknlenbiolec] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08] ==================== Serviços (Whitelisted) ======================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation) S3 DA0A3FB4-A71F-4CC3-8152-36F557717930; C:\Program Files\shopperz250120161400\Dodgylu.exe [294256 2016-01-25] () S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [347200 2015-03-26] (WildTangent) R2 GbpSv; C:\Program Files (x86)\GbPlugin\gbpsv.exe [579896 2015-04-29] (GAS Tecnologia) S2 GoogleChromeUpService; C:\ProgramData\service.exe [1734656 2016-01-11] () [Arquivo não assinado] S2 GoogleChromeUpSvc; C:\ProgramData\Windows Update\svrupg.exe [2786816 2016-01-27] (TODO: ) [Arquivo não assinado] S2 KMService; C:\windows\SysWOW64\srvany.exe [8192 2014-03-13] () [Arquivo não assinado] S3 MatSvc; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [343856 2011-06-13] (Microsoft Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation) S3 npggsvc; C:\windows\SysWOW64\GameMon.des [3473120 2015-08-10] (INCA Internet Co., Ltd.) R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2009-12-01] () [Arquivo não assinado] R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [Arquivo não assinado] R2 scpVista; C:\Program Files (x86)\Scpad\scpVista.exe [360640 2013-12-24] (Banco Bradesco S.A.) [Arquivo não assinado] R2 shopperz250120161400 Updater; C:\Program Files\shopperz250120161400\Lojtiuf.exe [159088 2016-01-25] () S2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3018800 2013-10-21] (Samsung Electronics CO., LTD.) R2 TheCalendarService; C:\Program Files (x86)\CalendarTool\2.0.0.11189\CalendarServ.exe [141960 2015-12-25] () R2 TheDesktopWeatherService; C:\Program Files (x86)\WeatherTool\2.0.0.11150\WeatherService.exe [153552 2015-12-09] () S2 WdMan; C:\ProgramData\nWdMn\WdMan.exe [326656 2016-01-07] (TU-Funs LIMITED) [Arquivo não assinado] R2 wucotusy; C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE\hnsgEEA4.tmp [416256 2016-01-25] () [Arquivo não assinado] R2 zutuzuni; C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE\jnsgBC5C.tmp [307712 2016-01-25] () [Arquivo não assinado] R2 zyzojupyzbt; C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE\knseAE56.tmp [186368 2016-02-01] () [Arquivo não assinado] ===================== Drivers (Whitelisted) ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R3 athr; C:\Windows\System32\DRIVERS\athrx.sys [2797056 2011-12-13] (Atheros Communications, Inc.) [Arquivo não assinado] R1 cherimoya; C:\Windows\System32\drivers\cherimoya.sys [61336 2016-01-25] (Cherimoya Ltd) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R3 GBPRCM; C:\Program Files (x86)\GbPlugin\gbprcm64.sys [21720 2015-04-29] (GAS Tecnologia) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation) S3 rtport; C:\windows\SysWOW64\drivers\rtport.sys [15144 2012-07-06] (Windows (R) 2003 DDK 3790 provider) S3 sdfhgdf; C:\Windows\System32\DRIVERS\sdfhgdf.sys [23208 2016-01-25] (Corporation) [Arquivo não assinado] R2 SGDrv; C:\Windows\System32\DRIVERS\SGdrv64.sys [7680 2011-04-11] (Phoenix Technologies Ltd.) R0 vsock; C:\Windows\System32\drivers\vsock.sys [75512 2015-11-05] (VMware, Inc.) R3 Warsaw_PP; C:\Program Files (x86)\GbPlugin\wsftprp64.sys [24792 2014-10-31] (GAS Tecnologia LTDA) R1 {2381c708-437b-40af-a3fc-1f3bd1d5172d}Gw64; C:\Windows\System32\drivers\{2381c708-437b-40af-a3fc-1f3bd1d5172d}Gw64.sys [48784 2015-07-24] (StdLib) R1 {7012eec1-4f37-42d4-a2cd-26727494d248}Gw64; C:\Windows\System32\drivers\{7012eec1-4f37-42d4-a2cd-26727494d248}Gw64.sys [48792 2014-10-13] (StdLib) R1 {a6762132-8e80-4305-b1ba-2bec91757ac2}Gw64; C:\Windows\System32\drivers\{a6762132-8e80-4305-b1ba-2bec91757ac2}Gw64.sys [48792 2014-10-22] (StdLib) R1 {e9bebce7-deb3-4ab9-896c-549739f208c5}Gw64; C:\Windows\System32\drivers\{e9bebce7-deb3-4ab9-896c-549739f208c5}Gw64.sys [48792 2014-10-06] (StdLib) S3 AthBTPort; system32\DRIVERS\btath_flt.sys [X] S1 bbbqxuzx; \??\C:\windows\system32\drivers\bbbqxuzx.sys [X] S3 BTATH_A2DP; system32\drivers\btath_a2dp.sys [X] S3 btath_avdt; system32\drivers\btath_avdt.sys [X] S3 BTATH_BUS; system32\DRIVERS\btath_bus.sys [X] S3 BTATH_HCRP; system32\DRIVERS\btath_hcrp.sys [X] S3 BTATH_LWFLT; system32\DRIVERS\btath_lwflt.sys [X] S3 BTATH_RCP; system32\DRIVERS\btath_rcp.sys [X] S1 gbpddfac; system32\drivers\gbpddfac64.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S1 iSafeNetFilter; system32\drivers\iSafeNetFilter.sys [X] S1 kkxkgham; \??\C:\windows\system32\drivers\kkxkgham.sys [X] S3 SBIOSIO; \??\C:\Users\Debora\AppData\Local\Temp\__Samsung_Update\SBIOSIO64.sys [X] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X] ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um Mês Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-02-02 10:11 - 2016-02-02 10:11 - 00042733 _____ C:\Users\Debora\Downloads\Shortcut.txt 2016-02-02 10:08 - 2016-02-02 10:11 - 00060577 _____ C:\Users\Debora\Downloads\Addition.txt 2016-02-02 10:05 - 2016-02-02 10:11 - 00037328 _____ C:\Users\Debora\Downloads\FRST.txt 2016-02-02 10:05 - 2016-02-02 10:11 - 00000000 ____D C:\FRST 2016-02-02 10:04 - 2016-02-02 10:04 - 02370560 _____ (Farbar) C:\Users\Debora\Downloads\FRST64.exe 2016-02-02 10:02 - 2016-02-02 10:03 - 00001684 _____ C:\Users\Debora\Desktop\Rkill.txt 2016-02-02 09:24 - 2016-02-02 09:24 - 00000000 ____D C:\Users\Debora\Documents\My Games 2016-02-02 09:24 - 2016-02-02 09:24 - 00000000 ____D C:\Users\Debora\AppData\Local\Pokemon Showdown 2016-02-02 09:18 - 2016-02-02 09:18 - 00002020 _____ C:\Users\Debora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokemon Showdown.lnk 2016-02-02 09:17 - 2016-02-02 09:24 - 00000000 ____D C:\Program Files (x86)\Pokemon Showdown 2016-02-02 09:14 - 2016-02-02 09:17 - 35241294 _____ C:\Users\Debora\Downloads\PokemonShowdownSetup.exe 2016-02-02 09:10 - 2016-02-02 09:10 - 00000000 ____D C:\Program Files (x86)\CalendarTool 2016-02-01 12:48 - 2016-02-01 12:48 - 00000000 ____D C:\Users\Debora\Downloads\Mod e jogo 2016-02-01 12:45 - 2016-01-31 12:33 - 102142456 ____N C:\Users\Debora\Downloads\Mod e jogo.zip 2016-02-01 12:30 - 2016-02-01 12:30 - 00000000 ____D C:\Users\Debora\.android 2016-02-01 12:29 - 2016-02-01 12:30 - 00000000 ____D C:\Users\Debora\AppData\Roaming\VMware 2016-02-01 12:27 - 2016-02-01 12:27 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Andy 2016-02-01 12:26 - 2016-02-01 12:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Andy 2016-02-01 12:25 - 2015-11-25 18:10 - 00934080 _____ (VMware, Inc.) C:\windows\system32\vnetlib64.dll 2016-02-01 12:25 - 2015-11-25 18:10 - 00392896 _____ (VMware, Inc.) C:\windows\SysWOW64\vmnat.exe 2016-02-01 12:25 - 2015-11-25 18:10 - 00358080 _____ (VMware, Inc.) C:\windows\SysWOW64\vmnetdhcp.exe 2016-02-01 12:25 - 2015-11-25 17:52 - 00026816 _____ (VMware, Inc.) C:\windows\system32\Drivers\vmnetuserif.sys 2016-02-01 12:25 - 2015-11-06 11:57 - 00057536 _____ (VMware, Inc.) C:\windows\system32\Drivers\hcmon.sys 2016-02-01 12:24 - 2016-02-01 12:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware 2016-02-01 12:24 - 2016-02-01 12:24 - 00000000 ____D C:\Program Files\Common Files\VMware 2016-02-01 12:24 - 2015-11-25 18:10 - 00066752 _____ (VMware, Inc.) C:\windows\system32\Drivers\vmx86.sys 2016-02-01 12:24 - 2015-11-25 18:10 - 00033472 _____ (VMware, Inc.) C:\windows\system32\Drivers\VMkbd.sys 2016-02-01 12:24 - 2015-11-05 19:25 - 00075512 _____ (VMware, Inc.) C:\windows\system32\Drivers\vsock.sys 2016-02-01 12:24 - 2015-11-05 19:25 - 00068288 _____ (VMware, Inc.) C:\windows\system32\vsocklib.dll 2016-02-01 12:24 - 2015-11-05 19:25 - 00064192 _____ (VMware, Inc.) C:\windows\SysWOW64\vsocklib.dll 2016-02-01 12:23 - 2016-02-02 09:05 - 00000000 ____D C:\ProgramData\VMware 2016-02-01 12:18 - 2016-02-01 12:30 - 00000000 ____D C:\Users\Debora\Andy 2016-02-01 12:18 - 2016-02-01 12:21 - 00000000 ____D C:\Program Files\Andy 2016-02-01 12:18 - 2016-02-01 12:18 - 00000000 ____D C:\Program Files (x86)\VMware 2016-02-01 12:14 - 2016-02-01 12:18 - 00000000 ____D C:\Program Files\AndyOfflineInstaller46.2 2016-02-01 11:11 - 2016-02-01 12:06 - 434769152 _____ C:\Users\Debora\Downloads\Andy_v46.2_53_x64.exe 2016-01-29 10:53 - 2016-01-29 10:53 - 00000008 _____ C:\END 2016-01-27 10:11 - 2016-01-27 10:11 - 00000000 ____D C:\Users\Public\Documents\Tools 2016-01-27 10:03 - 2016-01-27 10:03 - 00000000 ____D C:\windows\system32\log 2016-01-27 09:54 - 2016-01-27 09:54 - 01736192 _____ C:\ProgramData\upgsvr.exe 2016-01-27 09:54 - 2016-01-27 09:54 - 00621568 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Debora\AppData\Roaming\libeay32.dll 2016-01-27 09:54 - 2016-01-27 09:54 - 00162304 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Users\Debora\AppData\Roaming\ssleay32.dll 2016-01-27 09:54 - 2016-01-27 09:54 - 00000000 ____D C:\Users\Debora\AppData\Roaming\LightGate 2016-01-27 09:54 - 2015-12-10 08:39 - 01015808 _____ (d) C:\Users\Debora\AppData\Roaming\download.exe 2016-01-27 09:54 - 2015-12-04 13:14 - 01081344 _____ C:\Users\Debora\AppData\Roaming\LightGate.exe 2016-01-27 09:53 - 2016-02-02 09:07 - 00000000 ____D C:\ProgramData\WindowsMsg 2016-01-27 09:53 - 2016-02-02 09:07 - 00000000 ____D C:\Program Files (x86)\osTip 2016-01-27 09:53 - 2016-02-01 11:03 - 00000000 ____D C:\Users\Debora\AppData\Roaming\CalendarTool 2016-01-27 09:53 - 2016-01-27 10:36 - 00000000 ____D C:\Users\Debora\AppData\Local\Yeaplayer 2016-01-27 09:53 - 2016-01-27 09:50 - 02989680 _____ C:\Users\Debora\AppData\Roaming\8ec3f2c77d1f.exe 2016-01-27 09:53 - 2015-11-25 15:31 - 01100288 _____ C:\Users\Debora\AppData\Roaming\HomePage.exe 2016-01-27 09:53 - 2015-11-25 15:31 - 01100288 _____ C:\ProgramData\HomePage.exe 2016-01-27 09:52 - 2016-01-27 09:52 - 00000000 ____D C:\ProgramData\Windows Update 2016-01-27 09:52 - 2015-12-10 15:43 - 00600312 _____ C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe 2016-01-27 09:52 - 2015-11-14 21:06 - 02496403 _____ ( ) C:\Users\Debora\AppData\Roaming\yeaplayer_51447.exe 2016-01-27 09:51 - 2016-02-02 09:07 - 00009441 _____ C:\ProgramData\webad.xml 2016-01-27 09:51 - 2016-01-27 09:52 - 02786816 _____ (TODO: ) C:\Users\Debora\AppData\Roaming\svrupg.exe 2016-01-27 09:51 - 2016-01-27 09:51 - 00008643 _____ C:\Users\Debora\AppData\Roaming\webad.xml 2016-01-27 09:51 - 2016-01-27 09:51 - 00000000 ____D C:\Users\Debora\AppData\Local\Birds365 2016-01-27 09:51 - 2016-01-27 09:51 - 00000000 ____D C:\Users\Debora\AppData\Local\Birds 2016-01-27 09:51 - 2016-01-26 11:54 - 02415616 _____ C:\Users\Debora\AppData\Roaming\msiql.exe 2016-01-27 09:51 - 2016-01-26 11:54 - 02415616 _____ C:\ProgramData\msiql.exe 2016-01-27 09:51 - 2016-01-11 15:49 - 01734656 _____ C:\Users\Debora\AppData\Roaming\service.exe 2016-01-27 09:51 - 2016-01-11 15:49 - 01734656 _____ C:\ProgramData\service.exe 2016-01-27 09:51 - 2015-12-04 13:14 - 01081344 _____ C:\ProgramData\LightGate.exe 2016-01-27 09:48 - 2016-02-02 09:10 - 00000000 ____D C:\Users\Debora\AppData\Local\CleanBrowserApp 2016-01-27 09:45 - 2016-01-29 10:50 - 00000000 ____D C:\ProgramData\Tmp0x0x 2016-01-27 09:44 - 2016-01-27 10:38 - 00000000 ____D C:\Users\Debora\AppData\Local\gmsd_br_005010219 2016-01-27 09:44 - 2016-01-27 10:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GAMESDESKTOP 2016-01-27 09:43 - 2016-01-27 09:48 - 00000000 ____D C:\Program Files (x86)\CleanBrowser 2016-01-26 13:57 - 2016-01-26 13:57 - 00001076 _____ C:\windows\run.vbs 2016-01-26 09:55 - 2016-02-02 09:09 - 00003226 _____ C:\windows\System32\Tasks\SidebarExecute 2016-01-25 18:31 - 2012-02-02 21:03 - 00267776 _____ (Microsoft Corporation) C:\windows\system32\ieaksie.dll 2016-01-25 18:31 - 2012-02-02 21:03 - 00227840 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieaksie.dll 2016-01-25 18:31 - 2012-02-02 21:03 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieakui.dll 2016-01-25 18:31 - 2012-02-02 21:03 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\ieakui.dll 2016-01-25 18:31 - 2012-02-02 21:03 - 00160256 _____ (Microsoft Corporation) C:\windows\system32\ieakeng.dll 2016-01-25 18:31 - 2012-02-02 21:03 - 00130560 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieakeng.dll 2016-01-25 18:31 - 2012-02-02 21:03 - 00114176 _____ (Microsoft Corporation) C:\windows\system32\admparse.dll 2016-01-25 18:31 - 2012-02-02 21:03 - 00101888 _____ (Microsoft Corporation) C:\windows\SysWOW64\admparse.dll 2016-01-25 18:31 - 2012-02-02 21:03 - 00074240 _____ (Microsoft Corporation) C:\windows\SysWOW64\ie4uinit.exe 2016-01-25 18:31 - 2012-02-02 05:05 - 00174640 _____ (Symantec Corporation) C:\windows\system32\Drivers\SYMEVENT64x86.SYS 2016-01-25 18:31 - 2012-02-02 05:05 - 00007440 _____ C:\windows\system32\Drivers\SYMEVENT64x86.CAT 2016-01-25 18:31 - 2011-10-20 15:45 - 02791424 _____ (Atheros Communications, Inc.) C:\windows\system32\athrx.sys 2016-01-25 18:31 - 2011-10-12 05:53 - 07124304 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfc100ud.dll 2016-01-25 18:31 - 2011-10-12 05:53 - 07055696 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfc100d.dll 2016-01-25 18:31 - 2011-10-12 05:53 - 01505104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr100d.dll 2016-01-25 18:31 - 2011-10-12 05:53 - 00743760 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcp100d.dll 2016-01-25 18:31 - 2011-10-12 05:53 - 00105296 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcm100ud.dll 2016-01-25 18:31 - 2011-10-12 05:53 - 00103760 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcm100d.dll 2016-01-25 18:31 - 2011-08-12 02:29 - 03053160 _____ (Realtek Semiconductor Corp.) C:\windows\system32\Drivers\RTKVHD64.sys 2016-01-25 18:31 - 2011-08-09 11:39 - 02504296 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtPgEx64.dll 2016-01-25 18:31 - 2011-08-04 04:12 - 00093288 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RCoInst64.dll 2016-01-25 18:31 - 2011-07-29 03:46 - 01827944 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkApi64.dll 2016-01-25 18:31 - 2011-07-27 13:55 - 02604376 _____ (Waves Audio Ltd.) C:\windows\system32\WavesGUILib.dll 2016-01-25 18:31 - 2011-07-27 13:55 - 02132824 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxAudioEQ.dll 2016-01-25 18:31 - 2011-07-22 08:35 - 01247848 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RTCOM64.dll 2016-01-25 18:31 - 2011-07-08 06:05 - 00603984 _____ (Knowles Acoustics ) C:\windows\system32\KAAPORT64.dll 2016-01-25 18:31 - 2011-07-06 03:16 - 00289704 _____ (Atheros) C:\windows\system32\Drivers\btfilter.sys 2016-01-25 18:31 - 2011-06-30 05:14 - 01560168 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RTSnMg64.cpl 2016-01-25 18:31 - 2011-06-27 03:45 - 03768152 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxAudioRealtek.dll 2016-01-25 18:31 - 2011-05-30 22:42 - 01756264 _____ (DTS) C:\windows\system32\DTSS2SpeakerDLL64.dll 2016-01-25 18:31 - 2011-05-30 22:42 - 01568360 _____ (DTS) C:\windows\system32\DTSS2HeadphoneDLL64.dll 2016-01-25 18:31 - 2011-05-30 22:42 - 01486952 _____ (DTS) C:\windows\system32\DTSBoostDLL64.dll 2016-01-25 18:31 - 2011-05-30 22:42 - 00728680 _____ (DTS) C:\windows\system32\DTSBassEnhancementDLL64.dll 2016-01-25 18:31 - 2011-05-30 22:42 - 00712296 _____ (DTS) C:\windows\system32\DTSSymmetryDLL64.dll 2016-01-25 18:31 - 2011-05-30 22:42 - 00693352 _____ (DTS) C:\windows\system32\DTSVoiceClarityDLL64.dll 2016-01-25 18:31 - 2011-05-30 22:42 - 00491112 _____ (DTS) C:\windows\system32\DTSNeoPCDLL64.dll 2016-01-25 18:31 - 2011-05-30 22:42 - 00432744 _____ (DTS) C:\windows\system32\DTSLimiterDLL64.dll 2016-01-25 18:31 - 2011-05-30 22:42 - 00428648 _____ (DTS) C:\windows\system32\DTSGainCompensatorDLL64.dll 2016-01-25 18:31 - 2011-05-30 22:42 - 00242792 _____ (DTS) C:\windows\system32\DTSLFXAPO64.dll 2016-01-25 18:31 - 2011-05-30 22:42 - 00242792 _____ (DTS) C:\windows\system32\DTSGFXAPO64.dll 2016-01-25 18:31 - 2011-05-30 22:42 - 00241768 _____ (DTS) C:\windows\system32\DTSGFXAPONS64.dll 2016-01-25 18:31 - 2011-05-17 04:55 - 00107552 _____ (Realtek Semiconductor Corporation) C:\windows\system32\RTNUninst64.dll 2016-01-25 18:31 - 2011-05-17 04:55 - 00074272 _____ C:\windows\system32\RtNicProp64.dll 2016-01-25 18:31 - 2011-05-13 02:58 - 00001204 _____ C:\windows\system32\Drivers\ramps_0x01020200_40.dfu 2016-01-25 18:31 - 2011-05-05 04:24 - 02085440 _____ (Fortemedia Corporation) C:\windows\system32\FMAPO64.dll 2016-01-25 18:31 - 2011-05-05 03:15 - 00220512 _____ (Synopsys, Inc.) C:\windows\system32\SFNHK64.dll 2016-01-25 18:31 - 2011-05-05 03:14 - 00081248 _____ (Synopsys, Inc.) C:\windows\system32\SFCOM64.dll 2016-01-25 18:31 - 2011-05-05 03:14 - 00078176 _____ (Synopsys, Inc.) C:\windows\system32\SFAPO64.dll 2016-01-25 18:31 - 2011-05-02 03:27 - 03308376 _____ (Dolby Laboratories) C:\windows\system32\R4EEP64A.dll 2016-01-25 18:31 - 2011-05-02 03:27 - 00426328 _____ (Dolby Laboratories) C:\windows\system32\R4EED64A.dll 2016-01-25 18:31 - 2011-05-02 03:27 - 00136024 _____ (Dolby Laboratories) C:\windows\system32\R4EEL64A.dll 2016-01-25 18:31 - 2011-05-02 03:27 - 00118104 _____ (Dolby Laboratories) C:\windows\system32\R4EEA64A.dll 2016-01-25 18:31 - 2011-05-02 03:27 - 00074072 _____ (Dolby Laboratories) C:\windows\system32\R4EEG64A.dll 2016-01-25 18:31 - 2011-04-29 06:14 - 00042484 _____ C:\windows\system32\Drivers\AthrBT_0x01020200.dfu 2016-01-25 18:31 - 2010-11-21 01:24 - 00412160 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2016-01-25 18:31 - 2010-11-18 00:49 - 00121744 _____ (Sony Corporation) C:\windows\system32\SFSS_APO.dll 2016-01-25 18:31 - 2010-11-07 20:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEP64A.dll 2016-01-25 18:31 - 2010-11-07 20:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RP3DHT64.dll 2016-01-25 18:31 - 2010-11-07 20:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RP3DAA64.dll 2016-01-25 18:31 - 2010-11-07 20:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEED64A.dll 2016-01-25 18:31 - 2010-11-07 20:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEL64A.dll 2016-01-25 18:31 - 2010-11-07 20:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\windows\system32\RTEEG64A.dll 2016-01-25 18:31 - 2010-11-03 07:31 - 00332392 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtlCPAPI64.dll 2016-01-25 18:31 - 2010-11-03 07:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\windows\system32\RtkCfg64.dll 2016-01-25 18:31 - 2010-10-03 02:46 - 00341336 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxAudioAPO30.dll 2016-01-25 18:31 - 2010-09-26 22:34 - 00318808 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxAudioAPO20.dll 2016-01-25 18:31 - 2010-07-22 05:48 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\windows\SysWOW64\SFCOM.dll 2016-01-25 18:31 - 2010-07-22 05:37 - 00200800 _____ (Andrea Electronics Corporation) C:\windows\system32\AERTAC64.dll 2016-01-25 18:31 - 2010-05-06 06:34 - 00334680 _____ (Waves Audio Ltd.) C:\windows\system32\MaxxVolumeSDAPO.dll 2016-01-25 18:31 - 2009-11-23 22:55 - 00518896 _____ (SRS Labs, Inc.) C:\windows\system32\SRSTSX64.dll 2016-01-25 18:31 - 2009-11-23 22:55 - 00211184 _____ (SRS Labs, Inc.) C:\windows\system32\SRSTSH64.dll 2016-01-25 18:31 - 2009-11-23 22:55 - 00198896 _____ (SRS Labs, Inc.) C:\windows\system32\SRSHP64.dll 2016-01-25 18:31 - 2009-11-23 22:55 - 00155888 _____ (SRS Labs, Inc.) C:\windows\system32\SRSWOW64.dll 2016-01-25 18:31 - 2009-11-17 07:12 - 00108960 _____ (Andrea Electronics Corporation) C:\windows\system32\AERTAR64.dll 2016-01-25 18:31 - 2009-07-13 23:39 - 00071168 _____ (Microsoft Corporation) C:\windows\system32\lpremove.exe 2016-01-25 18:31 - 2009-06-10 18:45 - 00000003 _____ C:\windows\system32\Drivers\MsftWdf_Kernel_01009_Inbox_Critical.Wdf 2016-01-25 18:31 - 2008-11-08 20:09 - 00428544 _____ (Samsung Electronics) C:\windows\AutoReseal.exe 2016-01-25 18:31 - 2007-11-14 23:13 - 00423936 _____ (TODO: ) C:\windows\Reseal64.exe 2016-01-25 13:53 - 2016-01-26 09:57 - 00000000 ____D C:\Users\Debora\AppData\Roaming\systweak 2016-01-25 13:48 - 2016-01-25 13:48 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Real 2016-01-25 13:34 - 2016-02-02 09:30 - 00000000 ____D C:\Users\Debora\AppData\Roaming\WeatherTool 2016-01-25 13:34 - 2016-02-02 09:06 - 00000522 _____ C:\windows\Tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B}.job 2016-01-25 13:34 - 2016-01-25 13:34 - 00003624 _____ C:\windows\System32\Tasks\BaiduJP_Update_{8099779F-A13B-403e-B39A-65133857586B} 2016-01-25 13:34 - 2016-01-25 13:34 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Baidu 2016-01-25 13:34 - 2016-01-25 13:34 - 00000000 ____D C:\ProgramData\baidu 2016-01-25 13:34 - 2016-01-25 13:34 - 00000000 ____D C:\Program Files (x86)\WeatherTool 2016-01-25 13:31 - 2016-01-25 13:32 - 00000000 ____D C:\Users\Debora\AppData\Local\Tempfolder 2016-01-25 13:31 - 2016-01-25 13:31 - 00000000 ____D C:\windows\system32\hagb 2016-01-25 13:31 - 2016-01-25 13:31 - 00000000 ____D C:\Users\Debora\AppData\Roaming\BhnobBuielka 2016-01-25 13:30 - 2016-01-25 13:30 - 00003342 _____ C:\windows\System32\Tasks\Jybgovbi 2016-01-25 13:30 - 2016-01-25 13:30 - 00000000 ____D C:\Program Files\shopperz250120161400 2016-01-25 11:32 - 2016-01-25 11:50 - 00000000 ____D C:\Users\Debora\AppData\Local\Internet 2016-01-25 10:52 - 2016-01-25 10:52 - 00000000 ____D C:\Users\Debora\AppData\Local\ElevatedDiagnostics 2016-01-25 10:37 - 2016-01-27 10:49 - 00003436 _____ C:\windows\System32\Tasks\IBUpd 2016-01-25 10:37 - 2016-01-25 10:37 - 00003248 _____ C:\windows\System32\Tasks\IBUpd2 2016-01-25 10:36 - 2016-01-25 10:36 - 00000000 ____D C:\Users\Debora\AppData\Local\BrowserAir 2016-01-25 10:33 - 2016-01-25 12:56 - 00023208 _____ (Corporation) C:\windows\system32\Drivers\sdfhgdf.sys 2016-01-25 10:33 - 2016-01-25 10:33 - 00000000 ____D C:\Program Files (x86)\ppt 2016-01-25 10:32 - 2016-01-25 10:29 - 00001012 _____ C:\windows\system32\Drivers\etc\hp.bak 2016-01-25 10:31 - 2016-02-02 09:50 - 00000000 ____D C:\Program Files (x86)\7E88E41C-1453725076-11E1-9152-C9F8427D5FCE 2016-01-25 10:29 - 2016-01-25 10:29 - 00003338 _____ C:\windows\System32\Tasks\Pomugoje 2016-01-25 10:29 - 2016-01-25 10:29 - 00000000 ____D C:\Users\Debora\AppData\LocalLow\Company 2016-01-25 10:29 - 2016-01-25 10:29 - 00000000 ____D C:\Users\Debora\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A} 2016-01-25 10:29 - 2016-01-25 10:29 - 00000000 ____D C:\uninst 2016-01-25 10:27 - 2016-01-29 11:41 - 00000000 ____D C:\Program Files\Sound+ 2016-01-25 09:54 - 2016-01-25 10:29 - 00061336 _____ (Cherimoya Ltd) C:\windows\system32\Drivers\cherimoya.sys 2016-01-21 17:01 - 2016-01-21 17:01 - 00000000 ____D C:\Users\Debora\Downloads\Pack do tutorial - Zé Ruela Games 2015 2016-01-21 16:58 - 2016-01-21 17:00 - 12434322 _____ C:\Users\Debora\Downloads\Pack do tutorial - Zé Ruela Games 2015.rar 2016-01-21 16:41 - 2016-01-21 16:42 - 00000000 ____D C:\Users\Debora\Downloads\Terraria 2016-01-21 16:40 - 2016-01-21 16:41 - 101474421 _____ C:\Users\Debora\Downloads\Terraria.zip 2016-01-21 13:46 - 2016-01-21 16:38 - 416112128 _____ C:\Users\Debora\Downloads\minha intro.avi 2016-01-21 10:07 - 2016-01-29 11:15 - 00000000 ____D C:\Program Files (x86)\Picexa 2016-01-17 18:47 - 2016-01-17 18:48 - 18278658 _____ C:\Users\Debora\Downloads\Minecraft - Pocket Edition.apk 2016-01-17 14:03 - 2015-12-30 17:08 - 05572544 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe 2016-01-17 14:03 - 2015-12-30 17:05 - 01730496 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll 2016-01-17 14:03 - 2015-12-30 17:02 - 00215040 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll 2016-01-17 14:03 - 2015-12-30 17:02 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll 2016-01-17 14:03 - 2015-12-30 17:02 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll 2016-01-17 14:03 - 2015-12-30 17:01 - 01214464 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll 2016-01-17 14:03 - 2015-12-30 17:01 - 00344064 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll 2016-01-17 14:03 - 2015-12-30 17:00 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll 2016-01-17 14:03 - 2015-12-30 16:59 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll 2016-01-17 14:03 - 2015-12-30 16:59 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll 2016-01-17 14:03 - 2015-12-30 16:57 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll 2016-01-17 14:03 - 2015-12-30 16:57 - 00729600 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll 2016-01-17 14:03 - 2015-12-30 16:55 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll 2016-01-17 14:03 - 2015-12-30 16:55 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll 2016-01-17 14:03 - 2015-12-30 16:47 - 03993536 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe 2016-01-17 14:03 - 2015-12-30 16:47 - 03938240 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe 2016-01-17 14:03 - 2015-12-30 16:44 - 01311768 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll 2016-01-17 14:03 - 2015-12-30 16:41 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll 2016-01-17 14:03 - 2015-12-30 16:41 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll 2016-01-17 14:03 - 2015-12-30 16:41 - 00171520 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll 2016-01-17 14:03 - 2015-12-30 16:41 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll 2016-01-17 14:03 - 2015-12-30 16:40 - 00251392 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll 2016-01-17 14:03 - 2015-12-30 16:40 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll 2016-01-17 14:03 - 2015-12-30 16:39 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll 2016-01-17 14:03 - 2015-12-30 16:39 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll 2016-01-17 14:03 - 2015-12-30 16:38 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll 2016-01-17 14:03 - 2015-12-30 16:38 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll 2016-01-17 14:03 - 2015-12-30 15:43 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys 2016-01-17 14:03 - 2015-12-30 15:42 - 00290816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys 2016-01-17 14:03 - 2015-12-30 15:41 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe 2016-01-17 14:03 - 2015-12-30 15:32 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll 2016-01-17 14:03 - 2015-12-30 15:30 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll 2016-01-17 14:02 - 2015-12-30 17:02 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll 2016-01-17 14:02 - 2015-12-30 17:02 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll 2016-01-17 14:02 - 2015-12-30 17:02 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll 2016-01-17 14:02 - 2015-12-30 17:01 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll 2016-01-17 14:02 - 2015-12-30 17:01 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll 2016-01-17 14:02 - 2015-12-30 16:57 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll 2016-01-17 14:02 - 2015-12-30 16:55 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:54 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:41 - 00274944 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll 2016-01-17 14:02 - 2015-12-30 16:41 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll 2016-01-17 14:02 - 2015-12-30 16:41 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll 2016-01-17 14:02 - 2015-12-30 16:41 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll 2016-01-17 14:02 - 2015-12-30 16:39 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll 2016-01-17 14:02 - 2015-12-30 16:39 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00686080 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 16:37 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 15:50 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe 2016-01-17 14:02 - 2015-12-30 15:49 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe 2016-01-17 14:02 - 2015-12-30 15:44 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe 2016-01-17 14:02 - 2015-12-30 15:42 - 00129024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys 2016-01-17 14:02 - 2015-12-30 15:32 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe 2016-01-17 14:02 - 2015-12-30 15:32 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe 2016-01-17 14:02 - 2015-12-30 15:32 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe 2016-01-17 14:02 - 2015-12-30 15:30 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 15:30 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 15:30 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-01-17 14:02 - 2015-12-30 15:30 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-01-17 14:01 - 2015-12-30 17:08 - 00154560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys 2016-01-17 14:01 - 2015-12-30 17:08 - 00095680 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys 2016-01-17 14:01 - 2015-12-30 17:01 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll 2016-01-17 14:01 - 2015-12-30 17:01 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll 2016-01-17 14:01 - 2015-12-30 17:01 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll 2016-01-17 14:01 - 2015-12-30 16:59 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll 2016-01-17 14:01 - 2015-12-30 16:58 - 01461248 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll 2016-01-17 14:01 - 2015-12-30 16:58 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll 2016-01-17 14:01 - 2015-12-30 16:54 - 00686080 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll 2016-01-17 14:01 - 2015-12-30 15:57 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe 2016-01-17 14:01 - 2015-12-30 15:41 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe 2016-01-14 13:16 - 2016-01-20 14:18 - 00000001 _____ C:\windows\SysWOW64\br.html 2016-01-14 11:19 - 2016-01-21 10:05 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Picexa Viewer 2016-01-14 11:13 - 2016-01-14 11:15 - 00000000 ____D C:\windows\system32upd 2016-01-14 11:13 - 2016-01-14 11:14 - 00000000 ____D C:\ProgramData\nWdMn 2016-01-13 15:16 - 2015-12-23 21:13 - 00387784 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll 2016-01-13 15:16 - 2015-12-23 20:52 - 00341192 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll 2016-01-13 15:16 - 2015-12-12 16:54 - 25837568 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2016-01-13 15:16 - 2015-12-12 16:31 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2016-01-13 15:16 - 2015-12-12 16:30 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2016-01-13 15:16 - 2015-12-12 16:16 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2016-01-13 15:16 - 2015-12-12 16:15 - 02887168 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2016-01-13 15:16 - 2015-12-12 16:15 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll 2016-01-13 15:16 - 2015-12-12 16:15 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec 2016-01-13 15:16 - 2015-12-12 16:15 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2016-01-13 15:16 - 2015-12-12 16:14 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll 2016-01-13 15:16 - 2015-12-12 16:07 - 06051328 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2016-01-13 15:16 - 2015-12-12 16:07 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2016-01-13 15:16 - 2015-12-12 16:07 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2016-01-13 15:16 - 2015-12-12 16:03 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2016-01-13 15:16 - 2015-12-12 16:02 - 20367360 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll 2016-01-13 15:16 - 2015-12-12 16:02 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll 2016-01-13 15:16 - 2015-12-12 16:02 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2016-01-13 15:16 - 2015-12-12 16:02 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2016-01-13 15:16 - 2015-12-12 16:02 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2016-01-13 15:16 - 2015-12-12 15:55 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2016-01-13 15:16 - 2015-12-12 15:51 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll 2016-01-13 15:16 - 2015-12-12 15:49 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb 2016-01-13 15:16 - 2015-12-12 15:44 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll 2016-01-13 15:16 - 2015-12-12 15:40 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2016-01-13 15:16 - 2015-12-12 15:39 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll 2016-01-13 15:16 - 2015-12-12 15:37 - 00496640 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll 2016-01-13 15:16 - 2015-12-12 15:37 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll 2016-01-13 15:16 - 2015-12-12 15:37 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll 2016-01-13 15:16 - 2015-12-12 15:37 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll 2016-01-13 15:16 - 2015-12-12 15:36 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec 2016-01-13 15:16 - 2015-12-12 15:36 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll 2016-01-13 15:16 - 2015-12-12 15:35 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll 2016-01-13 15:16 - 2015-12-12 15:33 - 02280448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll 2016-01-13 15:16 - 2015-12-12 15:31 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll 2016-01-13 15:16 - 2015-12-12 15:30 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll 2016-01-13 15:16 - 2015-12-12 15:28 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll 2016-01-13 15:16 - 2015-12-12 15:27 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll 2016-01-13 15:16 - 2015-12-12 15:27 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll 2016-01-13 15:16 - 2015-12-12 15:27 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe 2016-01-13 15:16 - 2015-12-12 15:25 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll 2016-01-13 15:16 - 2015-12-12 15:23 - 00798208 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2016-01-13 15:16 - 2015-12-12 15:22 - 00718336 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2016-01-13 15:16 - 2015-12-12 15:21 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll 2016-01-13 15:16 - 2015-12-12 15:20 - 02123264 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2016-01-13 15:16 - 2015-12-12 15:19 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll 2016-01-13 15:16 - 2015-12-12 15:18 - 14457856 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2016-01-13 15:16 - 2015-12-12 15:14 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll 2016-01-13 15:16 - 2015-12-12 15:12 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll 2016-01-13 15:16 - 2015-12-12 15:10 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll 2016-01-13 15:16 - 2015-12-12 15:10 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll 2016-01-13 15:16 - 2015-12-12 15:09 - 04610560 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll 2016-01-13 15:16 - 2015-12-12 15:08 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll 2016-01-13 15:16 - 2015-12-12 15:06 - 02487808 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2016-01-13 15:16 - 2015-12-12 15:02 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll 2016-01-13 15:16 - 2015-12-12 15:00 - 12856320 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll 2016-01-13 15:16 - 2015-12-12 15:00 - 02050560 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl 2016-01-13 15:16 - 2015-12-12 15:00 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll 2016-01-13 15:16 - 2015-12-12 15:00 - 00687104 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll 2016-01-13 15:16 - 2015-12-12 14:54 - 01546752 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2016-01-13 15:16 - 2015-12-12 14:42 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2016-01-13 15:16 - 2015-12-12 14:41 - 02011136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll 2016-01-13 15:16 - 2015-12-12 14:38 - 01311744 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll 2016-01-13 15:16 - 2015-12-12 14:36 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll 2016-01-13 15:06 - 2015-11-13 21:09 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\mapistub.dll 2016-01-13 15:06 - 2015-11-13 21:09 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\mapi32.dll 2016-01-13 15:06 - 2015-11-13 21:08 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\fixmapi.exe 2016-01-13 15:06 - 2015-11-13 20:50 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mapistub.dll 2016-01-13 15:06 - 2015-11-13 20:50 - 00076800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mapi32.dll 2016-01-13 15:06 - 2015-11-13 20:49 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\fixmapi.exe 2016-01-13 15:04 - 2015-12-11 16:57 - 01164800 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2016-01-13 15:04 - 2015-12-08 19:54 - 02285056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msmpeg2vdec.dll 2016-01-13 15:04 - 2015-12-08 19:54 - 01620992 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVDECOD.DLL 2016-01-13 15:04 - 2015-12-08 19:54 - 01568768 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVENCOD.DLL 2016-01-13 15:04 - 2015-12-08 19:54 - 01325056 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMSPDMOE.DLL 2016-01-13 15:04 - 2015-12-08 19:54 - 00902144 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMADMOD.DLL 2016-01-13 15:04 - 2015-12-08 19:54 - 00815616 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMADMOE.DLL 2016-01-13 15:04 - 2015-12-08 19:54 - 00740352 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmpmde.dll 2016-01-13 15:04 - 2015-12-08 19:54 - 00739328 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMSPDMOD.DLL 2016-01-13 15:04 - 2015-12-08 19:54 - 00665088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVXENCD.DLL 2016-01-13 15:04 - 2015-12-08 19:54 - 00541184 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVSDECD.DLL 2016-01-13 15:04 - 2015-12-08 19:54 - 00358400 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMVSENCD.DLL 2016-01-13 15:04 - 2015-12-08 19:54 - 00154112 _____ (Microsoft Corporation) C:\windows\SysWOW64\VIDRESZR.DLL 2016-01-13 15:04 - 2015-12-08 19:53 - 03209728 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll 2016-01-13 15:04 - 2015-12-08 19:53 - 01329664 _____ (Microsoft Corporation) C:\windows\SysWOW64\quartz.dll 2016-01-13 15:04 - 2015-12-08 19:53 - 00970240 _____ (Microsoft Corporation) C:\windows\SysWOW64\msmpeg2adec.dll 2016-01-13 15:04 - 2015-12-08 19:53 - 00829952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSMPEG2ENC.DLL 2016-01-13 15:04 - 2015-12-08 19:53 - 00609280 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFWMAAEC.DLL 2016-01-13 15:04 - 2015-12-08 19:53 - 00519680 _____ (Microsoft Corporation) C:\windows\SysWOW64\qdvd.dll 2016-01-13 15:04 - 2015-12-08 19:53 - 00509952 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll 2016-01-13 15:04 - 2015-12-08 19:53 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\evr.dll 2016-01-13 15:04 - 2015-12-08 19:53 - 00415744 _____ (Microsoft Corporation) C:\windows\SysWOW64\MP4SDECD.DLL 2016-01-13 15:04 - 2015-12-08 19:53 - 00354816 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfplat.dll 2016-01-13 15:04 - 2015-12-08 19:53 - 00241152 _____ (Microsoft Corporation) C:\windows\SysWOW64\MPG4DECD.DLL 2016-01-13 15:04 - 2015-12-08 19:53 - 00241152 _____ (Microsoft Corporation) C:\windows\SysWOW64\MP43DECD.DLL 2016-01-13 15:04 - 2015-12-08 19:53 - 00206848 _____ (Microsoft Corporation) C:\windows\SysWOW64\RESAMPLEDMO.DLL 2016-01-13 15:04 - 2015-12-08 19:53 - 00206848 _____ (Microsoft Corporation) C:\windows\SysWOW64\qasf.dll 2016-01-13 15:04 - 2015-12-08 19:53 - 00193536 _____ (Microsoft Corporation) C:\windows\SysWOW64\ksproxy.ax 2016-01-13 15:04 - 2015-12-08 19:53 - 00153600 _____ (Microsoft Corporation) C:\windows\SysWOW64\COLORCNV.DLL 2016-01-13 15:04 - 2015-12-08 19:53 - 00103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll 2016-01-13 15:04 - 2015-12-08 19:53 - 00079872 _____ (Microsoft Corporation) C:\windows\SysWOW64\MP3DMOD.DLL 2016-01-13 15:04 - 2015-12-08 19:53 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\devenum.dll 2016-01-13 15:04 - 2015-12-08 19:53 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfvdsp.dll 2016-01-13 15:04 - 2015-12-08 19:53 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe 2016-01-13 15:04 - 2015-12-08 19:53 - 00023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe 2016-01-13 15:04 - 2015-12-08 19:53 - 00004608 _____ (Microsoft Corporation) C:\windows\SysWOW64\ksuser.dll 2016-01-13 15:04 - 2015-12-08 19:50 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 04121600 _____ (Microsoft Corporation) C:\windows\system32\mf.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 02777088 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2vdec.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 01955328 _____ (Microsoft Corporation) C:\windows\system32\WMVENCOD.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 01888768 _____ (Microsoft Corporation) C:\windows\system32\WMVDECOD.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 01575424 _____ (Microsoft Corporation) C:\windows\system32\WMSPDMOE.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 01573888 _____ (Microsoft Corporation) C:\windows\system32\quartz.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 01307136 _____ (Microsoft Corporation) C:\windows\system32\msmpeg2adec.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 01232896 _____ (Microsoft Corporation) C:\windows\system32\WMADMOD.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 01160192 _____ (Microsoft Corporation) C:\windows\system32\MSMPEG2ENC.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 01153024 _____ (Microsoft Corporation) C:\windows\system32\WMADMOE.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 01026048 _____ (Microsoft Corporation) C:\windows\system32\wmpmde.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 01010688 _____ (Microsoft Corporation) C:\windows\system32\mcmde.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 00978944 _____ (Microsoft Corporation) C:\windows\system32\WMSPDMOD.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 00666112 _____ (Microsoft Corporation) C:\windows\system32\WMVSDECD.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 00653824 _____ (Microsoft Corporation) C:\windows\system32\MP4SDECD.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 00642048 _____ (Microsoft Corporation) C:\windows\system32\WMVXENCD.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 00632320 _____ (Microsoft Corporation) C:\windows\system32\evr.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 00624640 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 00484864 _____ (Microsoft Corporation) C:\windows\system32\MFWMAAEC.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 00447488 _____ (Microsoft Corporation) C:\windows\system32\WMVSENCD.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 00432128 _____ (Microsoft Corporation) C:\windows\system32\mfplat.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 00378880 _____ (Microsoft Corporation) C:\windows\system32\SysFxUI.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 00371712 _____ (Microsoft Corporation) C:\windows\system32\qdvd.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 00292352 _____ (Microsoft Corporation) C:\windows\system32\VIDRESZR.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 00254464 _____ (Microsoft Corporation) C:\windows\system32\qasf.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 00225792 _____ (Microsoft Corporation) C:\windows\system32\RESAMPLEDMO.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 00224768 _____ (Microsoft Corporation) C:\windows\system32\MPG4DECD.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 00223744 _____ (Microsoft Corporation) C:\windows\system32\MP43DECD.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 00206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 00189952 _____ (Microsoft Corporation) C:\windows\system32\COLORCNV.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 00100864 _____ (Microsoft Corporation) C:\windows\system32\MP3DMOD.DLL 2016-01-13 15:04 - 2015-12-08 17:07 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\devenum.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\mfvdsp.dll 2016-01-13 15:04 - 2015-12-08 17:07 - 00055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe 2016-01-13 15:04 - 2015-12-08 17:07 - 00005120 _____ (Microsoft Corporation) C:\windows\system32\ksuser.dll 2016-01-13 15:04 - 2015-12-08 17:06 - 00250880 _____ (Microsoft Corporation) C:\windows\system32\ksproxy.ax 2016-01-13 15:04 - 2015-12-08 17:06 - 00024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe 2016-01-13 15:04 - 2015-12-08 17:04 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll 2016-01-13 15:04 - 2015-12-08 16:54 - 00116736 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmk.sys 2016-01-13 15:04 - 2015-12-08 16:12 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\Drivers\portcls.sys 2016-01-13 15:04 - 2015-12-08 16:11 - 00005632 _____ (Microsoft Corporation) C:\windows\system32\Drivers\drmkaud.sys 2016-01-13 15:04 - 2015-12-08 15:58 - 03211264 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2016-01-13 14:59 - 2015-12-08 19:53 - 00641536 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll 2016-01-13 14:59 - 2015-12-08 19:52 - 00312320 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll 2016-01-13 14:59 - 2015-12-08 17:07 - 00879104 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll 2016-01-13 14:59 - 2015-12-08 17:07 - 00405504 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll 2016-01-13 14:59 - 2015-11-16 23:11 - 00025024 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe 2016-01-13 14:59 - 2015-11-16 23:08 - 01381376 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll 2016-01-13 14:59 - 2015-11-16 23:08 - 00792064 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll 2016-01-13 14:59 - 2015-11-16 23:08 - 00705536 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll 2016-01-13 14:59 - 2015-11-16 23:08 - 00505856 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll 2016-01-13 14:59 - 2015-11-16 23:08 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll 2016-01-13 14:59 - 2015-11-16 18:17 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll 2016-01-10 21:34 - 2016-01-10 21:34 - 00049426 _____ C:\Users\Debora\Downloads\sophia silva 5759.pdf 2016-01-10 21:30 - 2016-01-10 21:30 - 00049445 _____ C:\Users\Debora\Downloads\laura silva 5758.pdf 2016-01-10 21:24 - 2016-01-10 21:24 - 00000000 ____D C:\ProgramData\Adobe 2016-01-06 14:16 - 2016-01-27 11:18 - 00000000 ____D C:\Riot Games 2016-01-04 12:22 - 2016-01-04 12:23 - 08972080 _____ C:\Users\Debora\Downloads\TX115_x64_660APS_C1.exe ==================== Um Mês Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-02-02 10:03 - 2013-09-22 18:34 - 00000902 _____ C:\windows\Tasks\Adobe Flash Player Updater.job 2016-02-02 09:57 - 2013-10-07 16:57 - 00000296 _____ C:\windows\Tasks\UpdaterEX.job 2016-02-02 09:53 - 2013-02-09 18:06 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Skype 2016-02-02 09:43 - 2014-03-31 15:43 - 00000304 _____ C:\windows\Tasks\PriceMeterUpdater.job 2016-02-02 09:23 - 2015-11-05 12:02 - 00001070 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-02-02 09:22 - 2015-11-05 12:02 - 00001066 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-02-02 09:22 - 2009-07-14 02:45 - 00028848 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-02-02 09:22 - 2009-07-14 02:45 - 00028848 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-02-02 09:17 - 2015-11-05 12:02 - 00004066 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA 2016-02-02 09:17 - 2015-11-05 12:02 - 00003814 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore 2016-02-02 09:11 - 2015-08-16 23:16 - 00002218 ____R C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-02-02 09:11 - 2015-08-16 23:16 - 00002189 ____R C:\Users\Public\Desktop\Google Chrome.lnk 2016-02-02 09:11 - 2015-06-19 13:51 - 00001167 ____R C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2016-02-02 09:06 - 2015-12-03 10:44 - 00000310 _____ C:\windows\Tasks\{5D559149-4358-4190-9CDA-25E643AA09DB}.job 2016-02-02 09:06 - 2015-08-03 12:27 - 00000660 _____ C:\windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job 2016-02-02 09:06 - 2015-07-24 19:24 - 00000912 _____ C:\windows\Tasks\globalUpdateUpdateTaskMachineCore.job 2016-02-02 09:05 - 2015-01-26 22:00 - 00000000 ____D C:\Program Files (x86)\GbPlugin 2016-02-02 09:05 - 2009-07-14 03:08 - 00000006 ____H C:\windows\Tasks\SA.DAT 2016-02-01 13:11 - 2015-09-22 12:21 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Andy 2016-02-01 12:30 - 2012-08-11 13:16 - 00000000 ____D C:\Users\Debora 2016-02-01 12:29 - 2015-07-24 19:24 - 00000916 _____ C:\windows\Tasks\globalUpdateUpdateTaskMachineUA.job 2016-02-01 12:24 - 2012-12-12 14:31 - 01662164 _____ C:\windows\SysWOW64\PerfStringBackup.INI 2016-02-01 12:24 - 2012-02-02 20:59 - 00711650 _____ C:\windows\system32\prfh0416.dat 2016-02-01 12:24 - 2012-02-02 20:59 - 00149956 _____ C:\windows\system32\prfc0416.dat 2016-02-01 12:24 - 2009-07-14 01:20 - 00000000 ____D C:\windows\inf 2016-02-01 11:24 - 2015-08-06 20:24 - 00000266 _____ C:\windows\Tasks\{6A128791-4857-4484-9BB2-71D4C1257200}.job 2016-02-01 10:26 - 2012-09-13 23:27 - 00000000 ____D C:\Users\Debora\AppData\Local\CrashDumps 2016-02-01 09:24 - 2013-07-05 16:20 - 00003930 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{7F4467AA-F429-4B21-A5B8-97BCC51FEDEF} 2016-02-01 09:22 - 2009-07-14 03:13 - 01643790 _____ C:\windows\system32\PerfStringBackup.INI 2016-01-29 11:13 - 2014-05-12 22:35 - 00000000 ____D C:\windows\pss 2016-01-29 10:31 - 2012-10-15 00:09 - 00000000 ____D C:\Positivo 2016-01-29 10:27 - 2012-09-19 14:40 - 00000000 ____D C:\Users\Debora\AppData\LocalLow\Scpad 2016-01-29 10:17 - 2014-07-19 01:13 - 00000000 ____D C:\Users\Debora\AppData\Local\Adobe 2016-01-27 10:16 - 2015-09-25 09:33 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windroy 2016-01-27 10:16 - 2013-10-09 13:44 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard 2016-01-27 10:03 - 2012-08-11 13:42 - 00001577 _____ C:\Users\Debora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-01-27 09:55 - 2009-07-14 02:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-01-27 09:51 - 2015-08-15 10:45 - 00000492 _____ C:\Users\Debora\Downloads\Desktop.lnk 2016-01-27 09:51 - 2009-07-14 03:09 - 00000000 ____D C:\windows\System32\Tasks\WPD 2016-01-25 18:33 - 2009-07-14 01:20 - 00000000 ____D C:\windows\SysWOW64\com 2016-01-25 18:33 - 2009-07-14 01:20 - 00000000 ____D C:\windows\system32\oobe 2016-01-25 18:33 - 2009-07-14 01:20 - 00000000 ____D C:\windows\system32\com 2016-01-25 18:05 - 2012-09-19 14:40 - 00000000 ____D C:\Program Files (x86)\Scpad 2016-01-25 18:05 - 2009-07-14 01:20 - 00000000 ____D C:\windows\registration 2016-01-25 16:47 - 2015-12-04 10:33 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Trove 2016-01-25 16:42 - 2015-12-09 08:59 - 00000000 ____D C:\ProgramData\7WdM7 2016-01-25 14:50 - 2013-02-19 21:42 - 00000000 ____D C:\Users\Debora\AppData\Roaming\AnySend 2016-01-25 14:50 - 2013-02-19 21:42 - 00000000 ____D C:\ProgramData\AnySend 2016-01-25 14:33 - 2015-08-09 18:45 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Steam 2016-01-25 14:33 - 2015-08-05 10:30 - 00000000 ____D C:\Users\Debora\AppData\Local\Steam 2016-01-25 13:31 - 2012-02-02 05:09 - 00357888 _____ (Microsoft Corporation) C:\windows\system32\dnsapi.dll 2016-01-25 13:31 - 2012-02-02 05:09 - 00270336 _____ (Microsoft Corporation) C:\windows\SysWOW64\dnsapi.dll 2016-01-25 12:40 - 2015-08-15 17:27 - 05116136 _____ C:\windows\system32\FNTCACHE.DAT 2016-01-25 12:38 - 2015-12-18 12:52 - 00539676 _____ C:\windows\ntbtlog.txt 2016-01-25 12:08 - 2013-12-15 14:14 - 00000433 _____ C:\windows\system32\Drivers\etc\hosts.ics 2016-01-21 16:53 - 2015-10-01 12:46 - 00000000 ____D C:\Users\Debora\Downloads\musicas 2016-01-21 16:40 - 2015-12-01 12:09 - 00000000 ____D C:\Users\Debora\Downloads\amv 2016-01-21 10:04 - 2013-09-22 18:34 - 00003840 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater 2016-01-21 10:04 - 2012-08-22 23:09 - 00796864 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe 2016-01-21 10:04 - 2012-08-22 23:09 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-01-21 10:03 - 2015-12-28 18:03 - 04499648 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe 2016-01-18 13:07 - 2016-01-01 20:28 - 00000000 ____D C:\Users\Debora\Downloads\TazerCraft Rig 2016-01-18 10:36 - 2015-12-22 16:09 - 00000000 ____D C:\Users\Debora\Downloads\page 2016-01-18 08:51 - 2013-03-15 23:49 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2016-01-18 08:51 - 2013-03-15 23:49 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2016-01-17 17:19 - 2015-11-12 22:01 - 00000000 ____D C:\Users\Debora\Downloads\illum 2016-01-17 13:51 - 2013-03-15 23:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight 2016-01-15 14:10 - 2015-12-04 16:47 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-01-15 09:10 - 2014-12-15 16:27 - 00000000 ____D C:\windows\system32\appraiser 2016-01-15 09:10 - 2014-05-13 00:09 - 00000000 ___SD C:\windows\system32\CompatTel 2016-01-14 17:54 - 2013-08-19 17:32 - 00000000 ____D C:\windows\system32\MRT 2016-01-14 17:54 - 2012-11-04 13:35 - 143671360 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2016-01-14 17:50 - 2009-07-14 00:34 - 00000606 _____ C:\windows\win.ini 2016-01-14 11:13 - 2015-09-24 11:49 - 00000074 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat 2016-01-06 14:17 - 2015-08-03 09:27 - 00000000 ____D C:\Users\Debora\AppData\Roaming\Riot Games ==================== Arquivos na raiz de alguns diretórios ======= 2015-07-29 23:07 - 2015-07-29 23:07 - 0000079 _____ () C:\Program Files (x86)\prefs.js 2016-01-27 09:53 - 2016-01-27 09:50 - 2989680 _____ () C:\Users\Debora\AppData\Roaming\8ec3f2c77d1f.exe 2016-01-27 09:54 - 2015-12-10 08:39 - 1015808 _____ (d) C:\Users\Debora\AppData\Roaming\download.exe 2016-01-27 09:53 - 2015-11-25 15:31 - 1100288 _____ () C:\Users\Debora\AppData\Roaming\HomePage.exe 2016-01-27 09:54 - 2016-01-27 09:54 - 0621568 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Debora\AppData\Roaming\libeay32.dll 2016-01-27 09:54 - 2015-12-04 13:14 - 1081344 _____ () C:\Users\Debora\AppData\Roaming\LightGate.exe 2005-10-31 17:12 - 2015-11-25 17:34 - 0032805 ____H () C:\Users\Debora\AppData\Roaming\logs.dat 2016-01-27 09:51 - 2016-01-26 11:54 - 2415616 _____ () C:\Users\Debora\AppData\Roaming\msiql.exe 2016-01-01 20:27 - 2016-01-01 20:27 - 0000132 _____ () C:\Users\Debora\AppData\Roaming\Preferências do Formato PNG do Adobe CS6 2016-01-27 09:51 - 2016-01-11 15:49 - 1734656 _____ () C:\Users\Debora\AppData\Roaming\service.exe 2016-01-27 09:54 - 2016-01-27 09:54 - 0162304 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Debora\AppData\Roaming\ssleay32.dll 2016-01-27 09:51 - 2016-01-27 09:52 - 2786816 _____ (TODO: ) C:\Users\Debora\AppData\Roaming\svrupg.exe 2016-01-27 09:51 - 2016-01-27 09:51 - 0008643 _____ () C:\Users\Debora\AppData\Roaming\webad.xml 2016-01-27 09:52 - 2015-11-14 21:06 - 2496403 _____ ( ) C:\Users\Debora\AppData\Roaming\yeaplayer_51447.exe 2015-11-18 08:33 - 2015-11-18 08:33 - 0000000 _____ () C:\Users\Debora\AppData\Local\{4C5BC80D-10E0-48BF-AA00-0AC70F7E6597} 2014-10-25 10:55 - 2014-10-25 10:55 - 0000020 _____ () C:\ProgramData\bc.ini 2014-01-15 03:15 - 2014-01-15 03:15 - 0167784 _____ (Baidu, Inc.) C:\ProgramData\FileSplitUpLoad.dll 2016-01-27 09:53 - 2015-11-25 15:31 - 1100288 _____ () C:\ProgramData\HomePage.exe 2016-01-27 09:51 - 2015-12-04 13:14 - 1081344 _____ () C:\ProgramData\LightGate.exe 2016-01-27 09:51 - 2016-01-26 11:54 - 2415616 _____ () C:\ProgramData\msiql.exe 2016-01-27 09:51 - 2016-01-11 15:49 - 1734656 _____ () C:\ProgramData\service.exe 2016-01-27 09:54 - 2016-01-27 09:54 - 1736192 _____ () C:\ProgramData\upgsvr.exe 2016-01-27 09:51 - 2016-02-02 09:07 - 0009441 _____ () C:\ProgramData\webad.xml 2016-01-27 09:52 - 2015-12-10 15:43 - 0600312 _____ () C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe 2012-02-02 06:09 - 2012-02-02 06:09 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log 2015-09-24 11:49 - 2016-01-14 11:13 - 0000074 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat 2012-02-02 06:00 - 2012-02-02 06:01 - 0000113 _____ () C:\ProgramData\{34FBC7C4-CD31-4D93-A428-0E524EAC4586}.log 2012-02-02 06:06 - 2012-02-02 06:06 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2012-02-02 06:01 - 2012-02-02 06:05 - 0000106 _____ () C:\ProgramData\{80E158EA-7181-40FE-A701-301CE6BE64AB}.log 2012-02-02 06:07 - 2012-02-02 06:09 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log Arquivos para serem movidos ou deletados: ==================== C:\ProgramData\FileSplitUpLoad.dll C:\ProgramData\HomePage.exe C:\ProgramData\LightGate.exe C:\ProgramData\msiql.exe C:\ProgramData\service.exe C:\ProgramData\upgsvr.exe C:\ProgramData\YeaPlayer_br_IBD_Bundle.exe C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat C:\Windows\Tasks\{2A6A6C0A-6DF1-4478-807F-2FF9BF46B935}.job C:\Windows\Tasks\{5D559149-4358-4190-9CDA-25E643AA09DB}.job C:\Windows\Tasks\{6A128791-4857-4484-9BB2-71D4C1257200}.job Alguns arquivos em TEMP: ==================== C:\Users\Debora\AppData\Local\Temp\tasklisten.exe ==================== Bamital & volsnap ================= (Não há correção automática para arquivos que não passaram na verificação.) C:\windows\system32\winlogon.exe => O arquivo é assinado digitalmente C:\windows\system32\wininit.exe => O arquivo é assinado digitalmente C:\windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente C:\windows\explorer.exe => O arquivo é assinado digitalmente C:\windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente C:\windows\system32\svchost.exe => O arquivo é assinado digitalmente C:\windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente C:\windows\system32\services.exe => O arquivo é assinado digitalmente C:\windows\system32\User32.dll => O arquivo é assinado digitalmente C:\windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente C:\windows\system32\userinit.exe => O arquivo é assinado digitalmente C:\windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente C:\windows\system32\rpcss.dll => O arquivo é assinado digitalmente C:\windows\system32\dnsapi.dll => O arquivo é assinado digitalmente C:\windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente C:\windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente LastRegBack: 2016-01-29 13:58 ==================== Fim de FRST.txt ============================