cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 17-04-2017 01
Executado por samuel (ATENÇÃO: O usuário não é o administrador) em MÁRCIA (18-04-2017 20:38:21)
Executando a partir de C:\Users\samuel\Downloads
Perfis Carregados: Gabriel & Marcia & samuel (Perfis Disponíveis: Gabriel & Marcia & samuel)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Idioma: Português (Brasil)
Internet Explorer Versão 9 (Navegador padrão: Chrome)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

Falha ao acessar processo -> smss.exe
Falha ao acessar processo -> csrss.exe
Falha ao acessar processo -> wininit.exe
Falha ao acessar processo -> services.exe
Falha ao acessar processo -> lsass.exe
Falha ao acessar processo -> lsm.exe
Falha ao acessar processo -> svchost.exe
Falha ao acessar processo -> svchost.exe
Falha ao acessar processo -> svchost.exe
Falha ao acessar processo -> svchost.exe
Falha ao acessar processo -> svchost.exe
Falha ao acessar processo -> svchost.exe
Falha ao acessar processo -> svchost.exe
Falha ao acessar processo -> AvastSvc.exe
Falha ao acessar processo -> spoolsv.exe
Falha ao acessar processo -> svchost.exe
Falha ao acessar processo -> afwServ.exe
Falha ao acessar processo -> armsvc.exe
Falha ao acessar processo -> mDNSResponder.exe
Falha ao acessar processo -> dragon_updater.exe
Falha ao acessar processo -> svchost.exe
Falha ao acessar processo -> LMIGuardianSvc.exe
Falha ao acessar processo -> ramaint.exe
Falha ao acessar processo -> mcsacore.exe
Falha ao acessar processo -> WLIDSVC.EXE
Falha ao acessar processo -> LogMeIn.exe
Falha ao acessar processo -> WLIDSVCM.EXE
Falha ao acessar processo -> aswidsagenta.exe
Falha ao acessar processo -> svchost.exe
Falha ao acessar processo -> svchost.exe
Falha ao acessar processo -> svchost.exe
Falha ao acessar processo -> WUDFHost.exe
Falha ao acessar processo -> WmiPrvSE.exe
Falha ao acessar processo -> sppsvc.exe
Falha ao acessar processo -> SearchIndexer.exe
Falha ao acessar processo -> csrss.exe
Falha ao acessar processo -> winlogon.exe
Falha ao acessar processo -> taskhost.exe
Falha ao acessar processo -> dwm.exe
Falha ao acessar processo -> explorer.exe
Falha ao acessar processo -> LogMeInSystray.exe
Falha ao acessar processo -> AvastUI.exe
Falha ao acessar processo -> uTorrent.exe
Falha ao acessar processo -> CCleaner64.exe
Falha ao acessar processo -> utorrentie.exe
Falha ao acessar processo -> utorrentie.exe
Falha ao acessar processo -> OriginWebHelperService.exe
Falha ao acessar processo -> taskeng.exe
Falha ao acessar processo -> AdobeARM.exe
Falha ao acessar processo -> AppleMobileDeviceService.exe
Falha ao acessar processo -> iTunesHelper.exe
Falha ao acessar processo -> LogonUI.exe
Falha ao acessar processo -> WUDFHost.exe
Falha ao acessar processo -> csrss.exe
Falha ao acessar processo -> winlogon.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Falha ao acessar processo -> iPodService.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Falha ao acessar processo -> SearchProtocolHost.exe
Falha ao acessar processo -> SearchFilterHost.exe

==================== Registro (Whitelisted) ====================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-04-07] (AVAST Software)
HKLM\...\Run: [LogMeIn GUI] => C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [423424 2017-04-08] (LogMeIn, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-03-22] (Apple Inc.)
HKU\S-1-5-21-504727180-2212920110-1669879925-1006\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-504727180-2212920110-1669879925-1006\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-504727180-2212920110-1669879925-1006\...\Policies\Explorer: [NoWindowsUpdate] 1
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-04-07] (AVAST Software)
GroupPolicy: Restrição <======= ATENÇÃO
GroupPolicy\User: Restrição <======= ATENÇÃO

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Hosts: Há mais de uma entrada no Hosts. Veja a seção Hosts do Addition.txt
Tcpip\Parameters: [DhcpNameServer] 200.222.122.133 200.165.132.148 192.168.1.1
Tcpip\..\Interfaces\{1092B604-3200-476D-877F-85B2BAA45679}: [DhcpNameServer] 200.222.122.133 200.165.132.148 192.168.1.1
Tcpip\..\Interfaces\{F42089FD-7F0E-44C1-AA25-B2DFE95AE743}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
URLSearchHook: [S-1-5-21-504727180-2212920110-1669879925-1001] ATENÇÃO => A URLSearchHook Padrão está ausente
URLSearchHook: [S-1-5-21-504727180-2212920110-1669879925-1002] ATENÇÃO => A URLSearchHook Padrão está ausente
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-07] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-03-27] (McAfee, Inc.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2012-11-29] (RealDownloader)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-26] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2013-02-08] (Sun Microsystems, Inc.)
BHO-x32: Auxiliar de Conexão do Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-03-27] (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2013-02-08] (Sun Microsystems, Inc.)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM-x32 - Sem Nome - {82E1477C-B154-48D3-9891-33D83C26BCD3} - Nenhum Arquivo
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-03-27] (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-03-27] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-03-27] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-03-27] (McAfee, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2011-11-03] (Skype Technologies)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF Extension: (McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2017-02-14]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF => não encontrado (a)
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF => não encontrado (a)
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF HKLM-x32\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-02-09] [não assinado]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2013-02-09] [não assinado]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF => não encontrado (a)
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF => não encontrado (a)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1228198.dll [2017-02-27] (Adobe Systems, Inc.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2013-04-02] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=1.6.0_39 -> C:\Windows\SysWOW64\npdeployJava1.dll [2013-02-08] (Sun Microsystems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll [2013-02-08] (Sun Microsystems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-22] (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.0.282 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll [2013-02-09] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2012-11-29] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2012-11-29] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2012-11-29] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.0.282 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll [2013-02-09] (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2012-11-29] (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default [2017-04-18]
CHR Extension: (Google Drive) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-07]
CHR Extension: (YouTube) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-07]
CHR Extension: (Avast SafePrice) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-04-18]
CHR Extension: (Documentos Google off-line) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-07]
CHR Extension: (http://www.filmesonlinegratis.net/) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\golbgngmocddeeekaddgaejknpfblcdc [2017-03-07]
CHR Extension: (http://translate.google.com.br/#pt/en/preto) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\iilfknhhfmdnfmihpgbgbfedhmgjjdgh [2017-03-07]
CHR Extension: (http://www.friv.com/) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdibpocepjhmjabdkmkgbhnpdjooamfn [2017-03-07]
CHR Extension: (http://clickjogos.uol.com.br/) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmpiplpookhngldieonhglmkicfkjlmg [2017-03-07]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
CHR Extension: (Gmail) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-07]
CHR Extension: (Chrome Media Router) - C:\Users\samuel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-18]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2017-02-10]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eooncjejnppfjjklapaamhcdmjbilmde] - C:\Users\Marcia\AppData\Roaming\Delta\delta.crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2017-02-10]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2012-11-29]

==================== Serviços (Whitelisted) ====================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-03-05] (SUPERAntiSpyware.com)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-03-17] (Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7398336 2017-04-07] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [261712 2017-04-07] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [310496 2017-04-07] (AVAST Software)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2139328 2014-05-27] (Comodo Security Solutions, Inc.)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [Arquivo não assinado]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [Arquivo não assinado]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1037824 2009-09-20] (Hewlett-Packard Co.) [Arquivo não assinado]
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-13] (Microsoft Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [419304 2017-04-08] (LogMeIn, Inc.)
R2 LMIMaint; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [509416 2017-04-08] (LogMeIn, Inc.)
R2 LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [407424 2012-11-29] (LogMeIn, Inc.)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [188264 2017-03-27] (McAfee, Inc.)
S4 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-06-10] (Nero AG)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [Arquivo não assinado]
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-13] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R2 nsi; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-13] (Microsoft Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2124296 2017-04-08] (Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2185232 2017-04-08] (Electronic Arts)
S4 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.) [Arquivo não assinado]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [Arquivo não assinado]
S4 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation)
S3 WMPNetworkSvc; não ImagePath

===================== Drivers (Whitelisted) ======================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [307736 2017-04-07] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-04-07] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334088 2017-04-07] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-04-07] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-04-07] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [32600 2017-04-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [127112 2017-04-07] (AVAST Software)
R3 aswNetNd6; C:\Windows\System32\DRIVERS\aswNetNd6.sys [29432 2017-04-07] (AVAST Software)
R1 aswNetSec; C:\Windows\system32\drivers\aswNetSec.sys [505880 2017-04-07] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [101152 2017-04-07] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-04-07] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1005048 2017-04-07] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [556784 2017-04-07] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [164064 2017-04-07] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [339696 2017-04-07] (AVAST Software)
S2 LMIInfo; C:\Windows\system32\drivers\LMIInfo.sys [30432 2017-01-11] (LogMeIn, Inc.)
S4 LMIRfsClientNP; não ImagePath
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [46240 2016-06-06] (McAfee, Inc.)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
U1 aswbdisk; não ImagePath
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Três Meses Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2017-04-18 20:38 - 2017-04-18 20:38 - 00022841 _____ C:\Users\samuel\Downloads\FRST.txt
2017-04-18 20:38 - 2017-04-18 20:38 - 00000000 ____D C:\FRST
2017-04-18 20:37 - 2017-04-18 20:37 - 02424832 _____ (Farbar) C:\Users\samuel\Downloads\FRST64.exe
2017-04-18 20:26 - 2017-04-18 20:26 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2017-04-18 20:26 - 2017-04-18 20:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2017-04-18 20:26 - 2017-04-18 20:26 - 00000000 ____D C:\Program Files\iPod
2017-04-18 20:24 - 2017-04-18 20:24 - 28273902 _____ C:\Users\samuel\Downloads\feydevocionrapida.rar
2017-04-18 19:58 - 2017-04-18 20:06 - 257659208 _____ (Apple Inc.) C:\Users\samuel\Downloads\iTunes64Setup.exe
2017-04-18 19:57 - 2017-04-18 20:08 - 62914602 _____ C:\Users\samuel\Downloads\FORBO5.rar
2017-04-18 19:57 - 2017-04-18 20:03 - 56284020 _____ C:\Users\samuel\Downloads\JOY57.rar
2017-04-18 19:56 - 2017-04-18 20:08 - 111727833 _____ C:\Users\samuel\Downloads\JOY40.rar
2017-04-17 23:25 - 2017-04-18 20:26 - 00000000 ____D C:\Program Files\iTunes
2017-04-17 23:18 - 2017-04-17 23:23 - 257659208 _____ (Apple Inc.) C:\Users\Gabriel\Downloads\iTunes64Setup (1).exe
2017-04-17 23:17 - 2017-04-17 23:17 - 00000000 ____D C:\Windows\system32\appmgmt
2017-04-17 22:50 - 2017-04-17 22:50 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2017-04-17 22:39 - 2017-04-17 22:43 - 257659208 _____ (Apple Inc.) C:\Users\Gabriel\Downloads\iTunes64Setup.exe
2017-04-17 21:02 - 2017-04-17 21:02 - 00000000 ____D C:\Users\Gabriel\AppData\Local\Apple
2017-04-14 13:29 - 2017-04-14 13:29 - 00043292 _____ C:\Users\Gabriel\Downloads\ComprovanteRendimento2016 (1).pdf
2017-04-14 13:24 - 2017-04-14 13:24 - 00043292 _____ C:\Users\Gabriel\Downloads\ComprovanteRendimento2016.pdf
2017-04-11 13:12 - 2017-04-17 20:56 - 00000000 ____D C:\Users\Gabriel\AppData\LocalLow\uTorrent
2017-04-08 17:46 - 2017-01-11 03:08 - 00030432 _____ (LogMeIn, Inc.) C:\Windows\system32\Drivers\LMIInfo.sys
2017-04-07 14:35 - 2017-04-07 14:35 - 00109224 _____ C:\Users\Gabriel\AppData\Local\GDIPFONTCACHEV1.DAT
2017-04-07 14:33 - 2017-04-07 14:33 - 00125994 _____ C:\Users\samuel\Desktop\Pedido_57669421.pdf
2017-04-07 14:30 - 2017-04-07 14:30 - 00000000 ____D C:\Users\samuel\AppData\Local\Apple
2017-04-07 14:15 - 2017-04-07 14:15 - 00008463 _____ C:\Users\samuel\Desktop\Contracheque.pdf
2017-04-07 14:14 - 2017-04-07 14:14 - 00008463 _____ C:\Users\samuel\Downloads\Contracheque.pdf
2017-04-07 13:47 - 2017-04-07 13:47 - 00104925 _____ C:\Users\samuel\Desktop\chrome-extension___mhjfbmdgcfjbbpaeojofohoefgiehjai_index.pdf
2017-04-07 13:19 - 2017-04-07 13:19 - 00000000 ____D C:\Program Files\Common Files\AV
2017-04-07 12:22 - 2017-04-07 12:22 - 00000000 ___HD C:\$AV_ASW
2017-04-07 12:18 - 2017-04-07 12:18 - 00399944 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-04-07 12:18 - 2017-04-07 12:17 - 00505880 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNetSec.sys
2017-04-07 12:17 - 2017-04-07 12:17 - 00029432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNetNd6.sys
2017-04-03 13:20 - 2017-04-03 13:20 - 00000000 __SHD C:\found.001
2017-03-30 13:27 - 2017-03-30 13:27 - 00002705 _____ C:\Users\samuel\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2017-03-30 13:24 - 2017-04-07 12:22 - 00000000 ____D C:\Users\samuel\AppData\Roaming\uTorrent
2017-03-29 17:08 - 2017-03-29 17:08 - 00112128 _____ C:\Users\samuel\Downloads\copy_of_FORMULRIO_SIGEPE_v1.21.xls
2017-03-28 14:54 - 2017-03-28 14:54 - 00000000 __SHD C:\found.000
2017-03-19 00:53 - 2017-03-19 00:53 - 00000000 ____D C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-03-19 00:53 - 2017-03-19 00:53 - 00000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-03-19 00:53 - 2017-03-19 00:53 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-03-19 00:53 - 2017-03-19 00:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-03-19 00:52 - 2017-03-19 00:53 - 00000000 ____D C:\Users\Usuário Padrão\AppData\Roaming\Adobe
2017-03-19 00:52 - 2017-03-19 00:53 - 00000000 ____D C:\Users\Default\AppData\Roaming\Adobe
2017-03-19 00:52 - 2017-03-19 00:53 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Adobe
2017-03-19 00:52 - 2017-03-19 00:52 - 00000000 ____D C:\Users\Usuário Padrão\AppData\Local\Adobe
2017-03-19 00:52 - 2017-03-19 00:52 - 00000000 ____D C:\Users\Default\AppData\Local\Adobe
2017-03-19 00:52 - 2017-03-19 00:52 - 00000000 ____D C:\Users\Default User\AppData\Local\Adobe
2017-03-17 22:45 - 2017-03-22 13:25 - 00221794 _____ C:\Windows\ntbtlog.txt
2017-03-12 13:17 - 2017-03-12 13:17 - 00000000 ____D C:\Users\Gabriel\.QtWebEngineProcess
2017-03-12 13:17 - 2017-03-12 13:17 - 00000000 ____D C:\Users\Gabriel\.Origin
2017-03-08 23:28 - 2017-03-08 23:34 - 28446306 _____ C:\Users\samuel\Downloads\Não confirmado 830701.crdownload
2017-03-08 23:19 - 2017-03-08 23:19 - 323251358 _____ C:\Users\samuel\Downloads\BJK-11.rar
2017-03-08 23:15 - 2017-03-08 23:15 - 122840000 _____ C:\Users\samuel\Downloads\BJK-15.rar
2017-03-08 22:19 - 2017-03-08 22:27 - 169461730 _____ C:\Users\samuel\Downloads\TS LTB.zip
2017-03-08 22:11 - 2017-03-08 22:11 - 00000000 ____D C:\Users\samuel\Desktop\Aldous Huxley - Admirável Mundo Novo.epub
2017-03-08 21:40 - 2017-03-08 21:40 - 00000324 _____ C:\Users\samuel\Desktop\iExplorer.appref-ms
2017-03-08 21:40 - 2017-03-08 21:40 - 00000000 ____D C:\Users\samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macroplant LLC
2017-03-08 21:38 - 2017-03-08 22:10 - 00000000 ____D C:\Users\samuel\AppData\Local\Deployment
2017-03-08 21:38 - 2017-03-08 21:38 - 00000000 ____D C:\Users\samuel\AppData\Local\Apps\2.0
2017-03-08 21:24 - 2017-03-08 21:24 - 00596184 _____ () C:\Users\samuel\Downloads\iExplorer-4.0.4 (2).exe
2017-03-08 08:29 - 2017-03-10 19:14 - 00000000 _____ C:\Windows\SysWOW64\last.dump
2017-03-08 06:59 - 2017-03-08 06:59 - 00033359 _____ C:\Users\samuel\Downloads\jackie2016720pblurayx264ytsag-portuguese-105282.zip
2017-03-08 05:50 - 2017-03-08 05:50 - 00000000 ____D C:\Users\samuel\AppData\Local\LogMeIn
2017-03-08 00:01 - 2017-03-08 00:01 - 00596184 _____ () C:\Users\samuel\Downloads\iExplorer-4.0.4 (1).exe
2017-03-08 00:00 - 2017-03-08 00:00 - 00000000 ____D C:\Users\samuel\AppData\Local\WinZip
2017-03-08 00:00 - 2013-11-18 04:53 - 00000000 ____D C:\Users\samuel\Downloads\iTools
2017-03-07 23:59 - 2017-03-08 00:00 - 03246852 _____ C:\Users\samuel\Downloads\iTools1115E.zip
2017-03-07 23:56 - 2017-03-07 23:57 - 00596184 _____ () C:\Users\samuel\Downloads\iExplorer-4.0.4.exe
2017-03-07 23:24 - 2017-03-08 22:32 - 00000000 ____D C:\Users\samuel\AppData\Roaming\vlc
2017-03-07 22:44 - 2017-03-07 22:44 - 00146030 _____ C:\Users\samuel\Desktop\renderbillet.pdf
2017-03-07 22:44 - 2017-03-07 22:44 - 00000000 ____D C:\Users\samuel\AppData\Roaming\Adobe
2017-03-07 22:44 - 2017-03-07 22:44 - 00000000 ____D C:\Users\samuel\AppData\LocalLow\Adobe
2017-03-07 22:44 - 2017-03-07 22:44 - 00000000 ____D C:\Users\samuel\AppData\Local\Adobe
2017-03-07 21:58 - 2017-03-07 21:59 - 30533688 _____ C:\Users\samuel\Downloads\vlc-media-player-2-2-4.exe
2017-03-07 21:01 - 2017-03-07 21:06 - 00000000 ____D C:\Users\samuel\AppData\LocalLow\HPAppData
2017-03-07 21:01 - 2017-03-07 21:01 - 00000000 ____D C:\Users\samuel\AppData\Roaming\RealNetworks
2017-03-07 20:59 - 2017-03-07 20:59 - 00039897 _____ C:\Users\samuel\Downloads\jackie.(2016).pob.1cd.(6879061).zip
2017-03-07 20:58 - 2017-03-07 20:58 - 00062830 _____ C:\Users\samuel\Downloads\fences.(2016).pob.1cd.(6843601).zip
2017-03-07 20:56 - 2017-03-07 20:56 - 00000000 ____D C:\Users\samuel\AppData\Roaming\Media Player Classic
2017-03-07 20:06 - 2017-03-07 20:06 - 00000000 ____D C:\Users\samuel\AppData\Roaming\AVAST Software
2017-03-07 20:06 - 2017-03-07 20:06 - 00000000 ____D C:\Users\samuel\AppData\Local\CEF
2017-03-07 20:00 - 2017-03-07 20:00 - 00109224 _____ C:\Users\samuel\AppData\Local\GDIPFONTCACHEV1.DAT
2017-03-07 19:59 - 2017-03-07 19:59 - 00000000 ____D C:\Users\samuel\AppData\Local\Apple Computer
2017-03-07 19:58 - 2017-03-07 19:58 - 00000000 ____D C:\Users\samuel\AppData\Roaming\WinRAR
2017-03-07 19:55 - 2017-03-07 20:06 - 00000000 ____D C:\Users\samuel\AppData\Local\Google
2017-03-07 19:55 - 2017-03-07 20:05 - 00000000 ____D C:\Users\samuel\AppData\Roaming\Apple Computer
2017-03-07 19:55 - 2017-03-07 19:55 - 00001419 _____ C:\Users\samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-03-07 19:55 - 2017-03-07 19:55 - 00001385 _____ C:\Users\samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2017-03-07 19:55 - 2017-03-07 19:55 - 00000836 __RSH C:\Users\samuel\ntuser.pol
2017-03-07 19:55 - 2017-03-07 19:55 - 00000020 ___SH C:\Users\samuel\ntuser.ini
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\Modelos
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\Meus documentos
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\Menu Iniciar
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\Documents\Minhas músicas
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\Documents\Minhas imagens
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\Documents\Meus vídeos
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\Dados de aplicativos
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\Configurações locais
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\AppData\Local\Histórico
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\AppData\Local\Dados de aplicativos
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\Ambiente de rede
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 _SHDL C:\Users\samuel\Ambiente de impressão
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 ____D C:\Users\samuel\AppData\LocalLow\COMODO
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 ____D C:\Users\samuel\AppData\Local\VirtualStore
2017-03-07 19:55 - 2017-03-07 19:55 - 00000000 ____D C:\Users\samuel
2017-03-07 19:55 - 2013-02-08 14:05 - 00000000 ____D C:\Users\samuel\AppData\Roaming\Macromedia
2017-03-07 19:55 - 2010-11-21 06:47 - 00000000 ____D C:\Users\samuel\AppData\Roaming\Media Center Programs
2017-03-07 19:36 - 2017-03-09 13:01 - 00000000 ____D C:\Users\Gabriel\AppData\Roaming\Apple Computer
2017-03-07 19:36 - 2017-03-07 19:36 - 00000000 ____D C:\Users\Todos os Usuários\Apple Computer
2017-03-07 19:36 - 2017-03-07 19:36 - 00000000 ____D C:\Users\Gabriel\AppData\Local\Apple Computer
2017-03-07 19:36 - 2017-03-07 19:36 - 00000000 ____D C:\ProgramData\Apple Computer
2017-03-07 19:35 - 2017-04-17 22:50 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2017-03-07 19:34 - 2017-04-17 23:14 - 00000000 ____D C:\Program Files\Common Files\Apple
2017-03-07 19:34 - 2017-03-07 19:35 - 00000000 ____D C:\Users\Todos os Usuários\Apple
2017-03-07 19:34 - 2017-03-07 19:35 - 00000000 ____D C:\ProgramData\Apple
2017-03-07 19:34 - 2017-03-07 19:34 - 00000000 ____D C:\Program Files\Bonjour
2017-03-07 19:34 - 2017-03-07 19:34 - 00000000 ____D C:\Program Files (x86)\Bonjour
2017-03-07 19:23 - 2017-03-07 19:33 - 177092424 _____ (Apple Inc.) C:\Users\Gabriel\Downloads\iTunes6464Setup.exe
2017-03-07 12:42 - 2017-03-07 12:42 - 00001043 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-03-07 12:41 - 2017-04-07 12:18 - 00032600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-03-07 12:28 - 2017-03-07 12:28 - 00000000 ____D C:\Users\Gabriel\AppData\Roaming\AVAST Software
2017-03-07 12:28 - 2017-03-07 12:28 - 00000000 ____D C:\Users\Gabriel\AppData\Local\CEF
2017-03-07 12:26 - 2017-04-07 12:18 - 00556784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-03-07 12:26 - 2017-04-07 12:18 - 00339696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-03-07 12:26 - 2017-04-07 12:18 - 00164064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-03-07 12:26 - 2017-04-07 12:18 - 00127112 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-03-07 12:26 - 2017-04-07 12:18 - 00101152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-03-07 12:26 - 2017-04-07 12:18 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-03-07 12:26 - 2017-04-07 12:18 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-03-07 12:26 - 2017-03-07 12:26 - 00992960 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-03-07 12:26 - 2017-03-07 12:26 - 00921280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-03-07 12:25 - 2017-04-07 12:18 - 01005048 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-03-07 12:25 - 2017-04-07 12:17 - 00334088 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-03-07 12:25 - 2017-04-07 12:17 - 00307736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-03-07 12:25 - 2017-04-07 12:17 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-03-07 12:25 - 2017-04-07 12:17 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-03-07 12:12 - 2017-03-07 12:12 - 06654960 _____ C:\Users\Gabriel\Downloads\avast_free_antivirus_setup_online_cnet2.exe
2017-03-07 12:09 - 2017-03-07 12:14 - 160710726 _____ C:\Users\Gabriel\Downloads\Aladdin Sane (30th Anniversary Edition).zip
2017-03-07 10:57 - 2017-04-02 21:15 - 00000000 ___SD C:\Users\Gabriel\AppData\LocalLow\Temp
2017-03-07 10:52 - 2017-03-07 10:52 - 02405056 _____ (BitTorrent Inc.) C:\Users\Gabriel\Downloads\uTorrent (1).exe
2017-03-06 22:00 - 2017-03-06 22:01 - 00416992 _____ C:\Windows\system32\FNTCACHE.DAT
2017-03-05 22:01 - 2017-03-05 22:02 - 09261616 _____ (Piriform Ltd) C:\Users\Gabriel\Downloads\ccsetup527.exe
2017-03-05 12:13 - 2017-03-05 12:13 - 00833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2017-03-05 12:13 - 2017-03-05 12:13 - 00410624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\systemcpl.dll
2017-03-05 12:13 - 2017-03-05 12:13 - 00113543 _____ C:\Windows\SysWOW64\slmgr.vbs
2017-03-05 12:13 - 2017-03-05 12:13 - 00002048 _____ C:\Windows\SysWOW64\winver.exe
2017-03-05 12:13 - 2017-03-05 12:13 - 00001536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppcomapi.dll
2017-03-05 11:51 - 2017-03-05 11:52 - 19844976 _____ (DsNET Corp ) C:\Users\Gabriel\Downloads\aTube_Catcher_ATU3_9110.exe
2017-03-05 11:50 - 2017-03-05 11:51 - 19844976 _____ (DsNET Corp ) C:\Users\Gabriel\Downloads\aTube_Catcher.exe
2017-03-05 11:48 - 2017-03-05 11:48 - 00000000 ____D C:\Users\Gabriel\AppData\Local\Ahead
2017-03-05 11:44 - 2017-03-05 11:48 - 00000000 ____D C:\Users\Gabriel\AppData\Roaming\vlc
2017-03-05 11:43 - 2017-03-05 11:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-03-05 11:43 - 2017-03-05 11:43 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2017-03-05 06:11 - 2010-11-21 00:23 - 00345088 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
2017-03-05 01:48 - 2017-03-05 01:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2017-03-05 01:48 - 2017-03-05 01:48 - 00000000 ____D C:\Program Files\VS Revo Group
2017-03-05 01:35 - 2017-03-05 01:35 - 00000000 ____D C:\SUPERDelete
2017-03-04 23:23 - 2017-03-04 23:23 - 00000000 ____D C:\Users\Gabriel\Downloads\ophcrack-vista-livecd-3.6.0
2017-03-04 14:31 - 2017-03-04 14:31 - 00000000 ____D C:\Users\Gabriel\Downloads\Hirens.BootCD.15.2
2017-03-04 13:50 - 2017-03-04 13:50 - 01972424 _____ C:\Users\Gabriel\Downloads\wrar540 (1).exe
2017-03-04 13:37 - 2017-03-04 13:48 - 621283886 _____ C:\Users\Gabriel\Downloads\Hirens.BootCD.15.2.zip
2017-03-04 03:11 - 2017-03-05 11:48 - 00000110 _____ C:\Users\Gabriel\AppData\default.pls
2017-02-18 23:26 - 2017-03-19 00:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-02-15 15:58 - 2017-04-18 20:38 - 00000000 ____D C:\Users\Gabriel\AppData\Roaming\uTorrent
2017-02-15 11:01 - 2017-02-15 11:01 - 00000000 ____H C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Coinstaller_Critical.Wdf
2017-02-15 11:01 - 2012-07-26 01:55 - 00785512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2017-02-15 11:01 - 2012-07-26 01:55 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2017-02-15 11:01 - 2012-07-25 23:36 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2017-02-15 11:01 - 2012-06-02 11:35 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2017-02-11 21:11 - 2017-04-08 18:10 - 00000000 ____D C:\Users\Gabriel\Desktop\musicas
2017-02-11 20:57 - 2017-02-11 20:57 - 00374899 _____ C:\Users\Gabriel\video-1486852376.mp4
2017-02-11 20:57 - 2017-02-11 20:57 - 00364702 _____ C:\Users\Gabriel\video-1486852560.mp4
2017-02-10 16:48 - 2017-02-10 16:48 - 01129376 _____ (Google Inc.) C:\Users\Gabriel\Downloads\ChromeSetup.exe

==================== Três Meses Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2017-04-18 20:36 - 2009-07-14 01:45 - 00016832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-18 20:36 - 2009-07-14 01:45 - 00016832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-18 17:12 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\system32\NDF
2017-04-17 23:32 - 2010-11-21 06:37 - 00705332 _____ C:\Windows\system32\prfh0416.dat
2017-04-17 23:32 - 2010-11-21 06:37 - 00147176 _____ C:\Windows\system32\prfc0416.dat
2017-04-17 23:32 - 2009-07-14 02:13 - 01633950 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-17 23:32 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\inf
2017-04-17 21:01 - 2014-07-17 15:33 - 00000000 ____D C:\Users\Todos os Usuários\Origin
2017-04-17 21:01 - 2014-07-17 15:33 - 00000000 ____D C:\ProgramData\Origin
2017-04-17 20:39 - 2014-01-29 06:10 - 00000988 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Control Panel.lnk
2017-04-17 20:39 - 2013-06-07 12:13 - 00001024 _____ C:\.rnd
2017-04-17 20:39 - 2013-02-09 16:56 - 00000000 ____D C:\Users\Todos os Usuários\LogMeIn
2017-04-17 20:39 - 2013-02-09 16:56 - 00000000 ____D C:\ProgramData\LogMeIn
2017-04-17 20:39 - 2009-07-14 02:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-11 13:48 - 2014-04-10 12:20 - 00566272 ___SH C:\Users\Gabriel\Thumbs.db
2017-04-11 13:19 - 2013-02-10 16:14 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-04-11 13:19 - 2013-02-10 16:14 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-04-11 13:19 - 2013-02-08 13:18 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-04-11 13:19 - 2013-02-08 13:18 - 00000000 ____D C:\Windows\system32\Macromed
2017-04-10 16:45 - 2013-02-08 12:56 - 00000000 ____D C:\Users\Gabriel
2017-04-08 17:56 - 2014-07-17 15:32 - 00000000 ____D C:\Program Files (x86)\Origin
2017-04-08 17:46 - 2013-02-09 16:56 - 00000000 ____D C:\Program Files (x86)\LogMeIn
2017-04-08 17:38 - 2013-02-09 16:56 - 00107488 _____ (LogMeIn, Inc.) C:\Windows\system32\LMIinit.dll
2017-04-07 12:19 - 2013-02-10 16:23 - 00002193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-07 12:19 - 2013-02-10 16:23 - 00002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-07 12:18 - 2013-02-07 16:42 - 00000000 ____D C:\Users\Todos os Usuários\AVAST Software
2017-04-07 12:18 - 2013-02-07 16:42 - 00000000 ____D C:\ProgramData\AVAST Software
2017-04-04 14:05 - 2014-07-17 16:05 - 00000000 ____D C:\Users\Gabriel\AppData\Roaming\Origin
2017-03-30 12:43 - 2013-02-07 22:28 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-03-19 00:53 - 2013-02-07 15:44 - 00000000 ____D C:\Program Files (x86)\WinRAR
2017-03-19 00:52 - 2013-02-09 00:06 - 00000000 ____D C:\Windows\SysWOW64\Adobe

==================== Arquivos na raiz de alguns diretórios =======

2013-02-09 23:07 - 2013-02-10 00:08 - 0002643 _____ () C:\ProgramData\hpzinstall.log

==================== Bamital & volsnap ======================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\system32\services.exe => O arquivo é assinado digitalmente
C:\Windows\system32\User32.dll
[2010-11-21 00:24] - [2010-11-21 00:24] - 1008640 ____A (Microsoft Corporation) E573BD9AB55C8E333C202B9E255F972E

C:\Windows\SysWOW64\User32.dll
[2017-03-05 12:13] - [2017-03-05 12:13] - 0833024 ____A (Microsoft Corporation) 2C9CC9F492CA596B1B9FC1AE5E916356

C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente


ATENÇÃO: ==> Não foi possível acessar BCD. O usuário não é o administrador

==================== Fim de FRST.txt ============================

Publicité


Signaler le contenu de ce document

Publicité