Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 19-11-2016 01
Executado por Mariana (administrador) em MARIANA-PC (20-11-2016 05:13:18)
Executando a partir de C:\Users\Mariana\Desktop
Perfis Carregados: Mariana (Perfis Disponíveis: Mariana)
Platform: Windows 7 Professional (X64) Idioma: Português (Brasil)
Internet Explorer Versão 8 (Navegador padrão: FF)
Modo da Inicialização: Normal
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\ProgramData\Windows Security\winsecurity.exe
() C:\Users\Mariana\AppData\Roaming\WMPNetworkAcSvc\WMPNetworkAcSvc.exe
() C:\Program Files (x86)\3FC4C0AE-1479615571-D37F-2E14-08626698C79A\trz1275.tmp
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(BitTorrent Inc.) C:\Users\Mariana\AppData\Roaming\uTorrent\uTorrent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(BitTorrent Inc.) C:\Users\Mariana\AppData\Roaming\uTorrent\updates\3.4.9_42923\utorrentie.exe
(BitTorrent Inc.) C:\Users\Mariana\AppData\Roaming\uTorrent\updates\3.4.9_42923\utorrentie.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Network\Dsq\network\sysnetwk.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8900104 2016-11-19] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2397120 2016-10-18] (NVIDIA Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-11-19] (AVAST Software)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-2972236348-867350917-3566710587-1000\...\Run: [uTorrent] => C:\Users\Mariana\AppData\Roaming\uTorrent\uTorrent.exe [2403008 2016-11-20] (BitTorrent Inc.)
HKU\S-1-5-21-2972236348-867350917-3566710587-1000\...\Run: [tsiVideo] => C:\Windows\SysWOW64\rundll32.exe C:\Users\Mariana\AppData\Local\Temp\mdi064.dll,fwnewsdf <===== ATENÇÃO
ShellExecuteHooks: - {E61BD264-A5BC-11E6-BDC9-64006A5CFC23} - C:\Users\Mariana\AppData\Roaming\Caduph\Climutholoty.dll [146944 2016-11-20] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-11-19] (AVAST Software)
BootExecute: autocheck autochk * aswBoot.exe /M:a86627a9a /wow /dir:"C:\Program Files\AVAST Software\Avast"

ProxyEnable: [S-1-5-21-2972236348-867350917-3566710587-1000] => Proxy está habilitado.
ProxyServer: [S-1-5-21-2972236348-867350917-3566710587-1000] => http=;https=
Hosts: Há mais de uma entrada no Hosts. Veja a seção Hosts do Addition.txt
Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{09EB3DEC-2536-44AD-B0BD-AE660322FDC0}: [NameServer]
Tcpip\..\Interfaces\{09EB3DEC-2536-44AD-B0BD-AE660322FDC0}: [DhcpNameServer]
Tcpip\..\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}: [NameServer]

HKU\S-1-5-21-2972236348-867350917-3566710587-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pt-br/?ocid=iehp
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-11-19] (AVAST Software)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-11-19] (AVAST Software)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-13] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-13] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-13] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-13] (Microsoft Corporation)

FF ProfilePath: C:\Users\Mariana\AppData\Roaming\Mozilla\Firefox\Profiles\0jjzrn6k.default [2016-11-20]
FF Homepage: Mozilla\Firefox\Profiles\0jjzrn6k.default -> google.com
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-11-19]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-11-19]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-10-18] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-10-18] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-11-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-11-19] (Google Inc.)
FF Plugin HKU\S-1-5-21-2972236348-867350917-3566710587-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Mariana\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2016-10-26] (Unity Technologies ApS)

CHR StartupUrls: Profile 1 -> "hxxps://www.google.com.br/"
CHR Profile: C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2016-11-20] <==== ATENÇÃO
CHR Extension: (Google Docs) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-11-19]
CHR Extension: (Google Drive) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-11-19]
CHR Extension: (YouTube) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-11-19]
CHR Extension: (Adblock Plus) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-11-19]
CHR Extension: (Avast SafePrice) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-11-19]
CHR Extension: (Planilhas do Google) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-11-19]
CHR Extension: (Super Mario World - Super Nintendo Emulator) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\fofigcdnkcjgidlpnonlajocnjlgbldj [2016-11-19]
CHR Extension: (Documentos Google off-line) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-19]
CHR Extension: (Vysor) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gidgenkbbabolejbgbpnhbimgjbffefm [2016-11-19]
CHR Extension: (Avast Online Security) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-11-19]
CHR Extension: (Top Friends) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ncmgphifjenjiafflmilknefljfccgnf [2016-11-19]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-11-19]
CHR Extension: (Gmail) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-11-19]
CHR Extension: (Chrome Media Router) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-19]
CHR Profile: C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1 [2016-11-20]
CHR Extension: (Google Apresentações) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-11-20]
CHR Extension: (Flash Video Downloader) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aiimdkdngfcipjohbjenkahhlhccpdbc [2016-11-20]
CHR Extension: (Google Docs) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-11-20]
CHR Extension: (Google Drive) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-11-20]
CHR Extension: (YouTube) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-11-20]
CHR Extension: (Adblock Plus) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-11-20]
CHR Extension: (Avast SafePrice) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-11-20]
CHR Extension: (Planilhas do Google) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-11-20]
CHR Extension: (Super Mario World - Super Nintendo Emulator) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fofigcdnkcjgidlpnonlajocnjlgbldj [2016-11-20]
CHR Extension: (Documentos Google off-line) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-11-20]
CHR Extension: (Vysor) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gidgenkbbabolejbgbpnhbimgjbffefm [2016-11-20]
CHR Extension: (Avast Online Security) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-11-20]
CHR Extension: (Top Friends) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ncmgphifjenjiafflmilknefljfccgnf [2016-11-20]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-11-20]
CHR Extension: (Gmail) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-11-20]
CHR Extension: (Chrome Media Router) - C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-20]
CHR Profile: C:\Users\Mariana\AppData\Local\Google\Chrome\User Data\System Profile [2016-11-20]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

U2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-11-19] (AVAST Software)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163712 2016-10-18] (NVIDIA Corporation)
R2 Mnerghtplurerdom; C:\Program Files (x86)\Clijege\voqlechufusysystem.dll [275968 2016-11-20] () [Arquivo não assinado]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-10-18] (NVIDIA Corporation)
S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3632576 2016-10-18] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2521024 2016-10-18] (NVIDIA Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)
R2 WindowsSecurity; C:\ProgramData\Windows Security\winsecurity.exe [1265664 2016-10-26] (Microsoft Corporation) [Arquivo não assinado] <==== ATENÇÃO
R2 WMPNetworkAcSvc; C:\Users\Mariana\AppData\Roaming\WMPNetworkAcSvc\WMPNetworkAcSvc.exe [5091840 2016-11-10] () [Arquivo não assinado] <==== ATENÇÃO

S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-11-19] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-11-19] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-11-19] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-11-19] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-11-19] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-11-19] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-11-19] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-11-19] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-11-19] (AVAST Software)
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-11-19] (REALiX(tm))
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-10-18] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [56384 2016-08-04] (NVIDIA Corporation)
S3 MSICDSetup; \??\E:\CDriver64.sys [X]
S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [X]

2016-11-20 04:13 - 2009-07-14 02:45 - 00009600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-11-20 04:13 - 2009-07-14 02:45 - 00009600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-11-20 02:30 - 2009-07-14 03:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2016-11-20 02:22 - 2009-07-14 03:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2016-11-20 02:22 - 2009-07-14 03:32 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-11-20 02:22 - 2009-07-14 03:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2016-11-20 02:22 - 2009-07-14 03:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2016-11-20 02:22 - 2009-07-14 03:32 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-11-20 02:22 - 2009-07-14 03:32 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-11-20 02:22 - 2009-07-14 01:20 - 00000000 ____D C:\Program Files (x86)\Windows NT
2016-11-20 02:22 - 2009-07-14 01:20 - 00000000 ____D C:\PerfLogs
2016-11-20 00:16 - 2009-07-29 13:58 - 00720590 _____ C:\Windows\system32\prfh0416.dat
2016-11-20 00:16 - 2009-07-29 13:58 - 00162608 _____ C:\Windows\system32\prfc0416.dat
2016-11-20 00:16 - 2009-07-14 03:13 - 00007666 _____ C:\Windows\system32\PerfStringBackup.INI
2016-11-20 00:10 - 2009-07-14 03:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-11-19 17:22 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\inf
2016-11-19 11:36 - 2009-07-14 02:45 - 00266016 _____ C:\Windows\system32\FNTCACHE.DAT
2016-11-19 06:03 - 2009-07-14 03:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2016-11-19 03:18 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\Help
2016-11-19 00:09 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\rescache
2016-11-19 00:08 - 2009-07-14 01:20 - 00000000 ____D C:\Program Files\Windows NT
2016-11-19 00:05 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\system32\sysprep
2016-11-19 00:04 - 2009-07-14 05:46 - 00000000 ____D C:\Windows\CSC

2016-11-19 01:11 - 2016-11-19 01:11 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\system32\services.exe => O arquivo é assinado digitalmente
C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente
C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente

