Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão:02-03-2016 Executado por Viviane (administrador) em VIVIANE-PC (03-03-2016 21:53:04) Executando a partir de C:\Users\Viviane\Downloads Perfis Carregados: Viviane (Perfis Disponíveis: Viviane) Platform: Windows 7 Ultimate (X64) Idioma: Português (Brasil) Internet Explorer Versão 9 (Navegador padrão: IE) Modo da Inicialização: Normal Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Todos) ========================= (Microsoft Corporation) C:\Windows\System32\smss.exe (Microsoft Corporation) C:\Windows\System32\csrss.exe (Microsoft Corporation) C:\Windows\System32\csrss.exe (Microsoft Corporation) C:\Windows\System32\wininit.exe (Microsoft Corporation) C:\Windows\System32\winlogon.exe (Microsoft Corporation) C:\Windows\System32\services.exe (Microsoft Corporation) C:\Windows\System32\lsass.exe (Microsoft Corporation) C:\Windows\System32\lsm.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (GAS Tecnologia) C:\Program Files (x86)\GbPlugin\GbpSv.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Microsoft Corporation) C:\Windows\System32\conhost.exe (Microsoft Corporation) C:\Windows\System32\dwm.exe (Microsoft Corporation) C:\Windows\explorer.exe (Microsoft Corporation) C:\Windows\System32\spoolsv.exe (Microsoft Corporation) C:\Windows\System32\taskhost.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Baidu, Inc.) C:\Program Files (x86)\Baidu-Security-2014-4.4.4.82805\Baidu Antivirus\5.6.2.130326.0\BAVSvc.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Solvusoft Corporation) C:\Program Files (x86)\DriverDoc\Solvusoftdd.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Baidu, Inc.) C:\Program Files (x86)\Baidu-Security-2014-4.4.4.82805\Baidu Antivirus\5.6.2.130326.0\BHipsSvc.exe (Dropbox, Inc.) C:\Users\Viviane\AppData\Roaming\Dropbox\bin\Dropbox.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Baidu, Inc.) C:\Program Files (x86)\Baidu-Security-2014-4.4.4.82805\Baidu Antivirus\5.6.2.130326.0\BavTray.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Microsoft Corporation) C:\Windows\System32\SearchIndexer.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Baidu, Inc.) C:\Program Files (x86)\Baidu-Security-2014-4.4.4.82805\Baidu Antivirus\5.6.2.130326.0\bavhm.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\conhost.exe (GAS Tecnologia) C:\Program Files (x86)\GbPlugin\GbpSv.exe (Microsoft Corporation) C:\Windows\System32\wbem\WmiPrvSE.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) C:\Windows\System32\notepad.exe (Microsoft Corporation) C:\Windows\System32\WUDFHost.exe (Microsoft Corporation) C:\Windows\System32\calc.exe (Microsoft Corporation) C:\Windows\System32\notepad.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\iexplore.exe (Adobe Systems Incorporated) C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_20_0_0_306_ActiveX.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\svchost.exe (Microsoft Corporation) C:\Windows\System32\notepad.exe (Microsoft Corporation) C:\Windows\System32\notepad.exe (Microsoft Corporation) C:\Windows\System32\SearchProtocolHost.exe (Microsoft Corporation) C:\Windows\System32\SearchFilterHost.exe (Farbar) C:\Users\Viviane\Downloads\FRST64.exe ==================== Registro (Whitelisted) =========================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Baidu Antivirus] => C:\Program Files (x86)\Baidu-Security-2014-4.4.4.82805\Baidu Antivirus\5.6.2.130326.0\BavTray.exe [2553328 2015-07-14] (Baidu, Inc.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111312 2015-11-06] (AVAST Software) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2015-07-27] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-13] (Adobe Systems Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\ GbPluginCef: C:\Program Files (x86)\GbPlugin\gbiehCef.dll [2015-09-01] (Caixa Economica Federal) HKU\S-1-5-21-1284938540-3583743031-995251729-1000\...\Run: [GoogleChromeAutoLaunch_95A9BE5EBEAC7F8AD845763E5918244E] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [746648 2016-02-18] (Google Inc.) HKU\S-1-5-21-1284938540-3583743031-995251729-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd) HKU\S-1-5-21-1284938540-3583743031-995251729-1000\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1284938540-3583743031-995251729-1000\...\Run: [Dropbox Update] => C:\Users\Viviane\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-18] (Dropbox, Inc.) HKU\S-1-5-21-1284938540-3583743031-995251729-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50368632 2015-12-17] (Skype Technologies S.A.) ShellExecuteHooks-x32: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399003} - C:\Program Files (x86)\GbPlugin\gbiehcef.dll [1867432 2015-09-01] (Caixa Economica Federal) ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Viviane\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Viviane\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Viviane\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Viviane\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Viviane\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Viviane\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Viviane\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Viviane\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => Nenhum Arquivo ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => Nenhum Arquivo ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => Nenhum Arquivo ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-12] (AVAST Software) ShellIconOverlayIdentifiers: [BaiduAntivirusIconLock] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CC} => C:\Program Files (x86)\Baidu-Security-2014-4.4.4.82805\Baidu Antivirus\5.6.2.130326.0\BavShx64.dll [2015-07-14] (Baidu, Inc.) ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => Nenhum Arquivo ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => Nenhum Arquivo ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => Nenhum Arquivo Startup: C:\Users\Viviane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-02-18] ShortcutTarget: Dropbox.lnk -> C:\Users\Viviane\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) GroupPolicy: Restrição - Chrome <======= ATENÇÃO CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4 8.8.8.8 Tcpip\..\Interfaces\{2D0EECA8-851D-458A-AF86-8CB53FCC60AA}: [DhcpNameServer] 8.8.8.8 8.8.4.4 8.8.8.8 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = hxxp://www.default-search.net/search?sid=492&aid=292&itype=n&ver=14733&tm=553&src=ds&p={searchTerms} SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = hxxp://www.default-search.net/search?sid=492&aid=292&itype=n&ver=14733&tm=553&src=ds&p={searchTerms} SearchScopes: HKU\S-1-5-21-1284938540-3583743031-995251729-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST500LM012XHN-M500MBB_S2ZAJ5DD821982&ts=1425182733&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1284938540-3583743031-995251729-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST500LM012XHN-M500MBB_S2ZAJ5DD821982&ts=1425182733&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1284938540-3583743031-995251729-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST500LM012XHN-M500MBB_S2ZAJ5DD821982&ts=1425182733&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1284938540-3583743031-995251729-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2492} URL = hxxp://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST500LM012XHN-M500MBB_S2ZAJ5DD821982&ts=1425182733&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1284938540-3583743031-995251729-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://www.key-find.com/web/?utm_source=b&utm_medium=cor&utm_campaign=install_ie&utm_content=ds&from=cor&uid=ST500LM012XHN-M500MBB_S2ZAJ5DD821982&ts=1425182733&type=default&q={searchTerms} BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation) BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-08-12] (Oracle Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) BHO-x32: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540003} -> C:\Program Files (x86)\GbPlugin\gbiehcef.dll [2015-09-01] (Caixa Economica Federal) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-12] (Oracle Corporation) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-01-08] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-01-08] (Microsoft Corporation) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Viviane\AppData\Roaming\Mozilla\Firefox\Profiles\ha9sp0i8.default FF SelectedSearchEngine: do-search FF Homepage: hxxp://br.hao123.com/?tn=bav_pro_hp_01_hao123_br FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-12] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-12] (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-12-17] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1284938540-3583743031-995251729-1000: gastecnologia.com.br/sf/cef -> C:\Users\Viviane\AppData\Local\GAS Tecnologia\GBBD\npsf_cef.dll [2015-01-18] (GAS Tecnologia) FF Extension: GBBD Caixa Economica Federal - C:\Users\Viviane\AppData\Local\GAS Tecnologia\GBBD\cef\xpi [2015-03-04] [não assinado] FF Extension: Lembrador Méliuz - C:\Users\Viviane\AppData\Roaming\Mozilla\Firefox\Profiles\ha9sp0i8.default\Extensions\jid1-NI2sWc3cvsAJsg@jetpack.xpi [2015-12-03] FF HKU\S-1-5-21-1284938540-3583743031-995251729-1000\...\Firefox\Extensions: [{87F8774F-B485-47E2-A755-A40A8A5E886D}] - C:\Users\Viviane\AppData\Local\GAS Tecnologia\GBBD\cef\xpi Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://isearch.omiga-plus.com/?type=hp&ts=1417840501&from=slbnew&uid=ST500LM012XHN-M500MBB_S2ZAJ5DD821982","hxxp://istart.webssearches.com/?type=hp&ts=1420964874&from=slbnew&uid=ST500LM012XHN-M500MBB_S2ZAJ5DD821982","hxxp://www.key-find.com/?type=hp&ts=1425182630&from=cor&uid=ST500LM012XHN-M500MBB_S2ZAJ5DD821982","hxxp://www.key-find.com/?type=hppp&ts=1425182685&from=cor&uid=ST500LM012XHN-M500MBB_S2ZAJ5DD821982","hxxp://do-search.com/?type=hp&ts=1429246224&from=cor&uid=ST500LM012XHN-M500MBB_S2ZAJ5DD821982","hxxp://br.hao123.com/?tn=sdkb_inner_protection_04_hao123_br&guid=70bebfafd55e388c20bb59df362a34c8" CHR Profile: C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Apresentações) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-04] CHR Extension: (Google Docs) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04] CHR Extension: (Google Drive) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21] CHR Extension: (YouTube) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25] CHR Extension: (Adblock Plus) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-03] CHR Extension: (Google Search) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (Planilhas do Google) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-04] CHR Extension: (Default-Search) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgbcffenncokfocljomejddmgcpppjom [2015-04-10] CHR Extension: (Documentos Google off-line) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-21] CHR Extension: (Dropbox) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2015-07-01] CHR Extension: (Lembrador Méliuz) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdcfmebflppkljibgpdlboifpcaalolg [2016-01-13] CHR Extension: (Skype) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-12-20] CHR Extension: (Baixou Agora) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbfjpmeddmamejnmmppjlfglfhcjbbai [2016-01-13] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24] CHR Extension: (Cupom Fácil) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\oedomppbbdbbbehcplgghdodacklobnk [2015-12-29] CHR Extension: (GBBD Caixa Economica Federal) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbcaplhfkihhldmlbjhgajdeghjdbffi [2014-12-14] CHR Extension: (Gmail) - C:\Users\Viviane\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-27] CHR HKLM-x32\...\Chrome\Extension: [fgbcffenncokfocljomejddmgcpppjom] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-01-08] ==================== Serviços (Whitelisted) ======================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-12] (AVAST Software) R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4047768 2015-08-12] (Avast Software) R2 BavSvc; C:\Program Files (x86)\Baidu-Security-2014-4.4.4.82805\Baidu Antivirus\5.6.2.130326.0\BavSvc.exe [2805208 2015-07-14] (Baidu, Inc.) R2 BHipsSvc; C:\Program Files (x86)\Baidu-Security-2014-4.4.4.82805\Baidu Antivirus\5.6.2.130326.0\BHipsSvc.exe [544032 2015-07-14] (Baidu, Inc.) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2016-01-08] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2016-01-08] (Microsoft Corporation) R2 GbpSv; C:\Program Files (x86)\GbPlugin\GbpSv.exe [587576 2015-08-13] (GAS Tecnologia) S3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [Arquivo não assinado] R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [26168 2015-12-20] (Hewlett-Packard Company) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272688 2012-08-23] () S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [Arquivo não assinado] S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [Arquivo não assinado] R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2015-05-21] (DEVGURU Co., LTD.) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [Arquivo não assinado] R2 VineyardsTaskSrv; C:\Windows\SysWOW64\bitszdata.dll [414488 2009-07-13] () R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation) R2 Xmlprofsrv; C:\Windows\SysWOW64\appnettime.dll [413824 2009-07-13] () S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3342640 2012-08-23] (Intel® Corporation) ===================== Drivers (Whitelisted) ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-12] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-12] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-12] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-12] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-06] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-06] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-12] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-12] (AVAST Software) U3 BdApiUtil; C:\Program Files (x86)\Baidu-Security-2014-4.4.4.82805\Baidu Antivirus\5.6.2.130326.0\BdApiUtil64.sys [116936 2015-07-14] (Baidu, Inc.) R3 bdark64; C:\Windows\system32\drivers\bdark64.sys [78792 2015-04-20] () U3 BdCameraProtect; C:\Program Files (x86)\Baidu-Security-2014-4.4.4.82805\Baidu Antivirus\5.6.2.130326.0\BdCameraProtect64.sys [25000 2015-07-14] (Baidu, Inc.) S3 BdSandbox; C:\Windows\System32\drivers\BdSandbox.sys [232440 2015-01-08] (Baidu, Inc.) R1 Bfilter; C:\Windows\System32\drivers\Bfilter.sys [62920 2015-07-14] (Baidu, Inc.) R1 Bfmon; C:\Windows\System32\drivers\Bfmon.sys [38344 2015-07-14] (Baidu, Inc.) R1 Bnbase; C:\Windows\System32\drivers\bnbasex64.sys [62792 2015-07-14] (Baidu, Inc.) R1 Bndef; C:\Windows\System32\drivers\bndef64.sys [487144 2015-07-14] (Baidu, Inc.) R3 BNmon; C:\Program Files (x86)\Baidu-Security-2014-4.4.4.82805\Baidu Antivirus\5.6.2.130326.0\Bnmon64.sys [82376 2015-07-14] (Baidu, Inc.) R1 Bprotect; C:\Windows\System32\drivers\Bprotect.sys [171464 2015-07-14] (Baidu, Inc.) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R3 GBPRCM; C:\Program Files (x86)\GbPlugin\gbprcm64.sys [29912 2015-09-03] (GAS Tecnologia) R2 hyperdetect; C:\Windows\system32\drivers\btsiztasks.sys [140984 2009-07-13] () R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-08-12] (Malwarebytes Corporation) R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [115152 2015-08-12] (AVAST Software) U5 RTSPER; C:\Windows\System32\Drivers\RTSPER.sys [465624 2014-01-03] (Realsil Semiconductor Corporation) R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [1514568 2013-05-02] (Realtek Semiconductor Corporation ) R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [273824 2015-08-12] (Avast Software) R3 Warsaw_PP; C:\Program Files (x86)\GbPlugin\wsftprp64.sys [24792 2015-09-03] (GAS Tecnologia LTDA) S2 wmzshandler; C:\Windows\system32\drivers\dxkzfldsport.sys [139952 2009-07-13] () S1 gbpddfac; system32\drivers\gbpddfac64.sys [X] ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um Mês Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-03-03 21:45 - 2016-03-03 21:48 - 00046339 _____ C:\Users\Viviane\Downloads\Addition.txt 2016-03-03 21:43 - 2016-03-03 21:53 - 00030309 _____ C:\Users\Viviane\Downloads\FRST.txt 2016-03-03 21:43 - 2016-03-03 21:53 - 00000000 ____D C:\FRST 2016-03-03 21:39 - 2016-03-03 21:39 - 02371584 _____ (Farbar) C:\Users\Viviane\Downloads\FRST64.exe 2016-03-02 19:41 - 2016-03-02 19:41 - 00074900 _____ C:\Users\Viviane\Downloads\Boleto viviane (2).pdf 2016-03-02 09:35 - 2016-03-02 09:36 - 00001645 _____ C:\Users\Viviane\Documents\shonda.txt 2016-03-02 08:58 - 2016-03-02 08:59 - 00000000 ____D C:\Users\Viviane\Documents\Whey Cor-performance 2LBS - Cellucor-bodyssupplements_files 2016-03-02 08:58 - 2016-03-02 08:58 - 00175305 _____ C:\Users\Viviane\Documents\Whey Cor-performance 2LBS - Cellucor-bodyssupplements.html 2016-03-01 06:50 - 2016-03-01 06:50 - 00000079 _____ C:\Users\Viviane\Documents\city.txt 2016-03-01 06:19 - 2016-03-01 06:19 - 00010349 _____ C:\Users\Viviane\Documents\magazineluiza.pdf 2016-03-01 04:20 - 2016-03-01 04:20 - 00024216 _____ C:\Users\Viviane\Downloads\proposta viviane (1).pdf 2016-03-01 04:10 - 2016-03-01 04:10 - 00074900 _____ C:\Users\Viviane\Downloads\Boleto viviane (1).pdf 2016-03-01 04:10 - 2016-03-01 04:10 - 00024216 _____ C:\Users\Viviane\Downloads\proposta viviane.pdf 2016-02-28 05:54 - 2016-02-28 05:54 - 00026713 _____ C:\Users\Viviane\Downloads\pass.pkpass 2016-02-28 05:44 - 2016-02-28 05:44 - 00096492 _____ C:\Users\Viviane\Documents\COMPREINGRESSOS1.pdf 2016-02-27 06:48 - 2016-02-27 06:48 - 00001126 _____ C:\Users\Viviane\Documents\gas.txt 2016-02-27 06:29 - 2016-02-27 06:29 - 00000246 _____ C:\Users\Viviane\Documents\dilma.txt 2016-02-26 15:19 - 2016-02-26 15:19 - 00038188 _____ C:\Users\Viviane\Downloads\Walt Disney Script.ttf 2016-02-26 05:58 - 2004-08-31 21:18 - 00054488 _____ C:\Users\Viviane\Downloads\Disney.otf 2016-02-26 05:58 - 2004-08-27 07:03 - 00066280 _____ C:\Users\Viviane\Downloads\waltographUI.ttf 2016-02-26 05:57 - 2016-02-26 05:57 - 00066934 _____ C:\Users\Viviane\Downloads\walt_disney.zip 2016-02-26 05:27 - 2016-02-26 05:27 - 00000000 ____D C:\output 2016-02-26 04:17 - 2004-08-27 05:25 - 00004796 _____ C:\Users\Viviane\Downloads\waltograph.txt 2016-02-26 04:17 - 2004-03-15 19:49 - 00010633 _____ C:\Users\Viviane\Downloads\license.txt 2016-02-26 04:15 - 2016-02-26 04:15 - 00020915 _____ C:\Users\Viviane\Downloads\538fonts_new-waltograph.zip 2016-02-26 04:02 - 2010-03-13 04:54 - 00000812 ____N C:\Users\Viviane\Downloads\readme.txt 2016-02-26 00:51 - 2016-03-03 02:04 - 00003122 _____ C:\Windows\System32\Tasks\DriverDocRunAtStartup 2016-02-26 00:51 - 2016-03-02 06:18 - 00000282 _____ C:\Windows\Tasks\DriverDoc_UPDATES.job 2016-02-26 00:51 - 2016-02-26 00:51 - 00003032 _____ C:\Windows\System32\Tasks\DriverDoc_UPDATES 2016-02-26 00:48 - 2016-02-26 00:48 - 00001029 _____ C:\Users\Public\Desktop\DriverDoc.lnk 2016-02-26 00:48 - 2016-02-26 00:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverDoc 2016-02-26 00:48 - 2016-02-26 00:48 - 00000000 ____D C:\Program Files (x86)\DriverDoc 2016-02-26 00:47 - 2016-02-26 00:47 - 00000000 ____D C:\Users\Viviane\AppData\Roaming\Solvusoft 2016-02-26 00:46 - 2016-02-26 00:47 - 03470120 _____ (Solvusoft Corporation ) C:\Users\Viviane\Downloads\DriverDoc_2016_Setup.exe 2016-02-25 20:06 - 2016-02-25 20:06 - 00076944 _____ C:\Users\Viviane\Downloads\agendamento detan 2.pdf 2016-02-25 20:05 - 2016-02-25 20:05 - 00078961 _____ C:\Users\Viviane\Downloads\Requerimento (1).pdf 2016-02-25 20:03 - 2016-02-25 20:03 - 00078298 _____ C:\Users\Viviane\Documents\agendamento detran.pdf 2016-02-25 20:01 - 2016-02-25 20:01 - 00080320 _____ C:\Users\Viviane\Downloads\Requerimento.pdf 2016-02-25 19:57 - 2016-02-25 19:57 - 00000011 _____ C:\Users\Viviane\Documents\cupom suppz.txt 2016-02-24 18:41 - 2016-02-24 18:41 - 00000480 _____ C:\Users\Viviane\Documents\kit gas.txt 2016-02-24 07:02 - 2016-01-18 11:10 - 00000000 ____D C:\Users\Viviane\Downloads\Aviões 2016.1 #AiEuViVantagem 2016-02-24 06:23 - 2016-02-24 06:23 - 115178009 _____ C:\Users\Viviane\Downloads\Avioes 2016-1 AiEuViVantagem.rar 2016-02-24 06:13 - 2016-01-15 11:28 - 00000000 ____D C:\Users\Viviane\Downloads\REI DA CACIMBINHA - VOLUME 3 - VERÃO 2016 2016-02-24 06:12 - 2016-02-24 06:13 - 112165774 _____ C:\Users\Viviane\Downloads\REI DA CACIMBINHA - VOLUME 3 - VERAO 2016.zip 2016-02-24 05:30 - 2016-02-24 05:30 - 00000057 _____ C:\Users\Viviane\Documents\boleto shopfisio.txt 2016-02-24 05:29 - 2016-02-24 05:29 - 00057020 _____ C:\Users\Viviane\Documents\Impressao boleto shopfisio.aspx 2016-02-21 20:01 - 2016-02-21 20:01 - 00000167 _____ C:\Users\Viviane\Documents\cabelo destruido.txt 2016-02-19 23:08 - 2016-03-02 09:11 - 00003198 _____ C:\Windows\System32\Tasks\HPCeeScheduleForViviane 2016-02-19 23:08 - 2016-03-02 09:11 - 00000340 _____ C:\Windows\Tasks\HPCeeScheduleForViviane.job 2016-02-19 19:48 - 2016-02-19 19:48 - 00000529 _____ C:\Users\Viviane\Documents\colchao.txt 2016-02-19 15:16 - 2016-02-19 16:17 - 00001121 _____ C:\Users\Viviane\Documents\pedido suples.txt 2016-02-19 13:48 - 2016-02-19 13:48 - 00000049 _____ C:\Users\Viviane\Documents\CNPJ.txt 2016-02-18 05:10 - 2016-02-18 05:10 - 00000000 ____D C:\Users\Viviane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2016-02-16 16:57 - 2016-02-16 16:57 - 00004144 _____ C:\Users\Viviane\Downloads\comprovante (1).html 2016-02-16 16:47 - 2015-10-27 19:59 - 00000000 ____D C:\Users\Viviane\Downloads\-REI DA CACIMBINHA PRA PAREDAO AUDIO 100% REP.NOVO NOVEMBRO 2015 GILARDO CDS 2016-02-16 16:40 - 2016-03-03 02:30 - 00000000 ____D C:\Users\Viviane\Downloads\joelma calypso 2016-02-16 16:38 - 2016-02-16 16:38 - 127488031 _____ C:\Users\Viviane\Downloads\Nao Teve Amor (1).zip 2016-02-16 15:01 - 2016-02-16 15:02 - 00000000 ____D C:\Users\Viviane\Downloads\WESLEY SAFADAO - GAROTA WHITE AO VIVO EM BRASILIA - DF - 30.01.2016 2016-02-16 15:00 - 2016-02-16 15:00 - 00000199 _____ C:\Users\Viviane\Documents\clembuterol.txt 2016-02-16 14:54 - 2016-02-16 14:54 - 127488031 _____ C:\Users\Viviane\Downloads\Nao Teve Amor.zip 2016-02-16 14:39 - 2016-02-16 14:39 - 04219169 _____ C:\Users\Viviane\Downloads\Joelma Calypso - Nao Teve Amor.rar 2016-02-16 14:36 - 2016-02-16 14:37 - 00000000 ____D C:\Users\Viviane\Downloads\VINGADORA VEM DANÇAR - VERÃO 2016 - WWW.ISRAELCDS.COM 2016-02-13 02:12 - 2016-02-13 02:12 - 00000009 _____ C:\Users\Viviane\Documents\cupom de desconto edge.txt 2016-02-12 11:40 - 2016-02-12 11:40 - 00004150 _____ C:\Users\Viviane\Downloads\comprovante.html 2016-02-11 15:08 - 2016-02-19 23:08 - 00000000 ____D C:\Users\Viviane\AppData\Local\Hewlett-Packard 2016-02-11 14:35 - 2016-02-11 14:35 - 00000000 ____D C:\Users\Viviane\AppData\Roaming\Hewlett-Packard 2016-02-11 14:28 - 2016-02-11 14:28 - 00002227 _____ C:\Users\Viviane\Desktop\HP Support Assistant.lnk 2016-02-11 14:28 - 2016-02-11 14:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support 2016-02-11 14:26 - 2016-02-11 14:26 - 00000000 ____D C:\System.sav 2016-02-11 14:23 - 2016-02-11 14:23 - 00000000 ____D C:\Users\Viviane\AppData\Roaming\hpqLog 2016-02-10 16:51 - 2016-02-24 04:03 - 00000117 _____ C:\Users\Viviane\Documents\shopfisio.txt 2016-02-10 14:14 - 2016-02-17 15:33 - 00000000 ____D C:\Windows\System32\Tasks\Hewlett-Packard 2016-02-10 13:43 - 2016-02-10 13:58 - 03762808 _____ (Oleg N. Scherbakov) C:\Users\Viviane\Downloads\HPSupportSolutionsFramework-12.0.30.473.exe 2016-02-08 10:22 - 2016-03-02 06:23 - 05039104 _____ C:\Windows\system32\FNTCACHE.DAT 2016-02-08 08:35 - 2016-02-26 19:52 - 00111928 _____ C:\Users\Viviane\AppData\Local\GDIPFONTCACHEV1.DAT ==================== Um Mês Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-03-03 21:43 - 2014-12-05 03:59 - 00000902 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-03-03 21:42 - 2014-12-05 03:19 - 00001070 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-03-03 21:28 - 2015-11-21 16:58 - 00000000 ____D C:\Users\Todos os Usuários\GbPlugin 2016-03-03 21:28 - 2015-11-21 16:58 - 00000000 ____D C:\ProgramData\GbPlugin 2016-03-03 20:55 - 2015-06-18 00:44 - 00001038 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1284938540-3583743031-995251729-1000UA.job 2016-03-03 20:19 - 2015-06-18 00:44 - 00000986 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-1284938540-3583743031-995251729-1000Core.job 2016-03-03 03:42 - 2014-12-05 03:19 - 00001066 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-03-03 02:11 - 2009-07-14 01:45 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-03-03 02:11 - 2009-07-14 01:45 - 00014192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-03-03 02:04 - 2014-12-07 01:38 - 00000000 ___RD C:\Users\Viviane\Dropbox 2016-03-03 02:04 - 2014-12-07 00:22 - 00000000 ____D C:\Users\Viviane\AppData\Roaming\Dropbox 2016-03-03 02:00 - 2015-11-21 16:58 - 00000000 ____D C:\Program Files (x86)\GbPlugin 2016-03-03 01:58 - 2009-07-14 02:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-03-02 06:31 - 2009-07-29 13:08 - 00705724 _____ C:\Windows\system32\prfh0416.dat 2016-03-02 06:31 - 2009-07-29 13:08 - 00147528 _____ C:\Windows\system32\prfc0416.dat 2016-03-02 06:31 - 2009-07-14 02:13 - 01636984 _____ C:\Windows\system32\PerfStringBackup.INI 2016-03-02 06:31 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\inf 2016-03-02 06:25 - 2014-12-06 03:48 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2016-03-02 06:10 - 2014-12-06 23:45 - 00000000 ____D C:\Users\Viviane\AppData\Roaming\Skype 2016-02-26 22:19 - 2015-05-13 04:22 - 00278528 ____H C:\Users\Viviane\Documents\photothumb.db 2016-02-26 22:18 - 2015-05-22 11:01 - 00000000 ____D C:\Users\Viviane\Documents\Originals 2016-02-26 20:25 - 2015-02-09 04:13 - 00023552 ____H C:\Users\Viviane\Downloads\photothumb.db 2016-02-26 19:19 - 2015-03-14 18:46 - 00000000 ____D C:\Users\Viviane\AppData\Roaming\HpUpdate 2016-02-26 19:18 - 2015-12-18 08:47 - 00002004 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk 2016-02-26 02:40 - 2014-12-06 03:09 - 00000000 ____D C:\Users\Viviane\AppData\Roaming\PhotoScape 2016-02-19 19:44 - 2014-12-05 03:20 - 00002404 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-02-18 05:10 - 2014-12-07 00:25 - 00005685 _____ C:\Users\Viviane\Documents\compras marcelo.txt 2016-02-17 15:33 - 2015-04-13 02:11 - 00000000 ____D C:\Users\Todos os Usuários\Hewlett-Packard 2016-02-17 15:33 - 2015-04-13 02:11 - 00000000 ____D C:\ProgramData\Hewlett-Packard 2016-02-16 14:36 - 2016-01-11 20:32 - 00000000 ____D C:\Users\Viviane\Downloads\BANDA MAGNIFICOS AO VIVO EM IGAPÓ 09-01-2016 2016-02-11 15:43 - 2014-12-05 03:59 - 00003840 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-02-11 14:44 - 2014-12-05 03:59 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-02-11 14:44 - 2014-12-05 03:59 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-02-11 14:26 - 2015-04-16 04:39 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard 2016-02-11 14:25 - 2014-12-05 01:41 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-02-10 16:50 - 2014-12-05 19:05 - 01601050 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2016-02-09 00:27 - 2014-12-09 22:43 - 00000000 ____D C:\Users\Todos os Usuários\GAS Tecnologia 2016-02-09 00:27 - 2014-12-09 22:43 - 00000000 ____D C:\ProgramData\GAS Tecnologia 2016-02-03 17:02 - 2015-12-01 07:50 - 00000067 _____ C:\Users\Viviane\Documents\tunnigs pedido.txt 2016-02-03 02:37 - 2014-12-05 03:19 - 00004066 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2016-02-03 02:37 - 2014-12-05 03:19 - 00003814 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore ==================== Arquivos na raiz de alguns diretórios ======= 2015-11-15 06:02 - 2015-11-15 06:02 - 0000132 _____ () C:\Users\Viviane\AppData\Roaming\Preferências do Formato GIF do Adobe CS6 2014-12-09 22:43 - 2014-12-09 22:43 - 0015660 _____ () C:\Users\Viviane\AppData\Roaming\unins000.dat 2014-12-09 22:43 - 2014-12-09 22:43 - 0730322 _____ () C:\Users\Viviane\AppData\Roaming\unins000.exe 2014-09-01 05:18 - 2014-09-01 05:18 - 0002086 _____ () C:\Users\Viviane\AppData\Roaming\VMGL 2014-09-01 05:18 - 2016-01-20 00:22 - 0000365 _____ () C:\Users\Viviane\AppData\Roaming\YVETWWON 2014-12-07 03:02 - 2014-12-07 03:02 - 0001456 _____ () C:\Users\Viviane\AppData\Local\Adobe Save for Web 13.0 Prefs 2015-04-16 04:36 - 2015-04-16 04:36 - 0000057 _____ () C:\ProgramData\Ament.ini 2015-03-07 04:41 - 2015-11-25 01:08 - 0012818 _____ () C:\ProgramData\hpzinstall.log Alguns arquivos em TEMP: ==================== C:\Users\Viviane\AppData\Local\Temp\NetFramework45.exe C:\Users\Viviane\AppData\Local\Temp\{12F2FE90-7D82-4018-8F3A-168C4485B022}-DropboxClient_3.14.7.exe ==================== Bamital & volsnap ================= (Não há correção automática para arquivos que não passaram na verificação.) C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente C:\Windows\explorer.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente C:\Windows\system32\services.exe => O arquivo é assinado digitalmente C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente C:\Windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente C:\Windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente LastRegBack: 2016-02-19 02:41 ==================== Fim de FRST.txt ============================