cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x86) Versão:25-04-2016
Executado por Marcos (administrador) em MAQUINA05 (26-04-2016 22:05:15)
Executando a partir de C:\Users\Marcos\Desktop
Perfis Carregados: Marcos & DefaultAppPool (Perfis Disponíveis: Marcos & DefaultAppPool)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) Idioma: Português (Brasil)
Internet Explorer Versão 11 (Navegador padrão: Chrome)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(GAS Tecnologia) C:\Program Files\GbPlugin\gbpsv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
() C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\BCMWLTRY.EXE
(ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\CISVC.EXE
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc.exe
() C:\ProgramData\service.exe
(Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe
(Nero AG) C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Microsoft Corporation) C:\Windows\System32\snmp.exe
(Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Baidu Inc.) C:\Program Files\ToolBox\26.1.7777.582\ToolBoxService.exe
() C:\Program Files\trolatunt\updatetrolatunt.exe
() C:\Program Files\trolatunt\bin\utiltrolatunt.exe
(GAS Tecnologia LTDA) C:\Program Files\Diebold\Warsaw\core.exe
(GAS Tecnologia) C:\Program Files\GbPlugin\gbpsv.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Microsoft Corporation) C:\Windows\System32\mqtgsvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
() C:\Program Files\SpaceSoundPro\idscservice.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(VLOME) C:\Users\Marcos\AppData\Local\Temp\00027936\casrss.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(BlackBerry Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(GAS Tecnologia LTDA) C:\Program Files\Diebold\Warsaw\core.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\SpaceSoundPro\idsccom_HKK.exe
(Seekar Ltd) C:\Program Files\Ares\Ares.exe
(Research In Motion) C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.DesktopHelper.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_TATII4E.EXE
(BlackBerry Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\ProgramData\msiql.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Logitech Inc.) C:\Program Files\SetPoint\SetPoint.exe
(Logitech Inc.) C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
() C:\ProgramData\conhost51495.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Users\Marcos\AppData\Local\Temp\24357\Setup.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe
(tsvr.com) C:\Users\Marcos\AppData\Roaming\TSv\TSvr.exe
(WFini LIMITED) C:\ProgramData\CwinpC\WFini.exe
() C:\Windows\Temp\24301\tim.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Tencent) C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCRTP.exe
(Tencent) C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCTray.exe
(Tencent) C:\Program Files\Common Files\Tencent\QQDownload\130\Tencentdl.exe
(Tencent) C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QQPCNetFlow.exe
(Tencent) C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCRealTimeSpeedup.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\inetsrv\w3wp.exe


==================== Registro (Whitelisted) ===========================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [Logitech Hardware Abstraction Layer] => C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE [100888 2007-10-09] (Logitech Inc.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [986872 2016-01-29] (Microsoft Corporation)
HKLM\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [443640 2014-10-31] (BlackBerry Limited)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157992 2015-07-11] (Apple Inc.)
HKLM\...\Run: [Diebold - Warsaw] => C:\Program Files\Diebold\Warsaw\core.exe [509752 2015-06-19] (GAS Tecnologia LTDA)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [595480 2016-03-20] (Oracle Corporation)
HKLM\...\Run: [tim.exe -start] => C:\Windows\TEMP\24301\tim.exe [2363392 2016-04-24] () <===== ATENÇÃO
HKLM\...\Run: [SpaceSoundPro] => "C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe"
HKLM\...\Run: [IDSCCOMHKK] => C:\Program Files\SpaceSoundPro\idsccom_HKK.exe [3935232 2016-04-24] ()
HKLM\...\Run: [apphide] => C:\Program Files\badu\uc.exe [337500 2016-04-24] ()
HKLM\...\Run: [ QQPCTray] => C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCTray.exe [356464 2016-04-26] (Tencent)
HKLM\...\RunOnce: [WINDOWS_SCREEN_MANAGER_UPDATER_1] => C:\Program Files\Windows Screen Manager\Windows screen manage updater.exe [16896 2016-04-25] (Wizzservices)
HKLM\...\RunOnce: [IDSCPRODUCT] => C:\Program Files\SpaceSoundPro\idscservice.exe [605184 2016-04-24] ()
Winlogon\Notify\ GbPluginBb: C:\Program Files\GbPlugin\gbieh.dll [2015-10-20] (Banco do Brasil)
Winlogon\Notify\ GbPluginUni: C:\Program Files\GbPlugin\gbiehUni.dll [2015-07-06] (Banco Itaú Unibanco)
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [ares] => C:\Program Files\Ares\Ares.exe [2758656 2014-03-28] (Seekar Ltd)
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [Rim.DesktopHelper.exe] => C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.DesktopHelper.exe [752656 2013-03-07] (Research In Motion)
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TATII4E.EXE [249440 2012-02-27] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [Installer] => C:\Users\Marcos\AppData\Local\Temp\yeaplayer51495.exe [1968640 2016-04-23] (TZ) <===== ATENÇÃO
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [Pritc] => C:\Users\Marcos\AppData\Local\Temp\00027936\casrss.exe [2958848 2016-04-23] (VLOME) <===== ATENÇÃO
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [osmsg] => C:\ProgramData\WindowsMsg\osmsg.exe [2055168 2016-04-16] ()
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [Yeaplayer] => C:\Program Files\Yeaplayer\Yeaplayermd.exe /autostart
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [msiql] => C:\ProgramData\msiql.exe [1907200 2016-04-24] ()
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {3e2ce3f1-879c-11e3-b3a7-001c23a57405} - F:\Setup.exe
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {412f1f41-db38-11e4-8843-001c23a57405} - E:\AutoRun.exe
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {7e7aa6b8-1007-11e4-8797-001c23a57405} - E:\AutoRun.exe
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {7e7aa6cc-1007-11e4-8797-001c23a57405} - E:\AutoRun.exe
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {80c911af-c7b8-11e4-843b-001c23a57405} - E:\AutoRun.exe
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {9bf9d9eb-d2c2-11e5-9dfc-001c23a57405} - E:\AutoRun.exe
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {9bf9da23-d2c2-11e5-9dfc-001c23a57405} - E:\AutoRun.exe
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {f2958b1b-92c6-11e4-a5e9-001c23a57405} - E:\AutoRun.exe
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [10240 2009-07-13] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-01-30] (Microsoft Corporation)
HKU\S-1-5-18\...\RunOnce: [iCloud] => C:\Program Files\Common Files\Apple\Internet Services\iCloud.exe [60688 2015-12-01] (Apple Inc.)
ShellExecuteHooks: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399F83} - C:\Program Files\GbPlugin\gbieh.dll [1945472 2015-10-20] (Banco do Brasil)
ShellExecuteHooks: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399008} - C:\PROGRAM FILES\GbPlugin\gbiehuni.dll [1759992 2015-07-06] (Banco Itaú Unibanco)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk [2015-09-03]
ShortcutTarget: QuickSet.lnk -> C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SetPoint.lnk [2014-05-20]
ShortcutTarget: SetPoint.lnk -> C:\Program Files\SetPoint\SetPoint.exe (Logitech Inc.)
GroupPolicy: Restrição - Chrome <======= ATENÇÃO
CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{97789A24-C7FB-44BC-A327-DFF4378C35D3}: [NameServer] 82.163.143.185,82.163.142.185
Tcpip\..\Interfaces\{97789A24-C7FB-44BC-A327-DFF4378C35D3}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.2345.com/?34838
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.oursurfing.com/web/?type=dspp&ts=1433814071&z=7fae58fde5ade31ab44c97ag7z1cfcfb7g8z1e7mez&from=smt&uid=ST9250410AS_5VG40QATXXXX5VG40QAT&q={searchTerms}
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.oursurfing.com/web/?type=dspp&ts=1433814071&z=7fae58fde5ade31ab44c97ag7z1cfcfb7g8z1e7mez&from=smt&uid=ST9250410AS_5VG40QATXXXX5VG40QAT&q={searchTerms}
HKU\S-1-5-21-1231958544-1669365884-389720028-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.2345.com/?34838
URLSearchHook: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 - (Sem Nome) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - Nenhum Arquivo
SearchScopes: HKLM -> {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://start.iminent.com/?appId=CB813EFA-1981-4A63-B25B-D8570AA79D43&ref=toolbox&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 -> {B0081CF8-51C3-4F52-BD6E-8AFC53DFFA06} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 -> {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
BHO: toolbox -> {063D037D-F7F6-4D75-940F-54EE0011F82B} -> C:\Users\Marcos\AppData\LocalLow\ToolBox\26.1.7777.582\toolbox.dll [2014-07-23] ()
BHO: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_77\bin\ssv.dll [2016-03-27] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation)
BHO: IMinent WebBooster (BHO) -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> Nenhum Arquivo
BHO: PriceFountain -> {b608cc98-54de-4775-96c9-097de398500c} -> C:\Users\Marcos\AppData\Local\PriceFountain\PriceFountainIE.dll => Nenhum Arquivo
BHO: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540000} -> C:\Program Files\GbPlugin\gbieh.dll [2015-10-20] (Banco do Brasil)
BHO: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540008} -> C:\PROGRAM FILES\GBPLUGIN\gbiehuni.dll [2015-07-06] (Banco Itaú Unibanco)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-03-27] (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION)
Toolbar: HKLM - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION)
DPF: {021AFC0F-30F4-474D-9903-CE42D9539B17} hxxp://192.168.1.36:90/dvr_ocx.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1401408544&from=smt&uid=ST9250410AS_5VG40QATXXXX5VG40QAT

FireFox:
========
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-27] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-27] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [Nenhum Arquivo]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @qq.com/QQPCMgr -> C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\npQMExtensionsMozilla.dll [2016-04-26] (Tencent Technology (Shenzhen) Company Limited)
FF Plugin: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2014-11-28] ()
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin: JFGuide -> C:\Program Files\NetSurveillance\CMS\npGuide.dll [Nenhum Arquivo]
FF Plugin: JFWeb -> C:\Program Files\NetSurveillance\CMS\npWebPlugin.dll [Nenhum Arquivo]
FF Plugin HKU\S-1-5-21-1231958544-1669365884-389720028-1000: gastecnologia.com.br/sf/bb -> C:\Users\Marcos\AppData\Local\GAS Tecnologia\GBBD\npsf_bb.dll [2015-03-06] (GAS Tecnologia)
FF Extension: Sem Nome - C:\Program Files\AmiExt\flashEnhancer\ff [não encontrado (a)]
FF HKLM\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files\Epson Software\E-Web Print\Firefox Add-on
FF Extension: E-Web Print - C:\Program Files\Epson Software\E-Web Print\Firefox Add-on [2015-06-19] [não assinado]

Chrome:
=======
CHR HomePage: Default -> hxxps://www.google.com.br/
CHR StartupUrls: Default -> "hxxps://www.google.com.br/"
CHR DefaultSearchURL: Default -> hxxp://www.mercadolivre.com.br/jm/search?as_word={searchTerms}
CHR DefaultSearchKeyword: Default -> mercadolivre.com.br
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.866\_platform_specific\win_x86\widevinecdmadapter.dll (Google Inc.)
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\49.0.2623.112\PepperFlash\pepflashplayer.dll ()
CHR Profile: C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default
CHR Extension: (Google Drive) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (YouTube) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-01]
CHR Extension: (Google Search) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-02]
CHR Extension: (GBBD Guardião - Itaú 30 horas) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\kgmpojlddncminmkddkpoegdjhojjipg [2015-05-16]
CHR Extension: (GBBD Banco do Brasil) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\mkeabchhfifpaaoefpockjhaphjmoapp [2015-05-16]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-05]
CHR Extension: (Gmail) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-31]
CHR HKLM\...\Chrome\Extension: [cabkchdidokfhjppnlphhodlnojncdao] - C:\Users\Marcos\AppData\Roaming\ToolBox\26.1.7777.582\Release.crx [2014-07-23]

==================== Serviços (Whitelisted) ========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R3 BlackBerry Device Manager; C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [588024 2014-10-31] (BlackBerry Limited)
S2 BugreportW; C:\Program Files\hohobnd\reekge.exe [961800 2016-04-22] ()
R2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [1962192 2015-05-22] (Dell Inc.)
R2 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [184528 2015-05-22] (Dell Inc.)
S2 Drvcoresrv; C:\Program Files\Dravsynlether\Drvcoresrv.exe [302336 2016-04-22] ()
R2 EpsonCustomerParticipation; C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [539744 2012-05-10] (SEIKO EPSON CORPORATION)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc.exe [122000 2011-12-12] (Seiko Epson Corporation)
R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [310272 2012-06-01] (Microsoft Corporation)
R2 GbpSv; C:\Program Files\GbPlugin\gbpsv.exe [593120 2015-09-22] (GAS Tecnologia)
R2 GoogleChromeUpService; C:\ProgramData\service.exe [1745920 2016-04-21] () [Arquivo não assinado]
R2 IhPul; C:\Users\Marcos\AppData\Roaming\TSv\TSvr.exe [376592 2016-04-24] (tsvr.com)
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [13824 2009-07-13] (Microsoft Corporation)
R2 iprip; C:\Windows\System32\iprip.dll [29696 2009-07-13] (Microsoft Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2016-01-29] (Microsoft Corporation)
R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [126464 2010-11-20] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-01-18] (Hewlett-Packard) [Arquivo não assinado]
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [292816 2016-01-29] (Microsoft Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-01-18] (Hewlett-Packard) [Arquivo não assinado]
R2 QQPCRTP; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCRTP.exe [301656 2016-04-26] (Tencent)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [20648 2015-06-11] (Dell Inc.)
R2 ToolBoxService; C:\Program Files\ToolBox\26.1.7777.582\ToolBoxService.exe [80576 2014-07-23] (Baidu Inc.) [Arquivo não assinado]
R2 Update trolatunt; C:\Program Files\trolatunt\updatetrolatunt.exe [321824 2014-07-28] ()
R2 Util trolatunt; C:\Program Files\trolatunt\bin\utiltrolatunt.exe [321824 2014-07-28] ()
R2 Warsaw Technology; C:\Program Files\Diebold\Warsaw\core.exe [509752 2015-06-19] (GAS Tecnologia LTDA)
R2 WdMan; C:\ProgramData\CwinpC\WFini.exe [574672 2016-04-25] (WFini LIMITED)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [4038656 2013-10-28] (Dell Inc.) [Arquivo não assinado]
S2 Update Deal Keeper; "C:\Program Files\Deal Keeper\updateDealKeeper.exe" [X]
S2 WindowsProtectManger; C:\ProgramData\WindowsProtectManger\wprotectmanager.exe -service [X] <==== ATENÇÃO

===================== Drivers (Whitelisted) ==========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2013-10-28] (Broadcom Corporation)
S3 CSRBC; C:\Windows\System32\Drivers\csrbcxp.sys [31744 2007-01-16] (CSR, plc) [Arquivo não assinado]
R3 DDDriver; C:\Windows\System32\drivers\DDDriver32Dcsa.sys [20688 2015-02-26] (Dell Computer Corporation)
R3 DellProf; C:\Windows\System32\drivers\DellProf.sys [22192 2015-05-22] (Dell Computer Corporation)
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [30616 2013-03-04] (Elaborate Bytes AG)
R0 GbpKm; C:\Windows\System32\drivers\gbpkm.sys [49496 2015-11-25] (GAS Tecnologia)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [253704 2015-11-13] (Microsoft Corporation)
R1 MpKsl98e72fff; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2A400B34-C865-4C75-AACA-953D24ECC052}\MpKsl98e72fff.sys [39168 2016-04-25] (Microsoft Corporation)
R1 ndisrd; C:\Windows\System32\DRIVERS\gbpndisrdn.sys [29400 2015-04-09] (GAS Tecnologia)
R1 QMIEProtect; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QMIEProtect.sys [50296 2016-04-26] ()
R1 QMUdisk; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QMUdisk.sys [104152 2016-02-27] (Tencent)
S1 QQPCHelper; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCHelper.sys [25336 2016-04-26] (Tencent)
R2 QQSysMon; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQSysMon.sys [108920 2016-04-26] (电脑管家)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb.sys [68608 2014-05-06] (BlackBerry Limited)
S3 silabenm; C:\Windows\System32\DRIVERS\silabenm.sys [16128 2014-04-11] (Silicon Laboratories)
S3 silabser; C:\Windows\System32\DRIVERS\silabser.sys [67968 2014-04-11] (Silicon Laboratories)
R1 softaal; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\softaal.sys [36216 2016-04-26] (Tencent)
S3 Spring; C:\Program Files\Baidu Security\Baidu Antivirus\Spring.sys [96608 2014-06-18] ()
R3 TAOAccelerator; C:\Windows\system32\Drivers\TAOAccelerator.sys [116408 2016-04-26] (Tencent)
R1 TAOKernelDriver; C:\Windows\system32\Drivers\TAOKernel.sys [100088 2016-04-26] (Tencent Technology(Shenzhen) Company Limited)
R3 TFsFlt; C:\Windows\System32\Drivers\TFsFlt.sys [150008 2016-04-26] (电脑管家)
S3 TosRfSnd; C:\Windows\System32\drivers\tosrfsnd.sys [53760 2010-04-26] (TOSHIBA Corporation) [Arquivo não assinado]
R1 TSDefenseBt; C:\Windows\System32\DRIVERS\TSDefenseBt.sys [14008 2016-04-26] (Tencent)
R0 TsFltMgr; C:\Windows\System32\drivers\TsFltMgr.sys [128216 2016-04-26] (电脑管家)
R1 TSKSP; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\TSKsp.sys [210616 2016-04-26] (电脑管家)
R2 tsnethlp; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\TsNetHlp.sys [43768 2016-04-26] ()
R3 TSSK; C:\Windows\System32\tssk.sys [73976 2016-04-26] (电脑管家)
R1 TSSysKit; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\TSSysKit.sys [102136 2016-04-26] (电脑管家)
R4 WinDivert1.1; C:\Program Files\Diebold\Warsaw\WinDivert32.sys [31448 2015-04-01] (Basil)
R1 {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw; C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw.sys [52928 2014-05-22] (StdLib)
R1 {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w; C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w.sys [52928 2014-05-22] (StdLib)
S3 Baidu PC Faster FileShredder; \??\C:\Program Files\Baidu Security\PC Faster\4.0.0.0\FileKill_x86.sys [X]
S1 Bfilter; \??\C:\Windows\System32\drivers\Bfilter.sys [X]
S1 Bfmon; \??\C:\Windows\System32\drivers\Bfmon.sys [X]
S0 Bhbase; System32\drivers\Bhbase.sys [X]
S3 BHipsEx; \??\C:\Windows\System32\drivers\BHipsEx.sys [X]
S1 Bnbase; System32\drivers\bnbasex.sys [X]
S1 Bndef; \??\C:\Windows\System32\drivers\bndef.sys [X]
S1 Bprotect; \??\C:\Windows\System32\drivers\Bprotect.sys [X]
S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X]
S3 BtAudioBusSrv; System32\Drivers\BtAudioBus.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S0 gbpddreg; system32\drivers\gbpddreg32.sys [X]
S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S0 MPCBase; System32\drivers\MPCBase.sys [X]
S1 MPCKpt; system32\DRIVERS\MPCKpt.sys [X]
S3 PCFApiUtil; \??\C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFApiUtil.sys [X]

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um Mês Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-04-26 22:05 - 2016-04-26 22:07 - 00029509 _____ C:\Users\Marcos\Desktop\FRST.txt
2016-04-26 21:37 - 2016-04-26 22:05 - 00000000 ____D C:\FRST
2016-04-26 21:31 - 2016-04-26 21:33 - 01726976 _____ (Farbar) C:\Users\Marcos\Desktop\FRST.exe
2016-04-26 21:31 - 2016-04-26 21:31 - 00005120 _____ C:\Users\Marcos\AppData\Roaming\GiftBag.db
2016-04-26 21:30 - 2016-04-26 21:30 - 00000000 ____D C:\Users\Todos os Usuários\TXQMPC
2016-04-26 21:30 - 2016-04-26 21:30 - 00000000 ____D C:\ProgramData\TXQMPC
2016-04-26 21:30 - 2016-04-26 21:28 - 00116408 _____ (Tencent) C:\Windows\system32\Drivers\TAOAccelerator.sys
2016-04-26 21:30 - 2016-04-26 21:28 - 00100088 _____ (Tencent Technology(Shenzhen) Company Limited) C:\Windows\system32\Drivers\TAOKernel.sys
2016-04-26 21:30 - 2016-04-26 21:28 - 00014008 _____ (Tencent) C:\Windows\system32\Drivers\TSDefenseBt.sys
2016-04-26 21:29 - 2016-04-26 21:36 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\Tencent
2016-04-26 21:29 - 2016-04-26 21:28 - 00073976 _____ (电脑管家) C:\Windows\system32\TSSK.sys
2016-04-26 21:28 - 2016-04-26 21:30 - 00000000 ____D C:\Program Files\Common Files\Tencent
2016-04-26 21:28 - 2016-04-26 21:28 - 00150008 _____ (电脑管家) C:\Windows\system32\Drivers\TFsFlt.sys
2016-04-26 21:28 - 2016-04-26 21:28 - 00128216 _____ (电脑管家) C:\Windows\system32\Drivers\TsFltMgr.sys
2016-04-26 21:26 - 2016-04-26 21:33 - 00000000 ____D C:\Users\Todos os Usuários\Tencent
2016-04-26 21:26 - 2016-04-26 21:33 - 00000000 ____D C:\ProgramData\Tencent
2016-04-26 21:26 - 2016-04-26 21:26 - 00000000 ____D C:\Program Files\Tencent
2016-04-26 20:27 - 2016-04-26 21:44 - 00000000 ____D C:\Program Files\WinZipper
2016-04-26 20:26 - 2016-04-26 20:26 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\WinZiper
2016-04-26 20:26 - 2016-04-26 20:26 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\eCyber
2016-04-26 20:21 - 2016-04-26 20:21 - 00000001 _____ C:\Windows\system32\br.html
2016-04-26 20:21 - 2016-04-26 20:21 - 00000000 ____D C:\Users\Todos os Usuários\CwinpC
2016-04-26 20:21 - 2016-04-26 20:21 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\TSv
2016-04-26 20:21 - 2016-04-26 20:21 - 00000000 ____D C:\ProgramData\CwinpC
2016-04-26 20:21 - 2016-04-26 20:21 - 00000000 ____D C:\Program Files\QQBrowser
2016-04-26 20:19 - 2016-04-26 20:19 - 00002292 _____ C:\Users\Todos os Usuários\webad.xml
2016-04-26 20:19 - 2016-04-26 20:19 - 00002292 _____ C:\ProgramData\webad.xml
2016-04-25 19:26 - 2016-04-25 19:16 - 00939008 _____ C:\Users\Marcos\AppData\Roaming\BlackEx.exe
2016-04-25 19:25 - 2016-04-25 19:16 - 00939008 _____ C:\Users\Marcos\AppData\Roaming\Geotouch.exe
2016-04-25 19:23 - 2016-04-25 19:23 - 00848437 _____ C:\Users\Marcos\AppData\Roaming\Qvo-In.bin
2016-04-25 19:20 - 2016-04-25 19:20 - 00000000 ____D C:\Users\Public\Documents\Tools
2016-04-25 19:19 - 2016-04-25 19:19 - 00000000 ____D C:\Users\Todos os Usuários\39158c0c-7203-0
2016-04-25 19:19 - 2016-04-25 19:19 - 00000000 ____D C:\Users\Todos os Usuários\39158c0c-24d5-1
2016-04-25 19:19 - 2016-04-25 19:19 - 00000000 ____D C:\ProgramData\39158c0c-7203-0
2016-04-25 19:19 - 2016-04-25 19:19 - 00000000 ____D C:\ProgramData\39158c0c-24d5-1
2016-04-25 19:18 - 2016-04-26 12:56 - 00000000 ____D C:\Program Files\DNS Unlocker
2016-04-25 19:18 - 2016-04-25 19:18 - 00000000 ____D C:\Program Files\badu
2016-04-25 19:17 - 2016-04-26 00:00 - 00000000 ____D C:\Program Files\sunnyday
2016-04-25 19:17 - 2016-04-25 19:19 - 00015408 _____ C:\Users\Marcos\AppData\Roaming\InstallationConfiguration.xml
2016-04-25 19:17 - 2016-04-25 19:17 - 00127488 _____ C:\Users\Marcos\AppData\Roaming\Installer.dat
2016-04-25 19:17 - 2016-04-25 19:17 - 00000000 ____D C:\Users\Marcos\AppData\Local\csdi_monetize_220160425
2016-04-25 19:16 - 2016-04-26 00:00 - 00000000 ____D C:\Program Files\comoBoss
2016-04-25 19:15 - 2016-04-25 19:18 - 00000000 ____D C:\Program Files\Windows Screen Manager
2016-04-25 19:15 - 2016-04-25 11:47 - 01266688 _____ C:\Users\Todos os Usuários\conhost51495.exe
2016-04-25 19:15 - 2016-04-25 11:47 - 01266688 _____ C:\ProgramData\conhost51495.exe
2016-04-24 17:04 - 2016-04-24 13:55 - 01907200 _____ C:\Users\Todos os Usuários\msiql.exe
2016-04-24 17:04 - 2016-04-24 13:55 - 01907200 _____ C:\ProgramData\msiql.exe
2016-04-24 16:03 - 2016-04-24 16:03 - 00000000 ____D C:\Users\Todos os Usuários\pdf-convert
2016-04-24 16:03 - 2016-04-24 16:03 - 00000000 ____D C:\ProgramData\pdf-convert
2016-04-24 15:39 - 2016-04-24 15:39 - 00000000 ____D C:\Windows\system32\pdfconverter
2016-04-24 15:39 - 2016-04-24 15:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pdf-convert
2016-04-24 15:39 - 2016-04-24 15:39 - 00000000 ____D C:\Program Files\pdf-convert
2016-04-24 15:39 - 2001-10-29 01:42 - 00116224 _____ C:\Windows\system32\pdfmonnt.dll
2016-04-24 15:32 - 2016-04-24 15:43 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\MOVAVI
2016-04-24 15:32 - 2016-04-24 15:32 - 00004979 _____ C:\Users\Todos os Usuários\bqeojehc.wbx
2016-04-24 15:32 - 2016-04-24 15:32 - 00004979 _____ C:\ProgramData\bqeojehc.wbx
2016-04-24 15:32 - 2016-04-24 15:32 - 00001155 _____ C:\Users\Public\Desktop\Movavi PowerPoint To Video Converter 2.lnk
2016-04-24 15:32 - 2016-04-24 15:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movavi PowerPoint To Video Converter 2
2016-04-24 15:31 - 2016-04-24 15:32 - 00000000 ____D C:\Program Files\Movavi PowerPoint To Video Converter 2
2016-04-24 15:23 - 2016-04-24 15:23 - 00000000 ____D C:\Users\Marcos\AppData\Local\{7D6A43FC-7C49-420E-BD57-415F45B9FA4B}
2016-04-24 14:54 - 2016-04-21 00:03 - 02496403 _____ ( ) C:\Users\Marcos\AppData\Roaming\yeaplayer_51495.exe
2016-04-24 14:31 - 2016-04-21 05:54 - 01745920 _____ C:\Users\Todos os Usuários\service.exe
2016-04-24 14:31 - 2016-04-21 05:54 - 01745920 _____ C:\ProgramData\service.exe
2016-04-24 14:15 - 2016-04-21 05:54 - 01745920 _____ C:\Users\Marcos\AppData\Roaming\service.exe
2016-04-24 13:50 - 2016-04-24 13:50 - 00000000 ____D C:\Users\Marcos\AppData\Local\csdi_monetize_320160423
2016-04-24 13:41 - 2016-04-24 15:47 - 00000000 ____D C:\Program Files\SpaceSoundPro
2016-04-24 13:10 - 2016-04-24 13:11 - 00000000 ____D C:\Users\Marcos\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-04-24 13:10 - 2016-04-24 13:10 - 00000000 ____D C:\Program Files\Dravsynlether
2016-04-24 13:10 - 2016-04-24 13:10 - 00000000 ____D C:\extensions
2016-04-24 13:09 - 2016-04-26 20:21 - 00000000 ____D C:\Program Files\hohobnd
2016-04-24 12:51 - 2016-04-24 13:10 - 00000000 ____D C:\Users\Public\Documents\dmp
2016-04-23 01:40 - 2016-04-23 01:40 - 00000000 ____D C:\Users\Todos os Usuários\Thunder Network
2016-04-23 01:40 - 2016-04-23 01:40 - 00000000 ____D C:\Users\Public\Thunder Network
2016-04-23 01:40 - 2016-04-23 01:40 - 00000000 ____D C:\ProgramData\Thunder Network
2016-04-23 01:26 - 2016-04-23 01:26 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\MCorp
2016-04-23 01:15 - 2016-04-23 08:47 - 00000000 ____D C:\Program Files\MPC Cleaner
2016-04-23 01:02 - 2016-04-23 01:02 - 00000286 __RSH C:\Users\Marcos\ntuser.pol
2016-04-23 00:51 - 2016-04-23 01:01 - 00000296 _____ C:\Windows\Tasks\Price Fountain.job
2016-04-23 00:51 - 2016-04-23 00:51 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\PriceFountain
2016-04-23 00:49 - 2016-04-23 00:49 - 00000000 ____D C:\Program Files\MixVideoPlayer
2016-04-23 00:49 - 2016-04-21 11:50 - 01266688 _____ C:\Users\Marcos\AppData\Roaming\conhost51495.exe
2016-04-23 00:48 - 2016-04-23 00:48 - 00000000 ____D C:\Users\Todos os Usuários\04fcec7e-2a93-0
2016-04-23 00:48 - 2016-04-23 00:48 - 00000000 ____D C:\ProgramData\04fcec7e-2a93-0
2016-04-23 00:47 - 2016-04-23 00:47 - 00000000 ____D C:\Users\Todos os Usuários\04fcec7e-2127-1
2016-04-23 00:47 - 2016-04-23 00:47 - 00000000 ____D C:\ProgramData\04fcec7e-2127-1
2016-04-23 00:45 - 2016-04-23 01:10 - 00000000 ____D C:\Users\Marcos\AppData\Local\Setup Wizard
2016-04-23 00:43 - 2016-04-23 00:43 - 00000000 ____D C:\Users\Todos os Usuários\WindowsMsg
2016-04-23 00:43 - 2016-04-23 00:43 - 00000000 ____D C:\ProgramData\WindowsMsg
2016-04-23 00:42 - 2016-04-24 12:46 - 00000000 ____D C:\Users\Todos os Usuários\UpService
2016-04-23 00:42 - 2016-04-24 12:46 - 00000000 ____D C:\ProgramData\UpService
2016-04-23 00:42 - 2016-04-23 00:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioVideoKit
2016-04-23 00:40 - 2016-04-26 00:40 - 00000308 _____ C:\Windows\Tasks\Update Service for Torrent Search2.job
2016-04-23 00:38 - 2016-04-23 00:38 - 00000000 ____D C:\Users\Marcos\AppData\Local\GetGo
2016-04-23 00:37 - 2016-04-23 00:37 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\GetGo Software
2016-04-23 00:36 - 2016-04-23 00:40 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GetGo Software
2016-04-23 00:36 - 2016-04-23 00:40 - 00000000 ____D C:\Program Files\GetGo Software
2016-04-23 00:34 - 2016-04-26 21:39 - 00000344 ____H C:\Windows\Tasks\OKABEPSHNWPJMSKM.job
2016-04-23 00:34 - 2016-04-23 00:42 - 00000000 ____D C:\Program Files\HomePageDefender
2016-04-23 00:34 - 2016-04-23 00:40 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\ImageCropResize
2016-04-23 00:34 - 2016-04-23 00:34 - 00000000 ____D C:\Users\Todos os Usuários\Service5184
2016-04-23 00:34 - 2016-04-23 00:34 - 00000000 ____D C:\Users\Todos os Usuários\12db864551ae4c578eb17db1a9f5d3cf
2016-04-23 00:34 - 2016-04-23 00:34 - 00000000 ____D C:\ProgramData\Service5184
2016-04-23 00:34 - 2016-04-23 00:34 - 00000000 ____D C:\ProgramData\12db864551ae4c578eb17db1a9f5d3cf
2016-04-23 00:30 - 2016-04-23 00:31 - 03621488 _____ C:\Users\Marcos\Downloads\office_convert_powerpoint_to_image_jpgjpeg_crack.exe
2016-04-23 00:14 - 2016-04-23 00:48 - 00000000 ____D C:\Program Files\office Convert PowerPoint to Image Jpg-Jpeg
2016-04-22 23:50 - 2016-04-23 00:12 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\GetRightToGo
2016-04-22 23:50 - 2016-04-23 00:00 - 24176672 _____ (fCoder Group, Inc. ) C:\Users\Marcos\Downloads\udc.exe
2016-04-22 23:48 - 2016-04-22 23:49 - 00367936 _____ (RegNow.com) C:\Users\Marcos\Downloads\Download_office-convert-powerpoint-to-image-jpg-jpeg-aff.exe
2016-04-22 22:53 - 2016-04-22 22:53 - 40616016 _____ C:\Users\Marcos\Desktop\Gratidão Gabriela Rocha.wav
2016-04-22 12:56 - 2016-04-22 12:57 - 00000000 ____D C:\Users\Marcos\AppData\Local\{62CC13B7-22E4-4720-8EED-A6A1467F7095}
2016-04-22 11:48 - 2016-04-22 11:48 - 00000000 ____D C:\Users\Marcos\AppData\Local\{D04FB502-88BE-4956-B52D-697DC2A790F5}
2016-04-22 11:48 - 2016-04-22 11:48 - 00000000 ____D C:\Users\Marcos\AppData\Local\{25BBBA8E-3FC7-4DC0-A76E-7F370C095331}
2016-04-22 11:47 - 2016-04-22 11:47 - 00000000 ____D C:\Users\Marcos\AppData\Local\{DC82D6F9-A385-43ED-8BCB-6C46BE0B72CF}
2016-04-22 11:46 - 2016-04-22 11:46 - 00000000 ____D C:\Users\Marcos\AppData\Local\{BA243885-EAD8-4B40-AFB4-70FE22A4C52C}
2016-04-22 11:41 - 2016-04-22 11:42 - 00000000 ____D C:\Users\Marcos\AppData\Local\{6DB0CB31-6565-4FD9-B565-6F13772C243B}
2016-04-22 01:39 - 2016-04-22 11:16 - 00000408 _____ C:\Windows\Tasks\Driver Easy Scheduled Scan.job
2016-04-22 01:39 - 2016-04-22 01:39 - 00001080 _____ C:\Users\Public\Desktop\Driver Easy.lnk
2016-04-22 01:39 - 2016-04-22 01:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Easy
2016-04-21 22:57 - 2016-04-22 11:40 - 00000000 ____D C:\Users\Marcos\Desktop\fotos festa
2016-04-21 13:44 - 2016-04-21 13:44 - 00000000 ____D C:\Users\Marcos\AppData\Local\{3DF9E8C8-8145-428E-80CD-E32385781F82}
2016-04-17 15:26 - 2016-04-17 15:27 - 00000000 ____D C:\Users\Marcos\AppData\Local\{B0BCEE1A-1600-4376-81F7-8C10C6AD35C0}
2016-04-17 15:19 - 2016-04-17 15:19 - 00000000 ____D C:\Users\Marcos\AppData\Local\{DCC2BD41-E275-47D8-AFF8-BEDE01A17BFE}
2016-04-17 15:18 - 2016-04-17 15:18 - 00000000 ____D C:\Users\Marcos\AppData\Local\{EAF945DC-5C91-4364-9CDF-F71A0BD3D104}
2016-04-16 23:34 - 2016-04-16 23:35 - 01090944 _____ (Unity Technologies ApS) C:\Users\Marcos\Downloads\UnityWebPlayer (3).exe
2016-04-16 23:34 - 2016-04-16 23:34 - 01090944 _____ (Unity Technologies ApS) C:\Users\Marcos\Downloads\UnityWebPlayer (2).exe
2016-04-16 01:16 - 2016-03-31 15:41 - 00346320 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-04-16 01:16 - 2016-03-30 21:03 - 20352512 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-04-16 01:16 - 2016-03-30 21:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-04-16 01:16 - 2016-03-30 21:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-04-16 01:16 - 2016-03-30 20:53 - 00496640 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-04-16 01:16 - 2016-03-30 20:52 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-04-16 01:16 - 2016-03-30 20:52 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-04-16 01:16 - 2016-03-30 20:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-04-16 01:16 - 2016-03-30 20:52 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-04-16 01:16 - 2016-03-30 20:51 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-04-16 01:16 - 2016-03-30 20:48 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-04-16 01:16 - 2016-03-30 20:48 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-04-16 01:16 - 2016-03-30 20:46 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-04-16 01:16 - 2016-03-30 20:45 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-04-16 01:16 - 2016-03-30 20:45 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-04-16 01:16 - 2016-03-30 20:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-04-16 01:16 - 2016-03-30 20:45 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-04-16 01:16 - 2016-03-30 20:41 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-04-16 01:16 - 2016-03-30 20:38 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-04-16 01:16 - 2016-03-30 20:34 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-04-16 01:16 - 2016-03-30 20:33 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-04-16 01:16 - 2016-03-30 20:31 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-04-16 01:16 - 2016-03-30 20:31 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-04-16 01:16 - 2016-03-30 20:30 - 04611072 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-04-16 01:16 - 2016-03-30 20:30 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-04-16 01:16 - 2016-03-30 20:29 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-04-16 01:16 - 2016-03-30 20:24 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-04-16 01:16 - 2016-03-30 20:23 - 02056192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-04-16 01:16 - 2016-03-30 20:23 - 00693248 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-04-16 01:16 - 2016-03-30 20:23 - 00689664 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-04-16 01:16 - 2016-03-30 20:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-04-16 01:16 - 2016-03-30 20:21 - 13811712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-04-16 01:16 - 2016-03-30 20:05 - 02121216 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-04-16 01:16 - 2016-03-30 20:02 - 01311744 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-04-16 01:16 - 2016-03-30 20:00 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-04-13 09:21 - 2016-04-04 14:54 - 00034024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-04-13 09:21 - 2016-04-04 14:42 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-04-13 09:21 - 2016-04-02 10:07 - 01218048 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-04-13 09:21 - 2016-03-23 11:02 - 00177664 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-04-13 09:21 - 2016-03-17 15:04 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-04-13 09:21 - 2016-03-17 15:04 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-04-13 09:21 - 2016-03-17 15:04 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-04-13 09:21 - 2016-03-17 15:04 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-04-13 09:05 - 2016-03-17 19:36 - 03998952 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2016-04-13 09:05 - 2016-03-17 19:36 - 03943144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-04-13 09:05 - 2016-03-17 19:28 - 01414144 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-04-13 09:05 - 2016-03-17 19:26 - 00294400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-04-13 09:05 - 2016-03-16 15:28 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\msorcl32.dll
2016-04-13 09:05 - 2016-03-16 15:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2016-04-13 09:05 - 2016-02-02 15:48 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2016-04-13 09:04 - 2016-03-17 19:36 - 00137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-04-13 09:04 - 2016-03-17 19:36 - 00067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-04-13 09:04 - 2016-03-17 19:33 - 01310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-04-13 09:04 - 2016-03-17 19:30 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-04-13 09:04 - 2016-03-17 19:30 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-04-13 09:04 - 2016-03-17 19:30 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-04-13 09:04 - 2016-03-17 19:30 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-04-13 09:04 - 2016-03-17 19:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-04-13 09:04 - 2016-03-17 19:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-04-13 09:04 - 2016-03-17 19:29 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-04-13 09:04 - 2016-03-17 19:29 - 00251392 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-04-13 09:04 - 2016-03-17 19:29 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-04-13 09:04 - 2016-03-17 19:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-04-13 09:04 - 2016-03-17 19:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-04-13 09:04 - 2016-03-17 19:27 - 00260608 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-04-13 09:04 - 2016-03-17 19:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-04-13 09:04 - 2016-03-17 19:27 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-04-13 09:04 - 2016-03-17 19:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-04-13 09:04 - 2016-03-17 19:26 - 01062400 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-04-13 09:04 - 2016-03-17 19:26 - 00872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-04-13 09:04 - 2016-03-17 19:26 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-04-13 09:04 - 2016-03-17 19:25 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-04-13 09:04 - 2016-03-17 19:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 18:42 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-04-13 09:04 - 2016-03-17 18:42 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-04-13 09:04 - 2016-03-17 18:42 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-04-13 09:04 - 2016-03-17 18:42 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-04-13 09:04 - 2016-03-17 18:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-04-13 09:04 - 2016-03-17 18:36 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-04-13 09:04 - 2016-03-17 18:35 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-04-13 09:04 - 2016-03-17 18:30 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-04-13 09:04 - 2016-03-17 18:30 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-04-13 09:04 - 2016-03-17 18:30 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-04-13 09:04 - 2016-03-17 18:29 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-04-13 09:04 - 2016-03-17 18:29 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-04-13 09:04 - 2016-03-17 18:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-04-13 09:04 - 2016-03-17 18:29 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-04-13 09:04 - 2016-03-17 18:29 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 18:29 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 18:29 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-04-13 09:04 - 2016-03-17 18:29 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-04-13 08:59 - 2016-03-15 20:53 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2016-04-13 08:59 - 2016-03-15 20:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2016-04-13 08:53 - 2016-03-11 15:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-04-13 08:53 - 2016-01-20 21:51 - 00057280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys
2016-04-13 08:48 - 2016-03-29 14:35 - 02397184 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-04-13 08:43 - 2016-03-06 15:38 - 01240576 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2016-04-13 08:43 - 2016-03-06 15:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2016-04-13 08:33 - 2016-02-05 15:44 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll
2016-04-13 08:33 - 2016-02-05 14:33 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\tbs.dll
2016-04-13 08:33 - 2015-06-03 17:22 - 00355456 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2016-04-12 00:33 - 2016-04-12 00:34 - 02568107 _____ C:\Users\Marcos\Downloads\LG WD-12596RD (1).pdf
2016-04-12 00:25 - 2016-04-12 00:26 - 02568107 _____ C:\Users\Marcos\Downloads\LG WD-12596RD.pdf
2016-04-10 22:13 - 2016-04-10 22:13 - 00002157 _____ C:\Users\Marcos\Desktop\Itaú.lnk
2016-04-10 22:13 - 2016-04-10 22:13 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicativo Itaú
2016-04-05 12:08 - 2016-04-05 12:08 - 00001199 _____ C:\Users\Marcos\Downloads\ComprovanteBB - 2016-04-05-120132.pdf
2016-04-05 12:08 - 2016-04-05 12:08 - 00001193 _____ C:\Users\Marcos\Downloads\ComprovanteBB - 2016-04-05-120321.pdf
2016-04-01 23:16 - 2016-04-01 23:16 - 00000000 ____D C:\Users\Marcos\Desktop\My Shared Folder
2016-03-30 08:06 - 2016-03-30 08:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2016-03-30 08:06 - 2016-03-30 08:06 - 00000000 ____D C:\Program Files\QuickTime
2016-03-30 07:54 - 2016-03-30 07:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2016-03-30 07:53 - 2016-03-30 07:53 - 00000000 ____D C:\Program Files\Apple Software Update
2016-03-29 16:15 - 2016-03-29 16:15 - 00000000 ____D C:\Windows\system32\dvr_hd
2016-03-27 13:54 - 2016-03-27 13:54 - 00000000 ____D C:\Program Files\Common Files\Java

==================== Um Mês Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-04-26 21:57 - 2014-07-28 17:03 - 00110592 ___SH C:\Users\Marcos\Thumbs.db
2016-04-26 21:48 - 2013-10-29 00:41 - 00000902 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-04-26 21:47 - 2015-02-16 23:21 - 00002052 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-04-26 21:47 - 2014-05-29 21:09 - 00002293 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-04-26 21:47 - 2013-10-28 12:14 - 00002311 _____ C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-04-26 21:31 - 2013-10-28 12:57 - 00110464 _____ C:\Users\Marcos\AppData\Local\GDIPFONTCACHEV1.DAT
2016-04-26 21:09 - 2013-10-28 23:33 - 00001058 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-26 20:39 - 2009-07-14 01:34 - 00026064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-04-26 20:39 - 2009-07-14 01:34 - 00026064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-04-26 20:19 - 2015-09-17 08:31 - 00000000 ____D C:\Users\Marcos\AppData\Local\CrashDumps
2016-04-26 20:18 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\system32\inetsrv
2016-04-26 20:17 - 2013-10-28 23:33 - 00001054 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-26 20:16 - 2009-07-14 01:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-04-26 00:33 - 2015-06-02 23:43 - 00000032 _____ C:\Windows\0
2016-04-26 00:33 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\inf
2016-04-26 00:27 - 2015-06-03 00:13 - 00000000 ____D C:\Users\Todos os Usuários\TOSHIBA
2016-04-26 00:27 - 2015-06-03 00:13 - 00000000 ____D C:\ProgramData\TOSHIBA
2016-04-26 00:11 - 2014-07-12 23:08 - 00000000 ____D C:\Windows\system32\appmgmt
2016-04-25 21:11 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\LiveKernelReports
2016-04-24 21:05 - 2016-03-08 20:41 - 00000000 ____D C:\Users\Marcos\Desktop\Festa Circulo de oração 2016
2016-04-24 18:51 - 2016-03-15 21:45 - 00000000 ____D C:\Users\Marcos\Desktop\HC640 Para DataShow – PowerPoint
2016-04-24 15:48 - 2015-04-09 01:40 - 00000000 ____D C:\Users\Todos os Usuários\GbPlugin
2016-04-24 15:48 - 2015-04-09 01:40 - 00000000 ____D C:\ProgramData\GbPlugin
2016-04-24 15:32 - 2013-10-28 12:10 - 01798186 _____ C:\Windows\system32\PerfStringBackup.INI
2016-04-24 15:32 - 2009-07-14 05:31 - 00768068 _____ C:\Windows\system32\prfh0416.dat
2016-04-24 15:32 - 2009-07-14 05:31 - 00169808 _____ C:\Windows\system32\prfc0416.dat
2016-04-23 01:17 - 2015-12-23 23:58 - 00000000 ____D C:\Program Files\No-IP
2016-04-23 01:15 - 2014-07-27 19:34 - 00000000 ____D C:\Program Files\VIVO INTERNET
2016-04-23 01:14 - 2014-07-27 19:35 - 00000000 ____D C:\Users\Todos os Usuários\DataCardService
2016-04-23 01:14 - 2014-07-27 19:35 - 00000000 ____D C:\ProgramData\DataCardService
2016-04-23 01:13 - 2016-03-03 16:28 - 00000000 ____D C:\Nex
2016-04-23 01:02 - 2013-10-28 12:14 - 00000000 ____D C:\Users\Marcos
2016-04-23 00:36 - 2014-03-29 12:10 - 00000874 __RSH C:\Users\Todos os Usuários\ntuser.pol
2016-04-23 00:36 - 2014-03-29 12:10 - 00000874 __RSH C:\ProgramData\ntuser.pol
2016-04-23 00:36 - 2009-07-13 23:37 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2016-04-22 04:57 - 2013-10-30 23:41 - 00374944 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-04-22 01:39 - 2013-10-28 12:57 - 00000000 ____D C:\Program Files\Easeware
2016-04-18 18:39 - 2014-07-28 23:20 - 00000000 ____D C:\Users\Marcos\Documents\FFOutput
2016-04-17 23:36 - 2009-07-14 01:53 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2016-04-17 15:22 - 2015-07-26 16:28 - 00000000 ____D C:\Users\Marcos\AppData\Local\Apple Computer
2016-04-17 15:19 - 2014-07-28 00:15 - 00000000 ____D C:\Users\Marcos\AppData\Local\Windows Live
2016-04-14 03:41 - 2009-07-14 01:33 - 00408344 _____ C:\Windows\system32\FNTCACHE.DAT
2016-04-14 03:38 - 2014-12-18 18:59 - 00000000 ____D C:\Windows\system32\appraiser
2016-04-14 03:22 - 2013-10-28 23:12 - 00000000 ____D C:\Users\Todos os Usuários\Microsoft Help
2016-04-14 03:19 - 2013-10-28 16:39 - 00000000 ____D C:\Windows\system32\MRT
2016-04-14 03:06 - 2013-10-28 16:39 - 132539272 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-04-13 23:59 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\system32\NDF
2016-04-10 22:32 - 2015-06-28 19:12 - 00000000 ___RD C:\Users\Marcos\Desktop\Pessoal
2016-04-10 22:13 - 2015-04-27 15:44 - 00000000 ____D C:\Users\Marcos\AppData\Local\Aplicativo Itau
2016-04-07 16:49 - 2013-10-29 00:41 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-04-07 16:49 - 2013-10-29 00:41 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-04-07 16:15 - 2014-07-28 02:10 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\Audacity
2016-03-30 13:09 - 2016-03-18 13:51 - 00000000 ___RD C:\Users\Marcos\Desktop\Oficina
2016-03-30 12:05 - 2015-04-09 01:40 - 00000000 ____D C:\Program Files\GbPlugin
2016-03-30 07:54 - 2015-07-26 16:28 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\Apple Computer
2016-03-30 07:53 - 2015-07-26 16:25 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2016-03-29 16:15 - 2009-07-14 01:52 - 00000000 ____D C:\Windows\Downloaded Program Files
2016-03-29 14:01 - 2014-02-10 22:55 - 00000000 ____D C:\Users\Marcos\AppData\Local\ElevatedDiagnostics
2016-03-27 13:55 - 2016-02-22 23:28 - 00000000 ____D C:\Program Files\Java
2016-03-27 13:54 - 2016-02-22 23:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-03-27 13:53 - 2016-02-22 23:30 - 00000000 ____D C:\Users\Marcos\.oracle_jre_usage
2016-03-27 13:53 - 2016-02-22 23:29 - 00095808 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll

==================== Arquivos na raiz de alguns diretórios =======

2016-04-25 19:26 - 2016-04-25 19:16 - 0939008 _____ () C:\Users\Marcos\AppData\Roaming\BlackEx.exe
2016-04-23 00:43 - 2016-04-23 00:43 - 0001213 _____ () C:\Users\Marcos\AppData\Roaming\Bubble Dock.boostrap.log
2016-04-23 00:49 - 2016-04-21 11:50 - 1266688 _____ () C:\Users\Marcos\AppData\Roaming\conhost51495.exe
2014-10-09 21:54 - 2015-11-02 17:18 - 0000138 _____ () C:\Users\Marcos\AppData\Roaming\default.rss
2016-04-25 19:25 - 2016-04-25 19:16 - 0939008 _____ () C:\Users\Marcos\AppData\Roaming\Geotouch.exe
2016-04-26 21:31 - 2016-04-26 21:31 - 0005120 _____ () C:\Users\Marcos\AppData\Roaming\GiftBag.db
2016-04-25 19:17 - 2016-04-25 19:19 - 0015408 _____ () C:\Users\Marcos\AppData\Roaming\InstallationConfiguration.xml
2016-04-25 19:17 - 2016-04-25 19:17 - 0127488 _____ () C:\Users\Marcos\AppData\Roaming\Installer.dat
2016-04-25 19:23 - 2016-04-25 19:23 - 0848437 _____ () C:\Users\Marcos\AppData\Roaming\Qvo-In.bin
2015-06-16 01:40 - 2016-04-26 00:07 - 0005884 _____ () C:\Users\Marcos\AppData\Roaming\Rim.Desktop.Exception.log
2015-06-16 01:38 - 2015-06-16 01:38 - 0001147 _____ () C:\Users\Marcos\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2015-06-16 01:40 - 2015-10-01 21:13 - 0000924 _____ () C:\Users\Marcos\AppData\Roaming\Rim.DesktopHelper.Exception.log
2016-04-24 14:15 - 2016-04-21 05:54 - 1745920 _____ () C:\Users\Marcos\AppData\Roaming\service.exe
2015-07-08 17:48 - 2015-07-08 17:48 - 0016776 _____ () C:\Users\Marcos\AppData\Roaming\unins000.dat
2015-07-08 17:48 - 2015-07-08 17:48 - 0815826 _____ () C:\Users\Marcos\AppData\Roaming\unins000.exe
2016-04-23 00:43 - 2016-04-23 00:43 - 0000097 _____ () C:\Users\Marcos\AppData\Roaming\WindApp.boostrap.log
2016-04-24 14:54 - 2016-04-21 00:03 - 2496403 _____ ( ) C:\Users\Marcos\AppData\Roaming\yeaplayer_51495.exe
2014-10-09 19:22 - 2015-08-16 20:48 - 0004608 _____ () C:\Users\Marcos\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-10-01 01:28 - 2015-10-01 01:28 - 0007605 _____ () C:\Users\Marcos\AppData\Local\Resmon.ResmonCfg
2016-04-24 15:32 - 2016-04-24 15:32 - 0004979 _____ () C:\ProgramData\bqeojehc.wbx
2016-04-25 19:15 - 2016-04-25 11:47 - 1266688 _____ () C:\ProgramData\conhost51495.exe
2013-11-15 12:03 - 2015-04-07 22:39 - 0005397 _____ () C:\ProgramData\hpzinstall.log
2013-10-28 22:47 - 2013-10-28 22:47 - 0000110 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2016-04-24 17:04 - 2016-04-24 13:55 - 1907200 _____ () C:\ProgramData\msiql.exe
2016-03-03 16:28 - 2016-03-03 16:28 - 0000047 _____ () C:\ProgramData\nex.ini
2016-04-24 14:31 - 2016-04-21 05:54 - 1745920 _____ () C:\ProgramData\service.exe
2016-04-26 20:19 - 2016-04-26 20:19 - 0002292 _____ () C:\ProgramData\webad.xml

Arquivos para serem movidos ou deletados:
====================
C:\Windows\TEMP\24301\tim.exe
C:\Users\Marcos\AppData\Local\Temp\yeaplayer51495.exe
C:\Users\Marcos\AppData\Local\Temp\00027936\casrss.exe
C:\ProgramData\conhost51495.exe
C:\ProgramData\msiql.exe
C:\ProgramData\service.exe
C:\Users\Todos os Usuários\conhost51495.exe
C:\Users\Todos os Usuários\msiql.exe
C:\Users\Todos os Usuários\service.exe


Alguns arquivos em TEMP:
====================
C:\Users\Marcos\AppData\Local\Temp\1a76e3dd-d4b8-4f5b-8168-348c40bf97fb.exe
C:\Users\Marcos\AppData\Local\Temp\23333.exe
C:\Users\Marcos\AppData\Local\Temp\6AKXNTAE4D.exe
C:\Users\Marcos\AppData\Local\Temp\abc.exe
C:\Users\Marcos\AppData\Local\Temp\aplicativoitau.exe
C:\Users\Marcos\AppData\Local\Temp\appshat_generic.exe
C:\Users\Marcos\AppData\Local\Temp\atcMedia8541429466207.exe
C:\Users\Marcos\AppData\Local\Temp\AudioConverterSetup.exe
C:\Users\Marcos\AppData\Local\Temp\bdgD506.exe
C:\Users\Marcos\AppData\Local\Temp\Browser_V5.6.11815.13_r_4739_(Build1604131623).exe
C:\Users\Marcos\AppData\Local\Temp\checkedlist.exe
C:\Users\Marcos\AppData\Local\Temp\component.exe
C:\Users\Marcos\AppData\Local\Temp\IrsoDLL.dll
C:\Users\Marcos\AppData\Local\Temp\jre-8u77-windows-au.exe
C:\Users\Marcos\AppData\Local\Temp\LV7DD6TLDD.exe
C:\Users\Marcos\AppData\Local\Temp\module-2.exe
C:\Users\Marcos\AppData\Local\Temp\module-3.exe
C:\Users\Marcos\AppData\Local\Temp\ms6920.tmp.exe
C:\Users\Marcos\AppData\Local\Temp\office convert powerpoint to image jpgjpeg crack.exe
C:\Users\Marcos\AppData\Local\Temp\PriceFountainUpdateVer.exe
C:\Users\Marcos\AppData\Local\Temp\Q4Y1Z9126C.exe
C:\Users\Marcos\AppData\Local\Temp\sdfDFA4.exe
C:\Users\Marcos\AppData\Local\Temp\searchiw-svd.ru_BR.exe
C:\Users\Marcos\AppData\Local\Temp\sercia-svd.ru_BR.exe
C:\Users\Marcos\AppData\Local\Temp\setup.exe
C:\Users\Marcos\AppData\Local\Temp\setup_nex_.exe
C:\Users\Marcos\AppData\Local\Temp\ts_10051.exe
C:\Users\Marcos\AppData\Local\Temp\ttwifi.exe
C:\Users\Marcos\AppData\Local\Temp\ucbrabs.exe
C:\Users\Marcos\AppData\Local\Temp\yeaplayer51495.exe
C:\Users\Marcos\AppData\Local\Temp\Yeaplayer_51384.exe
C:\Users\Marcos\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe


==================== Bamital & volsnap =================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\Windows\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\system32\services.exe => O arquivo é assinado digitalmente
C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente
C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente


LastRegBack: 2016-04-18 00:57

==================== Fim de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité