Additional scan result of Farbar Recovery Scan Tool (x86) Version: 09-08-2016 01 Ran by Micalu (2016-08-09 19:43:26) Running from C:\Users\Micalu\Desktop Microsoft Windows 7 Home Premium (X86) (2016-05-30 18:58:30) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrador (S-1-5-21-1261551153-2078032241-974631634-500 - Administrator - Disabled) Convidado (S-1-5-21-1261551153-2078032241-974631634-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1261551153-2078032241-974631634-1002 - Limited - Enabled) Micalu (S-1-5-21-1261551153-2078032241-974631634-1000 - Administrator - Enabled) => C:\Users\Micalu ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µTorrent (HKU\S-1-5-21-1261551153-2078032241-974631634-1000\...\uTorrent) (Version: 3.4.8.42449 - BitTorrent Inc.) Adobe Acrobat Reader DC - Português (HKLM\...\{AC76BA86-7AD7-1046-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated) AMD Catalyst Install Manager (HKLM\...\{BE46E7A1-EE5A-E414-39A3-CDCD5913F93F}) (Version: 8.0.881.0 - Advanced Micro Devices, Inc.) Curse (HKLM\...\{A20BFF62-AE3C-42BD-9C52-841CAB96BC49}) (Version: 6.0.0.0 - Curse) DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 5.0.1.0406 - Disc Soft Ltd) Google Chrome (HKLM\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.) Google Drive (HKLM\...\{709316AD-161C-4D5C-9AE7-0B3A822DA271}) (Version: 1.30.2170.0459 - Google, Inc.) Google Update Helper (Version: 1.3.31.5 - Google Inc.) Hidden Helbreath Argentina versão 1.0 (HKLM\...\{22CC575A-3CE7-41DB-85C2-1E766D9D096D}_is1) (Version: 1.0 - Helbreath Argentina) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Português) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 2070) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation) Revisores de Texto do Microsoft Office 2013 – Português do Brasil (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM\...\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft) Steam (HKLM\...\Steam) (Version: 2.10.91.91 - Valve Corporation) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH) Update for Skype for Business 2015 (KB3039776) 32-Bit Edition (HKLM\...\{90150000-012B-0416-0000-0000000FF1CE}_Office15.PROPLUSR_{7BDD179E-C954-438B-937D-EB411B701EAB}) (Version: - Microsoft) Warcraft III (HKLM\...\Warcraft III) (Version: - ) Warcraft III: All Products (HKU\S-1-5-21-1261551153-2078032241-974631634-1000\...\Warcraft III) (Version: - ) WinRAR 4.01 (32-bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) Yahoo! Powered (HKLM\...\winsearch) (Version: - ) youndoo - Uninstall (HKLM\...\{E625205B-BC56-4B2F-8E22-EE1AB136CF14}) (Version: - ) <==== ATTENTION ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {1832BDDB-CC92-4210-97FA-63B5E3085E03} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-05-30] (Google Inc.) Task: {2240225B-C1FB-4E00-B1AE-C09B579C0FBD} - System32\Tasks\Microsoft\Windows\Setup\EOSNotify => C:\Windows\system32\EOSNotify.exe [2016-06-25] (Microsoft Corporation) Task: {5D141FF2-D7A1-4940-B289-3428EB81704A} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {8742CBA7-9680-477D-8130-45EC2CC81B1C} - System32\Tasks\Yahoo! Powered tenof => Wscript.exe "C:\ProgramData\{0600C363-8C42-49A5-0A84-D7E790C65C29}\fele.txt" "687474703a2f2f7761676e672e636f6d" "433a5c50726f6772616d446174615c7b30363030433336332d384334322d343941352d304138342d4437453739304336354332397d5c7361666f7461" "433a5c50726f6772616d446174615c7b30363030433336332d384334322d343941352d304138 (the data entry has 78 more characters). Task: {8C902AB1-F832-4EA6-92C5-7BF115F73884} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated) Task: {99372604-B3C5-46F0-90AB-A0049934E8C0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2016-05-30] (Google Inc.) Task: {BC0DF75C-56B3-45FB-A144-2CC138338596} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation) Task: {E16BF252-FF2B-4681-84C4-2EDE5538522B} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation) Task: {E7AC0B95-489B-4CC8-B67B-C3E83B105149} - System32\Tasks\{A1F8AC89-B190-4B2C-B48D-AE088BE433AD} => pcalua.exe -a C:\Users\Micalu\Desktop\installer.exe -d C:\Users\Micalu\Desktop Task: {F1F14AA0-2D75-4F0C-B5A0-074C3DB759D8} - System32\Tasks\{03F02CB1-B890-1AF7-7E91-034D01A71D2E} => C:\Users\Micalu\AppData\Roaming\{6F1F5~1\UPDATE~1.EXE [2013-05-02] () <==== ATTENTION (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Yahoo! Powered tenof.job => Wscript.exe C:\ProgramData\{0600C363-8C42-49A5-0A84-D7E790C65C29}\fele.txt <==== ATTENTION Task: C:\Windows\Tasks\{03F02CB1-B890-1AF7-7E91-034D01A71D2E}.job => C:\Users\Micalu\AppData\Roaming\{6F1F5~1\UPDATE~1.EXE <==== ATTENTION ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2016-08-09 16:52 - 2016-08-09 16:52 - 00115712 _____ () C:\Program Files\Lwosyzaseing\Thaberied\Terhoingprejsp.dll 2016-05-30 17:14 - 2011-05-28 22:04 - 00140288 _____ () C:\Program Files\WinRAR\rarext.dll 2016-08-09 17:14 - 2016-08-09 17:33 - 00036864 _____ () C:\Users\Micalu\AppData\Local\Temp\CmdLineExt02.dll 2016-06-06 13:15 - 2016-08-02 19:08 - 00785920 _____ () C:\Program Files\Steam\SDL2.dll 2016-06-06 13:15 - 2016-08-02 19:10 - 04962816 _____ () C:\Program Files\Steam\v8.dll 2016-06-06 13:15 - 2016-08-02 19:09 - 01556992 _____ () C:\Program Files\Steam\icui18n.dll 2016-06-06 13:15 - 2016-08-02 19:09 - 01187840 _____ () C:\Program Files\Steam\icuuc.dll 2016-06-06 13:15 - 2016-08-02 21:00 - 02320160 _____ () C:\Program Files\Steam\video.dll 2016-06-06 13:15 - 2016-02-08 20:14 - 02549760 _____ () C:\Program Files\Steam\libavcodec-56.dll 2016-06-06 13:15 - 2016-02-08 20:14 - 00442880 _____ () C:\Program Files\Steam\libavutil-54.dll 2016-06-06 13:15 - 2016-02-08 20:14 - 00491008 _____ () C:\Program Files\Steam\libavformat-56.dll 2016-06-06 13:15 - 2016-02-08 20:14 - 00332800 _____ () C:\Program Files\Steam\libavresample-2.dll 2016-06-06 13:15 - 2016-02-08 20:14 - 00485888 _____ () C:\Program Files\Steam\libswscale-3.dll 2016-06-06 13:15 - 2016-08-02 20:59 - 00831776 _____ () C:\Program Files\Steam\bin\chromehtml.DLL 2016-06-06 13:15 - 2016-07-06 19:00 - 00266560 _____ () C:\Program Files\Steam\openvr_api.dll 2016-06-06 13:15 - 2016-06-14 16:14 - 49826080 _____ () C:\Program Files\Steam\bin\libcef.dll 2012-08-27 11:36 - 2012-08-27 11:36 - 00016384 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll 2016-08-09 16:52 - 2016-08-09 16:52 - 00131072 _____ () C:\Program Files\Google\Chrome\Application\WTSAPI32.dll 2016-08-04 17:52 - 2016-08-02 21:24 - 01771336 _____ () C:\Program Files\Google\Chrome\Application\52.0.2743.116\libglesv2.dll 2016-08-04 17:52 - 2016-08-02 21:23 - 00094024 _____ () C:\Program Files\Google\Chrome\Application\52.0.2743.116\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Windows\system32\drivers:GbpKmAp.lst [0] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.) ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-1261551153-2078032241-974631634-1000\...\caixa.gov.br -> hxxps://imagem.caixa.gov.br ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 23:04 - 2009-06-10 18:39 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1261551153-2078032241-974631634-1000\Control Panel\Desktop\\Wallpaper -> DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: Diebold - Warsaw => C:\Program Files\Diebold\Warsaw\core.exe MSCONFIG\startupreg: GoogleDriveSync => "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart MSCONFIG\startupreg: StartCCC => "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun MSCONFIG\startupreg: Steam => "C:\Program Files\Steam\steam.exe" -silent ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{9901CE7D-61DD-49B8-ADA4-6E6E8C23C12C}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe FirewallRules: [{9F51CD41-B6EA-454B-B77C-5C35498B3A56}] => (Allow) LPort=1688 FirewallRules: [{F4D25B2E-EC1B-4549-B4A4-EFFD7BED4402}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{47EA82C2-3B09-405E-A4F9-35BE75426313}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{634BB5A7-CBF0-4E0C-9714-486A2A1B9188}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{9FA0A98C-5F61-4DBA-9338-2479E11AFC39}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe FirewallRules: [{0522910D-C508-4223-89AF-84B8FBFE6418}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{187FEC83-1E58-4647-AB28-95B57031F3EC}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe FirewallRules: [{DA234A19-04B3-407D-8D87-A4CDCFE0421D}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [{739AAC51-B75D-4190-BC5D-57EE9B27C065}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe FirewallRules: [TCP Query User{BBB79CB9-46DB-4276-872D-F415201E1B5B}C:\users\micalu\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\micalu\appdata\roaming\utorrent\utorrent.exe FirewallRules: [UDP Query User{4DDF5028-B611-4E0D-8F02-EDDF6C0A4B92}C:\users\micalu\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\micalu\appdata\roaming\utorrent\utorrent.exe FirewallRules: [{A32853E9-5716-4BDC-8025-842DC82D57F3}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{EE840236-AECF-46F6-9A59-F9A2F12F8098}] => (Allow) C:\Program Files\Steam\Steam.exe FirewallRules: [{D33B02B9-84FD-4120-ACB5-66CDCC27AC9E}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe FirewallRules: [{AD18F736-9782-46E7-9AAD-89E75FB73954}] => (Allow) C:\Program Files\Steam\bin\steamwebhelper.exe FirewallRules: [TCP Query User{1B49186A-F7EC-42EA-B87A-7533D7673C86}C:\users\micalu\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\micalu\appdata\local\mycomgames\mycomgames.exe FirewallRules: [UDP Query User{F9A797D6-40DB-4D9C-ACE4-27B486CB73E4}C:\users\micalu\appdata\local\mycomgames\mycomgames.exe] => (Allow) C:\users\micalu\appdata\local\mycomgames\mycomgames.exe FirewallRules: [TCP Query User{AAAFB36E-C57C-4197-9FA0-F683E141601C}C:\users\micalu\appdata\local\mycomgames\mycomgames.exe] => (Block) C:\users\micalu\appdata\local\mycomgames\mycomgames.exe FirewallRules: [UDP Query User{234C396E-8B8D-4A4B-BF0A-4F163326C4CD}C:\users\micalu\appdata\local\mycomgames\mycomgames.exe] => (Block) C:\users\micalu\appdata\local\mycomgames\mycomgames.exe FirewallRules: [{6D3A3224-2E79-4A00-8485-5BD591EBB64C}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe FirewallRules: [{B7423103-71B9-4582-A24E-E79A2A2762FA}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{147BD63E-9B0E-4F15-BCE6-7B0A91C88089}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe FirewallRules: [{E3B102C3-4909-450B-919C-DE44839FA948}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [{6DA07448-EBFA-4E62-A44E-588187A861F0}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe FirewallRules: [TCP Query User{C56D9A7A-A594-4A8F-B9A7-2F13EBF20B00}C:\program files\warcraft iii\war3.exe] => (Block) C:\program files\warcraft iii\war3.exe FirewallRules: [UDP Query User{D1EA4302-81EE-4852-A60E-844E116A3DD3}C:\program files\warcraft iii\war3.exe] => (Block) C:\program files\warcraft iii\war3.exe ==================== Restore Points ========================= 04-08-2016 12:22:06 Windows Update 05-08-2016 07:50:59 Windows Update 06-08-2016 03:01:45 Windows Update 07-08-2016 03:01:50 Windows Update 07-08-2016 14:15:17 Installed DirectX 09-08-2016 09:25:23 Windows Update 09-08-2016 16:17:03 Instalação do Pacote de Controlador de Dispositivo: Disc Soft Ltd Controladores de armazenamento 09-08-2016 16:53:34 Instalação do Pacote de Controlador de Dispositivo: Disc Soft Ltd Controladores de armazenamento 09-08-2016 18:20:09 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 09-08-2016 18:21:44 Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 09-08-2016 18:31:51 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/09/2016 04:53:35 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: ) Description: Falha nos Serviços de Criptografia ao processar a chamada OnIdentity() no Objecto Escritor de Sistema. Details: AddLegacyDriverFiles: Unable to back up image of binary Gbp KernelMode. System Error: O sistema não conseguiu localizar o ficheiro especificado. . Error: (08/09/2016 04:35:04 PM) (Source: MsiInstaller) (EventID: 11704) (User: Micalu-PC) Description: Produto: Curse -- Erro 1704. Uma instalação de Microsoft Office Professional Plus 2013 está atualmente suspensa. Você deverá cancelar as alterações feitas por essa instalação antes de continuar. Deseja cancelar essas alterações? Error: (08/09/2016 04:19:59 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome da aplicação com falha: Explorer.EXE, versão: 6.1.7600.16385, carimbo de data/hora: 0x4a5bc60d Nome do módulo com falha: mso.dll_unloaded, versão: 0.0.0.0, carimbo de data/hora: 0x575fd646 Código de excepção: 0xc0000005 Desvio de falha: 0x0fdc8d67 ID do processo com falha: 0x5d4 Data/hora de início da aplicação com falha: 0xExplorer.EXE0 Caminho da aplicação com falha: Explorer.EXE1 Caminho do módulo com falha: Explorer.EXE2 ID do Relatório: Explorer.EXE3 Error: (08/09/2016 04:15:40 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome da aplicação com falha: DTUltra.exe, versão: 4.1.0.493, carimbo de data/hora: 0x579b4ae1 Nome do módulo com falha: KERNELBASE.dll, versão: 6.1.7600.16385, carimbo de data/hora: 0x4a5bdaae Código de excepção: 0xe0434352 Desvio de falha: 0x00009617 ID do processo com falha: 0xf4 Data/hora de início da aplicação com falha: 0xDTUltra.exe0 Caminho da aplicação com falha: DTUltra.exe1 Caminho do módulo com falha: DTUltra.exe2 ID do Relatório: DTUltra.exe3 Error: (08/09/2016 04:15:38 PM) (Source: .NET Runtime) (EventID: 1026) (User: ) Description: Aplicação: DTUltra.exe Versão do Framework: v4.0.30319 Descrição: O processo foi terminado devido a uma excepção não processada. Informações da Excepção: System.ArgumentNullException Pilha: em System.Windows.Window.ShowDialog() em DTClient.View.SecondaryWindows.DTMessageBox.Show(System.Windows.Window, System.String, System.String, System.Windows.MessageBoxButton, System.Windows.MessageBoxImage, System.String) em DTClient.BaseApp.OnStartup(System.Windows.StartupEventArgs) em System.Windows.Application.<.ctor>b__1(System.Object) em System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) em MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) em System.Windows.Threading.DispatcherOperation.InvokeImpl() em System.Windows.Threading.DispatcherOperation.InvokeInSecurityContext(System.Object) em System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) em System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean) em System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object) em System.Windows.Threading.DispatcherOperation.Invoke() em System.Windows.Threading.Dispatcher.ProcessQueue() em System.Windows.Threading.Dispatcher.WndProcHook(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) em MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef) em MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object) em System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32) em MS.Internal.Threading.ExceptionFilterHelper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate) em System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32) em MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr) em MS.Win32.UnsafeNativeMethods.DispatchMessage(System.Windows.Interop.MSG ByRef) em System.Windows.Threading.Dispatcher.PushFrameImpl(System.Windows.Threading.DispatcherFrame) em System.Windows.Threading.Dispatcher.PushFrame(System.Windows.Threading.DispatcherFrame) em System.Windows.Threading.Dispatcher.Run() em System.Windows.Application.RunDispatcher(System.Object) em System.Windows.Application.RunInternal(System.Windows.Window) em System.Windows.Application.Run(System.Windows.Window) em DTClient.BaseApp.Main(System.String[]) Error: (08/09/2016 12:52:43 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome da aplicação com falha: Helbreath Argentina.exe, versão: 5.0.0.0, carimbo de data/hora: 0x5783d765 Nome do módulo com falha: Helbreath Argentina.exe, versão: 5.0.0.0, carimbo de data/hora: 0x5783d765 Código de excepção: 0xc0000005 Desvio de falha: 0x00081807 ID do processo com falha: 0x334 Data/hora de início da aplicação com falha: 0xHelbreath Argentina.exe0 Caminho da aplicação com falha: Helbreath Argentina.exe1 Caminho do módulo com falha: Helbreath Argentina.exe2 ID do Relatório: Helbreath Argentina.exe3 Error: (08/08/2016 04:40:27 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome da aplicação com falha: Helbreath Argentina.exe, versão: 5.0.0.0, carimbo de data/hora: 0x5783d765 Nome do módulo com falha: Helbreath Argentina.exe, versão: 5.0.0.0, carimbo de data/hora: 0x5783d765 Código de excepção: 0xc0000094 Desvio de falha: 0x000085a8 ID do processo com falha: 0x1524 Data/hora de início da aplicação com falha: 0xHelbreath Argentina.exe0 Caminho da aplicação com falha: Helbreath Argentina.exe1 Caminho do módulo com falha: Helbreath Argentina.exe2 ID do Relatório: Helbreath Argentina.exe3 Error: (08/07/2016 02:18:51 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: O programa dota2.exe versão 0.0.0.0 deixou de interagir com o Windows e foi fechado. Para verificar se existem mais informações disponíveis sobre o problema, consulte o histórico de problemas no painel de controlo do Centro de Acção. ID do Processo: 634 Hora de Início: 01d1f0cf8647a804 Hora de Fim: 61 Caminho da Aplicação: C:\Program Files\Steam\steamapps\common\dota 2 beta\game\bin\win32\dota2.exe ID do Relatório: 0057f216-5cc3-11e6-88bd-00235a797910 Error: (08/06/2016 03:58:58 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1500) (User: Micalu-PC) Description: O Windows não consegue iniciar sessão para o utilizador, porque não é possível carregar o perfil. Verifique se está ligado à rede ou se a rede está a funcionar correctamente. DETALHE - O processo não pode aceder ao ficheiro porque este está a ser utilizado por outro processo. Error: (08/06/2016 03:58:58 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT AUTHORITY) Description: O Windows não conseguiu carregar o registo. Frequentemente, este problema deve-se a falta de memória ou a direitos de segurança insuficientes. DETALHE - O processo não pode aceder ao ficheiro porque este está a ser utilizado por outro processo. para C:\Users\TEMP\ntuser.dat System errors: ============= Error: (08/09/2016 04:52:38 PM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: O serviço Thaberied Configuration está marcado como um serviço interactivo. No entanto, o sistema está configurado para não permitir serviços interactivos. Este serviço poderá não funcionar correctamente. Error: (08/09/2016 04:34:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: O serviço Gbpddreg svc falhou o arranque devido ao seguinte erro: %%2 = O sistema não conseguiu localizar o ficheiro especificado. Error: (08/09/2016 04:20:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: O serviço Gbpddreg svc falhou o arranque devido ao seguinte erro: %%2 = O sistema não conseguiu localizar o ficheiro especificado. Error: (08/09/2016 08:44:05 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: O serviço Gbpddreg svc falhou o arranque devido ao seguinte erro: %%2 = O sistema não conseguiu localizar o ficheiro especificado. Error: (08/09/2016 08:44:05 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: O serviço Gbpddreg svc falhou o arranque devido ao seguinte erro: %%2 = O sistema não conseguiu localizar o ficheiro especificado. Error: (08/09/2016 08:43:56 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Falhou o carregamento dos seguintes controladores de início de arranque ou de início do sistema: gbpddreg Error: (08/09/2016 08:43:35 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: O anterior encerramento do sistema, ‎09/‎08/‎2016 às 08:41:38, foi inesperado. Error: (08/09/2016 07:48:27 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Foi atingido o tempo limite (30000 milissegundos) ao aguardar por uma resposta de transacção por parte do serviço Netman. Error: (08/08/2016 03:02:43 PM) (Source: bowser) (EventID: 8003) (User: ) Description: O browser principal recebeu um aviso de servidor a partir do computador SOSINF30347070 que pensa que é o browser principal do domínio no transporte NetBT_Tcpip_{2F81E830-6D8E-4F75-BD4E-A63. O browser principal está a ser terminado ou está a ser forçada uma eleição. Error: (08/08/2016 12:49:00 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: O serviço Warsaw Technology terminou inesperadamente. Já o fez 6 vez(es). Será efectuada a seguinte acção correctiva em 0 milissegundos: Reiniciar o serviço. ==================== Memory info =========================== Processor: AMD E-300 APU with Radeon(tm) HD Graphics Percentage of memory in use: 56% Total physical RAM: 1770.9 MB Available physical RAM: 773.84 MB Total Virtual: 3541.8 MB Available Virtual: 2283.69 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:297.99 GB) (Free:241.13 GB) NTFS Drive e: (Warcraft III) (CDROM) (Total:0.62 GB) (Free:0 GB) CDFS Drive g: (TheFrozenThrone) (CDROM) (Total:0.47 GB) (Free:0 GB) CDFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 32A8B0D7) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================