Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão:21-02-2016 01 Executado por win7 (administrador) em THULIO (23-02-2016 14:48:51) Executando a partir de C:\Users\win7\Downloads Perfis Carregados: win7 (Perfis Disponíveis: win7) Platform: Windows 7 Professional Service Pack 1 (X64) Idioma: Português (Brasil) Internet Explorer Versão 8 (Navegador padrão: Chrome) Modo da Inicialização: Normal Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (GAS Tecnologia) C:\Program Files (x86)\GbPlugin\gbpsv.exe (ALWIL Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (GAS Tecnologia) C:\Program Files (x86)\GbPlugin\gbpsv.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10.ENCOREPRO2\MSSQL\Binn\sqlservr.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Users\win7\AppData\Roaming\WireX\acim.exe (VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (ALWIL Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe (Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe () C:\ProgramData\WindowsMsg\osmsg.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe () C:\Program Files (x86)\EC482660-1454432410-11DD-BEDE-AC220BBCFE55\hnsrA2BD.tmp () C:\Program Files (x86)\EC482660-1454432410-11DD-BEDE-AC220BBCFE55\jnsh7C67.tmp (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\WINWORD.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE () C:\Windows\Temp\CEAA.tmp () C:\Users\win7\AppData\Local\EC482660-1456231507-11DD-BEDE-AC220BBCFE55\qnsa9256.tmp (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Program Files (x86)\EC482660-1454432410-11DD-BEDE-AC220BBCFE55\knso8112.tmp (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Autodesk, Inc.) C:\Program Files (x86)\AutoCAD 2007\acad.exe (Autodesk, Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\WSCommCntr1.exe (Microsoft Corporation) C:\Windows\splwow64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registro (Whitelisted) =========================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [112512 2010-03-13] (Microsoft Corporation) HKLM\...\Run: [SpaceSoundPro] => "C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe" HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5015040 2012-02-09] (VIA) HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKLM-x32\...\Run: [avast5] => C:\Program Files\Alwil Software\Avast5\avastUI.exe [2769336 2010-03-09] (ALWIL Software) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.) HKLM-x32\...\Run: [gmsd_br_88] => [X] HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2087264 2014-09-11] (Wondershare) HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe HKLM-x32\...\Run: [gmsd_br_005010226] => [X] HKLM-x32\...\Run: [rec_en_77] => [X] HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-13] (Adobe Systems Incorporated) HKLM-x32\...\RunOnce: [Update] => C:\Users\win7\AppData\Roaming\ASPackage\ASPackage.exe /runonce Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\ GbPluginUni: C:\Program Files (x86)\GbPlugin\gbiehUni.dll [2015-07-06] (Banco Itaú Unibanco) HKU\S-1-5-21-1401601514-3091200745-121831899-1000\...\Run: [PriceMeterW] => "C:\Users\win7\AppData\Local\PriceMeter\pricemeterw.exe" HKU\S-1-5-21-1401601514-3091200745-121831899-1000\...\Run: [osmsg] => C:\ProgramData\WindowsMsg\osmsg.exe [2036224 2016-02-09] () HKU\S-1-5-21-1401601514-3091200745-121831899-1000\...\Run: [Repil] => C:\Users\win7\AppData\Roaming\WireX\acim.exe [8706048 2016-02-17] () HKU\S-1-5-21-1401601514-3091200745-121831899-1000\...\MountPoints2: {1174a2f2-9427-11e5-a8a7-ac220bbcfe55} - F:\LGAutoRun.exe ShellExecuteHooks-x32: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399008} - C:\Program Files (x86)\GbPlugin\gbiehuni.dll [1759992 2015-07-06] (Banco Itaú Unibanco) ShellIconOverlayIdentifiers: [BaiduAntivirusIconLock] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CC} => C:\Program Files (x86)\Baidu Security\Baidu Antivirus\BavShx64.dll Nenhum Arquivo ShellIconOverlayIdentifiers-x32: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\SysWOW64\AcSignIcon.dll [2006-03-05] (Autodesk) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk [2014-05-08] ShortcutTarget: AutoCAD Startup Accelerator.lnk -> C:\Program Files (x86)\Common Files\Autodesk Shared\acstart17.exe (Autodesk, Inc) GroupPolicy: Restrição - Chrome <======= ATENÇÃO CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) AutoConfigURL: [S-1-5-21-1401601514-3091200745-121831899-1000] => hxxp://unblockservice.com/wpad.dat?212a0867f07338cae78e7d79f19f05fa5545946 Hosts: Há mais de uma entrada no Hosts. Veja a seção Hosts do Addition.txt Tcpip\Parameters: [DhcpNameServer] 201.17.128.74 201.17.128.79 Tcpip\..\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}: [NameServer] 104.197.191.4 Tcpip\..\Interfaces\{CA0CF3F3-90F9-499D-8400-7A2A6ACE1CF3}: [NameServer] 104.197.191.4 Tcpip\..\Interfaces\{CA0CF3F3-90F9-499D-8400-7A2A6ACE1CF3}: [DhcpNameServer] 172.20.10.1 Tcpip\..\Interfaces\{E4CFD979-9269-43FF-A6CE-B78F6E389678}: [NameServer] 104.197.191.4 Tcpip\..\Interfaces\{E4CFD979-9269-43FF-A6CE-B78F6E389678}: [DhcpNameServer] 201.17.128.74 201.17.128.79 ManualProxies: Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://br.hao123.com/?tn=sdks_inner_hp_09_hao123_br&guid=ae7e0a3f5364781190ca7a0b723e512d HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://br.hao123.com/?tn=sdks_inner_hp_09_hao123_br&guid=ae7e0a3f5364781190ca7a0b723e512d HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://do-search.com/web/?type=ds&ts=1432748879&z=ca51483bef21fcd9bace1d9gbz1cdo5m8z9b0bfm0m&from=cornl&uid=WDCXWD5000AVVS-63M8B0_WD-WCAV9989380693806&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://do-search.com/web/?type=ds&ts=1432748879&z=ca51483bef21fcd9bace1d9gbz1cdo5m8z9b0bfm0m&from=cornl&uid=WDCXWD5000AVVS-63M8B0_WD-WCAV9989380693806&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1432748879&z=ca51483bef21fcd9bace1d9gbz1cdo5m8z9b0bfm0m&from=cornl&uid=WDCXWD5000AVVS-63M8B0_WD-WCAV9989380693806&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://do-search.com/web/?type=ds&ts=1432748879&z=ca51483bef21fcd9bace1d9gbz1cdo5m8z9b0bfm0m&from=cornl&uid=WDCXWD5000AVVS-63M8B0_WD-WCAV9989380693806&q={searchTerms} HKU\S-1-5-21-1401601514-3091200745-121831899-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1421240424&from=tugs&uid=WDCXWD5000AVVS-63M8B0_WD-WCAV9989380693806&q={searchTerms} HKU\S-1-5-21-1401601514-3091200745-121831899-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-1401601514-3091200745-121831899-1000\Software\Microsoft\Internet Explorer\Main,Start Default_Page_URL = hxxp://search.certified-toolbar.com?si=39030&home=true&tid=619 HKU\S-1-5-21-1401601514-3091200745-121831899-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1421240424&from=tugs&uid=WDCXWD5000AVVS-63M8B0_WD-WCAV9989380693806&q={searchTerms} HKU\S-1-5-21-1401601514-3091200745-121831899-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=39030&tid=619&bs=true&q= SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://br.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_bxi01_15_23¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0A0CtBtBtD0B0B0C0F0EyDyD0BtB0B0EtN0D0Tzu0StCtByEtBtN1L2XzutAtFtCtDtFtCtDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCyByCzzyDtDyByDtGtByBzzyBtG0E0B0B0BtGtB0CtA0AtG0AyB0AyDtDyE0CtBzy0CtA0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FtDtCyCtByC0DyCtG0BzytDtBtGyEyD0AtAtGzytAyBzytGzytAyBzztDzy0ByCtC0C0AyD2QtN0A0LzuyE%26cr%3D1447802270%26a%3Dwncy_bxi01_15_23%26os%3DWindows 7 Professional&p={searchTerms} SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://br.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_bxi01_15_23¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0A0CtBtBtD0B0B0C0F0EyDyD0BtB0B0EtN0D0Tzu0StCtByEtBtN1L2XzutAtFtCtDtFtCtDtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCyByCzzyDtDyByDtGtByBzzyBtG0E0B0B0BtGtB0CtA0AtG0AyB0AyDtDyE0CtBzy0CtA0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FtDtCyCtByC0DyCtG0BzytDtBtGyEyD0AtAtGzytAyBzytGzytAyBzztDzy0ByCtC0C0AyD2QtN0A0LzuyE%26cr%3D1447802270%26a%3Dwncy_bxi01_15_23%26os%3DWindows 7 Professional&p={searchTerms} SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxp://vosteran.com/results.php?f=4&q={searchTerms}&a=vst_bxi01_15_04_ch&cd=2XzuyEtN2Y1L1Qzu0A0CtBtBtD0B0B0C0F0EyDyD0BtB0B0EtN0D0Tzu0StCtCtCyEtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1ByEtN1L1G1B1V1N2Y1L1Qzu2StCzy0C0E0F0FyEyEtG0ByDzy0BtG0AtByEzztGtByDyByEtGtC0B0FyBzz0Azz0A0A0FtAtC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FtDtCyCtByC0DyCtG0BzytDtBtGyEyD0AtAtGzytAyBzytGzytAyBzztDzy0ByCtC0C0AyD2Q&cr=183231802&ir= SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.certified-toolbar.com?si=39030&bs=true&tid=619&q={searchTerms} SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.certified-toolbar.com?si=39030&bs=true&tid=619&q={searchTerms} SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=39030&bs=true&tid=619&q={searchTerms} SearchScopes: HKU\S-1-5-21-1401601514-3091200745-121831899-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1401601514-3091200745-121831899-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: Sem Nome -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> Nenhum Arquivo BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-12] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation) BHO-x32: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540008} -> C:\Program Files (x86)\GbPlugin\gbiehuni.dll [2015-07-06] (Banco Itaú Unibanco) Toolbar: HKU\S-1-5-21-1401601514-3091200745-121831899-1000 -> Sem Nome - {D4027C7F-154A-4066-A1AD-4243D8127440} - Nenhum Arquivo Toolbar: HKU\S-1-5-21-1401601514-3091200745-121831899-1000 -> Sem Nome - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Nenhum Arquivo Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\zdcwvwli.default-1454517426066 FF Homepage: search.mpc.am FF Homepage: hxxp://br.hao123.com/?tn=sdks_inner_hp_09_hao123_br&guid=ae7e0a3f5364781190ca7a0b723e512d FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [Nenhum Arquivo] FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-05-06] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-12-17] (Adobe Systems Inc.) FF user.js: detected! => C:\Users\win7\AppData\Roaming\Mozilla\Firefox\Profiles\zdcwvwli.default-1454517426066\user.js [2016-02-17] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\buscape.xml [2015-08-28] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mercadolivre.xml [2015-08-28] FF HKLM\...\Firefox\Extensions: [{A34F5A77-D7DF-4F3C-89CE-37DA21C77380}] - C:\Program Files\shopperz020220161346\Firefox\{A34F5A77-D7DF-4F3C-89CE-37DA21C77380}.xpi => não encontrado (a) FF HKLM-x32\...\Firefox\Extensions: [{A34F5A77-D7DF-4F3C-89CE-37DA21C77380}] - C:\Program Files\shopperz020220161346\Firefox\{A34F5A77-D7DF-4F3C-89CE-37DA21C77380}.xpi => não encontrado (a) FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => não encontrado (a) Chrome: ======= CHR HomePage: Default -> search.mpc.am CHR StartupUrls: Default -> "search.mpc.am" CHR Profile: C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Apresentações) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-03] CHR Extension: (Google Docs) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-03] CHR Extension: (Google Drive) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-03] CHR Extension: (YouTube) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-03] CHR Extension: (Google Search) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-03] CHR Extension: (Planilhas do Google) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-03] CHR Extension: (Documentos Google off-line) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-03] CHR Extension: (AdBlock) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-02-15] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-03] CHR Extension: (Gmail) - C:\Users\win7\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-03] CHR HKLM\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-1401601514-3091200745-121831899-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [oilkkkefbalmbfppgjmgjoefbclebkce] - hxxps://clients2.google.com/service/update2/crx ==================== Serviços (Whitelisted) ======================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) S3 Autodesk Licensing Service; C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe [77944 2014-04-04] (Autodesk) R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2010-03-09] (ALWIL Software) S3 avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2010-03-09] (ALWIL Software) S3 avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2010-03-09] (ALWIL Software) R2 GbpSv; C:\Program Files (x86)\GbPlugin\gbpsv.exe [546104 2014-09-29] (GAS Tecnologia) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation) R2 MSSQL$ENCOREPRO2; c:\Program Files\Microsoft SQL Server\MSSQL10.ENCOREPRO2\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation) S4 SQLAgent$ENCOREPRO2; c:\Program Files\Microsoft SQL Server\MSSQL10.ENCOREPRO2\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation) R2 tivelidyzbt; C:\Program Files (x86)\EC482660-1454432410-11DD-BEDE-AC220BBCFE55\knso8112.tmp [207360 2016-02-23] () [Arquivo não assinado] R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-11-11] (VIA Technologies, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation) R2 wucotusy; C:\Program Files (x86)\EC482660-1454432410-11DD-BEDE-AC220BBCFE55\hnsrA2BD.tmp [416256 2016-02-02] () [Arquivo não assinado] R2 zigipyro; C:\Users\win7\AppData\Local\EC482660-1456231507-11DD-BEDE-AC220BBCFE55\qnsa9256.tmp [158720 2015-12-26] () [Arquivo não assinado] R2 zutuzuni; C:\Program Files (x86)\EC482660-1454432410-11DD-BEDE-AC220BBCFE55\jnsh7C67.tmp [307712 2016-02-02] () [Arquivo não assinado] S2 Syslogon; C:\Windows\SysWOW64\1052\lsass.exe [X] ===================== Drivers (Whitelisted) ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [22096 2010-03-09] (ALWIL Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [63568 2010-03-09] (ALWIL Software) R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [28752 2010-03-09] (ALWIL Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [121936 2010-03-09] (ALWIL Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [51280 2010-03-09] (ALWIL Software) R1 cherimoya; C:\Windows\System32\drivers\cherimoya.sys [61336 2016-02-17] (Cherimoya Ltd) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) S3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam620.sys [58512 2012-07-03] (Realtek Corporation) S1 MPCKpt; system32\DRIVERS\MPCKpt.sys [X] S1 wpnfd_1_10_0_6; system32\drivers\wpnfd_1_10_0_6.sys [X] ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um Mês Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-02-23 14:48 - 2016-02-23 14:49 - 00022285 _____ C:\Users\win7\Downloads\FRST.txt 2016-02-23 14:47 - 2016-02-23 14:48 - 00000000 ____D C:\FRST 2016-02-23 14:47 - 2016-02-23 14:47 - 02371072 _____ (Farbar) C:\Users\win7\Downloads\FRST64.exe 2016-02-23 14:47 - 2016-02-23 14:47 - 01722368 _____ (Farbar) C:\Users\win7\Downloads\FRST.exe 2016-02-23 14:39 - 2016-02-23 14:39 - 00116882 _____ C:\Users\win7\Desktop\C__Users_win7_Documents_LAUDOS DE ESTANQUEIDADE_LAUDOS 2016_CROQUI_POSTO SENHOR DO BOM JESUS - OURO BRANCO - MG Model (1).pdf 2016-02-23 14:36 - 2016-02-23 14:37 - 00031225 _____ C:\Users\win7\Desktop\DEM - POSTO SENHOR DO BOM JESUS.pdf 2016-02-23 12:45 - 2016-02-23 12:45 - 00000000 ____D C:\Users\win7\AppData\Local\EC482660-1456231507-11DD-BEDE-AC220BBCFE55 2016-02-22 14:52 - 2016-02-22 14:52 - 00029321 _____ C:\Users\win7\Desktop\DEM - MW COMERCIO DE COMBUSTIVEIS.pdf 2016-02-22 14:43 - 2016-02-22 14:43 - 00114586 _____ C:\Users\win7\Desktop\C__Users_win7_Documents_LAUDOS DE ESTANQUEIDADE_LAUDOS 2016_CROQUI_MW COMERCIO DE COMBUSTIVEIS - SÃO FRANCISCO - MG Model (1).pdf 2016-02-19 17:01 - 2016-02-19 17:01 - 00030612 _____ C:\Users\win7\Desktop\DEM - JOSE DE PAULA CARVALHO.pdf 2016-02-19 16:28 - 2016-02-19 16:28 - 00122036 _____ C:\Users\win7\Desktop\C__Users_win7_Documents_LAUDOS DE ESTANQUEIDADE_LAUDOS 2016_CROQUI_POSTO CIDADE IGARAPE - IGARAPE - MG Model (1).pdf 2016-02-19 15:33 - 2016-02-19 15:33 - 00027392 _____ C:\Users\win7\Desktop\DEM - POSTO VHR.pdf 2016-02-19 15:22 - 2015-12-21 14:29 - 00296288 _____ C:\Users\win7\Desktop\POSTO LUPUS ISABEL BUENO - BELO HORIZONTE - MG.dwg 2016-02-19 15:19 - 2016-02-19 15:19 - 00117567 _____ C:\Users\win7\Desktop\C__Users_win7_Documents_LAUDOS DE ESTANQUEIDADE_LAUDOS 2016_CROQUI_POSTO VHR LIMITADA - SANTA LUZIA - MG Model (1).pdf 2016-02-19 14:30 - 2016-02-19 14:30 - 00029746 _____ C:\Users\win7\Desktop\DEM - POSTO RIO PINHEIRO.pdf 2016-02-19 14:04 - 2016-02-19 14:04 - 00118779 _____ C:\Users\win7\Desktop\C__Users_win7_Documents_LAUDOS DE ESTANQUEIDADE_LAUDOS 2016_CROQUI_POSTO RIO PINHEIRO - CURVELO - MG Model (1).pdf 2016-02-19 12:11 - 2016-02-19 12:11 - 02561457 _____ C:\Users\win7\Desktop\LAUDO - 0271 - POSTO FAISÃO VII.pdf 2016-02-19 10:46 - 2016-02-19 10:46 - 02516023 _____ C:\Users\win7\Desktop\1LAUDO - 0339A - POSTO FAISÃO II, SERVIÇOS - RETESTE.pdf 2016-02-19 10:42 - 2016-02-19 10:42 - 00029718 _____ C:\Users\win7\Desktop\DEM - POSTO FAISÃO II - RETESTE.pdf 2016-02-19 09:47 - 2016-02-19 09:47 - 00115442 _____ C:\Users\win7\Desktop\CROQUI - POSTO AGUA BRANCA DERIVADOS DE PETR. - CONTAGEM - MG Mo.pdf 2016-02-19 07:23 - 2016-02-22 13:19 - 00084916 _____ C:\Users\win7\Desktop\ArtImprimir.pdf 2016-02-19 07:16 - 2016-02-23 08:14 - 00002898 _____ C:\Windows\System32\Tasks\AutoKMS 2016-02-18 10:25 - 2016-02-18 10:25 - 00000000 ____D C:\Users\win7\AppData\Roaming\WireX 2016-02-18 10:25 - 2016-02-18 10:25 - 00000000 _____ C:\Users\win7\AppData\Roaming\win64.txt 2016-02-17 10:04 - 2016-02-17 10:04 - 00003336 _____ C:\Windows\System32\Tasks\Pymkuo 2016-02-17 10:04 - 2016-02-17 10:04 - 00000000 ____D C:\Windows\system32\oros 2016-02-17 10:04 - 2016-02-17 10:04 - 00000000 ____D C:\Users\win7\AppData\Roaming\BomewChq 2016-02-17 10:03 - 2016-02-18 15:30 - 00000000 ____D C:\Program Files\shopperz170220161312 2016-02-17 08:15 - 2016-02-17 10:04 - 00061336 _____ (Cherimoya Ltd) C:\Windows\system32\Drivers\cherimoya.sys 2016-02-16 11:57 - 2016-02-16 11:57 - 00000000 ____D C:\Users\win7\AppData\Local\macpromosoft 2016-02-16 11:08 - 2016-02-16 11:08 - 00000000 ____D C:\Users\win7\AppData\Roaming\UG 2016-02-16 11:07 - 2016-02-16 11:57 - 00000000 ____D C:\Program Files (x86)\UPCleaner 2016-02-12 16:47 - 2016-02-22 08:44 - 00002240 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-02-12 16:47 - 2016-02-22 08:44 - 00002211 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-02-11 16:18 - 2016-02-11 16:18 - 00000000 ____D C:\Users\Todos os Usuários\Browser 2016-02-11 16:18 - 2016-02-11 16:18 - 00000000 ____D C:\ProgramData\Browser 2016-02-11 09:32 - 2016-02-11 09:32 - 00002908 _____ C:\Windows\System32\Tasks\osTip 2016-02-11 09:31 - 2016-02-11 09:32 - 00000000 ____D C:\Users\Todos os Usuários\WindowsMsg 2016-02-11 09:31 - 2016-02-11 09:32 - 00000000 ____D C:\ProgramData\WindowsMsg 2016-02-10 12:39 - 2016-02-10 12:39 - 00000000 ____D C:\Users\win7\AppData\Roaming\gplyra 2016-02-05 12:41 - 2016-02-05 12:41 - 00315392 _____ C:\Users\win7\Downloads\installer.exe 2016-02-05 09:58 - 2016-02-05 09:58 - 00281456 _____ C:\Windows\Minidump\020516-15943-01.dmp 2016-02-05 07:18 - 2016-02-05 07:18 - 00003088 _____ C:\Windows\System32\Tasks\{98B426AE-ADA3-49F5-B179-0B7CB31233D7} 2016-02-04 08:36 - 2016-02-05 09:22 - 00000000 ____D C:\Program Files (x86)\MPC Cleaner 2016-02-03 13:38 - 2016-02-23 14:43 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-02-03 13:38 - 2016-02-23 14:43 - 00001060 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-02-03 13:38 - 2016-02-03 13:38 - 00004060 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2016-02-03 13:38 - 2016-02-03 13:38 - 00003808 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2016-02-03 13:37 - 2016-02-03 13:37 - 00987728 _____ (Google Inc.) C:\Users\win7\Downloads\ChromeSetup(1).exe 2016-02-03 13:36 - 2016-02-03 13:36 - 00987728 _____ (Google Inc.) C:\Users\win7\Downloads\ChromeSetup.exe 2016-02-03 12:31 - 2016-02-03 12:31 - 01220566 _____ C:\Users\win7\Downloads\SetUp__15334_i1847985913_il175.rar 2016-02-03 12:08 - 2016-02-03 12:08 - 00000000 ____D C:\Users\win7\Downloads\The Walking Dead S05E02 720p HDTV Dual Audio 2016-02-03 12:07 - 2016-02-03 12:08 - 00000000 ____D C:\Users\win7\Downloads\The Walking Dead S05E07 HDTV Dual Audio Dublado 2016-02-03 12:06 - 2016-02-03 12:06 - 00000000 ____D C:\Users\win7\Downloads\The.Walking.Dead.S05E06.480p.HDTV.x264-Belex-Dual.Audio 2016-02-03 07:30 - 2016-02-03 07:30 - 00927832 _____ ( ) C:\Users\win7\Downloads\Iniciar Download 2016-02-02 15:54 - 2016-02-02 16:03 - 00000000 ____D C:\Users\win7\Downloads\The Walking Dead S05E05 HDTV Dual Audio 2016-02-02 15:54 - 2016-02-02 15:59 - 00000000 ____D C:\Users\win7\Downloads\The Walking Dead S05E04 HDTV Dual Audio 2016-02-02 15:40 - 2016-02-02 16:04 - 00000000 ____D C:\Users\win7\Downloads\The Walking Dead S05E03 HDTV Dual Audio 2016-02-02 14:39 - 2016-02-02 14:39 - 00000000 ____D C:\Users\win7\AppData\LocalLow\Apple Computer 2016-02-02 14:32 - 2016-02-17 10:04 - 00000000 ____D C:\Users\win7\AppData\Local\Tempfolder 2016-02-02 14:32 - 2016-02-02 14:32 - 00000000 ____D C:\Windows\system32\ile 2016-02-02 14:32 - 2016-02-02 14:32 - 00000000 ____D C:\Users\win7\AppData\Roaming\PusbTutsoc 2016-02-02 14:31 - 2016-02-02 14:47 - 00000000 ____D C:\Program Files\shopperz020220161346 2016-02-02 14:31 - 2016-02-02 14:31 - 00003340 _____ C:\Windows\System32\Tasks\Pakchai 2016-02-02 14:31 - 2016-02-02 14:31 - 00000000 ____D C:\Users\win7\AppData\LocalLow\Company 2016-02-02 14:31 - 2016-02-02 14:31 - 00000000 ____D C:\Users\win7\AppData\LocalLow\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A} 2016-02-02 14:31 - 2016-02-02 14:31 - 00000000 ____D C:\uninst 2016-02-02 14:19 - 2016-02-02 14:19 - 00000000 ____D C:\Users\Public\Documents\Tools 2016-02-02 14:19 - 2016-02-02 14:19 - 00000000 ____D C:\Users\Public\Documents\Guid 2016-02-02 14:18 - 2016-02-02 14:18 - 00000008 _____ C:\END 2016-02-02 14:18 - 2016-02-02 14:18 - 00000000 ____D C:\Users\Public\Documents\Baidu 2016-02-02 14:13 - 2016-02-15 07:23 - 00000000 ____D C:\Program Files (x86)\RCP 2016-02-02 14:12 - 2016-02-02 14:13 - 41404760 _____ (Apple Inc.) C:\Users\win7\Downloads\QuickTimeInstaller.exe 2016-02-02 14:03 - 2016-02-02 14:03 - 00000000 ____D C:\Windows\system32\Macromed 2016-02-02 14:03 - 2016-02-02 14:03 - 00000000 ____D C:\Users\win7\AppData\Roaming\SimpleFiles 2016-02-02 14:01 - 2016-02-02 14:12 - 00000000 ____D C:\Users\win7\AppData\Local\EC482660-1454425291-11DD-BEDE-AC220BBCFE55 2016-02-02 14:00 - 2016-02-23 14:13 - 00000000 ____D C:\Program Files (x86)\EC482660-1454432410-11DD-BEDE-AC220BBCFE55 2016-02-02 14:00 - 2016-02-02 13:59 - 00000965 _____ C:\Windows\system32\Drivers\etc\hp.bak 2016-02-02 13:57 - 2016-02-02 13:57 - 03467920 _____ (New Monte Inc) C:\Users\win7\Downloads\Real_Player_16_Plus_Crack_downloader.exe 2016-02-02 13:53 - 2016-02-02 14:29 - 00003334 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1401601514-3091200745-121831899-1000 2016-02-02 13:53 - 2016-02-02 14:29 - 00003198 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1401601514-3091200745-121831899-1000 2016-02-02 13:51 - 2016-02-02 14:33 - 00000000 ____D C:\Users\win7\AppData\Roaming\Real 2016-02-02 13:51 - 2016-02-02 14:33 - 00000000 ____D C:\Users\Todos os Usuários\Real 2016-02-02 13:51 - 2016-02-02 14:33 - 00000000 ____D C:\ProgramData\Real 2016-02-02 13:51 - 2016-02-02 14:33 - 00000000 ____D C:\Program Files (x86)\Real 2016-02-02 13:49 - 2016-02-02 13:50 - 39284832 _____ (RealNetworks, Inc.) C:\Users\win7\Downloads\RealPlayer_br.exe 2016-02-02 13:36 - 2016-02-02 13:37 - 00082107 _____ C:\Users\win7\Downloads\TWD S05E06.rar 2016-02-02 13:36 - 2016-02-02 13:36 - 00150874 _____ C:\Users\win7\Downloads\TWD S05E05.rar 2016-02-02 13:36 - 2016-02-02 13:36 - 00147953 _____ C:\Users\win7\Downloads\TWD S05E04.rar 2016-02-02 13:34 - 2016-02-02 13:34 - 00140504 _____ C:\Users\win7\Downloads\TWD S05E03.rar 2016-02-02 13:33 - 2016-02-02 14:58 - 00000000 ___SD C:\Users\win7\AppData\LocalLow\Temp 2016-02-02 13:33 - 2016-02-02 13:33 - 00126769 _____ C:\Users\win7\Downloads\TWD S05E02.rar 2016-02-02 13:30 - 2016-02-02 13:31 - 00118987 _____ C:\Users\win7\Downloads\TWD S05E01.rar 2016-02-02 12:25 - 2016-02-02 12:25 - 00000000 ____D C:\Users\win7\AppData\Roaming\RPEng 2016-02-02 12:23 - 2016-02-02 12:23 - 02065944 _____ (BitTorrent Inc.) C:\Users\win7\Downloads\uTorrent.exe 2016-02-01 07:51 - 2016-02-01 07:51 - 00001090 _____ C:\Users\win7\Documentos - Atalho.lnk 2016-01-27 12:23 - 2016-01-27 12:23 - 00281456 _____ C:\Windows\Minidump\012716-17877-01.dmp 2016-01-26 13:46 - 2016-01-26 13:46 - 00098931 _____ C:\Users\win7\Downloads\fatura_atual.pdf ==================== Um Mês Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-02-23 14:48 - 2014-04-07 09:48 - 00000000 ____D C:\Users\win7\Documents\Arquivos do Outlook 2016-02-23 08:59 - 2014-04-08 09:58 - 00000000 ____D C:\Users\Todos os Usuários\GbPlugin 2016-02-23 08:59 - 2014-04-08 09:58 - 00000000 ____D C:\ProgramData\GbPlugin 2016-02-23 08:19 - 2009-07-14 01:45 - 00031280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-02-23 08:19 - 2009-07-14 01:45 - 00031280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-02-23 08:18 - 2011-01-27 20:29 - 00772550 _____ C:\Windows\system32\prfh0416.dat 2016-02-23 08:18 - 2011-01-27 20:29 - 00172366 _____ C:\Windows\system32\prfc0416.dat 2016-02-23 08:18 - 2009-07-14 02:13 - 01823170 _____ C:\Windows\system32\PerfStringBackup.INI 2016-02-23 08:18 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\inf 2016-02-23 08:14 - 2014-04-03 09:17 - 00000268 _____ C:\Windows\Tasks\AutoKMS.job 2016-02-23 08:13 - 2009-07-14 02:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-02-22 08:27 - 2014-04-04 11:01 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2016-02-16 11:57 - 2015-05-28 09:55 - 00000492 __RSH C:\Users\Todos os Usuários\ntuser.pol 2016-02-16 11:57 - 2015-05-28 09:55 - 00000492 __RSH C:\ProgramData\ntuser.pol 2016-02-16 11:08 - 2009-07-14 00:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2016-02-16 11:08 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy 2016-02-15 08:56 - 2015-11-19 15:43 - 00000000 ___RD C:\Program Files (x86)\Skype 2016-02-15 07:23 - 2014-04-07 09:19 - 00000000 ____D C:\Users\win7\AppData\Roaming\systweak 2016-02-05 09:58 - 2015-11-04 12:51 - 00000000 ____D C:\Windows\Minidump 2016-02-03 16:00 - 2014-10-09 10:00 - 00000000 ____D C:\Users\Todos os Usuários\Apple 2016-02-03 16:00 - 2014-10-09 10:00 - 00000000 ____D C:\ProgramData\Apple 2016-02-03 15:54 - 2009-07-14 00:20 - 00000000 __RHD C:\Users\Public\Libraries 2016-02-03 13:39 - 2014-04-04 10:43 - 00000000 ____D C:\Users\win7\AppData\Local\Google 2016-02-03 13:38 - 2014-04-04 10:43 - 00000000 ____D C:\Program Files (x86)\Google 2016-02-03 13:37 - 2015-08-28 16:13 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-02-03 10:30 - 2014-04-04 11:34 - 00000000 ____D C:\Users\win7\Documents\CAMPO 2016-02-03 08:15 - 2014-04-07 09:20 - 00000000 ____D C:\Users\win7\AppData\Roaming\Baidu 2016-02-03 08:15 - 2014-04-07 09:20 - 00000000 ____D C:\Users\Todos os Usuários\baidu 2016-02-03 08:15 - 2014-04-07 09:20 - 00000000 ____D C:\ProgramData\baidu 2016-02-03 07:18 - 2009-07-14 02:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2016-02-03 07:17 - 2009-07-14 01:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-02-02 14:53 - 2014-10-09 10:03 - 00000000 ____D C:\Users\win7\AppData\Local\Apple Computer 2016-02-01 07:51 - 2014-04-02 17:30 - 00000000 ____D C:\Users\win7 2016-01-28 07:32 - 2015-10-16 10:53 - 00000000 ____D C:\Users\win7\Documents\CONTROLE INTERNO ==================== Arquivos na raiz de alguns diretórios ======= 2014-04-07 10:19 - 2014-11-26 09:19 - 0000139 _____ () C:\Users\win7\AppData\Roaming\WB.CFG 2016-02-18 10:25 - 2016-02-18 10:25 - 0000000 _____ () C:\Users\win7\AppData\Roaming\win64.txt 2015-01-19 15:57 - 2015-01-19 15:57 - 0000227 _____ () C:\ProgramData\bc.ini 2014-06-06 10:54 - 2014-06-06 10:55 - 4194358 ____H () C:\ProgramData\bf4ppp.bmp 2014-01-15 02:15 - 2014-01-15 02:15 - 0167784 _____ (Baidu, Inc.) C:\ProgramData\FileSplitUpLoad.dll 2014-06-06 10:54 - 2014-06-06 10:55 - 0000636 ____H () C:\ProgramData\gwp2.sys Arquivos para serem movidos ou deletados: ==================== C:\ProgramData\FileSplitUpLoad.dll C:\Users\Todos os Usuários\FileSplitUpLoad.dll Alguns arquivos em TEMP: ==================== C:\Users\win7\AppData\Local\Temp\1391.tmp.exe C:\Users\win7\AppData\Local\Temp\13F.tmp.exe C:\Users\win7\AppData\Local\Temp\1454498129.exe C:\Users\win7\AppData\Local\Temp\14BB.tmp.exe C:\Users\win7\AppData\Local\Temp\14DB.tmp.exe C:\Users\win7\AppData\Local\Temp\14DF.tmp.exe C:\Users\win7\AppData\Local\Temp\151A.tmp.exe C:\Users\win7\AppData\Local\Temp\151B.tmp.exe C:\Users\win7\AppData\Local\Temp\15A.tmp.exe C:\Users\win7\AppData\Local\Temp\15D7.tmp.exe C:\Users\win7\AppData\Local\Temp\1689.tmp.exe C:\Users\win7\AppData\Local\Temp\16B0.tmp.exe C:\Users\win7\AppData\Local\Temp\17EC.tmp.exe C:\Users\win7\AppData\Local\Temp\19F1.tmp.exe C:\Users\win7\AppData\Local\Temp\1AC5.tmp.exe C:\Users\win7\AppData\Local\Temp\1AD0.tmp.exe C:\Users\win7\AppData\Local\Temp\1AF3.tmp.exe C:\Users\win7\AppData\Local\Temp\1BBE.tmp.exe C:\Users\win7\AppData\Local\Temp\1D40.tmp.exe C:\Users\win7\AppData\Local\Temp\1D4D.tmp.exe C:\Users\win7\AppData\Local\Temp\1D67.tmp.exe C:\Users\win7\AppData\Local\Temp\1D92.tmp.exe C:\Users\win7\AppData\Local\Temp\1DF2.tmp.exe C:\Users\win7\AppData\Local\Temp\1EB7.tmp.exe C:\Users\win7\AppData\Local\Temp\1EBA.tmp.exe C:\Users\win7\AppData\Local\Temp\1F0A.tmp.exe C:\Users\win7\AppData\Local\Temp\1F2A.tmp.exe C:\Users\win7\AppData\Local\Temp\1FFB.tmp.exe C:\Users\win7\AppData\Local\Temp\2483.tmp.exe C:\Users\win7\AppData\Local\Temp\24AC.tmp.exe C:\Users\win7\AppData\Local\Temp\24B1.tmp.exe C:\Users\win7\AppData\Local\Temp\24E9.tmp.exe C:\Users\win7\AppData\Local\Temp\2513.tmp.exe C:\Users\win7\AppData\Local\Temp\251E.tmp.exe C:\Users\win7\AppData\Local\Temp\255C.tmp.exe C:\Users\win7\AppData\Local\Temp\264B.tmp.exe C:\Users\win7\AppData\Local\Temp\269B.tmp.exe C:\Users\win7\AppData\Local\Temp\26C8.tmp.exe C:\Users\win7\AppData\Local\Temp\270.tmp.exe C:\Users\win7\AppData\Local\Temp\274.tmp.exe C:\Users\win7\AppData\Local\Temp\289A.tmp.exe C:\Users\win7\AppData\Local\Temp\2AF0.tmp.exe C:\Users\win7\AppData\Local\Temp\2B1C.tmp.exe C:\Users\win7\AppData\Local\Temp\2B6B.tmp.exe C:\Users\win7\AppData\Local\Temp\2BD8.tmp.exe C:\Users\win7\AppData\Local\Temp\2D39.tmp.exe C:\Users\win7\AppData\Local\Temp\2D67.tmp.exe C:\Users\win7\AppData\Local\Temp\2FBE.tmp.exe C:\Users\win7\AppData\Local\Temp\301B.tmp.exe C:\Users\win7\AppData\Local\Temp\30B8.tmp.exe C:\Users\win7\AppData\Local\Temp\30C2.tmp.exe C:\Users\win7\AppData\Local\Temp\31EF.tmp.exe C:\Users\win7\AppData\Local\Temp\3321.tmp.exe C:\Users\win7\AppData\Local\Temp\33C3.tmp.exe C:\Users\win7\AppData\Local\Temp\33F1.tmp.exe C:\Users\win7\AppData\Local\Temp\3441.tmp.exe C:\Users\win7\AppData\Local\Temp\34D3.tmp.exe C:\Users\win7\AppData\Local\Temp\34F7.tmp.exe C:\Users\win7\AppData\Local\Temp\3575.tmp.exe C:\Users\win7\AppData\Local\Temp\35AB.tmp.exe C:\Users\win7\AppData\Local\Temp\3841.tmp.exe C:\Users\win7\AppData\Local\Temp\384D.tmp.exe C:\Users\win7\AppData\Local\Temp\3872.tmp.exe C:\Users\win7\AppData\Local\Temp\39D8.tmp.exe C:\Users\win7\AppData\Local\Temp\3BE4.tmp.exe C:\Users\win7\AppData\Local\Temp\3C5C.tmp.exe C:\Users\win7\AppData\Local\Temp\3C8C.tmp.exe C:\Users\win7\AppData\Local\Temp\3CED.tmp.exe C:\Users\win7\AppData\Local\Temp\3dqzgvln.dll C:\Users\win7\AppData\Local\Temp\3F05.tmp.exe C:\Users\win7\AppData\Local\Temp\40F.tmp.exe C:\Users\win7\AppData\Local\Temp\410F.tmp.exe C:\Users\win7\AppData\Local\Temp\4223.tmp.exe C:\Users\win7\AppData\Local\Temp\42AE.tmp.exe C:\Users\win7\AppData\Local\Temp\4357.tmp.exe C:\Users\win7\AppData\Local\Temp\4484.tmp.exe C:\Users\win7\AppData\Local\Temp\44FE.tmp.exe C:\Users\win7\AppData\Local\Temp\4639.tmp.exe C:\Users\win7\AppData\Local\Temp\46CF.tmp.exe C:\Users\win7\AppData\Local\Temp\47BA.tmp.exe C:\Users\win7\AppData\Local\Temp\4996.tmp.exe C:\Users\win7\AppData\Local\Temp\49E3.tmp.exe C:\Users\win7\AppData\Local\Temp\4B1.tmp.exe C:\Users\win7\AppData\Local\Temp\4CB4.tmp.exe C:\Users\win7\AppData\Local\Temp\4D4A.tmp.exe C:\Users\win7\AppData\Local\Temp\4E47.tmp.exe C:\Users\win7\AppData\Local\Temp\4E6F.tmp.exe C:\Users\win7\AppData\Local\Temp\4F1C.tmp.exe C:\Users\win7\AppData\Local\Temp\4F5D.tmp.exe C:\Users\win7\AppData\Local\Temp\5041.tmp.exe C:\Users\win7\AppData\Local\Temp\51A1.tmp.exe C:\Users\win7\AppData\Local\Temp\51E8.tmp.exe C:\Users\win7\AppData\Local\Temp\5304.tmp.exe C:\Users\win7\AppData\Local\Temp\530B.tmp.exe C:\Users\win7\AppData\Local\Temp\5513.tmp.exe C:\Users\win7\AppData\Local\Temp\58FD.tmp.exe C:\Users\win7\AppData\Local\Temp\594E.tmp.exe C:\Users\win7\AppData\Local\Temp\5B45.tmp.exe C:\Users\win7\AppData\Local\Temp\5B80.tmp.exe C:\Users\win7\AppData\Local\Temp\5DD4.tmp.exe C:\Users\win7\AppData\Local\Temp\5E09.tmp.exe C:\Users\win7\AppData\Local\Temp\5E0F.tmp.exe C:\Users\win7\AppData\Local\Temp\5E2C.tmp.exe C:\Users\win7\AppData\Local\Temp\6015.tmp.exe C:\Users\win7\AppData\Local\Temp\6196.tmp.exe C:\Users\win7\AppData\Local\Temp\61D3.tmp.exe C:\Users\win7\AppData\Local\Temp\6220.tmp.exe C:\Users\win7\AppData\Local\Temp\6223.tmp.exe C:\Users\win7\AppData\Local\Temp\62A8.tmp.exe C:\Users\win7\AppData\Local\Temp\62E.tmp.exe C:\Users\win7\AppData\Local\Temp\640A.tmp.exe C:\Users\win7\AppData\Local\Temp\6465.tmp.exe C:\Users\win7\AppData\Local\Temp\64B9.tmp.exe C:\Users\win7\AppData\Local\Temp\6502.tmp.exe C:\Users\win7\AppData\Local\Temp\66D5.tmp.exe C:\Users\win7\AppData\Local\Temp\6730.tmp.exe C:\Users\win7\AppData\Local\Temp\68CA.tmp.exe C:\Users\win7\AppData\Local\Temp\68D1.tmp.exe C:\Users\win7\AppData\Local\Temp\696F.tmp.exe C:\Users\win7\AppData\Local\Temp\69E9.tmp.exe C:\Users\win7\AppData\Local\Temp\6AD.tmp.exe C:\Users\win7\AppData\Local\Temp\6B4D.tmp.exe C:\Users\win7\AppData\Local\Temp\6C4F.tmp.exe C:\Users\win7\AppData\Local\Temp\6C57.tmp.exe C:\Users\win7\AppData\Local\Temp\6C7F.tmp.exe C:\Users\win7\AppData\Local\Temp\6C85.tmp.exe C:\Users\win7\AppData\Local\Temp\6E41.tmp.exe C:\Users\win7\AppData\Local\Temp\6F22.tmp.exe C:\Users\win7\AppData\Local\Temp\6F75.tmp.exe C:\Users\win7\AppData\Local\Temp\7037.tmp.exe C:\Users\win7\AppData\Local\Temp\71E8.tmp.exe C:\Users\win7\AppData\Local\Temp\7206.tmp.exe C:\Users\win7\AppData\Local\Temp\73BC.tmp.exe C:\Users\win7\AppData\Local\Temp\751A.tmp.exe C:\Users\win7\AppData\Local\Temp\7550.tmp.exe C:\Users\win7\AppData\Local\Temp\7744.tmp.exe C:\Users\win7\AppData\Local\Temp\778.tmp.exe C:\Users\win7\AppData\Local\Temp\77A2.tmp.exe C:\Users\win7\AppData\Local\Temp\7810.tmp.exe C:\Users\win7\AppData\Local\Temp\781A.tmp.exe C:\Users\win7\AppData\Local\Temp\7832.tmp.exe C:\Users\win7\AppData\Local\Temp\7A5F.tmp.exe C:\Users\win7\AppData\Local\Temp\7C1.tmp.exe C:\Users\win7\AppData\Local\Temp\7C8A.tmp.exe C:\Users\win7\AppData\Local\Temp\7C9F.tmp.exe C:\Users\win7\AppData\Local\Temp\7CC1.tmp.exe C:\Users\win7\AppData\Local\Temp\7CEB.tmp.exe C:\Users\win7\AppData\Local\Temp\7DC6.tmp.exe C:\Users\win7\AppData\Local\Temp\7E7A.tmp.exe C:\Users\win7\AppData\Local\Temp\7F5C.tmp.exe C:\Users\win7\AppData\Local\Temp\8021.tmp.exe C:\Users\win7\AppData\Local\Temp\81A3.tmp.exe C:\Users\win7\AppData\Local\Temp\829D.tmp.exe C:\Users\win7\AppData\Local\Temp\8302.tmp.exe C:\Users\win7\AppData\Local\Temp\8356.tmp.exe C:\Users\win7\AppData\Local\Temp\83B5.tmp.exe C:\Users\win7\AppData\Local\Temp\842C.tmp.exe C:\Users\win7\AppData\Local\Temp\848D.tmp.exe C:\Users\win7\AppData\Local\Temp\84AC.tmp.exe C:\Users\win7\AppData\Local\Temp\84DD.tmp.exe C:\Users\win7\AppData\Local\Temp\8501.tmp.exe C:\Users\win7\AppData\Local\Temp\8674.tmp.exe C:\Users\win7\AppData\Local\Temp\8749.tmp.exe C:\Users\win7\AppData\Local\Temp\8763.tmp.exe C:\Users\win7\AppData\Local\Temp\8912.tmp.exe C:\Users\win7\AppData\Local\Temp\8A49.tmp.exe C:\Users\win7\AppData\Local\Temp\8AB2.tmp.exe C:\Users\win7\AppData\Local\Temp\8B1B.tmp.exe C:\Users\win7\AppData\Local\Temp\8C3B.tmp.exe C:\Users\win7\AppData\Local\Temp\8CCB.tmp.exe C:\Users\win7\AppData\Local\Temp\8FE7.tmp.exe C:\Users\win7\AppData\Local\Temp\905E.tmp.exe C:\Users\win7\AppData\Local\Temp\9144.tmp.exe C:\Users\win7\AppData\Local\Temp\9168.tmp.exe C:\Users\win7\AppData\Local\Temp\927C.tmp.exe C:\Users\win7\AppData\Local\Temp\9416.tmp.exe C:\Users\win7\AppData\Local\Temp\94B9.tmp.exe C:\Users\win7\AppData\Local\Temp\9581.tmp.exe C:\Users\win7\AppData\Local\Temp\95A1.tmp.exe C:\Users\win7\AppData\Local\Temp\95DD.tmp.exe C:\Users\win7\AppData\Local\Temp\966F.tmp.exe C:\Users\win7\AppData\Local\Temp\96A0.tmp.exe C:\Users\win7\AppData\Local\Temp\97E7.tmp.exe C:\Users\win7\AppData\Local\Temp\97EB.tmp.exe C:\Users\win7\AppData\Local\Temp\9852.tmp.exe C:\Users\win7\AppData\Local\Temp\9958.tmp.exe C:\Users\win7\AppData\Local\Temp\997B.tmp.exe C:\Users\win7\AppData\Local\Temp\998.tmp.exe C:\Users\win7\AppData\Local\Temp\99BA.tmp.exe C:\Users\win7\AppData\Local\Temp\99ED.tmp.exe C:\Users\win7\AppData\Local\Temp\9A5C.tmp.exe C:\Users\win7\AppData\Local\Temp\9AC7.tmp.exe C:\Users\win7\AppData\Local\Temp\9D70.tmp.exe C:\Users\win7\AppData\Local\Temp\9DAC.tmp.exe C:\Users\win7\AppData\Local\Temp\9F8F.tmp.exe C:\Users\win7\AppData\Local\Temp\9FDB.tmp.exe C:\Users\win7\AppData\Local\Temp\A1D.tmp.exe C:\Users\win7\AppData\Local\Temp\A27A.tmp.exe C:\Users\win7\AppData\Local\Temp\A32A.tmp.exe C:\Users\win7\AppData\Local\Temp\A388.tmp.exe C:\Users\win7\AppData\Local\Temp\A3E4.tmp.exe C:\Users\win7\AppData\Local\Temp\A412.tmp.exe C:\Users\win7\AppData\Local\Temp\A41D.tmp.exe C:\Users\win7\AppData\Local\Temp\A59F.tmp.exe C:\Users\win7\AppData\Local\Temp\A5A4.tmp.exe C:\Users\win7\AppData\Local\Temp\A5C6.tmp.exe C:\Users\win7\AppData\Local\Temp\A62E.tmp.exe C:\Users\win7\AppData\Local\Temp\A671.tmp.exe C:\Users\win7\AppData\Local\Temp\A704.tmp.exe C:\Users\win7\AppData\Local\Temp\A841.tmp.exe C:\Users\win7\AppData\Local\Temp\A950.tmp.exe C:\Users\win7\AppData\Local\Temp\AC37.tmp.exe C:\Users\win7\AppData\Local\Temp\AC47.tmp.exe C:\Users\win7\AppData\Local\Temp\ACA5.tmp.exe C:\Users\win7\AppData\Local\Temp\ACCE.tmp.exe C:\Users\win7\AppData\Local\Temp\AcDeltree.exe C:\Users\win7\AppData\Local\Temp\AFB1.tmp.exe C:\Users\win7\AppData\Local\Temp\avs43AC.exe C:\Users\win7\AppData\Local\Temp\avsD975.exe C:\Users\win7\AppData\Local\Temp\B038.tmp.exe C:\Users\win7\AppData\Local\Temp\B058.tmp.exe C:\Users\win7\AppData\Local\Temp\B05D.tmp.exe C:\Users\win7\AppData\Local\Temp\B09A.tmp.exe C:\Users\win7\AppData\Local\Temp\B0FA.tmp.exe C:\Users\win7\AppData\Local\Temp\B143.tmp.exe C:\Users\win7\AppData\Local\Temp\B16D.tmp.exe C:\Users\win7\AppData\Local\Temp\B198.tmp.exe C:\Users\win7\AppData\Local\Temp\B258.tmp.exe C:\Users\win7\AppData\Local\Temp\B29D.tmp.exe C:\Users\win7\AppData\Local\Temp\B31B.tmp.exe C:\Users\win7\AppData\Local\Temp\B3D5.tmp.exe C:\Users\win7\AppData\Local\Temp\B48C.tmp.exe C:\Users\win7\AppData\Local\Temp\B57E.tmp.exe C:\Users\win7\AppData\Local\Temp\B5AD.tmp.exe C:\Users\win7\AppData\Local\Temp\B6E8.tmp.exe C:\Users\win7\AppData\Local\Temp\B6FB.tmp.exe C:\Users\win7\AppData\Local\Temp\B720.tmp.exe C:\Users\win7\AppData\Local\Temp\B7B4.tmp.exe C:\Users\win7\AppData\Local\Temp\B7C6.tmp.exe C:\Users\win7\AppData\Local\Temp\B854.tmp.exe C:\Users\win7\AppData\Local\Temp\B9C7.tmp.exe C:\Users\win7\AppData\Local\Temp\BA4A.tmp.exe C:\Users\win7\AppData\Local\Temp\BAC7.tmp.exe C:\Users\win7\AppData\Local\Temp\BackupSetup.exe C:\Users\win7\AppData\Local\Temp\Baidu_Secure_SystemUp_5.0.9.107990.exe C:\Users\win7\AppData\Local\Temp\BB10.tmp.exe C:\Users\win7\AppData\Local\Temp\BB61.tmp.exe C:\Users\win7\AppData\Local\Temp\BB67.tmp.exe C:\Users\win7\AppData\Local\Temp\BC5F.tmp.exe C:\Users\win7\AppData\Local\Temp\BDB.tmp.exe C:\Users\win7\AppData\Local\Temp\BEBB.tmp.exe C:\Users\win7\AppData\Local\Temp\BF2D.tmp.exe C:\Users\win7\AppData\Local\Temp\C13B.tmp.exe C:\Users\win7\AppData\Local\Temp\C164.tmp.exe C:\Users\win7\AppData\Local\Temp\C1DE.tmp.exe C:\Users\win7\AppData\Local\Temp\C218.tmp.exe C:\Users\win7\AppData\Local\Temp\C21F.tmp.exe C:\Users\win7\AppData\Local\Temp\C2C5.tmp.exe C:\Users\win7\AppData\Local\Temp\C2DF.tmp.exe C:\Users\win7\AppData\Local\Temp\C30F.tmp.exe C:\Users\win7\AppData\Local\Temp\C361.tmp.exe C:\Users\win7\AppData\Local\Temp\C3F4.tmp.exe C:\Users\win7\AppData\Local\Temp\C3FA.tmp.exe C:\Users\win7\AppData\Local\Temp\C5FA.tmp.exe C:\Users\win7\AppData\Local\Temp\C673.tmp.exe C:\Users\win7\AppData\Local\Temp\C7CF.tmp.exe C:\Users\win7\AppData\Local\Temp\C86E.tmp.exe C:\Users\win7\AppData\Local\Temp\C936.tmp.exe C:\Users\win7\AppData\Local\Temp\C9CB.tmp.exe C:\Users\win7\AppData\Local\Temp\CA37.tmp.exe C:\Users\win7\AppData\Local\Temp\CB53.tmp.exe C:\Users\win7\AppData\Local\Temp\CB5A.tmp.exe C:\Users\win7\AppData\Local\Temp\CBC0.tmp.exe C:\Users\win7\AppData\Local\Temp\CD68.tmp.exe C:\Users\win7\AppData\Local\Temp\CEDB.tmp.exe C:\Users\win7\AppData\Local\Temp\D35F.tmp.exe C:\Users\win7\AppData\Local\Temp\D365.tmp.exe C:\Users\win7\AppData\Local\Temp\D402.tmp.exe C:\Users\win7\AppData\Local\Temp\D40C.tmp.exe C:\Users\win7\AppData\Local\Temp\D50A.tmp.exe C:\Users\win7\AppData\Local\Temp\D6C7.tmp.exe C:\Users\win7\AppData\Local\Temp\D6FD.tmp.exe C:\Users\win7\AppData\Local\Temp\D72D.tmp.exe C:\Users\win7\AppData\Local\Temp\D77F.tmp.exe C:\Users\win7\AppData\Local\Temp\D8FB.tmp.exe C:\Users\win7\AppData\Local\Temp\D95F.tmp.exe C:\Users\win7\AppData\Local\Temp\DA08.tmp.exe C:\Users\win7\AppData\Local\Temp\DB4E.tmp.exe C:\Users\win7\AppData\Local\Temp\DB8A.tmp.exe C:\Users\win7\AppData\Local\Temp\DD3E.tmp.exe C:\Users\win7\AppData\Local\Temp\DD42.tmp.exe C:\Users\win7\AppData\Local\Temp\DD5A.tmp.exe C:\Users\win7\AppData\Local\Temp\DD6B.tmp.exe C:\Users\win7\AppData\Local\Temp\DD7F.tmp.exe C:\Users\win7\AppData\Local\Temp\DE9D.tmp.exe C:\Users\win7\AppData\Local\Temp\DFD.tmp.exe C:\Users\win7\AppData\Local\Temp\diam30936.exe C:\Users\win7\AppData\Local\Temp\E07B.tmp.exe C:\Users\win7\AppData\Local\Temp\E07F.tmp.exe C:\Users\win7\AppData\Local\Temp\E12A.tmp.exe C:\Users\win7\AppData\Local\Temp\E226.tmp.exe C:\Users\win7\AppData\Local\Temp\E350.tmp.exe C:\Users\win7\AppData\Local\Temp\E418.tmp.exe C:\Users\win7\AppData\Local\Temp\E53D.tmp.exe C:\Users\win7\AppData\Local\Temp\E63A.tmp.exe C:\Users\win7\AppData\Local\Temp\E63B.tmp.exe C:\Users\win7\AppData\Local\Temp\E685.tmp.exe C:\Users\win7\AppData\Local\Temp\E8FC.tmp.exe C:\Users\win7\AppData\Local\Temp\E92A.tmp.exe C:\Users\win7\AppData\Local\Temp\E94F.tmp.exe C:\Users\win7\AppData\Local\Temp\E9D0.tmp.exe C:\Users\win7\AppData\Local\Temp\EADF.tmp.exe C:\Users\win7\AppData\Local\Temp\EAFF.tmp.exe C:\Users\win7\AppData\Local\Temp\EB11.tmp.exe C:\Users\win7\AppData\Local\Temp\EB2C.tmp.exe C:\Users\win7\AppData\Local\Temp\EBD1.tmp.exe C:\Users\win7\AppData\Local\Temp\EC52.tmp.exe C:\Users\win7\AppData\Local\Temp\EC94.tmp.exe C:\Users\win7\AppData\Local\Temp\ECD1.tmp.exe C:\Users\win7\AppData\Local\Temp\EE8.tmp.exe C:\Users\win7\AppData\Local\Temp\EEB7.tmp.exe C:\Users\win7\AppData\Local\Temp\EFFC.tmp.exe C:\Users\win7\AppData\Local\Temp\F096.tmp.exe C:\Users\win7\AppData\Local\Temp\F0F8.tmp.exe C:\Users\win7\AppData\Local\Temp\F132.tmp.exe C:\Users\win7\AppData\Local\Temp\F35F.tmp.exe C:\Users\win7\AppData\Local\Temp\F398.tmp.exe C:\Users\win7\AppData\Local\Temp\F3A1.tmp.exe C:\Users\win7\AppData\Local\Temp\F4C4.tmp.exe C:\Users\win7\AppData\Local\Temp\F56B.tmp.exe C:\Users\win7\AppData\Local\Temp\F5C2.tmp.exe C:\Users\win7\AppData\Local\Temp\F5EA.tmp.exe C:\Users\win7\AppData\Local\Temp\F639.tmp.exe C:\Users\win7\AppData\Local\Temp\F671.tmp.exe C:\Users\win7\AppData\Local\Temp\F69E.tmp.exe C:\Users\win7\AppData\Local\Temp\F6B8.tmp.exe C:\Users\win7\AppData\Local\Temp\F6D9.tmp.exe C:\Users\win7\AppData\Local\Temp\F6DE.tmp.exe C:\Users\win7\AppData\Local\Temp\F7C8.tmp.exe C:\Users\win7\AppData\Local\Temp\F9C8.tmp.exe C:\Users\win7\AppData\Local\Temp\F9DF.tmp.exe C:\Users\win7\AppData\Local\Temp\FB3.tmp.exe C:\Users\win7\AppData\Local\Temp\FC9B.tmp.exe C:\Users\win7\AppData\Local\Temp\FCFC.tmp.exe C:\Users\win7\AppData\Local\Temp\FD78.tmp.exe C:\Users\win7\AppData\Local\Temp\FD83.tmp.exe C:\Users\win7\AppData\Local\Temp\FE72.tmp.exe C:\Users\win7\AppData\Local\Temp\FF0E.tmp.exe C:\Users\win7\AppData\Local\Temp\FF45.tmp.exe C:\Users\win7\AppData\Local\Temp\FFA2.tmp.exe C:\Users\win7\AppData\Local\Temp\FNP_ACT_InstallerCA.dll C:\Users\win7\AppData\Local\Temp\fsd5DF7.exe C:\Users\win7\AppData\Local\Temp\fsdC725.exe C:\Users\win7\AppData\Local\Temp\fsdDBBE.exe C:\Users\win7\AppData\Local\Temp\fUIYWb5L16.exe C:\Users\win7\AppData\Local\Temp\hib714F.exe C:\Users\win7\AppData\Local\Temp\hibDC79.exe C:\Users\win7\AppData\Local\Temp\ICReinstall_2483.tmp.exe C:\Users\win7\AppData\Local\Temp\ICReinstall_5B80.tmp.exe C:\Users\win7\AppData\Local\Temp\ICReinstall_71E8.tmp.exe C:\Users\win7\AppData\Local\Temp\ICReinstall_A32A.tmp.exe C:\Users\win7\AppData\Local\Temp\ICReinstall_C3F4.tmp.exe C:\Users\win7\AppData\Local\Temp\ICReinstall_CB5A.tmp.exe C:\Users\win7\AppData\Local\Temp\ICReinstall_DB8A.tmp.exe C:\Users\win7\AppData\Local\Temp\ICReinstall_DD6B.tmp.exe C:\Users\win7\AppData\Local\Temp\ICReinstall_DFD.tmp.exe C:\Users\win7\AppData\Local\Temp\InstallHelper.exe C:\Users\win7\AppData\Local\Temp\m3gjxohc.dll C:\Users\win7\AppData\Local\Temp\oprun12785.exe C:\Users\win7\AppData\Local\Temp\ose00000.exe C:\Users\win7\AppData\Local\Temp\PriceMeterUpdateVer.exe C:\Users\win7\AppData\Local\Temp\stubhelper.dll C:\Users\win7\AppData\Local\Temp\tmp767D.tmp.exe C:\Users\win7\AppData\Local\Temp\UninstallModule.exe C:\Users\win7\AppData\Local\Temp\vcredist_x64.exe C:\Users\win7\AppData\Local\Temp\zU6FPpq7SZ.exe C:\Users\win7\AppData\Local\Temp\_isBD45.exe ==================== Bamital & volsnap ================= (Não há correção automática para arquivos que não passaram na verificação.) C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente C:\Windows\explorer.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente C:\Windows\system32\services.exe => O arquivo é assinado digitalmente C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente C:\Windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente C:\Windows\system32\dnsapi.dll [2010-11-21 00:24] - [2010-11-21 00:24] - 0357888 ____A (Microsoft Corporation) 2E46CB91849B855D5FA031CD5E52FB47 C:\Windows\SysWOW64\dnsapi.dll [2010-11-21 00:24] - [2010-11-21 00:24] - 0270336 ____A (Microsoft Corporation) 6DAF79DAB4B542E18E25DDCF59C67383 C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente LastRegBack: 2016-02-18 09:30 ==================== Fim de FRST.txt ============================