cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão:09-06-2016
Executado por guilh (administrador) em DESKTOP-I1M8C69 (10-06-2016 01:11:02)
Executando a partir de C:\Users\guilh\Downloads
Perfis Carregados: guilh (Perfis Disponíveis: guilh)
Platform: Windows 10 Home Single Language Versão 1511 (X64) Idioma: Português (Brasil)
Internet Explorer Versão 11 (Navegador padrão: Chrome)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(A-Volute) C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
() C:\Program Files\WindowsApps\Microsoft.XboxApp_15.17.3003.0_x64__8wekyb3d8bbwe\XboxApp.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11602.1.26.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.0_none_95e4f9a171a1ad95\TiWorker.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RazerCortex.exe
(The CefSharp Authors) C:\Program Files (x86)\Razer\Razer Cortex\Cef\CefSharp.BrowserSubprocess.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Zepetto) E:\Pointblank\PointBlank.exe
(Wellbia.com) E:\Pointblank\XIGNCODE\xxd-0.xem


==================== Registro (Whitelisted) ===========================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14021336 2015-06-18] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242712 2015-09-07] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [RazerCortex] => C:\Program Files (x86)\Razer\Razer Cortex\CortexLauncher.exe [222160 2016-04-29] (Razer Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2016-05-24] (Razer Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7400064 2016-06-07] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-06-07] (AVAST Software)
ShellIconOverlayIdentifiers: [0SamsungLinkOverlayIconCreated] -> {D130049C-7512-4075-9145-7B8B18149060} => C:\Program Files\Samsung\SamsungLink\SLIconOverlay.dll [2015-11-24] (Samsung Electronics CO., LTD.)
ShellIconOverlayIdentifiers: [0SamsungLinkOverlayIconRenamed] -> {D130049D-7512-4075-9145-7B8B18149060} => C:\Program Files\Samsung\SamsungLink\SLIconOverlay.dll [2015-11-24] (Samsung Electronics CO., LTD.)

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9251ecca-94a6-4b8c-a40f-8679b20d6375}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-3706636870-2431795195-3318297819-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://samsung15.msn.com/?pc=SMTE
HKU\S-1-5-21-3706636870-2431795195-3318297819-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung15.msn.com/?pc=SMTE
SearchScopes: HKU\S-1-5-21-3706636870-2431795195-3318297819-1001 -> DefaultScope {A1D73FE5-718C-4FA2-B5C1-10D6F0E1FDCD} URL =
SearchScopes: HKU\S-1-5-21-3706636870-2431795195-3318297819-1001 -> {A1D73FE5-718C-4FA2-B5C1-10D6F0E1FDCD} URL =

FireFox:
========
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-20] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-20] (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-25] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-25] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-06-07]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF

Chrome:
=======
CHR Profile: C:\Users\guilh\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Apresentações) - C:\Users\guilh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-25]
CHR Extension: (Google Docs) - C:\Users\guilh\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-25]
CHR Extension: (Google Drive) - C:\Users\guilh\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-25]
CHR Extension: (YouTube) - C:\Users\guilh\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-25]
CHR Extension: (Planilhas do Google) - C:\Users\guilh\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-25]
CHR Extension: (Documentos Google off-line) - C:\Users\guilh\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-25]
CHR Extension: (Avast Online Security) - C:\Users\guilh\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-06-07]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\guilh\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-25]
CHR Extension: (Gmail) - C:\Users\guilh\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-25]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-06-07]

==================== Serviços (Whitelisted) ========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S4 AllShare Framework DMS; C:\Program Files\Samsung\SamsungLink\AllShare Framework DMS\bin\AllShareFrameworkManagerDMS.exe [403264 2015-11-24] (Samsung)
S4 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [323152 2015-11-18] (Windows (R) Win 7 DDK provider)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [243296 2016-06-07] (AVAST Software)
S4 ETDService; C:\Program Files\Elantech\ETDService.exe [131288 2015-09-07] (ELAN Microelectronics Corp.)
S4 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [350312 2015-08-31] (Intel Corporation)
S4 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-21] (Intel(R) Corporation)
S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223008 2015-07-06] (Intel Corporation)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187824 2016-04-18] ()
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [132864 2016-04-29] (Razer Inc.)
R2 RzSurroundVADStreamingService; C:\ProgramData\Razer\Synapse\Devices\Razer Surround\Driver\RzSurroundVADStreamingService.exe [4255232 2016-02-15] (A-Volute) [Arquivo não assinado]
S4 SamsungLinkService; C:\Program Files\Samsung\SamsungLink\SamsungLinkService.exe [24965304 2015-11-24] (Samsung Electronics CO., LTD.)
S4 SecPowerCtrlService; C:\Program Files (x86)\Samsung\PowerCtrlManager\PowerCtrlService.exe [1698512 2015-11-12] (Samsung Electronics CO., LTD.)
S4 Settings Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsLauncher.exe [1775256 2016-01-05] (Samsung Electronics Co., Ltd.)
S4 ss_conn_service; C:\Program Files\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [745224 2015-07-08] (DEVGURU Co., LTD.)
S4 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3199184 2016-01-14] (Samsung Electronics Co., Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-06-07] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-06-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-06-07] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-06-07] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-06-07] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-06-07] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [465792 2016-06-07] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [166432 2016-06-07] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287528 2016-06-07] (AVAST Software)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4316784 2015-06-15] (Qualcomm Atheros Communications, Inc.)
S3 dg_ssudbus; C:\Windows\System32\drivers\ssudbus.sys [129152 2016-04-25] (Samsung Electronics Co., Ltd.)
R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [32328 2015-09-07] (ELAN Microelectronic Corp.)
R3 iaLPSS_GPIO; C:\Windows\System32\drivers\iaLPSS_GPIO.sys [46856 2015-06-14] (Intel Corporation)
R3 iaLPSS_I2C; C:\Windows\System32\drivers\iaLPSS_I2C.sys [132360 2015-06-14] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [184096 2015-06-29] (Intel Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-06-22] (Realtek )
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [402136 2015-05-27] (Realsil Semiconductor Corporation)
R2 rzpmgrk; C:\windows\system32\drivers\rzpmgrk.sys [44144 2016-03-10] (Razer, Inc.)
R2 rzpnk; C:\windows\system32\drivers\rzpnk.sys [137840 2016-04-17] (Razer, Inc.)
R3 RZSURROUNDVADService; C:\Windows\system32\drivers\RzSurroundVAD.sys [40640 2016-02-15] (Windows (R) Win 7 DDK provider)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [221824 2016-04-25] (Samsung Electronics Co., Ltd.)
S3 ssudqcfilter; C:\Windows\System32\drivers\ssudqcfilter.sys [48896 2015-07-08] (QUALCOMM Incorporated)
S3 ss_conn_usb_driver; C:\Windows\System32\Drivers\ss_conn_usb_driver.sys [26368 2015-07-08] (DEVGURU Co., LTD.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
R3 xhunter1; C:\windows\xhunter1.sys [36904 2016-06-10] (Wellbia.com Co., Ltd.)
R3 xspirit; C:\windows\xspirit.sys [19176 2016-06-10] ()

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Três Meses Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-06-10 01:11 - 2016-06-10 01:11 - 00013089 _____ C:\Users\guilh\Downloads\FRST.txt
2016-06-10 01:10 - 2016-06-10 01:11 - 00000000 ____D C:\FRST
2016-06-10 01:09 - 2016-06-10 01:10 - 02385408 _____ (Farbar) C:\Users\guilh\Downloads\FRST64.exe
2016-06-07 18:15 - 2016-06-07 18:15 - 00000180 _____ C:\windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-06-07 17:09 - 2016-06-07 17:09 - 00037144 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2016-06-07 17:09 - 2016-06-07 17:09 - 00004026 _____ C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1465330192
2016-06-07 17:09 - 2016-06-07 17:09 - 00001092 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-06-07 17:09 - 2016-06-07 17:09 - 00001092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-06-07 16:45 - 2016-06-07 16:45 - 00001989 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2016-06-07 16:45 - 2016-06-07 16:45 - 00001977 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-06-07 16:45 - 2016-06-07 16:45 - 00000000 ____D C:\Users\guilh\AppData\Roaming\AVAST Software
2016-06-07 16:43 - 2016-06-07 16:43 - 00004006 _____ C:\windows\System32\Tasks\avast! Emergency Update
2016-06-07 16:43 - 2016-06-07 16:42 - 01070904 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2016-06-07 16:43 - 2016-06-07 16:42 - 00465792 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2016-06-07 16:43 - 2016-06-07 16:42 - 00287528 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2016-06-07 16:43 - 2016-06-07 16:42 - 00166432 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2016-06-07 16:43 - 2016-06-07 16:42 - 00107792 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2016-06-07 16:43 - 2016-06-07 16:42 - 00103064 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2016-06-07 16:43 - 2016-06-07 16:42 - 00074544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2016-06-07 16:43 - 2016-06-07 16:42 - 00037656 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys
2016-06-07 16:42 - 2016-06-07 16:42 - 00398152 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2016-06-07 16:42 - 2016-06-07 16:42 - 00052184 _____ (AVAST Software) C:\windows\avastSS.scr
2016-06-07 16:25 - 2016-06-07 17:09 - 00000000 ____D C:\Program Files\AVAST Software
2016-06-07 16:23 - 2016-06-07 17:09 - 00000000 ____D C:\ProgramData\AVAST Software
2016-06-07 16:18 - 2016-06-07 16:23 - 05168776 _____ (AVAST Software) C:\Users\guilh\Downloads\avast_free_antivirus_setup_online.exe
2016-06-07 15:14 - 2016-06-07 15:14 - 00118153 _____ C:\Users\guilh\Downloads\nxcharacter.2.8.1.dll.zip
2016-06-07 01:12 - 2016-06-07 23:42 - 00004184 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{34856D5D-8656-4448-8E33-E00DD1E4C2D8}
2016-06-07 00:33 - 2016-06-07 00:33 - 00000000 ____D C:\Users\guilh\AppData\Local\CEF
2016-06-07 00:26 - 2016-06-10 01:10 - 00000000 _____ C:\windows\system32\RzSurroundVADAudioDeviceManager_log.txt
2016-06-07 00:26 - 2016-06-07 00:26 - 00000000 ____D C:\ProgramData\RzSurroundVAD_1.1.61.0
2016-06-07 00:26 - 2016-06-07 00:26 - 00000000 _____ C:\windows\SysWOW64\RzSurroundVADAudioDeviceManager_log.txt
2016-06-06 21:54 - 2016-06-06 22:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2016-06-06 21:54 - 2016-06-06 21:54 - 00001378 _____ C:\Users\Public\Desktop\Razer Cortex.lnk
2016-06-06 21:54 - 2016-04-17 12:21 - 00137840 _____ (Razer, Inc.) C:\windows\system32\Drivers\rzpnk.sys
2016-06-06 21:53 - 2016-06-06 22:14 - 00000000 ____D C:\Program Files (x86)\Razer
2016-06-06 21:53 - 2016-03-10 16:17 - 00044144 _____ (Razer, Inc.) C:\windows\system32\Drivers\rzpmgrk.sys
2016-06-06 21:19 - 2016-06-07 00:33 - 00000000 ____D C:\Users\guilh\AppData\Local\Razer
2016-06-06 21:19 - 2016-06-07 00:33 - 00000000 ____D C:\ProgramData\Razer
2016-06-06 02:31 - 2016-06-06 02:31 - 00000000 ____D C:\Users\guilh\AppData\Local\ElevatedDiagnostics
2016-06-06 02:03 - 2016-06-07 01:46 - 00007598 _____ C:\Users\guilh\AppData\Local\Resmon.ResmonCfg
2016-06-02 13:36 - 2016-06-02 15:27 - 00000000 ____D C:\Users\guilh\AppData\Roaming\Skype
2016-06-02 13:36 - 2016-06-02 13:36 - 00000000 ____D C:\Users\guilh\AppData\Local\Skype
2016-06-02 13:16 - 2016-06-02 13:52 - 00000000 ____D C:\Users\guilh\AppData\Local\PointBlank
2016-06-02 13:13 - 2016-06-10 01:10 - 00036904 _____ (Wellbia.com Co., Ltd.) C:\windows\xhunter1.sys
2016-06-02 13:13 - 2016-06-10 00:48 - 00019176 _____ C:\windows\xspirit.sys
2016-05-30 14:23 - 2016-05-30 14:23 - 00000000 ____H C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2016-05-26 16:12 - 2016-05-26 16:12 - 00000000 ____D C:\windows\system32\SleepStudy
2016-05-25 16:14 - 2016-05-25 16:14 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_ETD_01009.Wdf
2016-05-25 16:14 - 2015-09-07 05:34 - 00032328 _____ (ELAN Microelectronic Corp.) C:\windows\system32\Drivers\ETDSMBus.sys
2016-05-25 15:09 - 2016-05-25 16:30 - 00000000 ____D C:\Users\guilh\Desktop\selecta
2016-05-25 15:07 - 2016-05-25 15:07 - 00001035 _____ C:\Users\guilh\Desktop\VirtualDJ 8.lnk
2016-05-25 13:03 - 2016-05-26 14:49 - 00000000 ____D C:\Users\guilh\OneDrive\Documentos\VirtualDJ
2016-05-25 13:03 - 2016-05-25 15:08 - 00000000 ____D C:\Users\guilh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
2016-05-25 13:03 - 2016-05-25 15:08 - 00000000 ____D C:\Program Files (x86)\VirtualDJ
2016-05-25 12:56 - 2016-06-10 01:02 - 00001108 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-05-25 12:56 - 2016-06-09 17:30 - 00001104 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-05-25 12:20 - 2016-06-08 17:42 - 00002282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-05-25 12:20 - 2016-06-08 17:42 - 00002270 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-05-25 12:04 - 2016-05-25 12:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PointBlank
2016-05-25 11:53 - 2016-05-25 11:53 - 00000000 ____D C:\Users\guilh\AppData\Local\NetworkTiles
2016-05-25 11:50 - 2016-06-05 14:37 - 00000000 ____D C:\Users\guilh\AppData\Local\Google
2016-05-25 11:50 - 2016-05-25 12:56 - 00004166 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-05-25 11:50 - 2016-05-25 12:56 - 00003934 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-05-25 11:50 - 2016-05-25 12:20 - 00000000 ____D C:\Program Files (x86)\Google
2016-05-25 11:50 - 2016-05-25 11:50 - 00002373 _____ C:\Users\guilh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-05-25 11:43 - 2016-06-09 18:05 - 00000000 ___RD C:\Users\guilh\OneDrive
2016-05-25 11:42 - 2016-05-25 16:20 - 00000000 ____D C:\Users\guilh\AppData\Local\Comms
2016-05-25 11:42 - 2016-05-25 12:10 - 00000000 ____D C:\Users\guilh\AppData\Local\MicrosoftEdge
2016-05-25 11:41 - 2016-05-25 11:41 - 00000000 ____D C:\Users\guilh\AppData\Local\ActiveSync
2016-05-25 11:40 - 2016-05-25 11:40 - 00000000 ____D C:\Users\guilh\AppData\Local\Publishers
2016-05-25 11:39 - 2016-06-07 18:15 - 00000000 __SHD C:\Users\guilh\IntelGraphicsProfiles
2016-05-25 11:39 - 2016-06-01 13:33 - 00000000 ____D C:\Users\guilh\AppData\Local\Packages
2016-05-25 11:39 - 2016-05-25 11:39 - 00000000 ____D C:\Users\guilh\AppData\Roaming\Samsung
2016-05-25 11:39 - 2016-05-25 11:39 - 00000000 ____D C:\Users\guilh\AppData\Roaming\Adobe
2016-05-25 11:39 - 2016-05-25 11:39 - 00000000 ____D C:\Users\guilh\AppData\Local\VirtualStore
2016-05-25 11:39 - 2016-05-25 11:39 - 00000000 ____D C:\Users\guilh\AppData\Local\TileDataLayer
2016-05-25 11:36 - 2016-06-07 18:14 - 00000000 ____D C:\Users\guilh
2016-05-25 11:36 - 2016-05-25 11:36 - 00000020 ___SH C:\Users\guilh\ntuser.ini
2016-05-25 11:36 - 2016-05-25 11:36 - 00000000 _SHDL C:\Users\guilh\Modelos
2016-05-25 11:36 - 2016-05-25 11:36 - 00000000 _SHDL C:\Users\guilh\Meus Documentos
2016-05-25 11:36 - 2016-05-25 11:36 - 00000000 _SHDL C:\Users\guilh\Menu Iniciar
2016-05-25 11:36 - 2016-05-25 11:36 - 00000000 _SHDL C:\Users\guilh\Dados de Aplicativos
2016-05-25 11:36 - 2016-05-25 11:36 - 00000000 _SHDL C:\Users\guilh\Configurações Locais
2016-05-25 11:36 - 2016-05-25 11:36 - 00000000 _SHDL C:\Users\guilh\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2016-05-25 11:36 - 2016-05-25 11:36 - 00000000 _SHDL C:\Users\guilh\AppData\Local\Histórico
2016-05-25 11:36 - 2016-05-25 11:36 - 00000000 _SHDL C:\Users\guilh\AppData\Local\Dados de Aplicativos
2016-05-25 11:36 - 2016-05-25 11:36 - 00000000 _SHDL C:\Users\guilh\Ambiente de Rede
2016-05-25 11:36 - 2016-05-25 11:36 - 00000000 _SHDL C:\Users\guilh\Ambiente de Impressão
2016-05-25 11:29 - 2016-05-25 11:29 - 00000000 _____ C:\windows\system32\Drivers\144D_SAMSUNG_na_370E4K_P06R.mrk
2016-05-13 04:56 - 2016-05-13 04:56 - 00015816 _____ (Razer Inc.) C:\windows\SysWOW64\RzStats.IPC.dll
2016-05-06 01:21 - 2016-05-06 01:21 - 00000002 _____ C:\windows\MSetup.pas
2016-04-25 00:35 - 2016-04-25 00:35 - 00221824 _____ (Samsung Electronics Co., Ltd.) C:\windows\system32\Drivers\ssudmdm.sys
2016-04-25 00:35 - 2016-04-25 00:35 - 00129152 _____ (Samsung Electronics Co., Ltd.) C:\windows\system32\Drivers\ssudbus.sys
2016-03-14 02:36 - 2016-03-14 02:36 - 00097752 _____ (Razer Inc) C:\windows\SysWOW64\rzdevinfo.dll

==================== Três Meses Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-06-10 01:10 - 2015-10-30 04:11 - 00000000 ____D C:\windows\CbsTemp
2016-06-09 16:30 - 2015-10-30 04:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-06-09 16:30 - 2015-10-30 04:24 - 00000000 ____D C:\windows\AppReadiness
2016-06-08 17:43 - 2015-10-30 06:03 - 00000000 ____D C:\windows\OCR
2016-06-08 03:27 - 2016-03-03 06:15 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-06-08 03:27 - 2016-03-02 14:46 - 00000000 ____D C:\ProgramData\Norton
2016-06-08 02:21 - 2016-03-03 06:20 - 00005428 _____ C:\windows\system32\PerfStringBackup.INI
2016-06-08 02:21 - 2016-03-03 05:30 - 00834686 _____ C:\windows\system32\prfh0416.dat
2016-06-08 02:21 - 2016-03-03 05:30 - 00202330 _____ C:\windows\system32\prfc0416.dat
2016-06-07 16:19 - 2016-03-02 14:46 - 00000000 ____D C:\windows\system32\Drivers\NSx64
2016-06-07 16:18 - 2015-10-30 04:24 - 00000000 ___HD C:\windows\ELAMBKUP
2016-06-07 16:18 - 2015-10-30 03:28 - 00032768 ___SH C:\windows\system32\config\ELAM
2016-06-07 00:25 - 2015-10-30 04:21 - 00000000 ____D C:\windows\INF
2016-06-06 02:35 - 2015-10-30 03:28 - 00524288 ___SH C:\windows\system32\config\BBI
2016-06-01 08:07 - 2015-10-30 04:24 - 00000000 ____D C:\windows\rescache
2016-05-30 16:13 - 2015-10-30 06:02 - 00000000 ____D C:\windows\SysWOW64\winrm
2016-05-30 16:13 - 2015-10-30 06:02 - 00000000 ____D C:\windows\SysWOW64\WCN
2016-05-30 16:13 - 2015-10-30 06:02 - 00000000 ____D C:\windows\SysWOW64\slmgr
2016-05-30 16:13 - 2015-10-30 06:02 - 00000000 ____D C:\windows\SysWOW64\Printing_Admin_Scripts
2016-05-30 16:13 - 2015-10-30 06:02 - 00000000 ____D C:\windows\system32\winrm
2016-05-30 16:13 - 2015-10-30 06:02 - 00000000 ____D C:\windows\system32\WCN
2016-05-30 16:13 - 2015-10-30 06:02 - 00000000 ____D C:\windows\system32\slmgr
2016-05-30 16:13 - 2015-10-30 06:02 - 00000000 ____D C:\windows\system32\Printing_Admin_Scripts
2016-05-30 16:13 - 2015-10-30 04:24 - 00000000 ___SD C:\windows\SysWOW64\F12
2016-05-30 16:13 - 2015-10-30 04:24 - 00000000 ___SD C:\windows\SysWOW64\DiagSvcs
2016-05-30 16:13 - 2015-10-30 04:24 - 00000000 ___SD C:\windows\system32\F12
2016-05-30 16:13 - 2015-10-30 04:24 - 00000000 ____D C:\windows\SysWOW64\oobe
2016-05-30 16:13 - 2015-10-30 04:24 - 00000000 ____D C:\windows\SysWOW64\en-GB
2016-05-30 16:13 - 2015-10-30 04:24 - 00000000 ____D C:\windows\system32\SystemResetPlatform
2016-05-30 16:13 - 2015-10-30 04:24 - 00000000 ____D C:\windows\system32\oobe
2016-05-30 16:13 - 2015-10-30 04:24 - 00000000 ____D C:\windows\system32\migwiz
2016-05-30 16:12 - 2015-10-30 06:05 - 00000000 ____D C:\Program Files\Windows Journal
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ___SD C:\windows\system32\dsc
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ___SD C:\windows\system32\DiagSvcs
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ___RD C:\windows\PurchaseDialog
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ___RD C:\windows\MiracastView
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ___RD C:\windows\ImmersiveControlPanel
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ___RD C:\windows\DevicesFlow
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ____D C:\windows\system32\en-GB
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ____D C:\windows\PolicyDefinitions
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ____D C:\windows\IME
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ____D C:\windows\Help
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files\Windows Defender
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files\Common Files\System
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-05-30 16:12 - 2015-10-30 04:24 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-05-30 16:12 - 2015-10-30 03:28 - 00000000 ____D C:\windows\servicing
2016-05-30 14:07 - 2015-10-30 04:24 - 00000000 ____D C:\windows\SysWOW64\Com
2016-05-30 14:07 - 2015-10-30 04:24 - 00000000 ____D C:\windows\system32\Com
2016-05-30 14:07 - 2015-10-30 03:28 - 00000000 ____D C:\windows\SysWOW64\Dism
2016-05-30 14:07 - 2015-10-30 03:28 - 00000000 ____D C:\windows\system32\Sysprep
2016-05-30 14:07 - 2015-10-30 03:28 - 00000000 ____D C:\windows\system32\Dism
2016-05-25 11:54 - 2016-03-03 06:13 - 00192992 _____ C:\windows\system32\FNTCACHE.DAT
2016-05-25 11:54 - 2016-03-02 14:43 - 00000000 ____D C:\Program Files\Elantech
2016-05-25 11:40 - 2015-10-30 04:24 - 00000000 ___RD C:\windows\PrintDialog
2016-05-25 11:39 - 2016-03-03 06:16 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-05-25 11:36 - 2015-10-30 04:24 - 00000000 ____D C:\windows\system32\WinBioDatabase
2016-05-25 11:29 - 2016-03-02 14:49 - 00000000 ____D C:\ProgramData\CacheWrite
2016-05-25 11:29 - 2016-03-02 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung

==================== Arquivos na raiz de alguns diretórios =======

2016-06-06 02:03 - 2016-06-07 01:46 - 0007598 _____ () C:\Users\guilh\AppData\Local\Resmon.ResmonCfg
2016-03-02 14:17 - 2016-03-02 14:17 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2016-03-02 14:48 - 2013-02-19 04:34 - 2064264 _____ (Samsung Electronics) C:\ProgramData\MakeMarkerFile.exe
2016-03-02 14:48 - 2013-01-12 11:51 - 0003004 _____ () C:\ProgramData\MakeMarkerFile.xml

Alguns arquivos em TEMP:
====================
C:\Users\guilh\AppData\Local\Temp\0b4024b36b056a1a1620c88a9656f121.dll
C:\Users\guilh\AppData\Local\Temp\287c499808bcff52a39d16f78044882a.dll


==================== Bamital & volsnap =================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\windows\explorer.exe => O arquivo é assinado digitalmente
C:\windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\windows\system32\services.exe => O arquivo é assinado digitalmente
C:\windows\system32\User32.dll => O arquivo é assinado digitalmente
C:\windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente
C:\windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
C:\windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente


LastRegBack: 2016-06-05 13:54

==================== Fim de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité