Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 01-03-2017 Executado por Gustavo (administrador) em GUSTAVO-PC (01-03-2017 15:10:40) Executando a partir de C:\Users\Gustavo\Downloads Perfis Carregados: Gustavo (Perfis Disponíveis: Gustavo) Platform: Windows 7 Home Basic Service Pack 1 (X64) Idioma: Português (Brasil) Internet Explorer Versão 8 (Navegador padrão: Chrome) Modo da Inicialização: Normal Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe (SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe (Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe (Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe (Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe (Microsoft Corporation) C:\Windows\System32\wusa.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registro (Whitelisted) ==================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13874392 1999-12-31] (Realtek Semiconductor) HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-12-21] (AVAST Software) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2383040 2016-10-25] (Adobe Systems Incorporated) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-12-21] (AVAST Software) ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Hosts: 127.0.0.1 validation.sls.microsoft.com Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{48A1F945-C8A0-4938-ACEF-CB1656B40049}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKU\S-1-5-21-2291930349-3429565107-474410669-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pt-br/?ocid=iehp BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-12-21] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-12-21] (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-12-21] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-12-21] (AVAST Software) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation) FireFox: ======== FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-12-21] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-12-21] FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-12-21] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-12-21] (Oracle Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-25] (Adobe Systems) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-11-14] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-11-14] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-21] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-21] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-25] (Adobe Systems) Chrome: ======= CHR Profile: C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default [2017-03-01] CHR Extension: (Google Apresentações) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-21] CHR Extension: (Google Docs) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-21] CHR Extension: (Google Drive) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-21] CHR Extension: (YouTube) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-21] CHR Extension: (Adobe Acrobat) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-02-06] CHR Extension: (Planilhas do Google) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-21] CHR Extension: (Documentos Google off-line) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-21] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-25] CHR Extension: (Gmail) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-21] CHR Extension: (Chrome Media Router) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-08] CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Serviços (Whitelisted) ==================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-25] (Adobe Systems Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2207960 2016-09-26] (Adobe Systems, Incorporated) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-12-21] (AVAST Software) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation) R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-12] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2016-12-12] (NVIDIA Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-12-21] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-12-21] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-12-21] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-12-21] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-12-21] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-12-21] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-12-21] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-12-21] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-12-21] (AVAST Software) R0 mv61xx; C:\Windows\System32\DRIVERS\mv61xx.sys [181040 2010-10-26] (Marvell Semiconductor, Inc.) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-12] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-12-12] (NVIDIA Corporation) S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16056 2017-03-01] (SlimWare Utilities, Inc.) ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um Mês Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2017-03-01 15:10 - 2017-03-01 15:10 - 02423808 _____ (Farbar) C:\Users\Gustavo\Downloads\FRST64.exe 2017-03-01 15:10 - 2017-03-01 15:10 - 00014341 _____ C:\Users\Gustavo\Downloads\FRST.txt 2017-03-01 15:10 - 2017-03-01 15:10 - 00000000 ____D C:\FRST 2017-03-01 15:08 - 2017-03-01 15:08 - 32823032 _____ (Tweaking.com) C:\Users\Gustavo\Downloads\tweaking.com_windows_repair_aio_setup.exe 2017-03-01 15:03 - 2017-03-01 15:03 - 00001125 _____ C:\Users\Public\Desktop\DLL-Files.com Client.lnk 2017-03-01 15:03 - 2017-03-01 15:03 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\DLL-files.com 2017-03-01 15:03 - 2017-03-01 15:03 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\DFXCT 2017-03-01 15:03 - 2017-03-01 15:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DLL-Files.com Client 2017-03-01 15:03 - 2017-03-01 15:03 - 00000000 ____D C:\Program Files (x86)\DLL-Files.com Client 2017-03-01 15:02 - 2017-03-01 15:03 - 02729024 _____ (DLL-Files.com Client ) C:\Users\Gustavo\Downloads\clientsetup_fde-0.exe 2017-03-01 14:59 - 2017-03-01 14:59 - 00000000 ___HT C:\Windows\wusa.lock 2017-03-01 14:59 - 2017-03-01 14:59 - 00000000 ____D C:\cbab9155ebff000c3bdc9bee 2017-03-01 14:38 - 2017-03-01 14:38 - 01034556 _____ C:\Users\Gustavo\Downloads\Windows6.1-KB2999226-x64 (3).msu 2017-03-01 14:37 - 2017-03-01 14:37 - 01034556 _____ C:\Users\Gustavo\Downloads\Windows6.1-KB2999226-x64 (2).msu 2017-03-01 14:35 - 2017-03-01 14:35 - 01034556 _____ C:\Users\Gustavo\Downloads\Windows6.1-KB2999226-x64 (1).msu 2017-03-01 12:02 - 2017-03-01 12:02 - 01034556 _____ C:\Users\Gustavo\Downloads\Windows6.1-KB2999226-x64.msu 2017-03-01 12:02 - 2017-03-01 12:02 - 00000000 ____D C:\e141bc0b096d765f02ba 2017-03-01 11:59 - 2017-03-01 14:41 - 00000000 ___RD C:\Users\Gustavo\Creative Cloud Files 2017-03-01 11:59 - 2017-03-01 14:41 - 00000000 ____D C:\Users\Todos os Usuários\boost_interprocess 2017-03-01 11:59 - 2017-03-01 14:41 - 00000000 ____D C:\ProgramData\boost_interprocess 2017-03-01 11:57 - 2017-03-01 11:57 - 00001298 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017 (32 Bit).lnk 2017-03-01 11:40 - 2017-03-01 11:40 - 15068056 _____ (Microsoft Corporation) C:\Users\Gustavo\Downloads\vc_redist.x64 (1).exe 2017-03-01 11:33 - 2017-03-01 11:34 - 14749120 _____ (Microsoft Corporation) C:\Users\Gustavo\Downloads\vc_redist.x64.exe 2017-03-01 11:27 - 2017-03-01 11:57 - 00000000 ____D C:\Users\Gustavo\Documents\Adobe 2017-03-01 11:27 - 2017-03-01 11:51 - 00001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk 2017-03-01 11:23 - 2017-03-01 11:26 - 00000000 ____D C:\Program Files\Common Files\Adobe 2017-03-01 11:23 - 2017-03-01 11:23 - 00000000 ____D C:\Program Files\Adobe 2017-03-01 11:22 - 2017-03-01 11:22 - 00001221 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2017-03-01 11:22 - 2017-03-01 11:22 - 00001209 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2017-03-01 09:44 - 2017-03-01 11:52 - 00000000 ____D C:\Users\Gustavo\Downloads\Adobe Photoshop CC 2017.0.0 (2016.10.12.r.53) Ml_Rus 2017-03-01 09:38 - 2017-03-01 09:38 - 00019358 _____ C:\Users\Gustavo\Downloads\93D58FDD7B1A903514409F962A5D7BC2983AFA74_www.CPturbo.org.torrent 2017-02-28 10:11 - 2017-02-28 10:14 - 00000000 ____D C:\Users\Gustavo\Downloads\Riverdale.S01E05.Chapter.Five.Heart.Of.Darkness.720p.NF.WEBRip.DD5.1.x264-NTb[rarbg] 2017-02-27 04:42 - 2017-02-27 04:42 - 00001756 _____ C:\Users\Gustavo\Downloads\ANA (1).txt 2017-02-27 04:42 - 2017-02-27 04:42 - 00000323 _____ C:\Users\Gustavo\Downloads\recomeço (1).txt 2017-02-27 04:25 - 2017-02-27 04:25 - 00001756 _____ C:\Users\Gustavo\Downloads\ANA.txt 2017-02-27 04:25 - 2017-02-27 04:25 - 00000323 _____ C:\Users\Gustavo\Downloads\recomeço.txt 2017-02-23 22:12 - 2017-02-23 22:12 - 00001293 _____ C:\Users\Gustavo\Desktop\Continuar a Instalação de WinRAR.lnk 2017-02-23 02:07 - 2017-02-28 10:16 - 00000000 ____D C:\Users\Gustavo\Desktop\Riverdale 2017-02-06 18:06 - 2017-02-07 18:09 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2017-02-06 18:06 - 2017-02-06 18:06 - 00000000 ____D C:\Users\Gustavo\AppData\LocalLow\Adobe 2017-02-06 18:05 - 2017-02-23 02:32 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-02-06 18:05 - 2017-02-06 18:05 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2017-02-06 18:04 - 2017-03-01 11:59 - 00000000 ____D C:\Users\Todos os Usuários\Adobe 2017-02-06 18:04 - 2017-03-01 11:59 - 00000000 ____D C:\ProgramData\Adobe 2017-02-06 18:04 - 2017-03-01 11:53 - 00000000 ____D C:\Program Files (x86)\Adobe 2017-02-06 18:03 - 2017-03-01 14:41 - 00000000 ____D C:\Users\Gustavo\AppData\Local\Adobe 2017-02-06 18:02 - 2017-02-06 18:03 - 01844640 _____ (File Lite Fast ) C:\Users\Gustavo\Downloads\Baixaki_adobe-reader_VMoUqf.exe 2017-02-03 01:17 - 2017-03-01 09:42 - 00000000 ____D C:\Users\Gustavo\AppData\LocalLow\uTorrent 2017-02-03 00:49 - 2017-03-01 04:00 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\vlc 2017-02-03 00:48 - 2017-02-03 00:48 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\WinRAR 2017-02-03 00:47 - 2017-02-23 21:31 - 00000000 ____D C:\Users\Gustavo\Desktop\Arrow 2017-02-03 00:47 - 2017-02-23 02:11 - 00000000 ____D C:\Users\Gustavo\Desktop\Flash 2017-02-03 00:13 - 2017-02-03 00:13 - 03342040 _____ C:\Users\Gustavo\Downloads\Baixaki_winrar.exe 2017-02-03 00:13 - 2017-02-03 00:13 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-02-03 00:13 - 2017-02-03 00:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-02-03 00:13 - 2017-02-03 00:13 - 00000000 ____D C:\Program Files (x86)\WinRAR 2017-02-03 00:10 - 2017-02-03 00:10 - 00001066 _____ C:\Users\Public\Desktop\VLC media player.lnk 2017-02-03 00:10 - 2017-02-03 00:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2017-02-03 00:10 - 2017-02-03 00:10 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2017-02-03 00:09 - 2017-02-03 00:09 - 30533688 _____ C:\Users\Gustavo\Downloads\Baixaki_vlc-media-player.exe 2017-02-03 00:09 - 2017-02-03 00:09 - 01798216 _____ ( ) C:\Users\Gustavo\Downloads\Baixaki_winrar_Vc8MLE.exe 2017-02-03 00:08 - 2017-02-03 00:08 - 01798216 _____ ( ) C:\Users\Gustavo\Downloads\Baixaki_vlc-media-player_VeLnBb.exe 2017-02-02 23:50 - 2017-02-02 23:50 - 00002611 _____ C:\Users\Gustavo\Desktop\µTorrent.lnk 2017-02-02 23:50 - 2017-02-02 23:50 - 00002611 _____ C:\Users\Gustavo\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk 2017-02-02 23:50 - 2017-02-02 23:50 - 00000000 ___SD C:\Users\Gustavo\AppData\LocalLow\Temp 2017-02-02 23:49 - 2017-03-01 11:44 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\uTorrent 2017-02-02 23:49 - 2017-02-02 23:49 - 02370560 _____ (BitTorrent Inc.) C:\Users\Gustavo\Downloads\Baixaki_utorrent.exe 2017-02-02 23:48 - 2017-02-02 23:48 - 01798216 _____ ( ) C:\Users\Gustavo\Downloads\Baixaki_utorrent_VQCle5.exe ==================== Um Mês Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2017-03-01 15:05 - 2009-07-14 01:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-03-01 15:05 - 2009-07-14 01:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-03-01 15:00 - 2016-12-21 16:03 - 00000902 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2017-03-01 14:47 - 2009-07-14 14:55 - 00654272 _____ C:\Windows\system32\prfh0416.dat 2017-03-01 14:47 - 2009-07-14 14:55 - 00124724 _____ C:\Windows\system32\prfc0416.dat 2017-03-01 14:47 - 2009-07-14 02:13 - 01491932 _____ C:\Windows\system32\PerfStringBackup.INI 2017-03-01 14:47 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\inf 2017-03-01 14:42 - 2016-12-21 17:47 - 00000000 ____D C:\Users\Todos os Usuários\NVIDIA 2017-03-01 14:42 - 2016-12-21 17:47 - 00000000 ____D C:\ProgramData\NVIDIA 2017-03-01 14:40 - 2016-12-21 16:06 - 00002844 _____ C:\Windows\System32\Tasks\SlimDrivers Startup 2017-03-01 14:40 - 2016-12-21 16:06 - 00000414 _____ C:\Windows\Tasks\SlimDrivers Startup.job 2017-03-01 14:40 - 2016-12-21 16:05 - 00016056 _____ (SlimWare Utilities, Inc.) C:\Windows\system32\Drivers\SWDUMon.sys 2017-03-01 14:40 - 2009-07-14 02:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-03-01 14:38 - 2016-12-21 17:47 - 00007609 _____ C:\Users\Todos os Usuários\NvTelemetryContainer.log_backup1 2017-03-01 14:38 - 2016-12-21 17:47 - 00007609 _____ C:\ProgramData\NvTelemetryContainer.log_backup1 2017-03-01 14:38 - 2016-12-21 15:53 - 00000000 ____D C:\Users\Gustavo 2017-03-01 12:02 - 2016-12-21 16:03 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\Adobe 2017-03-01 11:57 - 2016-12-21 18:50 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2017-03-01 11:41 - 2016-12-21 17:36 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache 2017-03-01 11:41 - 2016-12-21 17:36 - 00000000 ____D C:\ProgramData\Package Cache 2017-03-01 11:20 - 2009-07-14 00:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2017-02-15 01:00 - 2016-12-21 16:03 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-02-15 01:00 - 2016-12-21 16:03 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-02-15 01:00 - 2016-12-21 16:03 - 00003840 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-02-15 01:00 - 2016-12-21 16:03 - 00000000 ____D C:\Windows\system32\Macromed 2017-02-15 01:00 - 2016-12-21 16:02 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-02-06 17:51 - 2016-12-21 17:44 - 00002193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-02-06 17:51 - 2016-12-21 17:44 - 00002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk ==================== Arquivos na raiz de alguns diretórios ======= 2016-12-21 17:13 - 2016-12-21 17:13 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2016-12-21 17:47 - 2017-03-01 14:40 - 0002938 _____ () C:\ProgramData\NvTelemetryContainer.log 2016-12-21 17:47 - 2017-03-01 14:38 - 0007609 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1 Alguns arquivos em TEMP: ==================== 2017-02-23 22:12 - 2017-02-23 22:12 - 1798216 _____ ( ) C:\Users\Gustavo\AppData\Local\Temp\ICReinstall_Baixaki_winrar_Vc8MLE.exe ==================== Bamital & volsnap ====================== (Não há correção automática para arquivos que não passaram na verificação.) C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente C:\Windows\explorer.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente C:\Windows\system32\services.exe => O arquivo é assinado digitalmente C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente C:\Windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente C:\Windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente LastRegBack: 2011-02-07 00:54 ==================== Fim de FRST.txt ============================