Resultado do exame da Farbar Recovery Scan Tool (FRST) (x86) Versão:25-04-2016 Executado por Marcos (administrador) em MAQUINA05 (26-04-2016 22:05:15) Executando a partir de C:\Users\Marcos\Desktop Perfis Carregados: Marcos & DefaultAppPool (Perfis Disponíveis: Marcos & DefaultAppPool) Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) Idioma: Português (Brasil) Internet Explorer Versão 11 (Navegador padrão: Chrome) Modo da Inicialização: Normal Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (GAS Tecnologia) C:\Program Files\GbPlugin\gbpsv.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe () C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\BCMWLTRY.EXE (ABBYY) C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\System32\CISVC.EXE (SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc.exe () C:\ProgramData\service.exe (Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe (Nero AG) C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE (Microsoft Corporation) C:\Windows\System32\snmp.exe (Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe (Baidu Inc.) C:\Program Files\ToolBox\26.1.7777.582\ToolBoxService.exe () C:\Program Files\trolatunt\updatetrolatunt.exe () C:\Program Files\trolatunt\bin\utiltrolatunt.exe (GAS Tecnologia LTDA) C:\Program Files\Diebold\Warsaw\core.exe (GAS Tecnologia) C:\Program Files\GbPlugin\gbpsv.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe (Microsoft Corporation) C:\Windows\System32\mqtgsvc.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Google Inc.) C:\Program Files\Google\Update\1.3.29.5\GoogleCrashHandler.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe () C:\Program Files\SpaceSoundPro\idscservice.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (VLOME) C:\Users\Marcos\AppData\Local\Temp\00027936\casrss.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (BlackBerry Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (GAS Tecnologia LTDA) C:\Program Files\Diebold\Warsaw\core.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe () C:\Program Files\SpaceSoundPro\idsccom_HKK.exe (Seekar Ltd) C:\Program Files\Ares\Ares.exe (Research In Motion) C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.DesktopHelper.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_TATII4E.EXE (BlackBerry Limited) C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\ProgramData\msiql.exe (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe (Logitech Inc.) C:\Program Files\SetPoint\SetPoint.exe (Logitech Inc.) C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.exe (Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe () C:\ProgramData\conhost51495.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Users\Marcos\AppData\Local\Temp\24357\Setup.exe (Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe (tsvr.com) C:\Users\Marcos\AppData\Roaming\TSv\TSvr.exe (WFini LIMITED) C:\ProgramData\CwinpC\WFini.exe () C:\Windows\Temp\24301\tim.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Tencent) C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCRTP.exe (Tencent) C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCTray.exe (Tencent) C:\Program Files\Common Files\Tencent\QQDownload\130\Tencentdl.exe (Tencent) C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\plugins\QMNetMon\QQPCNetFlow.exe (Tencent) C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCRealTimeSpeedup.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\inetsrv\w3wp.exe ==================== Registro (Whitelisted) =========================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [Logitech Hardware Abstraction Layer] => C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE [100888 2007-10-09] (Logitech Inc.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [986872 2016-01-29] (Microsoft Corporation) HKLM\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [443640 2014-10-31] (BlackBerry Limited) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157992 2015-07-11] (Apple Inc.) HKLM\...\Run: [Diebold - Warsaw] => C:\Program Files\Diebold\Warsaw\core.exe [509752 2015-06-19] (GAS Tecnologia LTDA) HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [595480 2016-03-20] (Oracle Corporation) HKLM\...\Run: [tim.exe -start] => C:\Windows\TEMP\24301\tim.exe [2363392 2016-04-24] () <===== ATENÇÃO HKLM\...\Run: [SpaceSoundPro] => "C:\Program Files\SpaceSoundPro\SpaceSoundPro.exe" HKLM\...\Run: [IDSCCOMHKK] => C:\Program Files\SpaceSoundPro\idsccom_HKK.exe [3935232 2016-04-24] () HKLM\...\Run: [apphide] => C:\Program Files\badu\uc.exe [337500 2016-04-24] () HKLM\...\Run: [ QQPCTray] => C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCTray.exe [356464 2016-04-26] (Tencent) HKLM\...\RunOnce: [WINDOWS_SCREEN_MANAGER_UPDATER_1] => C:\Program Files\Windows Screen Manager\Windows screen manage updater.exe [16896 2016-04-25] (Wizzservices) HKLM\...\RunOnce: [IDSCPRODUCT] => C:\Program Files\SpaceSoundPro\idscservice.exe [605184 2016-04-24] () Winlogon\Notify\ GbPluginBb: C:\Program Files\GbPlugin\gbieh.dll [2015-10-20] (Banco do Brasil) Winlogon\Notify\ GbPluginUni: C:\Program Files\GbPlugin\gbiehUni.dll [2015-07-06] (Banco Itaú Unibanco) HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [ares] => C:\Program Files\Ares\Ares.exe [2758656 2014-03-28] (Seekar Ltd) HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [Rim.DesktopHelper.exe] => C:\Program Files\Research In Motion\BlackBerry Desktop\Rim.DesktopHelper.exe [752656 2013-03-07] (Research In Motion) HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TATII4E.EXE [249440 2012-02-27] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [Installer] => C:\Users\Marcos\AppData\Local\Temp\yeaplayer51495.exe [1968640 2016-04-23] (TZ) <===== ATENÇÃO HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [Pritc] => C:\Users\Marcos\AppData\Local\Temp\00027936\casrss.exe [2958848 2016-04-23] (VLOME) <===== ATENÇÃO HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [osmsg] => C:\ProgramData\WindowsMsg\osmsg.exe [2055168 2016-04-16] () HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [Yeaplayer] => C:\Program Files\Yeaplayer\Yeaplayermd.exe /autostart HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Run: [msiql] => C:\ProgramData\msiql.exe [1907200 2016-04-24] () HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {3e2ce3f1-879c-11e3-b3a7-001c23a57405} - F:\Setup.exe HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {412f1f41-db38-11e4-8843-001c23a57405} - E:\AutoRun.exe HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {7e7aa6b8-1007-11e4-8797-001c23a57405} - E:\AutoRun.exe HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {7e7aa6cc-1007-11e4-8797-001c23a57405} - E:\AutoRun.exe HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {80c911af-c7b8-11e4-843b-001c23a57405} - E:\AutoRun.exe HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {9bf9d9eb-d2c2-11e5-9dfc-001c23a57405} - E:\AutoRun.exe HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {9bf9da23-d2c2-11e5-9dfc-001c23a57405} - E:\AutoRun.exe HKU\S-1-5-21-1231958544-1669365884-389720028-1000\...\MountPoints2: {f2958b1b-92c6-11e4-a5e9-001c23a57405} - E:\AutoRun.exe HKU\S-1-5-21-1231958544-1669365884-389720028-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [10240 2009-07-13] (Microsoft Corporation) HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-01-30] (Microsoft Corporation) HKU\S-1-5-18\...\RunOnce: [iCloud] => C:\Program Files\Common Files\Apple\Internet Services\iCloud.exe [60688 2015-12-01] (Apple Inc.) ShellExecuteHooks: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399F83} - C:\Program Files\GbPlugin\gbieh.dll [1945472 2015-10-20] (Banco do Brasil) ShellExecuteHooks: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399008} - C:\PROGRAM FILES\GbPlugin\gbiehuni.dll [1759992 2015-07-06] (Banco Itaú Unibanco) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickSet.lnk [2015-09-03] ShortcutTarget: QuickSet.lnk -> C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SetPoint.lnk [2014-05-20] ShortcutTarget: SetPoint.lnk -> C:\Program Files\SetPoint\SetPoint.exe (Logitech Inc.) GroupPolicy: Restrição - Chrome <======= ATENÇÃO CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{97789A24-C7FB-44BC-A327-DFF4378C35D3}: [NameServer] 82.163.143.185,82.163.142.185 Tcpip\..\Interfaces\{97789A24-C7FB-44BC-A327-DFF4378C35D3}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.2345.com/?34838 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-1231958544-1669365884-389720028-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.oursurfing.com/web/?type=dspp&ts=1433814071&z=7fae58fde5ade31ab44c97ag7z1cfcfb7g8z1e7mez&from=smt&uid=ST9250410AS_5VG40QATXXXX5VG40QAT&q={searchTerms} HKU\S-1-5-21-1231958544-1669365884-389720028-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.oursurfing.com/web/?type=dspp&ts=1433814071&z=7fae58fde5ade31ab44c97ag7z1cfcfb7g8z1e7mez&from=smt&uid=ST9250410AS_5VG40QATXXXX5VG40QAT&q={searchTerms} HKU\S-1-5-21-1231958544-1669365884-389720028-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.2345.com/?34838 URLSearchHook: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 - (Sem Nome) - {84FF7BD6-B47F-46F8-9130-01B2696B36CB} - Nenhum Arquivo SearchScopes: HKLM -> {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://start.iminent.com/?appId=CB813EFA-1981-4A63-B25B-D8570AA79D43&ref=toolbox&q={searchTerms} SearchScopes: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE SearchScopes: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 -> {B0081CF8-51C3-4F52-BD6E-8AFC53DFFA06} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 -> {BFFED5CA-8BDF-47CC-AED0-23F4E6D77732} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} SearchScopes: HKU\S-1-5-21-1231958544-1669365884-389720028-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms} BHO: toolbox -> {063D037D-F7F6-4D75-940F-54EE0011F82B} -> C:\Users\Marcos\AppData\LocalLow\ToolBox\26.1.7777.582\toolbox.dll [2014-07-23] () BHO: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_77\bin\ssv.dll [2016-03-27] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION) BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll [2012-03-08] (Microsoft Corporation) BHO: IMinent WebBooster (BHO) -> {A09AB6EB-31B5-454C-97EC-9B294D92EE2A} -> Nenhum Arquivo BHO: PriceFountain -> {b608cc98-54de-4775-96c9-097de398500c} -> C:\Users\Marcos\AppData\Local\PriceFountain\PriceFountainIE.dll => Nenhum Arquivo BHO: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540000} -> C:\Program Files\GbPlugin\gbieh.dll [2015-10-20] (Banco do Brasil) BHO: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540008} -> C:\PROGRAM FILES\GBPLUGIN\gbiehuni.dll [2015-07-06] (Banco Itaú Unibanco) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-03-27] (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll [2012-01-25] (SEIKO EPSON CORPORATION) Toolbar: HKLM - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION) DPF: {021AFC0F-30F4-474D-9903-CE42D9539B17} hxxp://192.168.1.36:90/dvr_ocx.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll [2009-02-26] (Microsoft Corporation) StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1401408544&from=smt&uid=ST9250410AS_5VG40QATXXXX5VG40QAT FireFox: ======== FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-03-27] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-03-27] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Nenhum Arquivo] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin: @qq.com/QQPCMgr -> C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\npQMExtensionsMozilla.dll [2016-04-26] (Tencent Technology (Shenzhen) Company Limited) FF Plugin: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2014-11-28] () FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-03] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.) FF Plugin: JFGuide -> C:\Program Files\NetSurveillance\CMS\npGuide.dll [Nenhum Arquivo] FF Plugin: JFWeb -> C:\Program Files\NetSurveillance\CMS\npWebPlugin.dll [Nenhum Arquivo] FF Plugin HKU\S-1-5-21-1231958544-1669365884-389720028-1000: gastecnologia.com.br/sf/bb -> C:\Users\Marcos\AppData\Local\GAS Tecnologia\GBBD\npsf_bb.dll [2015-03-06] (GAS Tecnologia) FF Extension: Sem Nome - C:\Program Files\AmiExt\flashEnhancer\ff [não encontrado (a)] FF HKLM\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files\Epson Software\E-Web Print\Firefox Add-on FF Extension: E-Web Print - C:\Program Files\Epson Software\E-Web Print\Firefox Add-on [2015-06-19] [não assinado] Chrome: ======= CHR HomePage: Default -> hxxps://www.google.com.br/ CHR StartupUrls: Default -> "hxxps://www.google.com.br/" CHR DefaultSearchURL: Default -> hxxp://www.mercadolivre.com.br/jm/search?as_word={searchTerms} CHR DefaultSearchKeyword: Default -> mercadolivre.com.br CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.866\_platform_specific\win_x86\widevinecdmadapter.dll (Google Inc.) CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\49.0.2623.112\PepperFlash\pepflashplayer.dll () CHR Profile: C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default CHR Extension: (Google Drive) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23] CHR Extension: (YouTube) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-01] CHR Extension: (Google Search) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-02] CHR Extension: (GBBD Guardião - Itaú 30 horas) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\kgmpojlddncminmkddkpoegdjhojjipg [2015-05-16] CHR Extension: (GBBD Banco do Brasil) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\mkeabchhfifpaaoefpockjhaphjmoapp [2015-05-16] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-05] CHR Extension: (Gmail) - C:\Users\Marcos\AppData\Local\Google\Chrome\User Data\default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-31] CHR HKLM\...\Chrome\Extension: [cabkchdidokfhjppnlphhodlnojncdao] - C:\Users\Marcos\AppData\Roaming\ToolBox\26.1.7777.582\Release.crx [2014-07-23] ==================== Serviços (Whitelisted) ======================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY) R3 BlackBerry Device Manager; C:\Program Files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [588024 2014-10-31] (BlackBerry Limited) S2 BugreportW; C:\Program Files\hohobnd\reekge.exe [961800 2016-04-22] () R2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [1962192 2015-05-22] (Dell Inc.) R2 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [184528 2015-05-22] (Dell Inc.) S2 Drvcoresrv; C:\Program Files\Dravsynlether\Drvcoresrv.exe [302336 2016-04-22] () R2 EpsonCustomerParticipation; C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe [539744 2012-05-10] (SEIKO EPSON CORPORATION) R2 EpsonScanSvc; C:\Windows\system32\EscSvc.exe [122000 2011-12-12] (Seiko Epson Corporation) R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [310272 2012-06-01] (Microsoft Corporation) R2 GbpSv; C:\Program Files\GbPlugin\gbpsv.exe [593120 2015-09-22] (GAS Tecnologia) R2 GoogleChromeUpService; C:\ProgramData\service.exe [1745920 2016-04-21] () [Arquivo não assinado] R2 IhPul; C:\Users\Marcos\AppData\Roaming\TSv\TSvr.exe [376592 2016-04-24] (tsvr.com) R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [13824 2009-07-13] (Microsoft Corporation) R2 iprip; C:\Windows\System32\iprip.dll [29696 2009-07-13] (Microsoft Corporation) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2016-01-29] (Microsoft Corporation) R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [126464 2010-11-20] (Microsoft Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-01-18] (Hewlett-Packard) [Arquivo não assinado] R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [292816 2016-01-29] (Microsoft Corporation) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-01-18] (Hewlett-Packard) [Arquivo não assinado] R2 QQPCRTP; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCRTP.exe [301656 2016-04-26] (Tencent) R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [20648 2015-06-11] (Dell Inc.) R2 ToolBoxService; C:\Program Files\ToolBox\26.1.7777.582\ToolBoxService.exe [80576 2014-07-23] (Baidu Inc.) [Arquivo não assinado] R2 Update trolatunt; C:\Program Files\trolatunt\updatetrolatunt.exe [321824 2014-07-28] () R2 Util trolatunt; C:\Program Files\trolatunt\bin\utiltrolatunt.exe [321824 2014-07-28] () R2 Warsaw Technology; C:\Program Files\Diebold\Warsaw\core.exe [509752 2015-06-19] (GAS Tecnologia LTDA) R2 WdMan; C:\ProgramData\CwinpC\WFini.exe [574672 2016-04-25] (WFini LIMITED) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [4038656 2013-10-28] (Dell Inc.) [Arquivo não assinado] S2 Update Deal Keeper; "C:\Program Files\Deal Keeper\updateDealKeeper.exe" [X] S2 WindowsProtectManger; C:\ProgramData\WindowsProtectManger\wprotectmanager.exe -service [X] <==== ATENÇÃO ===================== Drivers (Whitelisted) ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2013-10-28] (Broadcom Corporation) S3 CSRBC; C:\Windows\System32\Drivers\csrbcxp.sys [31744 2007-01-16] (CSR, plc) [Arquivo não assinado] R3 DDDriver; C:\Windows\System32\drivers\DDDriver32Dcsa.sys [20688 2015-02-26] (Dell Computer Corporation) R3 DellProf; C:\Windows\System32\drivers\DellProf.sys [22192 2015-05-22] (Dell Computer Corporation) R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [30616 2013-03-04] (Elaborate Bytes AG) R0 GbpKm; C:\Windows\System32\drivers\gbpkm.sys [49496 2015-11-25] (GAS Tecnologia) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [253704 2015-11-13] (Microsoft Corporation) R1 MpKsl98e72fff; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{2A400B34-C865-4C75-AACA-953D24ECC052}\MpKsl98e72fff.sys [39168 2016-04-25] (Microsoft Corporation) R1 ndisrd; C:\Windows\System32\DRIVERS\gbpndisrdn.sys [29400 2015-04-09] (GAS Tecnologia) R1 QMIEProtect; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QMIEProtect.sys [50296 2016-04-26] () R1 QMUdisk; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QMUdisk.sys [104152 2016-02-27] (Tencent) S1 QQPCHelper; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQPCHelper.sys [25336 2016-04-26] (Tencent) R2 QQSysMon; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\QQSysMon.sys [108920 2016-04-26] (电脑管家) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb.sys [68608 2014-05-06] (BlackBerry Limited) S3 silabenm; C:\Windows\System32\DRIVERS\silabenm.sys [16128 2014-04-11] (Silicon Laboratories) S3 silabser; C:\Windows\System32\DRIVERS\silabser.sys [67968 2014-04-11] (Silicon Laboratories) R1 softaal; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\softaal.sys [36216 2016-04-26] (Tencent) S3 Spring; C:\Program Files\Baidu Security\Baidu Antivirus\Spring.sys [96608 2014-06-18] () R3 TAOAccelerator; C:\Windows\system32\Drivers\TAOAccelerator.sys [116408 2016-04-26] (Tencent) R1 TAOKernelDriver; C:\Windows\system32\Drivers\TAOKernel.sys [100088 2016-04-26] (Tencent Technology(Shenzhen) Company Limited) R3 TFsFlt; C:\Windows\System32\Drivers\TFsFlt.sys [150008 2016-04-26] (电脑管家) S3 TosRfSnd; C:\Windows\System32\drivers\tosrfsnd.sys [53760 2010-04-26] (TOSHIBA Corporation) [Arquivo não assinado] R1 TSDefenseBt; C:\Windows\System32\DRIVERS\TSDefenseBt.sys [14008 2016-04-26] (Tencent) R0 TsFltMgr; C:\Windows\System32\drivers\TsFltMgr.sys [128216 2016-04-26] (电脑管家) R1 TSKSP; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\TSKsp.sys [210616 2016-04-26] (电脑管家) R2 tsnethlp; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\TsNetHlp.sys [43768 2016-04-26] () R3 TSSK; C:\Windows\System32\tssk.sys [73976 2016-04-26] (电脑管家) R1 TSSysKit; C:\Program Files\Tencent\QQPCMgr\11.4.17339.217\TSSysKit.sys [102136 2016-04-26] (电脑管家) R4 WinDivert1.1; C:\Program Files\Diebold\Warsaw\WinDivert32.sys [31448 2015-04-01] (Basil) R1 {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw; C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw.sys [52928 2014-05-22] (StdLib) R1 {8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w; C:\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}w.sys [52928 2014-05-22] (StdLib) S3 Baidu PC Faster FileShredder; \??\C:\Program Files\Baidu Security\PC Faster\4.0.0.0\FileKill_x86.sys [X] S1 Bfilter; \??\C:\Windows\System32\drivers\Bfilter.sys [X] S1 Bfmon; \??\C:\Windows\System32\drivers\Bfmon.sys [X] S0 Bhbase; System32\drivers\Bhbase.sys [X] S3 BHipsEx; \??\C:\Windows\System32\drivers\BHipsEx.sys [X] S1 Bnbase; System32\drivers\bnbasex.sys [X] S1 Bndef; \??\C:\Windows\System32\drivers\bndef.sys [X] S1 Bprotect; \??\C:\Windows\System32\drivers\Bprotect.sys [X] S3 BprotectEx; \??\C:\Windows\System32\drivers\BprotectEx.sys [X] S3 BtAudioBusSrv; System32\Drivers\BtAudioBus.sys [X] S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X] S0 gbpddreg; system32\drivers\gbpddreg32.sys [X] S3 huawei_cdcacm; system32\DRIVERS\ew_jucdcacm.sys [X] S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X] S0 MPCBase; System32\drivers\MPCBase.sys [X] S1 MPCKpt; system32\DRIVERS\MPCKpt.sys [X] S3 PCFApiUtil; \??\C:\Program Files\Baidu Security\PC Faster\4.0.0.0\PCFApiUtil.sys [X] ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um Mês Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-04-26 22:05 - 2016-04-26 22:07 - 00029509 _____ C:\Users\Marcos\Desktop\FRST.txt 2016-04-26 21:37 - 2016-04-26 22:05 - 00000000 ____D C:\FRST 2016-04-26 21:31 - 2016-04-26 21:33 - 01726976 _____ (Farbar) C:\Users\Marcos\Desktop\FRST.exe 2016-04-26 21:31 - 2016-04-26 21:31 - 00005120 _____ C:\Users\Marcos\AppData\Roaming\GiftBag.db 2016-04-26 21:30 - 2016-04-26 21:30 - 00000000 ____D C:\Users\Todos os Usuários\TXQMPC 2016-04-26 21:30 - 2016-04-26 21:30 - 00000000 ____D C:\ProgramData\TXQMPC 2016-04-26 21:30 - 2016-04-26 21:28 - 00116408 _____ (Tencent) C:\Windows\system32\Drivers\TAOAccelerator.sys 2016-04-26 21:30 - 2016-04-26 21:28 - 00100088 _____ (Tencent Technology(Shenzhen) Company Limited) C:\Windows\system32\Drivers\TAOKernel.sys 2016-04-26 21:30 - 2016-04-26 21:28 - 00014008 _____ (Tencent) C:\Windows\system32\Drivers\TSDefenseBt.sys 2016-04-26 21:29 - 2016-04-26 21:36 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\Tencent 2016-04-26 21:29 - 2016-04-26 21:28 - 00073976 _____ (电脑管家) C:\Windows\system32\TSSK.sys 2016-04-26 21:28 - 2016-04-26 21:30 - 00000000 ____D C:\Program Files\Common Files\Tencent 2016-04-26 21:28 - 2016-04-26 21:28 - 00150008 _____ (电脑管家) C:\Windows\system32\Drivers\TFsFlt.sys 2016-04-26 21:28 - 2016-04-26 21:28 - 00128216 _____ (电脑管家) C:\Windows\system32\Drivers\TsFltMgr.sys 2016-04-26 21:26 - 2016-04-26 21:33 - 00000000 ____D C:\Users\Todos os Usuários\Tencent 2016-04-26 21:26 - 2016-04-26 21:33 - 00000000 ____D C:\ProgramData\Tencent 2016-04-26 21:26 - 2016-04-26 21:26 - 00000000 ____D C:\Program Files\Tencent 2016-04-26 20:27 - 2016-04-26 21:44 - 00000000 ____D C:\Program Files\WinZipper 2016-04-26 20:26 - 2016-04-26 20:26 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\WinZiper 2016-04-26 20:26 - 2016-04-26 20:26 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\eCyber 2016-04-26 20:21 - 2016-04-26 20:21 - 00000001 _____ C:\Windows\system32\br.html 2016-04-26 20:21 - 2016-04-26 20:21 - 00000000 ____D C:\Users\Todos os Usuários\CwinpC 2016-04-26 20:21 - 2016-04-26 20:21 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\TSv 2016-04-26 20:21 - 2016-04-26 20:21 - 00000000 ____D C:\ProgramData\CwinpC 2016-04-26 20:21 - 2016-04-26 20:21 - 00000000 ____D C:\Program Files\QQBrowser 2016-04-26 20:19 - 2016-04-26 20:19 - 00002292 _____ C:\Users\Todos os Usuários\webad.xml 2016-04-26 20:19 - 2016-04-26 20:19 - 00002292 _____ C:\ProgramData\webad.xml 2016-04-25 19:26 - 2016-04-25 19:16 - 00939008 _____ C:\Users\Marcos\AppData\Roaming\BlackEx.exe 2016-04-25 19:25 - 2016-04-25 19:16 - 00939008 _____ C:\Users\Marcos\AppData\Roaming\Geotouch.exe 2016-04-25 19:23 - 2016-04-25 19:23 - 00848437 _____ C:\Users\Marcos\AppData\Roaming\Qvo-In.bin 2016-04-25 19:20 - 2016-04-25 19:20 - 00000000 ____D C:\Users\Public\Documents\Tools 2016-04-25 19:19 - 2016-04-25 19:19 - 00000000 ____D C:\Users\Todos os Usuários\39158c0c-7203-0 2016-04-25 19:19 - 2016-04-25 19:19 - 00000000 ____D C:\Users\Todos os Usuários\39158c0c-24d5-1 2016-04-25 19:19 - 2016-04-25 19:19 - 00000000 ____D C:\ProgramData\39158c0c-7203-0 2016-04-25 19:19 - 2016-04-25 19:19 - 00000000 ____D C:\ProgramData\39158c0c-24d5-1 2016-04-25 19:18 - 2016-04-26 12:56 - 00000000 ____D C:\Program Files\DNS Unlocker 2016-04-25 19:18 - 2016-04-25 19:18 - 00000000 ____D C:\Program Files\badu 2016-04-25 19:17 - 2016-04-26 00:00 - 00000000 ____D C:\Program Files\sunnyday 2016-04-25 19:17 - 2016-04-25 19:19 - 00015408 _____ C:\Users\Marcos\AppData\Roaming\InstallationConfiguration.xml 2016-04-25 19:17 - 2016-04-25 19:17 - 00127488 _____ C:\Users\Marcos\AppData\Roaming\Installer.dat 2016-04-25 19:17 - 2016-04-25 19:17 - 00000000 ____D C:\Users\Marcos\AppData\Local\csdi_monetize_220160425 2016-04-25 19:16 - 2016-04-26 00:00 - 00000000 ____D C:\Program Files\comoBoss 2016-04-25 19:15 - 2016-04-25 19:18 - 00000000 ____D C:\Program Files\Windows Screen Manager 2016-04-25 19:15 - 2016-04-25 11:47 - 01266688 _____ C:\Users\Todos os Usuários\conhost51495.exe 2016-04-25 19:15 - 2016-04-25 11:47 - 01266688 _____ C:\ProgramData\conhost51495.exe 2016-04-24 17:04 - 2016-04-24 13:55 - 01907200 _____ C:\Users\Todos os Usuários\msiql.exe 2016-04-24 17:04 - 2016-04-24 13:55 - 01907200 _____ C:\ProgramData\msiql.exe 2016-04-24 16:03 - 2016-04-24 16:03 - 00000000 ____D C:\Users\Todos os Usuários\pdf-convert 2016-04-24 16:03 - 2016-04-24 16:03 - 00000000 ____D C:\ProgramData\pdf-convert 2016-04-24 15:39 - 2016-04-24 15:39 - 00000000 ____D C:\Windows\system32\pdfconverter 2016-04-24 15:39 - 2016-04-24 15:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\pdf-convert 2016-04-24 15:39 - 2016-04-24 15:39 - 00000000 ____D C:\Program Files\pdf-convert 2016-04-24 15:39 - 2001-10-29 01:42 - 00116224 _____ C:\Windows\system32\pdfmonnt.dll 2016-04-24 15:32 - 2016-04-24 15:43 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\MOVAVI 2016-04-24 15:32 - 2016-04-24 15:32 - 00004979 _____ C:\Users\Todos os Usuários\bqeojehc.wbx 2016-04-24 15:32 - 2016-04-24 15:32 - 00004979 _____ C:\ProgramData\bqeojehc.wbx 2016-04-24 15:32 - 2016-04-24 15:32 - 00001155 _____ C:\Users\Public\Desktop\Movavi PowerPoint To Video Converter 2.lnk 2016-04-24 15:32 - 2016-04-24 15:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movavi PowerPoint To Video Converter 2 2016-04-24 15:31 - 2016-04-24 15:32 - 00000000 ____D C:\Program Files\Movavi PowerPoint To Video Converter 2 2016-04-24 15:23 - 2016-04-24 15:23 - 00000000 ____D C:\Users\Marcos\AppData\Local\{7D6A43FC-7C49-420E-BD57-415F45B9FA4B} 2016-04-24 14:54 - 2016-04-21 00:03 - 02496403 _____ ( ) C:\Users\Marcos\AppData\Roaming\yeaplayer_51495.exe 2016-04-24 14:31 - 2016-04-21 05:54 - 01745920 _____ C:\Users\Todos os Usuários\service.exe 2016-04-24 14:31 - 2016-04-21 05:54 - 01745920 _____ C:\ProgramData\service.exe 2016-04-24 14:15 - 2016-04-21 05:54 - 01745920 _____ C:\Users\Marcos\AppData\Roaming\service.exe 2016-04-24 13:50 - 2016-04-24 13:50 - 00000000 ____D C:\Users\Marcos\AppData\Local\csdi_monetize_320160423 2016-04-24 13:41 - 2016-04-24 15:47 - 00000000 ____D C:\Program Files\SpaceSoundPro 2016-04-24 13:10 - 2016-04-24 13:11 - 00000000 ____D C:\Users\Marcos\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108 2016-04-24 13:10 - 2016-04-24 13:10 - 00000000 ____D C:\Program Files\Dravsynlether 2016-04-24 13:10 - 2016-04-24 13:10 - 00000000 ____D C:\extensions 2016-04-24 13:09 - 2016-04-26 20:21 - 00000000 ____D C:\Program Files\hohobnd 2016-04-24 12:51 - 2016-04-24 13:10 - 00000000 ____D C:\Users\Public\Documents\dmp 2016-04-23 01:40 - 2016-04-23 01:40 - 00000000 ____D C:\Users\Todos os Usuários\Thunder Network 2016-04-23 01:40 - 2016-04-23 01:40 - 00000000 ____D C:\Users\Public\Thunder Network 2016-04-23 01:40 - 2016-04-23 01:40 - 00000000 ____D C:\ProgramData\Thunder Network 2016-04-23 01:26 - 2016-04-23 01:26 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\MCorp 2016-04-23 01:15 - 2016-04-23 08:47 - 00000000 ____D C:\Program Files\MPC Cleaner 2016-04-23 01:02 - 2016-04-23 01:02 - 00000286 __RSH C:\Users\Marcos\ntuser.pol 2016-04-23 00:51 - 2016-04-23 01:01 - 00000296 _____ C:\Windows\Tasks\Price Fountain.job 2016-04-23 00:51 - 2016-04-23 00:51 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\PriceFountain 2016-04-23 00:49 - 2016-04-23 00:49 - 00000000 ____D C:\Program Files\MixVideoPlayer 2016-04-23 00:49 - 2016-04-21 11:50 - 01266688 _____ C:\Users\Marcos\AppData\Roaming\conhost51495.exe 2016-04-23 00:48 - 2016-04-23 00:48 - 00000000 ____D C:\Users\Todos os Usuários\04fcec7e-2a93-0 2016-04-23 00:48 - 2016-04-23 00:48 - 00000000 ____D C:\ProgramData\04fcec7e-2a93-0 2016-04-23 00:47 - 2016-04-23 00:47 - 00000000 ____D C:\Users\Todos os Usuários\04fcec7e-2127-1 2016-04-23 00:47 - 2016-04-23 00:47 - 00000000 ____D C:\ProgramData\04fcec7e-2127-1 2016-04-23 00:45 - 2016-04-23 01:10 - 00000000 ____D C:\Users\Marcos\AppData\Local\Setup Wizard 2016-04-23 00:43 - 2016-04-23 00:43 - 00000000 ____D C:\Users\Todos os Usuários\WindowsMsg 2016-04-23 00:43 - 2016-04-23 00:43 - 00000000 ____D C:\ProgramData\WindowsMsg 2016-04-23 00:42 - 2016-04-24 12:46 - 00000000 ____D C:\Users\Todos os Usuários\UpService 2016-04-23 00:42 - 2016-04-24 12:46 - 00000000 ____D C:\ProgramData\UpService 2016-04-23 00:42 - 2016-04-23 00:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioVideoKit 2016-04-23 00:40 - 2016-04-26 00:40 - 00000308 _____ C:\Windows\Tasks\Update Service for Torrent Search2.job 2016-04-23 00:38 - 2016-04-23 00:38 - 00000000 ____D C:\Users\Marcos\AppData\Local\GetGo 2016-04-23 00:37 - 2016-04-23 00:37 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\GetGo Software 2016-04-23 00:36 - 2016-04-23 00:40 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GetGo Software 2016-04-23 00:36 - 2016-04-23 00:40 - 00000000 ____D C:\Program Files\GetGo Software 2016-04-23 00:34 - 2016-04-26 21:39 - 00000344 ____H C:\Windows\Tasks\OKABEPSHNWPJMSKM.job 2016-04-23 00:34 - 2016-04-23 00:42 - 00000000 ____D C:\Program Files\HomePageDefender 2016-04-23 00:34 - 2016-04-23 00:40 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\ImageCropResize 2016-04-23 00:34 - 2016-04-23 00:34 - 00000000 ____D C:\Users\Todos os Usuários\Service5184 2016-04-23 00:34 - 2016-04-23 00:34 - 00000000 ____D C:\Users\Todos os Usuários\12db864551ae4c578eb17db1a9f5d3cf 2016-04-23 00:34 - 2016-04-23 00:34 - 00000000 ____D C:\ProgramData\Service5184 2016-04-23 00:34 - 2016-04-23 00:34 - 00000000 ____D C:\ProgramData\12db864551ae4c578eb17db1a9f5d3cf 2016-04-23 00:30 - 2016-04-23 00:31 - 03621488 _____ C:\Users\Marcos\Downloads\office_convert_powerpoint_to_image_jpgjpeg_crack.exe 2016-04-23 00:14 - 2016-04-23 00:48 - 00000000 ____D C:\Program Files\office Convert PowerPoint to Image Jpg-Jpeg 2016-04-22 23:50 - 2016-04-23 00:12 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\GetRightToGo 2016-04-22 23:50 - 2016-04-23 00:00 - 24176672 _____ (fCoder Group, Inc. ) C:\Users\Marcos\Downloads\udc.exe 2016-04-22 23:48 - 2016-04-22 23:49 - 00367936 _____ (RegNow.com) C:\Users\Marcos\Downloads\Download_office-convert-powerpoint-to-image-jpg-jpeg-aff.exe 2016-04-22 22:53 - 2016-04-22 22:53 - 40616016 _____ C:\Users\Marcos\Desktop\Gratidão Gabriela Rocha.wav 2016-04-22 12:56 - 2016-04-22 12:57 - 00000000 ____D C:\Users\Marcos\AppData\Local\{62CC13B7-22E4-4720-8EED-A6A1467F7095} 2016-04-22 11:48 - 2016-04-22 11:48 - 00000000 ____D C:\Users\Marcos\AppData\Local\{D04FB502-88BE-4956-B52D-697DC2A790F5} 2016-04-22 11:48 - 2016-04-22 11:48 - 00000000 ____D C:\Users\Marcos\AppData\Local\{25BBBA8E-3FC7-4DC0-A76E-7F370C095331} 2016-04-22 11:47 - 2016-04-22 11:47 - 00000000 ____D C:\Users\Marcos\AppData\Local\{DC82D6F9-A385-43ED-8BCB-6C46BE0B72CF} 2016-04-22 11:46 - 2016-04-22 11:46 - 00000000 ____D C:\Users\Marcos\AppData\Local\{BA243885-EAD8-4B40-AFB4-70FE22A4C52C} 2016-04-22 11:41 - 2016-04-22 11:42 - 00000000 ____D C:\Users\Marcos\AppData\Local\{6DB0CB31-6565-4FD9-B565-6F13772C243B} 2016-04-22 01:39 - 2016-04-22 11:16 - 00000408 _____ C:\Windows\Tasks\Driver Easy Scheduled Scan.job 2016-04-22 01:39 - 2016-04-22 01:39 - 00001080 _____ C:\Users\Public\Desktop\Driver Easy.lnk 2016-04-22 01:39 - 2016-04-22 01:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Easy 2016-04-21 22:57 - 2016-04-22 11:40 - 00000000 ____D C:\Users\Marcos\Desktop\fotos festa 2016-04-21 13:44 - 2016-04-21 13:44 - 00000000 ____D C:\Users\Marcos\AppData\Local\{3DF9E8C8-8145-428E-80CD-E32385781F82} 2016-04-17 15:26 - 2016-04-17 15:27 - 00000000 ____D C:\Users\Marcos\AppData\Local\{B0BCEE1A-1600-4376-81F7-8C10C6AD35C0} 2016-04-17 15:19 - 2016-04-17 15:19 - 00000000 ____D C:\Users\Marcos\AppData\Local\{DCC2BD41-E275-47D8-AFF8-BEDE01A17BFE} 2016-04-17 15:18 - 2016-04-17 15:18 - 00000000 ____D C:\Users\Marcos\AppData\Local\{EAF945DC-5C91-4364-9CDF-F71A0BD3D104} 2016-04-16 23:34 - 2016-04-16 23:35 - 01090944 _____ (Unity Technologies ApS) C:\Users\Marcos\Downloads\UnityWebPlayer (3).exe 2016-04-16 23:34 - 2016-04-16 23:34 - 01090944 _____ (Unity Technologies ApS) C:\Users\Marcos\Downloads\UnityWebPlayer (2).exe 2016-04-16 01:16 - 2016-03-31 15:41 - 00346320 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2016-04-16 01:16 - 2016-03-30 21:03 - 20352512 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-04-16 01:16 - 2016-03-30 21:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2016-04-16 01:16 - 2016-03-30 21:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2016-04-16 01:16 - 2016-03-30 20:53 - 00496640 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2016-04-16 01:16 - 2016-03-30 20:52 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2016-04-16 01:16 - 2016-03-30 20:52 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2016-04-16 01:16 - 2016-03-30 20:52 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2016-04-16 01:16 - 2016-03-30 20:52 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2016-04-16 01:16 - 2016-03-30 20:51 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-04-16 01:16 - 2016-03-30 20:48 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2016-04-16 01:16 - 2016-03-30 20:48 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2016-04-16 01:16 - 2016-03-30 20:46 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2016-04-16 01:16 - 2016-03-30 20:45 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2016-04-16 01:16 - 2016-03-30 20:45 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2016-04-16 01:16 - 2016-03-30 20:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2016-04-16 01:16 - 2016-03-30 20:45 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2016-04-16 01:16 - 2016-03-30 20:41 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2016-04-16 01:16 - 2016-03-30 20:38 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2016-04-16 01:16 - 2016-03-30 20:34 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2016-04-16 01:16 - 2016-03-30 20:33 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2016-04-16 01:16 - 2016-03-30 20:31 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2016-04-16 01:16 - 2016-03-30 20:31 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2016-04-16 01:16 - 2016-03-30 20:30 - 04611072 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2016-04-16 01:16 - 2016-03-30 20:30 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2016-04-16 01:16 - 2016-03-30 20:29 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2016-04-16 01:16 - 2016-03-30 20:24 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2016-04-16 01:16 - 2016-03-30 20:23 - 02056192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2016-04-16 01:16 - 2016-03-30 20:23 - 00693248 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2016-04-16 01:16 - 2016-03-30 20:23 - 00689664 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2016-04-16 01:16 - 2016-03-30 20:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2016-04-16 01:16 - 2016-03-30 20:21 - 13811712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-04-16 01:16 - 2016-03-30 20:05 - 02121216 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2016-04-16 01:16 - 2016-03-30 20:02 - 01311744 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2016-04-16 01:16 - 2016-03-30 20:00 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2016-04-13 09:21 - 2016-04-04 14:54 - 00034024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2016-04-13 09:21 - 2016-04-04 14:42 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2016-04-13 09:21 - 2016-04-02 10:07 - 01218048 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2016-04-13 09:21 - 2016-03-23 11:02 - 00177664 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2016-04-13 09:21 - 2016-03-17 15:04 - 00560640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2016-04-13 09:21 - 2016-03-17 15:04 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2016-04-13 09:21 - 2016-03-17 15:04 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2016-04-13 09:21 - 2016-03-17 15:04 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2016-04-13 09:05 - 2016-03-17 19:36 - 03998952 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2016-04-13 09:05 - 2016-03-17 19:36 - 03943144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-04-13 09:05 - 2016-03-17 19:28 - 01414144 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2016-04-13 09:05 - 2016-03-17 19:26 - 00294400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-04-13 09:05 - 2016-03-16 15:28 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\msorcl32.dll 2016-04-13 09:05 - 2016-03-16 15:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll 2016-04-13 09:05 - 2016-02-02 15:48 - 00376320 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2016-04-13 09:04 - 2016-03-17 19:36 - 00137960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-04-13 09:04 - 2016-03-17 19:36 - 00067304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-04-13 09:04 - 2016-03-17 19:33 - 01310528 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-04-13 09:04 - 2016-03-17 19:30 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2016-04-13 09:04 - 2016-03-17 19:30 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-04-13 09:04 - 2016-03-17 19:30 - 00171008 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2016-04-13 09:04 - 2016-03-17 19:30 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-04-13 09:04 - 2016-03-17 19:30 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-04-13 09:04 - 2016-03-17 19:30 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2016-04-13 09:04 - 2016-03-17 19:29 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-04-13 09:04 - 2016-03-17 19:29 - 00251392 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-04-13 09:04 - 2016-03-17 19:29 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll 2016-04-13 09:04 - 2016-03-17 19:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2016-04-13 09:04 - 2016-03-17 19:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-04-13 09:04 - 2016-03-17 19:27 - 00260608 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-04-13 09:04 - 2016-03-17 19:27 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-04-13 09:04 - 2016-03-17 19:27 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-04-13 09:04 - 2016-03-17 19:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-04-13 09:04 - 2016-03-17 19:26 - 01062400 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-04-13 09:04 - 2016-03-17 19:26 - 00872448 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2016-04-13 09:04 - 2016-03-17 19:26 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-04-13 09:04 - 2016-03-17 19:25 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-04-13 09:04 - 2016-03-17 19:25 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 19:24 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 18:42 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2016-04-13 09:04 - 2016-03-17 18:42 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2016-04-13 09:04 - 2016-03-17 18:42 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2016-04-13 09:04 - 2016-03-17 18:42 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2016-04-13 09:04 - 2016-03-17 18:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-04-13 09:04 - 2016-03-17 18:36 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2016-04-13 09:04 - 2016-03-17 18:35 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2016-04-13 09:04 - 2016-03-17 18:30 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-04-13 09:04 - 2016-03-17 18:30 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-04-13 09:04 - 2016-03-17 18:30 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-04-13 09:04 - 2016-03-17 18:29 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-04-13 09:04 - 2016-03-17 18:29 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2016-04-13 09:04 - 2016-03-17 18:29 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-04-13 09:04 - 2016-03-17 18:29 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-04-13 09:04 - 2016-03-17 18:29 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 18:29 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 18:29 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-04-13 09:04 - 2016-03-17 18:29 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-04-13 08:59 - 2016-03-15 20:53 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2016-04-13 08:59 - 2016-03-15 20:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2016-04-13 08:53 - 2016-03-11 15:35 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2016-04-13 08:53 - 2016-01-20 21:51 - 00057280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys 2016-04-13 08:48 - 2016-03-29 14:35 - 02397184 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-04-13 08:43 - 2016-03-06 15:38 - 01240576 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2016-04-13 08:43 - 2016-03-06 15:38 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2016-04-13 08:33 - 2016-02-05 15:44 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\fveapibase.dll 2016-04-13 08:33 - 2016-02-05 14:33 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\tbs.dll 2016-04-13 08:33 - 2015-06-03 17:22 - 00355456 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll 2016-04-12 00:33 - 2016-04-12 00:34 - 02568107 _____ C:\Users\Marcos\Downloads\LG WD-12596RD (1).pdf 2016-04-12 00:25 - 2016-04-12 00:26 - 02568107 _____ C:\Users\Marcos\Downloads\LG WD-12596RD.pdf 2016-04-10 22:13 - 2016-04-10 22:13 - 00002157 _____ C:\Users\Marcos\Desktop\Itaú.lnk 2016-04-10 22:13 - 2016-04-10 22:13 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicativo Itaú 2016-04-05 12:08 - 2016-04-05 12:08 - 00001199 _____ C:\Users\Marcos\Downloads\ComprovanteBB - 2016-04-05-120132.pdf 2016-04-05 12:08 - 2016-04-05 12:08 - 00001193 _____ C:\Users\Marcos\Downloads\ComprovanteBB - 2016-04-05-120321.pdf 2016-04-01 23:16 - 2016-04-01 23:16 - 00000000 ____D C:\Users\Marcos\Desktop\My Shared Folder 2016-03-30 08:06 - 2016-03-30 08:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2016-03-30 08:06 - 2016-03-30 08:06 - 00000000 ____D C:\Program Files\QuickTime 2016-03-30 07:54 - 2016-03-30 07:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2016-03-30 07:53 - 2016-03-30 07:53 - 00000000 ____D C:\Program Files\Apple Software Update 2016-03-29 16:15 - 2016-03-29 16:15 - 00000000 ____D C:\Windows\system32\dvr_hd 2016-03-27 13:54 - 2016-03-27 13:54 - 00000000 ____D C:\Program Files\Common Files\Java ==================== Um Mês Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-04-26 21:57 - 2014-07-28 17:03 - 00110592 ___SH C:\Users\Marcos\Thumbs.db 2016-04-26 21:48 - 2013-10-29 00:41 - 00000902 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-04-26 21:47 - 2015-02-16 23:21 - 00002052 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-04-26 21:47 - 2014-05-29 21:09 - 00002293 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-04-26 21:47 - 2013-10-28 12:14 - 00002311 _____ C:\Users\Marcos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-04-26 21:31 - 2013-10-28 12:57 - 00110464 _____ C:\Users\Marcos\AppData\Local\GDIPFONTCACHEV1.DAT 2016-04-26 21:09 - 2013-10-28 23:33 - 00001058 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-04-26 20:39 - 2009-07-14 01:34 - 00026064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-04-26 20:39 - 2009-07-14 01:34 - 00026064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-04-26 20:19 - 2015-09-17 08:31 - 00000000 ____D C:\Users\Marcos\AppData\Local\CrashDumps 2016-04-26 20:18 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\system32\inetsrv 2016-04-26 20:17 - 2013-10-28 23:33 - 00001054 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-04-26 20:16 - 2009-07-14 01:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-04-26 00:33 - 2015-06-02 23:43 - 00000032 _____ C:\Windows\0 2016-04-26 00:33 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\inf 2016-04-26 00:27 - 2015-06-03 00:13 - 00000000 ____D C:\Users\Todos os Usuários\TOSHIBA 2016-04-26 00:27 - 2015-06-03 00:13 - 00000000 ____D C:\ProgramData\TOSHIBA 2016-04-26 00:11 - 2014-07-12 23:08 - 00000000 ____D C:\Windows\system32\appmgmt 2016-04-25 21:11 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\LiveKernelReports 2016-04-24 21:05 - 2016-03-08 20:41 - 00000000 ____D C:\Users\Marcos\Desktop\Festa Circulo de oração 2016 2016-04-24 18:51 - 2016-03-15 21:45 - 00000000 ____D C:\Users\Marcos\Desktop\HC640 Para DataShow – PowerPoint 2016-04-24 15:48 - 2015-04-09 01:40 - 00000000 ____D C:\Users\Todos os Usuários\GbPlugin 2016-04-24 15:48 - 2015-04-09 01:40 - 00000000 ____D C:\ProgramData\GbPlugin 2016-04-24 15:32 - 2013-10-28 12:10 - 01798186 _____ C:\Windows\system32\PerfStringBackup.INI 2016-04-24 15:32 - 2009-07-14 05:31 - 00768068 _____ C:\Windows\system32\prfh0416.dat 2016-04-24 15:32 - 2009-07-14 05:31 - 00169808 _____ C:\Windows\system32\prfc0416.dat 2016-04-23 01:17 - 2015-12-23 23:58 - 00000000 ____D C:\Program Files\No-IP 2016-04-23 01:15 - 2014-07-27 19:34 - 00000000 ____D C:\Program Files\VIVO INTERNET 2016-04-23 01:14 - 2014-07-27 19:35 - 00000000 ____D C:\Users\Todos os Usuários\DataCardService 2016-04-23 01:14 - 2014-07-27 19:35 - 00000000 ____D C:\ProgramData\DataCardService 2016-04-23 01:13 - 2016-03-03 16:28 - 00000000 ____D C:\Nex 2016-04-23 01:02 - 2013-10-28 12:14 - 00000000 ____D C:\Users\Marcos 2016-04-23 00:36 - 2014-03-29 12:10 - 00000874 __RSH C:\Users\Todos os Usuários\ntuser.pol 2016-04-23 00:36 - 2014-03-29 12:10 - 00000874 __RSH C:\ProgramData\ntuser.pol 2016-04-23 00:36 - 2009-07-13 23:37 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2016-04-22 04:57 - 2013-10-30 23:41 - 00374944 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2016-04-22 01:39 - 2013-10-28 12:57 - 00000000 ____D C:\Program Files\Easeware 2016-04-18 18:39 - 2014-07-28 23:20 - 00000000 ____D C:\Users\Marcos\Documents\FFOutput 2016-04-17 23:36 - 2009-07-14 01:53 - 00032608 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2016-04-17 15:22 - 2015-07-26 16:28 - 00000000 ____D C:\Users\Marcos\AppData\Local\Apple Computer 2016-04-17 15:19 - 2014-07-28 00:15 - 00000000 ____D C:\Users\Marcos\AppData\Local\Windows Live 2016-04-14 03:41 - 2009-07-14 01:33 - 00408344 _____ C:\Windows\system32\FNTCACHE.DAT 2016-04-14 03:38 - 2014-12-18 18:59 - 00000000 ____D C:\Windows\system32\appraiser 2016-04-14 03:22 - 2013-10-28 23:12 - 00000000 ____D C:\Users\Todos os Usuários\Microsoft Help 2016-04-14 03:19 - 2013-10-28 16:39 - 00000000 ____D C:\Windows\system32\MRT 2016-04-14 03:06 - 2013-10-28 16:39 - 132539272 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-04-13 23:59 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\system32\NDF 2016-04-10 22:32 - 2015-06-28 19:12 - 00000000 ___RD C:\Users\Marcos\Desktop\Pessoal 2016-04-10 22:13 - 2015-04-27 15:44 - 00000000 ____D C:\Users\Marcos\AppData\Local\Aplicativo Itau 2016-04-07 16:49 - 2013-10-29 00:41 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2016-04-07 16:49 - 2013-10-29 00:41 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2016-04-07 16:15 - 2014-07-28 02:10 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\Audacity 2016-03-30 13:09 - 2016-03-18 13:51 - 00000000 ___RD C:\Users\Marcos\Desktop\Oficina 2016-03-30 12:05 - 2015-04-09 01:40 - 00000000 ____D C:\Program Files\GbPlugin 2016-03-30 07:54 - 2015-07-26 16:28 - 00000000 ____D C:\Users\Marcos\AppData\Roaming\Apple Computer 2016-03-30 07:53 - 2015-07-26 16:25 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2016-03-29 16:15 - 2009-07-14 01:52 - 00000000 ____D C:\Windows\Downloaded Program Files 2016-03-29 14:01 - 2014-02-10 22:55 - 00000000 ____D C:\Users\Marcos\AppData\Local\ElevatedDiagnostics 2016-03-27 13:55 - 2016-02-22 23:28 - 00000000 ____D C:\Program Files\Java 2016-03-27 13:54 - 2016-02-22 23:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-03-27 13:53 - 2016-02-22 23:30 - 00000000 ____D C:\Users\Marcos\.oracle_jre_usage 2016-03-27 13:53 - 2016-02-22 23:29 - 00095808 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll ==================== Arquivos na raiz de alguns diretórios ======= 2016-04-25 19:26 - 2016-04-25 19:16 - 0939008 _____ () C:\Users\Marcos\AppData\Roaming\BlackEx.exe 2016-04-23 00:43 - 2016-04-23 00:43 - 0001213 _____ () C:\Users\Marcos\AppData\Roaming\Bubble Dock.boostrap.log 2016-04-23 00:49 - 2016-04-21 11:50 - 1266688 _____ () C:\Users\Marcos\AppData\Roaming\conhost51495.exe 2014-10-09 21:54 - 2015-11-02 17:18 - 0000138 _____ () C:\Users\Marcos\AppData\Roaming\default.rss 2016-04-25 19:25 - 2016-04-25 19:16 - 0939008 _____ () C:\Users\Marcos\AppData\Roaming\Geotouch.exe 2016-04-26 21:31 - 2016-04-26 21:31 - 0005120 _____ () C:\Users\Marcos\AppData\Roaming\GiftBag.db 2016-04-25 19:17 - 2016-04-25 19:19 - 0015408 _____ () C:\Users\Marcos\AppData\Roaming\InstallationConfiguration.xml 2016-04-25 19:17 - 2016-04-25 19:17 - 0127488 _____ () C:\Users\Marcos\AppData\Roaming\Installer.dat 2016-04-25 19:23 - 2016-04-25 19:23 - 0848437 _____ () C:\Users\Marcos\AppData\Roaming\Qvo-In.bin 2015-06-16 01:40 - 2016-04-26 00:07 - 0005884 _____ () C:\Users\Marcos\AppData\Roaming\Rim.Desktop.Exception.log 2015-06-16 01:38 - 2015-06-16 01:38 - 0001147 _____ () C:\Users\Marcos\AppData\Roaming\Rim.Desktop.HttpServerSetup.log 2015-06-16 01:40 - 2015-10-01 21:13 - 0000924 _____ () C:\Users\Marcos\AppData\Roaming\Rim.DesktopHelper.Exception.log 2016-04-24 14:15 - 2016-04-21 05:54 - 1745920 _____ () C:\Users\Marcos\AppData\Roaming\service.exe 2015-07-08 17:48 - 2015-07-08 17:48 - 0016776 _____ () C:\Users\Marcos\AppData\Roaming\unins000.dat 2015-07-08 17:48 - 2015-07-08 17:48 - 0815826 _____ () C:\Users\Marcos\AppData\Roaming\unins000.exe 2016-04-23 00:43 - 2016-04-23 00:43 - 0000097 _____ () C:\Users\Marcos\AppData\Roaming\WindApp.boostrap.log 2016-04-24 14:54 - 2016-04-21 00:03 - 2496403 _____ ( ) C:\Users\Marcos\AppData\Roaming\yeaplayer_51495.exe 2014-10-09 19:22 - 2015-08-16 20:48 - 0004608 _____ () C:\Users\Marcos\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-10-01 01:28 - 2015-10-01 01:28 - 0007605 _____ () C:\Users\Marcos\AppData\Local\Resmon.ResmonCfg 2016-04-24 15:32 - 2016-04-24 15:32 - 0004979 _____ () C:\ProgramData\bqeojehc.wbx 2016-04-25 19:15 - 2016-04-25 11:47 - 1266688 _____ () C:\ProgramData\conhost51495.exe 2013-11-15 12:03 - 2015-04-07 22:39 - 0005397 _____ () C:\ProgramData\hpzinstall.log 2013-10-28 22:47 - 2013-10-28 22:47 - 0000110 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc 2016-04-24 17:04 - 2016-04-24 13:55 - 1907200 _____ () C:\ProgramData\msiql.exe 2016-03-03 16:28 - 2016-03-03 16:28 - 0000047 _____ () C:\ProgramData\nex.ini 2016-04-24 14:31 - 2016-04-21 05:54 - 1745920 _____ () C:\ProgramData\service.exe 2016-04-26 20:19 - 2016-04-26 20:19 - 0002292 _____ () C:\ProgramData\webad.xml Arquivos para serem movidos ou deletados: ==================== C:\Windows\TEMP\24301\tim.exe C:\Users\Marcos\AppData\Local\Temp\yeaplayer51495.exe C:\Users\Marcos\AppData\Local\Temp\00027936\casrss.exe C:\ProgramData\conhost51495.exe C:\ProgramData\msiql.exe C:\ProgramData\service.exe C:\Users\Todos os Usuários\conhost51495.exe C:\Users\Todos os Usuários\msiql.exe C:\Users\Todos os Usuários\service.exe Alguns arquivos em TEMP: ==================== C:\Users\Marcos\AppData\Local\Temp\1a76e3dd-d4b8-4f5b-8168-348c40bf97fb.exe C:\Users\Marcos\AppData\Local\Temp\23333.exe C:\Users\Marcos\AppData\Local\Temp\6AKXNTAE4D.exe C:\Users\Marcos\AppData\Local\Temp\abc.exe C:\Users\Marcos\AppData\Local\Temp\aplicativoitau.exe C:\Users\Marcos\AppData\Local\Temp\appshat_generic.exe C:\Users\Marcos\AppData\Local\Temp\atcMedia8541429466207.exe C:\Users\Marcos\AppData\Local\Temp\AudioConverterSetup.exe C:\Users\Marcos\AppData\Local\Temp\bdgD506.exe C:\Users\Marcos\AppData\Local\Temp\Browser_V5.6.11815.13_r_4739_(Build1604131623).exe C:\Users\Marcos\AppData\Local\Temp\checkedlist.exe C:\Users\Marcos\AppData\Local\Temp\component.exe C:\Users\Marcos\AppData\Local\Temp\IrsoDLL.dll C:\Users\Marcos\AppData\Local\Temp\jre-8u77-windows-au.exe C:\Users\Marcos\AppData\Local\Temp\LV7DD6TLDD.exe C:\Users\Marcos\AppData\Local\Temp\module-2.exe C:\Users\Marcos\AppData\Local\Temp\module-3.exe C:\Users\Marcos\AppData\Local\Temp\ms6920.tmp.exe C:\Users\Marcos\AppData\Local\Temp\office convert powerpoint to image jpgjpeg crack.exe C:\Users\Marcos\AppData\Local\Temp\PriceFountainUpdateVer.exe C:\Users\Marcos\AppData\Local\Temp\Q4Y1Z9126C.exe C:\Users\Marcos\AppData\Local\Temp\sdfDFA4.exe C:\Users\Marcos\AppData\Local\Temp\searchiw-svd.ru_BR.exe C:\Users\Marcos\AppData\Local\Temp\sercia-svd.ru_BR.exe C:\Users\Marcos\AppData\Local\Temp\setup.exe C:\Users\Marcos\AppData\Local\Temp\setup_nex_.exe C:\Users\Marcos\AppData\Local\Temp\ts_10051.exe C:\Users\Marcos\AppData\Local\Temp\ttwifi.exe C:\Users\Marcos\AppData\Local\Temp\ucbrabs.exe C:\Users\Marcos\AppData\Local\Temp\yeaplayer51495.exe C:\Users\Marcos\AppData\Local\Temp\Yeaplayer_51384.exe C:\Users\Marcos\AppData\Local\Temp\ytaiesmt_smtyc_setup.exe ==================== Bamital & volsnap ================= (Não há correção automática para arquivos que não passaram na verificação.) C:\Windows\explorer.exe => O arquivo é assinado digitalmente C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente C:\Windows\system32\services.exe => O arquivo é assinado digitalmente C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente LastRegBack: 2016-04-18 00:57 ==================== Fim de FRST.txt ============================