Resultado do exame Adicional Farbar Recovery Scan Tool (x86) Versão:03-06-2016 Executado por Dani (2016-06-04 08:13:56) Executando a partir de C:\Users\Dani\Desktop Microsoft Windows 10 Pro (X86) (2016-02-22 19:06:38) Modo da Inicialização: Normal ========================================================== ==================== Contas: ============================= Administrador (S-1-5-21-727165953-1638059719-37826139-500 - Administrator - Disabled) Convidado (S-1-5-21-727165953-1638059719-37826139-501 - Limited - Disabled) Dani (S-1-5-21-727165953-1638059719-37826139-1000 - Administrator - Enabled) => C:\Users\Dani DefaultAccount (S-1-5-21-727165953-1638059719-37826139-503 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-727165953-1638059719-37826139-1002 - Limited - Enabled) ==================== Central de Segurança ======================== (Se uma entrada for incluída na fixlist, será removida.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Programas Instalados ====================== (Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.) µTorrent (HKU\S-1-5-21-727165953-1638059719-37826139-1000\...\uTorrent) (Version: 3.4.7.42330 - BitTorrent Inc.) Adobe Acrobat Reader DC - Português (HKLM\...\{AC76BA86-7AD7-1046-7B44-AC0F074E4100}) (Version: 15.016.20045 - Adobe Systems Incorporated) Adobe Photoshop 7.0 (HKLM\...\Adobe Photoshop 7.0) (Version: 7.0 - Adobe Systems, Inc.) Advanced Calendar 2.0.0.11356 (HKLM\...\{D9BAB2C9-5236-48c3-AF02-67E799F09BBD}) (Version: 2.0.0.11356 - MEIXIAN XIE) <==== ATENÇÃO Atualização do produto Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0416-0000-0000000FF1CE}_ENTERPRISE_{717C9095-8AAE-41CB-B046-BD6E8399F4F3}) (Version: - Microsoft) Atualização do produto Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0416-0000-0000000FF1CE}_ENTERPRISE_{5016CB22-B9A7-44FB-AA72-AF28B27B15EA}) (Version: - Microsoft) Atualização do produto Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0416-0000-0000000FF1CE}_ENTERPRISE_{BE3A7C0C-0081-4694-B5F9-980DD66BDDF8}) (Version: - Microsoft) Atualização do produto Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0416-0000-0000000FF1CE}_ENTERPRISE_{7297E3A9-FCD4-4E0E-A306-7A90359E50E3}) (Version: - Microsoft) Google Chrome (HKLM\...\Google Chrome) (Version: 50.0.2661.102 - Google Inc.) Google Update Helper (Version: 1.3.30.3 - Google Inc.) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) MPC-HC 1.7.10 (HKLM\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.7.10 - MPC-HC Team) Popcorn Time (HKLM\...\Popcorn Time_is1) (Version: 5.4.1.0 - Popcorn Time) <==== ATENÇÃO Popcorn Time (HKLM\...\Popcorn-Time) (Version: 0.3.2 - Popcorn Official) <==== ATENÇÃO Skype™ 7.18 (HKLM\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 14.0.6.0 - Synaptics Incorporated) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) ==================== Exame Personalizado CLSID (Whitelisted): ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) CustomCLSID: HKU\S-1-5-21-727165953-1638059719-37826139-1000_Classes\CLSID\{034DF736-A378-4292-ACAE-A561088999F5}\InprocServer32 -> C:\Users\Dani\AppData\Local\PPTAssist\pptassist.dll (珠海金山办公软件有限公司) CustomCLSID: HKU\S-1-5-21-727165953-1638059719-37826139-1000_Classes\CLSID\{1077138E-896C-445E-BD31-CFCFFA4636C4}\InprocServer32 -> C:\Users\Dani\AppData\Local\PPTAssist\pptassist.dll (珠海金山办公软件有限公司) CustomCLSID: HKU\S-1-5-21-727165953-1638059719-37826139-1000_Classes\CLSID\{C4917602-2AC8-4ECE-8E5D-390C3871ABB3}\InprocServer32 -> C:\Users\Dani\AppData\Local\PPTAssist\tabassist.dll (珠海金山办公软件有限公司) CustomCLSID: HKU\S-1-5-21-727165953-1638059719-37826139-1000_Classes\CLSID\{E00310B2-F036-4771-9347-C131257D990F}\InprocServer32 -> C:\Users\Dani\AppData\Local\PPTAssist\tabassist.dll (珠海金山办公软件有限公司) ==================== Tarefas Agendadas (Whitelisted) ============= (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) Task: {07F7EF55-0EC2-4B84-AE6D-23520CEE3656} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-03-16] (Google Inc.) Task: {10FBC798-F20D-428F-B295-E614BEEA937D} - System32\Tasks\{DD2A00A7-6155-4277-BB53-EE39396B6133} => launchwinapp.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=7.18.0.112&LastError=12002 Task: {1A62B2BD-D0B7-4EC4-946E-BD02F5518E11} - System32\Tasks\PPTAssistantUpdateTask_SISTEMA => C:\WINDOWS\system32\config\systemprofile\AppData\Local\PPTAssist\assistupdate.exe [2016-06-02] (Zhuhai Kingsoft Office Software Co.,Ltd) Task: {4A2BF415-4AA6-4FAD-806D-B78CA26BF27E} - System32\Tasks\UCBrowserUpdater => C:\Program Files\UCBrowser\Application\update_task.exe Task: {67A4ADF6-B1D0-45AB-9320-8CBB5EAB9B5B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-04-22] (Adobe Systems Incorporated) Task: {6E402B89-5363-48C7-A0CA-193FE38B1A4F} - System32\Tasks\osTip => C:\ProgramData\WindowsMsg\osmsg.exe [2016-06-01] () Task: {83B960B1-8DC9-4A73-9B10-F51EC3F90792} - System32\Tasks\Ateredomkefisp Cache => C:\Program Files\Ateredomkefisp\AteredomkefispCchtask.exe <==== ATENÇÃO Task: {888FCEB7-356D-435D-BF54-421090A5E47F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-03-16] (Google Inc.) Task: {A6265210-ED06-496F-AE2F-3858C16969AF} - System32\Tasks\ttwifi => C:\Program Files\ttwifi\tiantianwifi.exe Task: {FE1E4E30-9239-4823-BB73-14EE762D9742} - System32\Tasks\PPTAssistantNotifyTask_Dani => C:\Users\Dani\AppData\Local\PPTAssist\notify.exe [2016-06-03] (珠海金山办公软件有限公司) (Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.) Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\PPTAssistantNotifyTask_Dani.job => C:\Users\Dani\AppData\Local\PPTAssist\notify.exe Task: C:\WINDOWS\Tasks\PPTAssistantUpdateTask_SISTEMA.job => C:\WINDOWS\system32\config\systemprofile\AppData\Local\PPTAssist\assistupdate.exe Task: C:\WINDOWS\Tasks\UCBrowserUpdater.job => C:\Program Files\UCBrowser\Application\update_task.exe ==================== Atalhos ============================= (As entradas podem ser listadas para serem restauradas ou removidas.) WMI_ActiveScriptEventConsumer_ASEC: <===== ATENÇÃO (yeabests) ShortcutWithArgument: C:\Users\Dani\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> "hxxp://trustedsurf.com/?ssid=1464809492&a=1003679&src=sh&uuid=a03644ae-93fb-4fbc-89c8-86cd5a706181" ShortcutWithArgument: C:\Users\Dani\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://yeabests.cc ShortcutWithArgument: C:\Users\Dani\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://yeabests.cc ShortcutWithArgument: C:\Users\Dani\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> hxxp://yeabests.cc ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://yeabests.cc ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://yeabests.cc ==================== Módulos Carregados (Whitelisted) ============== 2015-09-16 08:21 - 2015-09-16 08:21 - 00025088 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll 2015-09-16 08:21 - 2015-09-16 08:21 - 00284672 _____ () C:\WINDOWS\System32\diagtrack_win.dll 2016-05-10 04:27 - 2016-05-10 04:27 - 00152200 _____ () C:\Program Files\CalendarTool\2.0.0.11356\CalendarServ.exe 2016-05-10 04:25 - 2016-05-10 04:25 - 00543368 _____ () C:\Program Files\CalendarTool\2.0.0.11356\EVPTask.dll 2016-05-10 04:24 - 2016-05-10 04:24 - 00406664 _____ () C:\Program Files\CalendarTool\2.0.0.11356\EVPNet.dll 2016-05-10 04:23 - 2016-05-10 04:23 - 00428680 _____ () C:\Program Files\CalendarTool\2.0.0.11356\EVPDR.dll 2016-04-14 12:06 - 2016-03-16 01:21 - 01767000 _____ () C:\WINDOWS\system32\CoreUIComponents.dll 2016-05-10 04:15 - 2016-05-10 04:15 - 02249864 _____ () C:\Program Files\CalendarTool\2.0.0.11356\Calendar.exe 2016-05-10 04:16 - 2016-05-10 04:16 - 00128648 _____ () C:\Program Files\CalendarTool\2.0.0.11356\CalendarEntry.dll 2016-04-14 12:06 - 2016-03-16 01:21 - 01767000 _____ () C:\WINDOWS\System32\CoreUIComponents.dll 2015-07-10 05:24 - 2015-07-10 05:24 - 00288768 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll 2012-11-26 23:54 - 2012-11-26 23:54 - 00094208 _____ () C:\Windows\System32\IccLibDll.dll 2016-04-12 13:43 - 2016-04-12 13:43 - 04621824 _____ () C:\Users\Dani\AppData\Roaming\cpuminer\cpm.exe 2016-06-01 18:23 - 2016-06-01 22:48 - 01920000 _____ () C:\ProgramData\msiql.exe 2016-05-16 13:01 - 2016-05-11 08:48 - 01738904 _____ () C:\Program Files\Google\Chrome\Application\50.0.2661.102\libglesv2.dll 2016-05-16 13:01 - 2016-05-11 08:48 - 00086168 _____ () C:\Program Files\Google\Chrome\Application\50.0.2661.102\libegl.dll 2015-12-10 23:18 - 2015-11-25 01:01 - 04317696 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2015-12-10 23:18 - 2015-11-25 00:58 - 00377856 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2015-12-10 23:18 - 2015-11-25 00:59 - 01183232 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2015-10-01 09:21 - 2015-09-17 02:26 - 01425920 _____ () C:\WINDOWS\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll ==================== Alternate Data Streams (Whitelisted) ========= (Se uma entrada for incluída na fixlist, somente o ADS será removido.) ==================== Modo de Segurança (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O valor "AlternateShell" será restaurado.) ==================== Associação (Whitelisted) =============== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido.) ==================== Internet Explorer confiável/restrito =============== (Se uma entrada for incluída na fixlist, será removida do Registro.) ==================== Hosts Conteúdo: ========================== (Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.) 2016-02-22 15:27 - 2016-06-01 16:31 - 00001006 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 down.baidu2016.com 127.0.0.1 123.sogou.com 127.0.0.1 www.czzsyzgm.com 127.0.0.1 www.czzsyzxl.com 127.0.0.1 union.baidu2019.com ==================== Outras Áreas ============================ (Atualmente não há nenhuma correção automática para esta seção.) HKU\S-1-5-21-727165953-1638059719-37826139-1000\Control Panel\Desktop\\Wallpaper -> c:\users\dani\appdata\local\microsoft\windows\themes\br-wp6.jpg DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Firewall do Windows está desabilitado. ==================== MSCONFIG/TASK MANAGER ítens desabilitados == (Atualmente não há nenhuma correção automática para esta seção.) HKU\S-1-5-21-727165953-1638059719-37826139-1000\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-727165953-1638059719-37826139-1000\...\StartupApproved\Run: => "Skype" ==================== Regras do Firewall (Whitelisted) =============== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{C6D4B8B1-3659-40FF-89BE-6261D275A250}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe FirewallRules: [{D2D10048-7CE3-4301-A7CA-1DF366986724}] => (Allow) C:\Users\Dani\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{564D8510-9251-4F8B-8D8F-4A9281C90301}] => (Allow) C:\Users\Dani\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{C710AC68-EA9A-4BA0-A229-3CD0FBE12664}] => (Allow) C:\Users\Dani\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{92689BBA-A3AD-4C30-8E0D-F7B760F2D089}] => (Allow) C:\Users\Dani\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{20A94E4B-C887-48E8-B56D-AF3F8E4FEC8E}] => (Allow) C:\Users\Dani\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{3BD2EDDD-6A3D-4D54-87ED-0006C426C977}] => (Allow) C:\Users\Dani\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{F40B9189-6773-4605-BBD2-6432CBD42BA3}] => (Allow) C:\Program Files\Popcorn Time\Updater.exe FirewallRules: [{CF29F2B2-D646-4535-9841-FFE9D4BF7FA2}] => (Allow) C:\Program Files\Popcorn Time\Updater.exe FirewallRules: [{32C22CD4-9336-4F3A-BD76-2398E3404F22}] => (Allow) C:\Program Files\Popcorn Time\PopcornTimeDesktop.exe FirewallRules: [{7E846270-78A6-4359-BCCB-37787195CFC3}] => (Allow) C:\Program Files\Popcorn Time\PopcornTimeDesktop.exe FirewallRules: [{7ED5D4CE-3DC7-4427-AD6A-F3885E3FF97A}] => (Allow) C:\Program Files\Popcorn Time\chromecast\node.exe FirewallRules: [{BA9BA9C2-53F7-4F86-8AE5-0E47F14F604E}] => (Allow) C:\Program Files\Popcorn Time\chromecast\node.exe FirewallRules: [{59F1A0D3-EBBA-47CD-9370-C973B915FC2A}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe FirewallRules: [{BEABA3D0-9408-44BD-9F22-C0F470E6CA5D}] => (Allow) C:\Program Files\Max Driver Updater\maxdu.exe FirewallRules: [{D96C5760-C301-40C9-8BC4-57B526654746}] => (Allow) C:\Program Files\SrpnFiles\SrpnFiles.exe FirewallRules: [{15B52518-697A-4CA3-99CC-1847DC9A195E}] => (Allow) C:\Program Files\SrpnFiles\SrpnFiles.exe FirewallRules: [{D679DBD3-2495-4766-9BBD-92DDEB6041BD}] => (Allow) C:\Program Files\SrpnFiles\downloader.exe FirewallRules: [{9A3EDF85-C9B0-4498-8415-E310BBE6A29D}] => (Allow) C:\Program Files\SrpnFiles\downloader.exe FirewallRules: [{2A8D6935-5704-4E72-89FD-DA3363731C1C}] => (Allow) C:\Program Files\ADSKIP\ADSkipSvc.exe FirewallRules: [{DE25D73F-0221-4973-B6AC-3370E10B537B}] => (Allow) C:\Program Files\ADSKIP\ADSkip.exe FirewallRules: [{31E06F9E-4287-4A49-A16E-140040DF538E}] => (Allow) C:\Program Files\ADSKIP\ADSkipSvc.exe FirewallRules: [{41B71431-1199-44D6-9978-8D698F282116}] => (Allow) C:\Program Files\ADSKIP\ADSkip.exe FirewallRules: [{FB398094-9F41-4018-B63D-77CF79934B87}] => (Allow) C:\Program Files\ADSKIP\ADSkip.exe FirewallRules: [{13518370-EB71-43CA-BC48-34E4FE923711}] => (Allow) C:\Program Files\ADSKIP\ADSkipSvc.exe FirewallRules: [{2EAC75B8-2FC5-46F9-BEE3-841B0E4ABAF6}] => (Allow) C:\Users\Dani\Desktop\FRST.exe FirewallRules: [{C040358C-88B5-440B-8994-A92A7412A887}] => (Allow) C:\Users\Dani\Desktop\FRST.exe FirewallRules: [{F3295E40-BCC3-4030-9678-110121926509}] => (Allow) C:\Users\Dani\Desktop\FRST.exe FirewallRules: [{7722BB7D-3F75-4B16-950E-99EDC0BE0396}] => (Allow) C:\Users\Dani\Desktop\FRST.exe FirewallRules: [{8F90D3C5-5654-4241-89D4-17F95F76055F}] => (Allow) C:\Program Files\ADSKIP\ADSkip.exe FirewallRules: [{CCF6A671-3EC6-47E9-9114-F973B5766F87}] => (Allow) C:\Program Files\ADSKIP\ADSkip.exe FirewallRules: [{A37A3C1A-7443-4F58-8C49-B13C607F1BC9}] => (Allow) C:\Program Files\ADSKIP\ADSkip.exe FirewallRules: [{1EEB0ED3-DA82-4FF4-9019-C3F45ACF3060}] => (Allow) C:\Program Files\ADSKIP\ADSkipSvc.exe FirewallRules: [{C809A31A-45F4-4B24-881F-18EAC878670B}] => (Allow) C:\Program Files\ADSKIP\ADSkipSvc.exe FirewallRules: [{15739738-DE8E-49FD-9872-56856835B0F4}] => (Allow) C:\Program Files\ADSKIP\ADSkipSvc.exe ==================== Pontos de Restauração ========================= 02-05-2016 13:35:41 Ponto de Verificação Agendado 21-05-2016 08:45:46 Ponto de Verificação Agendado 25-05-2016 15:52:29 Windows Update 01-06-2016 16:40:26 Removed Skype Click to Call ==================== Dispositivos Apresentando Falhas No Gerenciador ============= ==================== Erros no Log de eventos: ========================= Erros em Aplicativos: ================== Error: (06/04/2016 08:09:26 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DANI-PC) Description: Falha na ativação do aplicativo 62632UNETA.492836F161CC8_rmspfwnbz040j!App com o erro: -2144927148. Veja o log Microsoft-Windows-TWinUI/Operational para obter informações adicionais. Error: (06/04/2016 07:54:36 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DANI-PC) Description: Falha na ativação do aplicativo 62632UNETA.492836F161CC8_rmspfwnbz040j!App com o erro: -2144927148. Veja o log Microsoft-Windows-TWinUI/Operational para obter informações adicionais. Error: (06/04/2016 07:44:52 AM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost (5204) Não é possível criar um novo arquivo de log porque o banco de dados não pode gravar na unidade de log. Talvez a unidade seja somente leitura, tenha espaço em disco insuficiente, esteja mal configurada ou esteja corrompida. Erro -1032. Error: (06/04/2016 07:44:52 AM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost (5204) Uma tentativa de criar o arquivo "C:\WINDOWS\system32\edbtmp.log" falhou com o erro de sistema 5 (0x00000005): "Acesso negado. ". A operação para criar o arquivo falhará com o erro -1032 (0xfffffbf8). Error: (06/04/2016 07:44:42 AM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost (5204) Não é possível criar um novo arquivo de log porque o banco de dados não pode gravar na unidade de log. Talvez a unidade seja somente leitura, tenha espaço em disco insuficiente, esteja mal configurada ou esteja corrompida. Erro -1032. Error: (06/04/2016 07:44:42 AM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost (5204) Uma tentativa de criar o arquivo "C:\WINDOWS\system32\edbtmp.log" falhou com o erro de sistema 5 (0x00000005): "Acesso negado. ". A operação para criar o arquivo falhará com o erro -1032 (0xfffffbf8). Error: (06/04/2016 07:44:32 AM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost (5204) Não é possível criar um novo arquivo de log porque o banco de dados não pode gravar na unidade de log. Talvez a unidade seja somente leitura, tenha espaço em disco insuficiente, esteja mal configurada ou esteja corrompida. Erro -1032. Error: (06/04/2016 07:44:32 AM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost (5204) Uma tentativa de criar o arquivo "C:\WINDOWS\system32\edbtmp.log" falhou com o erro de sistema 5 (0x00000005): "Acesso negado. ". A operação para criar o arquivo falhará com o erro -1032 (0xfffffbf8). Error: (06/04/2016 07:44:21 AM) (Source: ESENT) (EventID: 413) (User: ) Description: SettingSyncHost (5204) Não é possível criar um novo arquivo de log porque o banco de dados não pode gravar na unidade de log. Talvez a unidade seja somente leitura, tenha espaço em disco insuficiente, esteja mal configurada ou esteja corrompida. Erro -1032. Error: (06/04/2016 07:44:21 AM) (Source: ESENT) (EventID: 488) (User: ) Description: SettingSyncHost (5204) Uma tentativa de criar o arquivo "C:\WINDOWS\system32\edbtmp.log" falhou com o erro de sistema 5 (0x00000005): "Acesso negado. ". A operação para criar o arquivo falhará com o erro -1032 (0xfffffbf8). Erros de Sistema: ============= Error: (06/04/2016 07:41:58 AM) (Source: DCOM) (EventID: 10016) (User: AUTORIDADE NT) Description: específico do aplicativoLocalAtivação{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}AUTORIDADE NTSERVIÇO LOCALS-1-5-19LocalHost (Usando LRPC)Não DisponívelNão Disponível Error: (06/04/2016 07:39:47 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Reservation Plastic devido ao seguinte erro: %%2 Error: (06/04/2016 07:39:47 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Start Menu Reverse devido ao seguinte erro: %%2 Error: (06/04/2016 07:39:46 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Renew Single Click devido ao seguinte erro: %%2 Error: (06/03/2016 10:49:33 PM) (Source: Microsoft-Windows-HAL) (EventID: 13) (User: AUTORIDADE NT) Description: O temporizador watchdog do sistema foi disparado. Error: (06/03/2016 10:49:53 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: O desligamento do sistema que ocorreu às 22:43:37 do dia ‎03/‎06/‎2016 não era esperado. Error: (06/03/2016 10:43:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Start Menu Reverse devido ao seguinte erro: %%2 Error: (06/03/2016 10:43:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Reservation Plastic devido ao seguinte erro: %%2 Error: (06/03/2016 10:43:47 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Renew Single Click devido ao seguinte erro: %%2 Error: (06/03/2016 10:43:18 PM) (Source: Microsoft-Windows-HAL) (EventID: 13) (User: AUTORIDADE NT) Description: O temporizador watchdog do sistema foi disparado. CodeIntegrity: =================================== Date: 2016-06-03 21:45:46.722 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-05-30 10:21:37.135 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-05-22 11:43:37.111 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-04-30 20:09:20.603 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-04-27 23:31:50.990 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-04-25 20:02:43.315 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-04-24 01:34:47.858 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-04-22 01:47:22.373 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-04-20 17:51:28.621 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2016-04-19 11:47:22.887 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Informações da Memória =========================== Processador: Intel(R) Core(TM) i3 CPU M 350 @ 2.27GHz Percentagem de memória em uso: 49% RAM física total: 2870.76 MB RAM física disponível: 1458.19 MB Virtual Total: 3574.76 MB Virtual disponível: 2133.23 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:179.86 GB) (Free:14.73 GB) NTFS ==================== MBR & Tabela de Partições ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 2137B94E) Partition 1: (Not Active) - (Size=12 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=179.9 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=106.1 GB) - (Type=05) ==================== Fim de Addition.txt ============================