Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão:07-02-2016 Executado por Abdias (administrador) em ABDIAS (16-02-2016 23:25:43) Executando a partir de C:\Users\Abdias\Downloads Perfis Carregados: Abdias (Perfis Disponíveis: Abdias & Administrador & Convidado) Platform: Windows 10 Home Single Language Versão 1511 (X64) Idioma: Português (Brasil) Internet Explorer Versão 11 (Navegador padrão: Chrome) Modo da Inicialização: Normal Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\QQPCRTP.exe () C:\Program Files (x86)\UPCleaner\1.0.27.12725\UGSvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe () C:\Program Files (x86)\Hotkey\PowerBiosServer.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\QQPCTray.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (© 2015 Microsoft Corporation) C:\Users\Abdias\AppData\Local\Microsoft\BingSvc\BingSvc.exe () C:\Program Files (x86)\Hotkey\Hotkey.exe () C:\Program Files (x86)\Megareg\MEGAREG.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Users\Abdias\Downloads\Software Remove Master v5.0.1.3 Portable BY INVASOR VIRTUAL\Software Remove Master v5.0.1.3 Portable BY INVASOR_VIRTUAL.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\HelpPane.exe (Tencent) C:\Program Files (x86)\Common Files\Tencent\QQDownload\130\Tencentdl.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Tencent) C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\QMChExt.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registro (Whitelisted) =========================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-24] (Synaptics Incorporated) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-12-09] (Apple Inc.) HKLM-x32\...\Run: [rec_en_77] => [X] HKLM-x32\...\Run: [gmsd_br_005010123] => [X] HKLM-x32\...\Run: [gmsd_br_005010126] => [X] HKLM-x32\...\Run: [QuickTime Task] => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime HKLM-x32\...\Run: [ QQPCTray] => C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\QQPCTRAY.EXE [355296 2016-02-16] (Tencent) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1665768600-814039987-2456762191-1001\...\Run: [BingSvc] => C:\Users\Abdias\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-12] (© 2015 Microsoft Corporation) HKU\S-1-5-21-1665768600-814039987-2456762191-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-11-30] (Apple Inc.) HKU\S-1-5-21-1665768600-814039987-2456762191-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [103696 2015-11-30] (Apple Inc.) HKU\S-1-5-21-1665768600-814039987-2456762191-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [61200 2015-11-30] (Apple Inc.) HKU\S-1-5-21-1665768600-814039987-2456762191-1001\...\RunOnce: [Uninstall C:\Users\Abdias\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Abdias\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64" HKU\S-1-5-21-1665768600-814039987-2456762191-1001\...\MountPoints2: {8b66b001-6183-11e5-be9e-0090f5e24e96} - "E:\LG_PC_Programs.exe" ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Abdias\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64\FileSyncShell64.dll [2016-02-10] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Abdias\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64\FileSyncShell64.dll [2016-02-10] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Abdias\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64\FileSyncShell64.dll [2016-02-10] (Microsoft Corporation) ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\QMGCShellExt64.dll [2016-02-16] (Tencent) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => Nenhum Arquivo ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Abdias\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileSyncShell.dll [2016-02-10] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Abdias\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileSyncShell.dll [2016-02-10] (Microsoft Corporation) ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Abdias\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileSyncShell.dll [2016-02-10] (Microsoft Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hotkey.lnk [2013-01-09] ShortcutTarget: Hotkey.lnk -> C:\Program Files (x86)\Hotkey\Hotkey.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Megareg.lnk [2013-01-09] ShortcutTarget: Megareg.lnk -> C:\Program Files (x86)\Megareg\MEGAREG.EXE () GroupPolicy: Restrição - Chrome <======= ATENÇÃO CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{20f4ab3d-d44d-4b26-822e-407c6a8b4b37}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{c1e87f66-5848-43da-98ad-4fc2809cd2e7}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKU\S-1-5-21-1665768600-814039987-2456762191-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://br.hao123.com/?tn=sdks_inner_hp_09_hao123_br&guid=91facb2d51b3759a92180dfdc5d6ac4c URLSearchHook: [S-1-5-21-1665768600-814039987-2456762191-1001] ATENÇÃO => A URLSearchHook Padrão está ausente URLSearchHook: HKU\S-1-5-21-1665768600-814039987-2456762191-1001 - (Sem Nome) - {0633EE93-D776-472f-A0FF-E1416B8B2E3D} - Nenhum Arquivo SearchScopes: HKU\S-1-5-21-1665768600-814039987-2456762191-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1665768600-814039987-2456762191-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3D} URL = SearchScopes: HKU\S-1-5-21-1665768600-814039987-2456762191-1001 -> {0BB7C1DB-CECB-460F-A7C7-20A45BA1F7FC} URL = SearchScopes: HKU\S-1-5-21-1665768600-814039987-2456762191-1001 -> {A62F4C59-73F0-4EEF-9CE7-21083500DD45} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2015-10-25] (Oracle Corporation) BHO: 电脑管家网页防火墙 -> {7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B} -> C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\TSWebMon64.dat [2016-02-16] (Tencent) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2015-10-25] (Oracle Corporation) BHO-x32: Ó¦Óñ¦Ò»¼ü°²×°²å¼þ -> {50F4150A-48B2-417A-BE4C-C83F580FB904} -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll [2015-10-25] () FF Plugin: @java.com/DTPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2015-10-25] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.80.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2015-10-25] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-25] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation) FF Plugin-x32: @qq.com/npAndroidAssistant -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司) FF Plugin-x32: @qq.com/QQPCMgr -> C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\npQMExtensionsMozilla.dll [2016-02-16] (Tencent Technology (Shenzhen) Company Limited) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-01-31] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-01-31] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.) FF HKLM\...\Firefox\Extensions: [{6BDE555F-F5D0-43CA-812A-242273AC0CFC}] - C:\Program Files\shopperz241020151423\Firefox => não encontrado (a) FF HKLM-x32\...\Firefox\Extensions: [{6BDE555F-F5D0-43CA-812A-242273AC0CFC}] - C:\Program Files\shopperz241020151423\Firefox => não encontrado (a) Chrome: ======= CHR HomePage: Default -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=pt-br CHR StartupUrls: Default -> "hxxps://www.google.com.br/" CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms} CHR DefaultSearchKeyword: Default -> bing.com CHR Profile: C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Apresentações) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-25] CHR Extension: (Google Docs) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-25] CHR Extension: (Google Drive) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-25] CHR Extension: (YouTube) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-25] CHR Extension: (Webmail Ad Blocker) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbhfdchmklhpcngcgjmpdbjakdggkkjp [2016-02-14] CHR Extension: (Adblock Plus) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-14] CHR Extension: (Google Search) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (clipchamp - convert, compress, record video) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\delkpojpfkkfgmknffmblbhmlamkjioi [2016-02-14] CHR Extension: (Planilhas do Google) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-25] CHR Extension: (Assassin's Creed III) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\geadmffjboclimmeiaimcafapjaefnfn [2016-02-14] CHR Extension: (Documentos Google off-line) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-17] CHR Extension: (AdBlock) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-02-15] CHR Extension: (Avast Online Security) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-02-14] CHR Extension: (Conversor de vídeo) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcjjnhgakghmggnimjkldjmmpabhnhne [2016-02-14] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-25] CHR Extension: (电脑管家上网防护) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\ooebklgpfnbcnpokahmdidgbmlcdepkm [2016-02-16] CHR Extension: (Gmail) - C:\Users\Abdias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-25] CHR HKU\S-1-5-21-1665768600-814039987-2456762191-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx Opera: ======= OPR StartupUrls: "hxxps://www.google.com.br/webhp?hl=pt-BR" ==================== Serviços (Whitelisted) ======================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.) S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [134512 2015-07-30] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [134512 2015-07-30] (Dropbox, Inc.) R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\PowerBiosServer.exe [45568 2012-09-13] () [Arquivo não assinado] R2 QQPCRTP; C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\QQPCRTP.exe [301728 2016-02-16] (Tencent) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH) R2 UGSVC; C:\Program Files (x86)\UPCleaner\1.0.27.12725\UGSvc.exe [698240 2015-09-24] () R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [36504 2015-06-22] (VIA Technologies, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2014-05-27] (Google Inc) S3 AndnetBus; C:\Windows\System32\drivers\lgandnetbus64.sys [20992 2014-05-27] (LG Electronics Inc.) S3 AndNetDiag; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys [29184 2014-07-07] (LG Electronics Inc.) S3 ANDNetModem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys [36352 2014-07-07] (LG Electronics Inc.) R1 cherimoya; C:\Windows\System32\drivers\cherimoya.sys [56736 2015-09-24] (Windows (R) Win 7 DDK provider) R2 inpoutx64; C:\Windows\System32\Drivers\inpoutx64.sys [15008 2015-11-13] (Highresolution Enterprises [www.highrez.co.uk]) R2 NPF; C:\Program Files (x86)\UPCleaner\1.0.27.12725\npf64.sys [36600 2015-09-24] (Riverbed Technology, Inc.) R1 QMUdisk; C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\QMUdisk64.sys [79672 2016-02-16] (Tencent) R2 QQSysMonX64; C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\QQSysMonX64.sys [138040 2016-02-16] (电脑管家) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-06-18] (Realtek ) R3 rtwlane_13; C:\Windows\System32\drivers\rtwlane_13.sys [3749888 2015-10-30] (Realtek Semiconductor Corporation ) R1 softaal; C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\softaal64.sys [35128 2016-02-16] (Tencent) R1 swsedrvr_vw_1_10_0_25; C:\Windows\System32\drivers\swsedrvr_vw_1_10_0_25.sys [57720 2015-09-22] (SS) R3 TAOAccelerator; C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys [88632 2016-02-16] (Tencent) R2 TAOKernelDriver; C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys [127800 2016-02-16] (Tencent Technology(Shenzhen) Company Limited) R3 TFsFlt; C:\Windows\System32\Drivers\TFsFltX64.sys [87864 2016-02-16] (电脑管家) R3 TS888x64; C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\TS888x64.sys [28984 2016-02-16] (Tencent) S1 TSDefenseBt; C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\TSDefenseBT64.sys [28984 2016-02-16] (Tencent) R4 TSSysKit; C:\Program Files (x86)\Tencent\QQPCMgr\11.2.17058.221\TSSysKit64.sys [87352 2016-02-16] (电脑管家) R1 UGBroMon; C:\Program Files (x86)\UPCleaner\1.0.27.12725\UGBroMon64.sys [62808 2015-09-24] () R1 UGProtect; C:\Program Files (x86)\UPCleaner\1.0.27.12725\UGProtect64.sys [40280 2015-09-24] () R2 UPKernel; C:\Program Files (x86)\UPCleaner\1.0.27.12725\UPKernel64.sys [21848 2015-09-24] () S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) R1 wwfd_vw_1_10_0_24; C:\Windows\System32\drivers\wwfd_vw_1_10_0_24.sys [57728 2015-09-02] (WordWizard) ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um Mês Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-02-16 23:25 - 2016-02-16 23:26 - 00023344 _____ C:\Users\Abdias\Downloads\FRST.txt 2016-02-16 23:25 - 2016-02-16 23:25 - 00000000 ____D C:\FRST 2016-02-16 23:24 - 2016-02-16 23:25 - 02370560 _____ (Farbar) C:\Users\Abdias\Downloads\FRST64.exe 2016-02-16 22:48 - 2016-02-16 22:48 - 00001242 _____ C:\Users\Public\Desktop\Free Mouse Auto Clicker.lnk 2016-02-16 22:48 - 2016-02-16 22:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeMouseAutoClicker 2016-02-16 22:48 - 2016-02-16 22:48 - 00000000 ____D C:\Program Files (x86)\FreeMouseAutoClicker 2016-02-16 22:47 - 2016-02-16 22:47 - 00478768 _____ (Advanced Mouse Auto Clicker ltd. ) C:\Users\Abdias\Downloads\FreeMouseAutoClickerSetup.exe 2016-02-16 22:17 - 2016-02-16 22:17 - 00000000 ____D C:\Users\Abdias\Documents\Arquivos do Outlook 2016-02-16 21:47 - 2012-08-04 18:13 - 00000000 ____D C:\Users\Abdias\Downloads\Software Remove Master v5.0.1.3 Portable BY INVASOR VIRTUAL 2016-02-16 21:46 - 2016-02-16 21:46 - 01878743 _____ C:\Users\Abdias\Downloads\software remove master v9.0 portable.rar 2016-02-16 20:26 - 2016-02-16 20:26 - 00096786 _____ C:\Users\Abdias\Downloads\CD Hack 6.0.rar 2016-02-16 18:50 - 2016-02-16 18:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件 2016-02-16 18:38 - 2016-02-16 18:38 - 00000000 ____D C:\Users\Abdias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件 2016-02-16 17:36 - 2016-02-16 17:36 - 00028984 _____ (Tencent) C:\WINDOWS\SysWOW64\Drivers\TS888x64.sys 2016-02-16 17:36 - 2016-02-16 17:36 - 00000000 ___HD C:\OneDriveTemp 2016-02-16 14:46 - 2016-01-14 07:47 - 00128280 _____ (电脑管家) C:\WINDOWS\SysWOW64\Drivers\TsFltMgr.sys 2016-02-16 14:44 - 2016-02-16 14:44 - 00005120 _____ C:\Users\Abdias\AppData\Roaming\GiftBag.db 2016-02-16 14:44 - 2016-02-16 14:41 - 00127800 _____ (Tencent Technology(Shenzhen) Company Limited) C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys 2016-02-16 14:44 - 2016-02-16 14:41 - 00088632 _____ (Tencent) C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys 2016-02-16 14:43 - 2016-02-16 14:43 - 00000000 ____D C:\Users\Todos os Usuários\TXQMPC 2016-02-16 14:43 - 2016-02-16 14:43 - 00000000 ____D C:\ProgramData\TXQMPC 2016-02-16 14:43 - 2016-02-16 14:43 - 00000000 ____D C:\Program Files\Common Files\Tencent 2016-02-16 14:42 - 2016-02-16 14:41 - 00087864 _____ (电脑管家) C:\WINDOWS\system32\Drivers\TFsFltX64.sys 2016-02-16 14:41 - 2016-02-16 18:03 - 00000000 ____D C:\Users\Abdias\AppData\Roaming\Tencent 2016-02-16 14:41 - 2016-02-16 14:46 - 00000000 ____D C:\Users\Todos os Usuários\Tencent 2016-02-16 14:41 - 2016-02-16 14:46 - 00000000 ____D C:\ProgramData\Tencent 2016-02-16 14:41 - 2016-02-16 14:41 - 00000000 ____D C:\Program Files (x86)\Tencent 2016-02-16 14:25 - 2016-02-16 14:25 - 07608920 _____ C:\Users\Abdias\Downloads\P7_v3.9.rar.exe 2016-02-14 19:38 - 2016-02-16 20:55 - 00000000 ____D C:\Users\Abdias\Downloads\css 2016-02-14 18:37 - 2016-02-14 18:36 - 12570207 _____ () C:\Users\Abdias\Documents\CSS_Patch_v18_30-10-2007-DZ.exe 2016-02-14 18:37 - 2016-02-14 18:35 - 09906342 _____ C:\Users\Abdias\Documents\CSS_Patch_v17_04-04-2007-DZ.exe 2016-02-14 18:37 - 2016-02-14 18:24 - 240954926 _____ C:\Users\Abdias\Documents\CSS_Patch_v1_TO_v16_18-12-2006-DZ.exe 2016-02-14 18:17 - 2016-02-14 18:19 - 12492056 _____ C:\Users\Abdias\Documents\patch v18 Counter Strike Source.rar 2016-02-14 18:14 - 2016-02-14 18:15 - 09888324 _____ C:\Users\Abdias\Documents\patch v17 Counter Strike Source .rar 2016-02-14 17:36 - 2016-02-14 18:09 - 240955277 _____ C:\Users\Abdias\Documents\patch v16 Counter Strike Source.rar 2016-02-14 14:51 - 2016-02-16 21:09 - 00000844 _____ C:\Users\Abdias\Desktop\Counter-Strike Source.lnk 2016-02-14 08:21 - 2016-02-14 14:51 - 00000868 _____ C:\Users\Abdias\AppData\Roaming\Microsoft\Windows\Start Menu\Counter-Strike Source.lnk 2016-02-14 04:51 - 2016-02-14 04:52 - 00002044 _____ C:\Users\Abdias\Desktop\Drakensang Online.lnk 2016-02-14 04:51 - 2016-02-14 04:51 - 00000000 ____D C:\Users\Abdias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Drakensang Online 2016-02-14 04:51 - 2016-02-14 04:51 - 00000000 ____D C:\Program Files (x86)\Drakensang Online 2016-02-14 04:04 - 2016-02-14 04:04 - 00003950 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1455429825 2016-02-14 04:03 - 2016-02-14 04:03 - 00001211 _____ C:\Users\Public\Desktop\Opera.lnk 2016-02-14 04:03 - 2016-02-14 04:03 - 00001211 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2016-02-14 03:57 - 2016-02-14 04:05 - 00000000 ____D C:\Program Files (x86)\Opera 2016-02-14 03:48 - 2016-02-14 03:48 - 00001559 _____ C:\Users\Abdias\Desktop\Iexplore.lnk 2016-02-14 01:16 - 2016-02-14 07:33 - 1332452569 ____R C:\Users\Abdias\Documents\Counter-Strike Source.exe 2016-02-13 19:53 - 2016-02-13 21:05 - 00001161 _____ C:\Users\Abdias\Desktop\Cheat Engine.lnk 2016-02-13 19:53 - 2016-02-13 19:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.5 2016-02-13 19:53 - 2016-02-13 19:53 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.5 2016-02-13 18:32 - 2016-02-13 18:32 - 00000000 ____D C:\Users\Abdias\AppData\Roaming\Red Crucible 2 2016-02-13 03:17 - 2016-02-13 03:17 - 00001892 _____ C:\Users\Public\Desktop\SharpKeys.lnk 2016-02-13 03:17 - 2016-02-13 03:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RandyRants.com 2016-02-13 03:17 - 2016-02-13 03:17 - 00000000 ____D C:\Program Files (x86)\RandyRants.com 2016-02-12 16:58 - 2016-02-12 16:58 - 00000000 ____D C:\sound 2016-02-12 16:58 - 2016-02-12 16:58 - 00000000 ____D C:\scripts 2016-02-12 16:58 - 2016-02-12 16:58 - 00000000 ____D C:\models 2016-02-12 16:58 - 2016-02-12 16:58 - 00000000 ____D C:\materials 2016-02-12 02:21 - 2016-02-14 07:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Strogino CS Portal 2016-02-09 22:48 - 2016-02-14 00:45 - 00000000 ____D C:\Users\Abdias\Documents\Counter-Strike Source v2230303.1 2016-02-09 02:09 - 2016-02-09 02:09 - 00000000 ____D C:\Users\Todos os Usuários\Gazillion Entertainment 2016-02-09 02:09 - 2016-02-09 02:09 - 00000000 ____D C:\ProgramData\Gazillion Entertainment 2016-02-09 02:09 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll 2016-02-09 02:09 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll 2016-02-09 02:09 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll 2016-02-09 02:09 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll 2016-02-09 02:09 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll 2016-02-09 02:09 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll 2016-02-09 02:09 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll 2016-02-09 02:09 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll 2016-02-09 02:09 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll 2016-02-09 02:09 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll 2016-02-09 02:09 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll 2016-02-09 02:09 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll 2016-02-09 02:09 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll 2016-02-09 02:09 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll 2016-02-09 02:09 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll 2016-02-09 02:09 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll 2016-02-09 02:09 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll 2016-02-09 02:09 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll 2016-02-09 02:09 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll 2016-02-09 02:09 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll 2016-02-09 02:09 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll 2016-02-09 02:09 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll 2016-02-09 02:09 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll 2016-02-09 02:09 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll 2016-02-09 02:09 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll 2016-02-09 02:09 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll 2016-02-09 02:09 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll 2016-02-09 02:09 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll 2016-01-21 12:00 - 2016-01-21 12:00 - 00000000 ____D C:\WINDOWS\system32\SleepStudy ==================== Um Mês Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-02-16 23:12 - 2015-08-12 12:17 - 00001090 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2016-02-16 23:12 - 2015-07-30 23:02 - 00001034 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job 2016-02-16 23:12 - 2015-07-30 23:02 - 00001030 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job 2016-02-16 22:34 - 2013-01-09 11:17 - 00000902 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2016-02-16 21:12 - 2015-08-12 12:17 - 00001086 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2016-02-16 19:02 - 2015-08-25 14:05 - 00004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{9A12B376-91A9-444D-8BDA-CAA4468CBF56} 2016-02-16 18:50 - 2015-10-24 18:50 - 00001064 _____ C:\WINDOWS\Tasks\MyBrowser.job 2016-02-16 17:47 - 2015-10-30 05:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2016-02-16 17:36 - 2015-10-30 05:21 - 00000000 ____D C:\WINDOWS\INF 2016-02-16 17:36 - 2015-08-12 17:06 - 00000000 __RDO C:\Users\Abdias\OneDrive 2016-02-16 15:27 - 2015-10-30 17:12 - 00785460 _____ C:\WINDOWS\system32\prfh0416.dat 2016-02-16 15:27 - 2015-10-30 17:12 - 00154246 _____ C:\WINDOWS\system32\prfc0416.dat 2016-02-16 15:27 - 2015-08-23 05:27 - 01819274 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2016-02-16 15:19 - 2015-12-15 11:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2016-02-16 15:19 - 2015-12-15 10:37 - 00334328 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2016-02-16 15:15 - 2015-10-30 05:24 - 00000000 ___SD C:\WINDOWS\system32\F12 2016-02-16 15:15 - 2015-10-30 05:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2016-02-16 15:15 - 2015-10-30 05:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2016-02-16 15:15 - 2015-10-30 05:24 - 00000000 ____D C:\WINDOWS\system32\oobe 2016-02-16 15:15 - 2015-10-30 05:24 - 00000000 ____D C:\WINDOWS\system32\appraiser 2016-02-16 15:14 - 2015-10-30 17:15 - 00000000 ____D C:\Program Files\Windows Journal 2016-02-16 15:14 - 2015-10-30 05:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog 2016-02-16 15:14 - 2015-10-30 05:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2016-02-16 15:14 - 2015-10-30 05:24 - 00000000 ____D C:\WINDOWS\Provisioning 2016-02-16 15:14 - 2015-10-30 05:24 - 00000000 ____D C:\WINDOWS\bcastdvr 2016-02-16 15:05 - 2015-10-30 04:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI 2016-02-16 14:46 - 2015-07-25 02:34 - 00000000 ____D C:\Users\Abdias\AppData\Local\VirtualStore 2016-02-15 14:08 - 2015-08-13 03:26 - 00000000 ____D C:\Users\Abdias\AppData\Roaming\uTorrent 2016-02-15 00:39 - 2015-09-09 21:59 - 00000000 ____D C:\Users\Abdias\AppData\LocalLow\uTorrent 2016-02-14 16:39 - 2015-12-15 10:53 - 00000000 ____D C:\Users\Convidado 2016-02-14 16:39 - 2015-12-15 10:53 - 00000000 ____D C:\Users\Administrator 2016-02-14 16:25 - 2015-12-15 10:53 - 00000000 ____D C:\Users\Abdias 2016-02-14 16:01 - 2015-10-30 05:24 - 00000000 ____D C:\WINDOWS\system32\NDF 2016-02-14 14:16 - 2013-07-27 14:47 - 00000000 ____D C:\Games 2016-02-14 04:30 - 2015-10-25 02:35 - 00000000 ____D C:\Users\Todos os Usuários\Ultra Adware Killer 2016-02-14 04:30 - 2015-10-25 02:35 - 00000000 ____D C:\ProgramData\Ultra Adware Killer 2016-02-14 03:32 - 2015-08-04 20:56 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2016-02-13 19:13 - 2015-07-25 02:34 - 00000000 ____D C:\Users\Abdias\AppData\Local\Packages 2016-02-13 16:54 - 2015-10-30 05:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2016-02-13 09:41 - 2015-07-30 23:01 - 00000000 ____D C:\Users\Abdias\AppData\Local\Dropbox 2016-02-13 09:41 - 2015-05-30 04:29 - 00000000 ___RD C:\Users\Abdias\Dropbox 2016-02-13 03:17 - 2013-01-09 12:21 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-02-12 16:18 - 2015-10-30 05:24 - 00000000 ___HD C:\Program Files\WindowsApps 2016-02-12 14:35 - 2016-01-13 16:12 - 00000000 ___RD C:\Users\Abdias\iCloudDrive 2016-02-11 02:32 - 2015-10-30 05:24 - 00000000 ____D C:\WINDOWS\rescache 2016-02-10 22:03 - 2015-08-23 19:15 - 00002379 _____ C:\Users\Abdias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2016-02-10 15:32 - 2015-11-01 19:35 - 00000000 ____D C:\Users\Todos os Usuários\Microsoft Help 2016-02-10 15:31 - 2013-08-22 11:25 - 00000269 _____ C:\WINDOWS\win.ini 2016-02-10 15:27 - 2015-07-31 02:24 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-02-10 15:26 - 2013-05-10 20:58 - 00000383 _____ C:\Users\Abdias\Desktop\Painel de Controle - Atalho.lnk 2016-02-10 15:14 - 2015-07-31 02:24 - 146614896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-02-10 01:15 - 2015-09-16 22:01 - 00000000 ___RD C:\Users\Abdias\3D Objects 2016-02-09 22:36 - 2016-01-13 16:12 - 00000000 ____D C:\Users\Abdias\AppData\Local\3C8B66CD-0844-408F-90A0-EFDB9AA9BCEF.aplzod 2016-02-09 02:14 - 2016-01-13 17:40 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache 2016-02-09 02:14 - 2016-01-13 17:40 - 00000000 ____D C:\ProgramData\Package Cache 2016-02-07 20:50 - 2015-11-08 00:22 - 00001155 _____ C:\Users\Abdias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Songr.lnk 2016-02-07 20:50 - 2015-09-08 18:20 - 00000000 ____D C:\Users\Abdias\AppData\Local\Songr 2016-02-03 17:01 - 2015-10-30 05:26 - 00828920 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2016-02-03 17:01 - 2015-10-30 05:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2016-01-31 21:07 - 2015-08-12 12:17 - 00004148 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2016-01-31 21:07 - 2015-08-12 12:17 - 00003916 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2016-01-22 13:33 - 2015-09-08 03:21 - 00000000 ____D C:\Users\Abdias\AppData\Local\ElevatedDiagnostics 2016-01-21 22:50 - 2015-11-23 00:13 - 00000000 ____D C:\Users\Abdias\AppData\Local\Package Cache 2016-01-21 14:01 - 2015-10-24 23:20 - 00003364 _____ C:\Users\Abdias\Desktop\google.lnk ==================== Arquivos na raiz de alguns diretórios ======= 2015-08-11 00:26 - 2015-08-11 00:26 - 6420480 _____ () C:\Program Files (x86)\GUT7B02.tmp 2016-02-16 14:44 - 2016-02-16 14:44 - 0005120 _____ () C:\Users\Abdias\AppData\Roaming\GiftBag.db 2015-10-24 18:50 - 2015-10-24 23:31 - 0000102 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat Arquivos para serem movidos ou deletados: ==================== C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat C:\Users\Todos os Usuários\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat Alguns arquivos em TEMP: ==================== C:\Users\Abdias\AppData\Local\Temp\1450547389.exe C:\Users\Abdias\AppData\Local\Temp\7za.exe C:\Users\Abdias\AppData\Local\Temp\qqpcmgr_v11.2.17058.221_45220_Silence.exe C:\Users\Abdias\AppData\Local\Temp\setup.exe C:\Users\Abdias\AppData\Local\Temp\updateX.exe ==================== Bamital & volsnap ================= (Não há correção automática para arquivos que não passaram na verificação.) C:\WINDOWS\system32\winlogon.exe => O arquivo é assinado digitalmente C:\WINDOWS\system32\wininit.exe => O arquivo é assinado digitalmente C:\WINDOWS\explorer.exe => O arquivo é assinado digitalmente C:\WINDOWS\SysWOW64\explorer.exe => O arquivo é assinado digitalmente C:\WINDOWS\system32\svchost.exe => O arquivo é assinado digitalmente C:\WINDOWS\SysWOW64\svchost.exe => O arquivo é assinado digitalmente C:\WINDOWS\system32\services.exe => O arquivo é assinado digitalmente C:\WINDOWS\system32\User32.dll => O arquivo é assinado digitalmente C:\WINDOWS\SysWOW64\User32.dll => O arquivo é assinado digitalmente C:\WINDOWS\system32\userinit.exe => O arquivo é assinado digitalmente C:\WINDOWS\SysWOW64\userinit.exe => O arquivo é assinado digitalmente C:\WINDOWS\system32\rpcss.dll => O arquivo é assinado digitalmente C:\WINDOWS\system32\dnsapi.dll => O arquivo é assinado digitalmente C:\WINDOWS\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente C:\WINDOWS\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente LastRegBack: 2016-02-10 15:03 ==================== Fim de FRST.txt ============================