cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 01-03-2017
Executado por Gustavo (administrador) em GUSTAVO-PC (01-03-2017 15:10:40)
Executando a partir de C:\Users\Gustavo\Downloads
Perfis Carregados: Gustavo (Perfis Disponíveis: Gustavo)
Platform: Windows 7 Home Basic Service Pack 1 (X64) Idioma: Português (Brasil)
Internet Explorer Versão 8 (Navegador padrão: Chrome)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(SlimWare Utilities, Inc.) C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Windows\System32\wusa.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registro (Whitelisted) ====================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13874392 1999-12-31] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-12-21] (AVAST Software)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2383040 2016-10-25] (Adobe Systems Incorporated)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-12-21] (AVAST Software)

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Hosts: 127.0.0.1 validation.sls.microsoft.com
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{48A1F945-C8A0-4938-ACEF-CB1656B40049}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-2291930349-3429565107-474410669-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pt-br/?ocid=iehp
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-12-21] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-12-21] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-12-21] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-12-21] (AVAST Software)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-20] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-20] (Microsoft Corporation)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-12-21]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-12-21]
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-12-21] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-12-21] (Oracle Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-25] (Adobe Systems)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-11-14] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-11-14] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-21] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-25] (Adobe Systems)

Chrome:
=======
CHR Profile: C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default [2017-03-01]
CHR Extension: (Google Apresentações) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-21]
CHR Extension: (Google Docs) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-21]
CHR Extension: (Google Drive) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-21]
CHR Extension: (YouTube) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-21]
CHR Extension: (Adobe Acrobat) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-02-06]
CHR Extension: (Planilhas do Google) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-21]
CHR Extension: (Documentos Google off-line) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-21]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-25]
CHR Extension: (Gmail) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-21]
CHR Extension: (Chrome Media Router) - C:\Users\Gustavo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-08]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

==================== Serviços (Whitelisted) ====================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-25] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2207960 2016-09-26] (Adobe Systems, Incorporated)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-12-21] (AVAST Software)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-12-12] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-12-12] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2016-12-12] (NVIDIA Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-12-21] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-12-21] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-12-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-12-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-12-21] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-12-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-12-21] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-12-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-12-21] (AVAST Software)
R0 mv61xx; C:\Windows\System32\DRIVERS\mv61xx.sys [181040 2010-10-26] (Marvell Semiconductor, Inc.)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-12-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [46016 2016-12-12] (NVIDIA Corporation)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16056 2017-03-01] (SlimWare Utilities, Inc.)

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Um Mês Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2017-03-01 15:10 - 2017-03-01 15:10 - 02423808 _____ (Farbar) C:\Users\Gustavo\Downloads\FRST64.exe
2017-03-01 15:10 - 2017-03-01 15:10 - 00014341 _____ C:\Users\Gustavo\Downloads\FRST.txt
2017-03-01 15:10 - 2017-03-01 15:10 - 00000000 ____D C:\FRST
2017-03-01 15:08 - 2017-03-01 15:08 - 32823032 _____ (Tweaking.com) C:\Users\Gustavo\Downloads\tweaking.com_windows_repair_aio_setup.exe
2017-03-01 15:03 - 2017-03-01 15:03 - 00001125 _____ C:\Users\Public\Desktop\DLL-Files.com Client.lnk
2017-03-01 15:03 - 2017-03-01 15:03 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\DLL-files.com
2017-03-01 15:03 - 2017-03-01 15:03 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\DFXCT
2017-03-01 15:03 - 2017-03-01 15:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DLL-Files.com Client
2017-03-01 15:03 - 2017-03-01 15:03 - 00000000 ____D C:\Program Files (x86)\DLL-Files.com Client
2017-03-01 15:02 - 2017-03-01 15:03 - 02729024 _____ (DLL-Files.com Client ) C:\Users\Gustavo\Downloads\clientsetup_fde-0.exe
2017-03-01 14:59 - 2017-03-01 14:59 - 00000000 ___HT C:\Windows\wusa.lock
2017-03-01 14:59 - 2017-03-01 14:59 - 00000000 ____D C:\cbab9155ebff000c3bdc9bee
2017-03-01 14:38 - 2017-03-01 14:38 - 01034556 _____ C:\Users\Gustavo\Downloads\Windows6.1-KB2999226-x64 (3).msu
2017-03-01 14:37 - 2017-03-01 14:37 - 01034556 _____ C:\Users\Gustavo\Downloads\Windows6.1-KB2999226-x64 (2).msu
2017-03-01 14:35 - 2017-03-01 14:35 - 01034556 _____ C:\Users\Gustavo\Downloads\Windows6.1-KB2999226-x64 (1).msu
2017-03-01 12:02 - 2017-03-01 12:02 - 01034556 _____ C:\Users\Gustavo\Downloads\Windows6.1-KB2999226-x64.msu
2017-03-01 12:02 - 2017-03-01 12:02 - 00000000 ____D C:\e141bc0b096d765f02ba
2017-03-01 11:59 - 2017-03-01 14:41 - 00000000 ___RD C:\Users\Gustavo\Creative Cloud Files
2017-03-01 11:59 - 2017-03-01 14:41 - 00000000 ____D C:\Users\Todos os Usuários\boost_interprocess
2017-03-01 11:59 - 2017-03-01 14:41 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-03-01 11:57 - 2017-03-01 11:57 - 00001298 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017 (32 Bit).lnk
2017-03-01 11:40 - 2017-03-01 11:40 - 15068056 _____ (Microsoft Corporation) C:\Users\Gustavo\Downloads\vc_redist.x64 (1).exe
2017-03-01 11:33 - 2017-03-01 11:34 - 14749120 _____ (Microsoft Corporation) C:\Users\Gustavo\Downloads\vc_redist.x64.exe
2017-03-01 11:27 - 2017-03-01 11:57 - 00000000 ____D C:\Users\Gustavo\Documents\Adobe
2017-03-01 11:27 - 2017-03-01 11:51 - 00001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk
2017-03-01 11:23 - 2017-03-01 11:26 - 00000000 ____D C:\Program Files\Common Files\Adobe
2017-03-01 11:23 - 2017-03-01 11:23 - 00000000 ____D C:\Program Files\Adobe
2017-03-01 11:22 - 2017-03-01 11:22 - 00001221 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2017-03-01 11:22 - 2017-03-01 11:22 - 00001209 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2017-03-01 09:44 - 2017-03-01 11:52 - 00000000 ____D C:\Users\Gustavo\Downloads\Adobe Photoshop CC 2017.0.0 (2016.10.12.r.53) Ml_Rus
2017-03-01 09:38 - 2017-03-01 09:38 - 00019358 _____ C:\Users\Gustavo\Downloads\93D58FDD7B1A903514409F962A5D7BC2983AFA74_www.CPturbo.org.torrent
2017-02-28 10:11 - 2017-02-28 10:14 - 00000000 ____D C:\Users\Gustavo\Downloads\Riverdale.S01E05.Chapter.Five.Heart.Of.Darkness.720p.NF.WEBRip.DD5.1.x264-NTb[rarbg]
2017-02-27 04:42 - 2017-02-27 04:42 - 00001756 _____ C:\Users\Gustavo\Downloads\ANA (1).txt
2017-02-27 04:42 - 2017-02-27 04:42 - 00000323 _____ C:\Users\Gustavo\Downloads\recomeço (1).txt
2017-02-27 04:25 - 2017-02-27 04:25 - 00001756 _____ C:\Users\Gustavo\Downloads\ANA.txt
2017-02-27 04:25 - 2017-02-27 04:25 - 00000323 _____ C:\Users\Gustavo\Downloads\recomeço.txt
2017-02-23 22:12 - 2017-02-23 22:12 - 00001293 _____ C:\Users\Gustavo\Desktop\Continuar a Instalação de WinRAR.lnk
2017-02-23 02:07 - 2017-02-28 10:16 - 00000000 ____D C:\Users\Gustavo\Desktop\Riverdale
2017-02-06 18:06 - 2017-02-07 18:09 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-02-06 18:06 - 2017-02-06 18:06 - 00000000 ____D C:\Users\Gustavo\AppData\LocalLow\Adobe
2017-02-06 18:05 - 2017-02-23 02:32 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-06 18:05 - 2017-02-06 18:05 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2017-02-06 18:04 - 2017-03-01 11:59 - 00000000 ____D C:\Users\Todos os Usuários\Adobe
2017-02-06 18:04 - 2017-03-01 11:59 - 00000000 ____D C:\ProgramData\Adobe
2017-02-06 18:04 - 2017-03-01 11:53 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-02-06 18:03 - 2017-03-01 14:41 - 00000000 ____D C:\Users\Gustavo\AppData\Local\Adobe
2017-02-06 18:02 - 2017-02-06 18:03 - 01844640 _____ (File Lite Fast ) C:\Users\Gustavo\Downloads\Baixaki_adobe-reader_VMoUqf.exe
2017-02-03 01:17 - 2017-03-01 09:42 - 00000000 ____D C:\Users\Gustavo\AppData\LocalLow\uTorrent
2017-02-03 00:49 - 2017-03-01 04:00 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\vlc
2017-02-03 00:48 - 2017-02-03 00:48 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\WinRAR
2017-02-03 00:47 - 2017-02-23 21:31 - 00000000 ____D C:\Users\Gustavo\Desktop\Arrow
2017-02-03 00:47 - 2017-02-23 02:11 - 00000000 ____D C:\Users\Gustavo\Desktop\Flash
2017-02-03 00:13 - 2017-02-03 00:13 - 03342040 _____ C:\Users\Gustavo\Downloads\Baixaki_winrar.exe
2017-02-03 00:13 - 2017-02-03 00:13 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-02-03 00:13 - 2017-02-03 00:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-02-03 00:13 - 2017-02-03 00:13 - 00000000 ____D C:\Program Files (x86)\WinRAR
2017-02-03 00:10 - 2017-02-03 00:10 - 00001066 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-02-03 00:10 - 2017-02-03 00:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-02-03 00:10 - 2017-02-03 00:10 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2017-02-03 00:09 - 2017-02-03 00:09 - 30533688 _____ C:\Users\Gustavo\Downloads\Baixaki_vlc-media-player.exe
2017-02-03 00:09 - 2017-02-03 00:09 - 01798216 _____ ( ) C:\Users\Gustavo\Downloads\Baixaki_winrar_Vc8MLE.exe
2017-02-03 00:08 - 2017-02-03 00:08 - 01798216 _____ ( ) C:\Users\Gustavo\Downloads\Baixaki_vlc-media-player_VeLnBb.exe
2017-02-02 23:50 - 2017-02-02 23:50 - 00002611 _____ C:\Users\Gustavo\Desktop\µTorrent.lnk
2017-02-02 23:50 - 2017-02-02 23:50 - 00002611 _____ C:\Users\Gustavo\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2017-02-02 23:50 - 2017-02-02 23:50 - 00000000 ___SD C:\Users\Gustavo\AppData\LocalLow\Temp
2017-02-02 23:49 - 2017-03-01 11:44 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\uTorrent
2017-02-02 23:49 - 2017-02-02 23:49 - 02370560 _____ (BitTorrent Inc.) C:\Users\Gustavo\Downloads\Baixaki_utorrent.exe
2017-02-02 23:48 - 2017-02-02 23:48 - 01798216 _____ ( ) C:\Users\Gustavo\Downloads\Baixaki_utorrent_VQCle5.exe

==================== Um Mês Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2017-03-01 15:05 - 2009-07-14 01:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-03-01 15:05 - 2009-07-14 01:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-03-01 15:00 - 2016-12-21 16:03 - 00000902 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-03-01 14:47 - 2009-07-14 14:55 - 00654272 _____ C:\Windows\system32\prfh0416.dat
2017-03-01 14:47 - 2009-07-14 14:55 - 00124724 _____ C:\Windows\system32\prfc0416.dat
2017-03-01 14:47 - 2009-07-14 02:13 - 01491932 _____ C:\Windows\system32\PerfStringBackup.INI
2017-03-01 14:47 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\inf
2017-03-01 14:42 - 2016-12-21 17:47 - 00000000 ____D C:\Users\Todos os Usuários\NVIDIA
2017-03-01 14:42 - 2016-12-21 17:47 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-01 14:40 - 2016-12-21 16:06 - 00002844 _____ C:\Windows\System32\Tasks\SlimDrivers Startup
2017-03-01 14:40 - 2016-12-21 16:06 - 00000414 _____ C:\Windows\Tasks\SlimDrivers Startup.job
2017-03-01 14:40 - 2016-12-21 16:05 - 00016056 _____ (SlimWare Utilities, Inc.) C:\Windows\system32\Drivers\SWDUMon.sys
2017-03-01 14:40 - 2009-07-14 02:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-03-01 14:38 - 2016-12-21 17:47 - 00007609 _____ C:\Users\Todos os Usuários\NvTelemetryContainer.log_backup1
2017-03-01 14:38 - 2016-12-21 17:47 - 00007609 _____ C:\ProgramData\NvTelemetryContainer.log_backup1
2017-03-01 14:38 - 2016-12-21 15:53 - 00000000 ____D C:\Users\Gustavo
2017-03-01 12:02 - 2016-12-21 16:03 - 00000000 ____D C:\Users\Gustavo\AppData\Roaming\Adobe
2017-03-01 11:57 - 2016-12-21 18:50 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2017-03-01 11:41 - 2016-12-21 17:36 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache
2017-03-01 11:41 - 2016-12-21 17:36 - 00000000 ____D C:\ProgramData\Package Cache
2017-03-01 11:20 - 2009-07-14 00:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2017-02-15 01:00 - 2016-12-21 16:03 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-02-15 01:00 - 2016-12-21 16:03 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-02-15 01:00 - 2016-12-21 16:03 - 00003840 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-02-15 01:00 - 2016-12-21 16:03 - 00000000 ____D C:\Windows\system32\Macromed
2017-02-15 01:00 - 2016-12-21 16:02 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-02-06 17:51 - 2016-12-21 17:44 - 00002193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-06 17:51 - 2016-12-21 17:44 - 00002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk

==================== Arquivos na raiz de alguns diretórios =======

2016-12-21 17:13 - 2016-12-21 17:13 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2016-12-21 17:47 - 2017-03-01 14:40 - 0002938 _____ () C:\ProgramData\NvTelemetryContainer.log
2016-12-21 17:47 - 2017-03-01 14:38 - 0007609 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1

Alguns arquivos em TEMP:
====================
2017-02-23 22:12 - 2017-02-23 22:12 - 1798216 _____ ( ) C:\Users\Gustavo\AppData\Local\Temp\ICReinstall_Baixaki_winrar_Vc8MLE.exe

==================== Bamital & volsnap ======================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\system32\services.exe => O arquivo é assinado digitalmente
C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente
C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente

LastRegBack: 2011-02-07 00:54

==================== Fim de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité