Resultado do exame Adicional Farbar Recovery Scan Tool (x64) Versão: 28-09-2016 Executado por Usuario (29-09-2016 13:13:21) Executando a partir de C:\Users\Usuario\Desktop Windows 7 Ultimate Service Pack 1 (X64) (2014-04-05 18:57:45) Modo da Inicialização: Normal ========================================================== ==================== Contas: ============================= Administrador (S-1-5-21-1886511979-3729726640-2495196762-500 - Administrator - Disabled) Convidado (S-1-5-21-1886511979-3729726640-2495196762-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1886511979-3729726640-2495196762-1005 - Limited - Enabled) Usuario (S-1-5-21-1886511979-3729726640-2495196762-1000 - Administrator - Enabled) => C:\Users\Usuario ==================== Central de Segurança ======================== (Se uma entrada for incluída na fixlist, será removida.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Programas Instalados ====================== (Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.) µTorrent (HKU\S-1-5-21-1886511979-3729726640-2495196762-1000\...\uTorrent) (Version: 3.4.8.42576 - BitTorrent Inc.) Adobe Acrobat Reader DC - Português (HKLM-x32\...\{AC76BA86-7AD7-1046-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated) Adobe Flash Player 23 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 23.0.0.162 - Adobe Systems Incorporated) Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.162 - Adobe Systems Incorporated) Akamai NetSession Interface (HKU\S-1-5-21-1886511979-3729726640-2495196762-1000\...\Akamai) (Version: - Akamai Technologies, Inc) Albion Online (HKLM-x32\...\SandboxAlbionOnline) (Version: - Sandbox Interactive GmbH) AutoCAD 2013 - English (HKLM\...\AutoCAD 2013 - English) (Version: 19.0.55.0 - Autodesk) AutoCAD 2013 - English (Version: 19.0.55.0 - Autodesk) Hidden AutoCAD 2013 Language Pack - English (Version: 19.0.55.0 - Autodesk) Hidden Autodesk Content Service (HKLM-x32\...\Autodesk Content Service) (Version: 3.0.84.0 - Autodesk) Autodesk Content Service (x32 Version: 3.0.84.0 - Autodesk) Hidden Autodesk Content Service Language Pack (x32 Version: 3.0.84.0 - Autodesk) Hidden Autodesk Material Library 2013 (HKLM-x32\...\{117EBEEB-5DB0-43C8-9FD6-DD583DB152DD}) (Version: 3.0.13 - Autodesk) Autodesk Material Library Base Resolution Image Library 2013 (HKLM-x32\...\{606E12B9-641F-4644-A22A-FF38AE980AFD}) (Version: 3.0.13 - Autodesk) Autodesk Sync (HKLM\...\{EE5F74BC-5CD5-4EF2-86BA-81E6CF46A18F}) (Version: 3.5.24.0 - Autodesk, Inc.) AutoHotkey 1.0.48.05 (HKLM-x32\...\AutoHotkey) (Version: 1.0.48.05 - Chris Mallett) Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.2.2262 - AVAST Software) Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment) Battlerite Beta (HKLM\...\Steam App 427460) (Version: - ) BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - ) BattlEye Uninstall (HKLM-x32\...\BattlEye for A2) (Version: - ) Bethesda.net Launcher (HKLM-x32\...\{3448917E-E4FE-4E30-9502-9FD52EABB6F5}_is1) (Version: 1.0 - Bethesda Softworks) CCleaner (HKLM\...\CCleaner) (Version: 4.11 - Piriform) Circuit Wizard (HKLM-x32\...\InstallShield_{66220469-8515-401E-A0E2-8F424852C1EF}) (Version: 1.15.0000 - New Wave Concepts Limited) Circuit Wizard (x32 Version: 1.15.0000 - New Wave Concepts Limited) Hidden Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) CrazyTalk Cam Suite (HKLM-x32\...\{D1504C77-1B19-4AF0-8DEC-946666123B55}) (Version: 2.0 - Reallusion) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Discord (HKU\S-1-5-21-1886511979-3729726640-2495196762-1000\...\Discord) (Version: 0.0.296 - Hammer & Chisel, Inc.) EAC eSports (HKLM\...\Steam App 282660) (Version: - EasyAntiCheat Ltd) FARO LS 1.1.406.58 (HKLM-x32\...\{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}) (Version: 4.6.58.2 - FARO Scanner Production) FreeMouseAutoClicker 3.7 (HKLM-x32\...\{292F00C5-25EF-4FBE-9873-13EF1F69DEED}_is1) (Version: - Advanced Mouse Auto Clicker ltd.) Glary Utilities 4.7 (HKLM-x32\...\Glary Utilities 4) (Version: 4.7.0.96 - Glarysoft Ltd) Gloria Victis (HKLM\...\Steam App 327070) (Version: - Black Eye Games) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 53.0.2785.116 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden Guild Wars 2 (HKLM-x32\...\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.) Happy Cloud Client (HKU\S-1-5-21-1886511979-3729726640-2495196762-1000\...\HappyCloud) (Version: 4.28 - Happy Cloud, Inc.) HiPatch (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF000}) (Version: 5.0.3.9 - Hi-Rez Studios) Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios) HP LaserJet Professional M1130-M1210 MFP Series (HKLM\...\HP LaserJet Professional M1130-M1210 MFP Series) (Version: - ) IdleMaster (HKU\S-1-5-21-1886511979-3729726640-2495196762-1000\...\1d85483b1c982d8c) (Version: 1.4.0.0 - IdleMaster) Intel(R) Driver Update Utility 2.6 (x32 Version: 2.6.0.32 - Intel) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4226 - Intel Corporation) Intel® Driver Update Utility (HKLM-x32\...\{3e714701-b89c-4cf2-bf3b-41b2c105ffdc}) (Version: 2.6.0.32 - Intel) Java 8 Update 101 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation) K-Lite Codec Pack 10.3.5 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.3.5 - ) League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games) League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden MATLAB R2011a (HKLM\...\MatlabR2011a) (Version: 7.12 - The MathWorks, Inc.) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{92B8FD1F-C1AE-3750-8577-631B0AA85DF5}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{887868A2-D6DE-3255-AA92-AA0B5A59B874}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation) Módulo de Segurança - Banco do Brasil (HKLM-x32\...\{36386dc9-8543-4b12-ae6b-220fd52f19f3}_is1) (Version: 3.11.0.1 - ) Mozilla Firefox 43.0.1 (x86 pt-BR) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 pt-BR)) (Version: 43.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla) MPC-HC 1.6.3.5818 (HKLM-x32\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.6.3.5818 - MPC-HC Team) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 7 Premium (HKLM-x32\...\{43FFE159-3199-4188-A1CD-629166AD1046}) (Version: 7.02.6445 - Nero AG) NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.10.2.4863 - Electronic Arts, Inc.) Pacote de Idiomas do Microsoft .NET Framework 4.5 - Português (Brasil) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1046) (Version: 4.5.50709 - Microsoft Corporation) Paladins (HKLM\...\Steam App 444090) (Version: - Hi-Rez Studios) PlaysTV (HKLM-x32\...\PlaysTV) (Version: 1.8.6-r109060-release - Plays.tv, LLC) PowerDVD (HKLM-x32\...\InstallShield_{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 7.30.0000 - CyberLink) PowerDVD (x32 Version: 7.30.0000 - CyberLink) Hidden Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6971 - Realtek Semiconductor Corp.) SafeZone Stable 1.48.2066.101 (x32 Version: 1.48.2066.101 - Avast Software) Hidden Scan To (HKLM\...\{E8A34AC8-0137-4515-A94B-0A0946DDC251}) (Version: 2.0.1 - HP) scilab-5.5.2 (64-bit) (HKLM\...\scilab-5.5.2 (64-bit)_is1) (Version: - Scilab Enterprises) Skype Web Plugin (HKLM-x32\...\{F6C18D35-D3EB-4AEA-B266-C2F11B6DB723}) (Version: 7.12.0.55 - Skype Technologies S.A.) Skype™ 7.28 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.28.101 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-1886511979-3729726640-2495196762-1000\...\Spotify) (Version: 1.0.33.106.g60b5d1f0 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation) System Requirements Lab CYRI (HKLM-x32\...\{906B34E5-573C-445A-A5D3-40B6BF0A2EC4}) (Version: 6.0.21.0 - Husdawg, LLC) System Requirements Lab Detection (HKLM-x32\...\{D086AE9C-FF5B-4616-A0AA-0FF690B64A18}) (Version: 6.1.6.0 - Husdawg, LLC) TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH) The Elder Scrolls Legends (HKLM-x32\...\The Elder Scrolls Legends) (Version: - Bethesda Softworks) Tree of Life (HKLM\...\Steam App 361800) (Version: - oddonegames) Unity Web Player (HKU\S-1-5-21-1886511979-3729726640-2495196762-1000\...\UnityWebPlayer) (Version: 5.3.3f1 - Unity Technologies ApS) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Uplay (HKLM-x32\...\Uplay) (Version: 22.2 - Ubisoft) Victor Vran (HKLM\...\Steam App 345180) (Version: - Haemimont Games) WinRAR 5.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Exame Personalizado CLSID (Whitelisted): ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) CustomCLSID: HKU\S-1-5-21-1886511979-3729726640-2495196762-1000_Classes\CLSID\{0783EB25-59F8-4F02-B6B0-F1D4349F0000}\InprocServer32 -> C:\Users\Usuario\AppData\Local\GAS Tecnologia\GBBD\npsf_bb_64.dll (GAS Tecnologia) CustomCLSID: HKU\S-1-5-21-1886511979-3729726640-2495196762-1000_Classes\CLSID\{0783EB25-59F8-4F02-B6B1-F1D4349F0000}\InprocServer32 -> C:\Users\Usuario\AppData\Local\GAS Tecnologia\GBBD\npsf_bb_64.dll (GAS Tecnologia) CustomCLSID: HKU\S-1-5-21-1886511979-3729726640-2495196762-1000_Classes\CLSID\{147D75F3-19D5-4810-800D-7F50A02E8B60}\InprocServer32 -> C:\Users\Usuario\AppData\Local\SkypePlugin\7.12.0.55\GatewayActiveX-x64.dll (Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-1886511979-3729726640-2495196762-1000_Classes\CLSID\{6A221957-2D85-42A7-8E19-BE33950D1DEB}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2013\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1886511979-3729726640-2495196762-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation) CustomCLSID: HKU\S-1-5-21-1886511979-3729726640-2495196762-1000_Classes\CLSID\{B9BE850C-F3F7-48AD-BB5B-A0CDA0706DB5}\localserver32 -> C:\Users\Usuario\AppData\Local\SkypePlugin\7.12.0.55\GatewayVersion-x64.exe (Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-1886511979-3729726640-2495196762-1000_Classes\CLSID\{BD0DEB94-63DB-4392-9420-6EEE05094B1F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2013\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1886511979-3729726640-2495196762-1000_Classes\CLSID\{CBF9CD8C-2714-4F36-B76A-43E6C7547BC2}\localserver32 -> C:\Users\Usuario\AppData\Local\SkypePlugin\7.12.0.55\EdgeCalling.exe (Skype Technologies S.A.) CustomCLSID: HKU\S-1-5-21-1886511979-3729726640-2495196762-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2013\en-US\acadficn.dll (Autodesk, Inc.) ==================== Tarefas Agendadas (Whitelisted) ============= (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) Task: {0E0668DC-4D1B-4CCC-B2D3-8B70102424D3} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [2016-03-17] (Intel Corporation) Task: {15169EB1-5B13-4EB8-AA7C-69BCC9535100} - System32\Tasks\GameNet => C:\Program Files (x86)\QGNA\qGNA.exe Task: {1C81F8F8-72D7-4577-8248-17D9E709F1A2} - System32\Tasks\{345F8B5F-363B-4615-A211-DB73F2ED4D81} => C:\Program Files (x86)\Steam\steamapps\common\Cryptic Studios\Neverwinter.exe Task: {2019214D-17B0-4F9A-B383-D63C253F3DD9} - System32\Tasks\SafeZone scheduled Autoupdate 1458734582 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-04-15] (Avast Software) Task: {25731A6A-7673-4969-8E91-D3485F4CEFE8} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-11-28] () Task: {5878A463-AC16-4176-BDE6-942C0F892BE4} - System32\Tasks\{72FFB98D-BE69-4780-B664-2A6F37C5F4E5} => pcalua.exe -a C:\Users\Usuario\AppData\Roaming\Nox\bin\Nox_unload.exe Task: {69A840E6-CCDE-4EA2-B017-07EE2DF809EA} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-06-04] (AVAST Software) Task: {74BDD2E4-0B7A-4627-BD5F-2FD2CAF25962} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-02-20] (Piriform Ltd) Task: {798859D7-D7E8-4947-885B-05A3BDF0D468} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-09-14] (Adobe Systems Incorporated) Task: {849B88E7-7765-4ED4-9727-86B2611F9EA4} - System32\Tasks\{2FCBA007-DC2A-4071-8F64-5E12F6FEF70F} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=7.17.0.105&LastError=12002 Task: {8D6F7FEF-36BB-436E-87CC-B41B47F3AE16} - System32\Tasks\{E95773AF-608B-47F6-85F5-FEEC06E35143} => C:\Program Files (x86)\MKJogo\MKLOL\MK.exe Task: {975C3D46-348F-481A-9A98-829D6C84E37B} - System32\Tasks\{9D55A09A-52FB-44C6-8722-A15158BA380E} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.5.0.119/pt/abandoninstall?page=tsMain&installinfo=google-toolbar:offered-installed,google-chrome:notoffered;toolbaroffered Task: {AAFD5E93-D010-46B1-B165-59D3720AFAEE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-08] (Adobe Systems Incorporated) Task: {D796CD83-A559-4436-A879-B260AD1AD3AA} - System32\Tasks\USER_ESRV_SVC_WILLAMETTE => Wscript.exe //B //NoLogo "C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\task.vbs" Task: {DC93DD29-FF15-4947-9723-2A730CE4E32C} - System32\Tasks\update-S-1-5-21-1886511979-3729726640-2495196762-1000 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2014-11-28] () Task: {DE837542-EC26-43A2-901A-F52DACD64547} - System32\Tasks\{299B192E-4069-47AE-8E24-BCA64927EAFA} => Chrome.exe hxxp://ui.skype.com/ui/0/7.17.0.105/pt/abandoninstall?source=lightinstaller&page=tsInstall Task: {E0CA05FF-967E-4B04-83CA-41D3975381D0} - System32\Tasks\GlaryInitialize 4 => C:\Program Files (x86)\Glary Utilities 4\Initialize.exe [2014-02-28] (Glarysoft Ltd) Task: {E5DEA923-21C1-4BFE-BF0D-56992462ACCF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) Task: {EC970E18-D3C8-42DE-BB54-98D8D0145A85} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-05-12] (AVAST Software) Task: {FC7B26F5-4E9C-4F25-8E00-780921CF09B8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.) (Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GlaryInitialize 4.job => C:\Program Files (x86)\Glary Utilities 4\Initialize.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\update-S-1-5-21-1886511979-3729726640-2495196762-1000.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe Task: C:\Windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe ==================== Atalhos ============================= (As entradas podem ser listadas para serem restauradas ou removidas.) Shortcut: C:\Users\Usuario\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Terraria\Dedicated Server.lnk -> C:\Program Files (x86)\Terraria\start-server.bat () ==================== Módulos Carregados (Whitelisted) ============== 2014-04-08 14:23 - 2012-09-29 13:25 - 00409088 _____ () C:\Windows\System32\HPM1210LM.DLL 2014-04-08 14:23 - 2012-09-29 13:25 - 00074240 _____ () C:\Windows\system32\spool\PRTPROCS\x64\HPM1210PP.dll 2014-04-06 17:51 - 2007-02-07 16:29 - 00173616 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe 2016-06-08 18:04 - 2016-06-08 18:04 - 00117400 _____ () C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe 2016-06-08 18:04 - 2016-06-08 18:04 - 00256152 _____ () C:\Program Files (x86)\Intel Driver Update Utility\SUR\analyzer.dll 2016-05-12 09:39 - 2016-05-12 09:39 - 00123344 _____ () C:\Program Files\AVAST Software\Avast\log.dll 2016-05-12 09:39 - 2016-05-12 09:39 - 00135816 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2016-09-29 08:36 - 2016-09-29 08:36 - 03118360 _____ () C:\Program Files\AVAST Software\Avast\defs\16092900\algo.dll 2016-05-12 09:39 - 2016-05-12 09:39 - 00309912 _____ () C:\Program Files\AVAST Software\Avast\browser_pass.dll 2016-05-12 09:39 - 2016-05-12 09:39 - 00479680 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2015-11-24 17:48 - 2015-11-24 17:48 - 00028160 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\servicemanager.pyd 2015-11-24 17:46 - 2015-11-24 17:46 - 00110592 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\pywintypes26.dll 2015-11-24 17:48 - 2015-11-24 17:48 - 00041472 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32service.pyd 2015-11-24 17:48 - 2015-11-24 17:48 - 00096256 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32api.pyd 2015-11-24 17:43 - 2015-11-24 17:43 - 00356864 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\_hashlib.pyd 2015-11-24 17:48 - 2015-11-24 17:48 - 00017920 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32event.pyd 2015-11-24 17:48 - 2015-11-24 17:48 - 00019968 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32evtlog.pyd 2015-11-24 17:48 - 2015-11-24 17:48 - 00036352 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32process.pyd 2015-11-24 17:43 - 2015-11-24 17:43 - 00043008 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\_socket.pyd 2015-11-24 17:43 - 2015-11-24 17:43 - 00805376 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\_ssl.pyd 2015-11-24 17:43 - 2015-11-24 17:43 - 00087040 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\_ctypes.pyd 2015-11-24 17:46 - 2015-11-24 17:46 - 00354304 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\pythoncom26.dll 2015-11-24 17:48 - 2015-11-24 17:48 - 00167936 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\win32gui.pyd 2015-11-24 17:47 - 2015-11-24 17:47 - 01980928 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtGui.pyd 2015-12-07 17:57 - 2015-12-07 17:57 - 00077824 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\sip.pyd 2015-11-24 17:47 - 2015-11-24 17:47 - 01862144 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtCore.pyd 2015-11-24 17:47 - 2015-11-24 17:47 - 00516608 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtNetwork.pyd 2015-11-24 17:47 - 2015-11-24 17:47 - 04060160 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\PyQt5.QtWidgets.pyd 2015-11-24 17:43 - 2015-11-24 17:43 - 00010240 _____ () C:\Program Files (x86)\Raptr Inc\PlaysTV\select.pyd 2016-01-25 18:53 - 2016-01-25 18:53 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-10-14 14:24 - 2015-04-24 16:40 - 00043520 _____ () C:\Users\Usuario\AppData\Local\THORN\QtSolutions_Service-head.dll 2015-10-14 14:24 - 2014-08-28 10:36 - 00732160 _____ () C:\Users\Usuario\AppData\Local\THORN\libGLESv2.dll 2015-10-14 14:24 - 2014-08-28 10:41 - 00856576 _____ () C:\Users\Usuario\AppData\Local\THORN\platforms\qwindows.dll 2015-10-14 14:24 - 2014-08-28 10:36 - 00047104 _____ () C:\Users\Usuario\AppData\Local\THORN\libEGL.dll 2016-09-17 00:01 - 2016-09-13 21:38 - 01806152 _____ () C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.116\libglesv2.dll 2016-09-17 00:01 - 2016-09-13 21:38 - 00094024 _____ () C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.116\libegl.dll ==================== Alternate Data Streams (Whitelisted) ========= (Se uma entrada for incluída na fixlist, somente o ADS será removido.) AlternateDataStreams: C:\ProgramData:NT [40] AlternateDataStreams: C:\ProgramData:NT2 [322] AlternateDataStreams: C:\Windows\System32:9E99C86C_Bb.gbp [2] AlternateDataStreams: C:\Users\All Users:NT [40] AlternateDataStreams: C:\Users\All Users:NT2 [322] AlternateDataStreams: C:\Users\Todos os Usuários:NT [40] AlternateDataStreams: C:\Users\Todos os Usuários:NT2 [322] AlternateDataStreams: C:\ProgramData\Application Data:NT [40] AlternateDataStreams: C:\ProgramData\Application Data:NT2 [322] AlternateDataStreams: C:\ProgramData\Dados de aplicativos:NT [40] AlternateDataStreams: C:\ProgramData\Dados de aplicativos:NT2 [322] AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40] AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [322] AlternateDataStreams: C:\ProgramData\TEMP:A1EDB939 [114] AlternateDataStreams: C:\Users\Todos os Usuários\Application Data:NT [40] AlternateDataStreams: C:\Users\Todos os Usuários\Application Data:NT2 [322] AlternateDataStreams: C:\Users\Todos os Usuários\Dados de aplicativos:NT [40] AlternateDataStreams: C:\Users\Todos os Usuários\Dados de aplicativos:NT2 [322] AlternateDataStreams: C:\Users\Todos os Usuários\MTA San Andreas All:NT [40] AlternateDataStreams: C:\Users\Todos os Usuários\MTA San Andreas All:NT2 [322] AlternateDataStreams: C:\Users\Todos os Usuários\TEMP:A1EDB939 [114] AlternateDataStreams: C:\Users\Usuario\Dados de aplicativos:NT [40] AlternateDataStreams: C:\Users\Usuario\Dados de aplicativos:NT2 [322] AlternateDataStreams: C:\Users\Usuario\AppData\Roaming:NT [40] AlternateDataStreams: C:\Users\Usuario\AppData\Roaming:NT2 [322] AlternateDataStreams: C:\Users\Usuario\AppData\Roaming\Scilab:NT [40] AlternateDataStreams: C:\Users\Usuario\AppData\Roaming\Scilab:NT2 [322] ==================== Modo de Segurança (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O valor "AlternateShell" será restaurado.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver" ==================== Associação (Whitelisted) =============== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido.) HKU\S-1-5-21-1886511979-3729726640-2495196762-1000\Software\Classes\.scr: AutoCADScriptFile => C:\Windows\system32\notepad.exe "%1" ==================== Internet Explorer confiável/restrito =============== (Se uma entrada for incluída na fixlist, será removida do Registro.) IE trusted site: HKU\.DEFAULT\...\bancobrasil.com.br -> hxxps://www14.bancobrasil.com.br IE trusted site: HKU\.DEFAULT\...\bb.com.br -> hxxps://seg.bb.com.br IE trusted site: HKU\S-1-5-21-1886511979-3729726640-2495196762-1000\...\bancobrasil.com.br -> hxxps://www14.bancobrasil.com.br IE trusted site: HKU\S-1-5-21-1886511979-3729726640-2495196762-1000\...\bb.com.br -> hxxps://seg.bb.com.br ==================== Hosts Conteúdo: =============================== (Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.) 2009-07-13 23:34 - 2016-02-10 13:47 - 00000027 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Outras Áreas ============================ (Atualmente não há nenhuma correção automática para esta seção.) HKU\S-1-5-21-1886511979-3729726640-2495196762-1000\Control Panel\Desktop\\Wallpaper -> DNS Servers: 8.8.8.8 - 8.8.4.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Firewall do Windows está habilitado. ==================== MSCONFIG/TASK MANAGER ítens desabilitados == ==================== Regras do Firewall (Whitelisted) =============== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) FirewallRules: [{CD1B9A32-7285-499D-A2F6-685A9F2AF15B}] => (Allow) C:\Program Files (x86)\Cyberlink\PowerDVD\PowerDVD.EXE FirewallRules: [{B18D1D5D-4135-483A-AAB3-ACA7248ADC10}] => (Allow) LPort=50248 FirewallRules: [{D3592C64-C24A-4B91-AA76-B531FD33A9F9}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{913E2029-5785-4A05-B454-51289D262C30}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{C28A508D-AB1D-437B-8A05-DD5A15BB76C7}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{6D3155AE-A3AB-47CF-8A09-39CFA003FEDE}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe FirewallRules: [{AA5682D8-0C93-451D-99DF-67877A3D7CDE}] => (Allow) C:\Users\Usuario\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{9B5DB47F-4659-4875-8D23-21B0F1457279}] => (Allow) C:\Users\Usuario\AppData\Roaming\uTorrent\uTorrent.exe FirewallRules: [{E9272162-E78C-4295-859A-DA4196DE873E}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{C7DD52AB-0BB9-4759-904C-2FCFC267F580}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{C0599438-ACC1-4147-89DD-E29D65D96598}] => (Allow) C:\Users\Usuario\AppData\Roaming\Spotify\spotify.exe FirewallRules: [{1ACA3DC6-1914-4A5B-B8BF-BC861C4B1FCD}] => (Allow) C:\Users\Usuario\AppData\Roaming\Spotify\spotify.exe FirewallRules: [{5B32D67C-19EE-4725-AA59-B220F60AF4B2}] => (Allow) C:\Users\Usuario\AppData\Roaming\Spotify\spotify.exe FirewallRules: [{30FE162B-6512-48A2-B5DA-876247DBCB68}] => (Allow) C:\Users\Usuario\AppData\Roaming\Spotify\spotify.exe FirewallRules: [{C43C9BA0-B1A3-489B-888C-5EC55290E7B3}] => (Allow) C:\Program Files (x86)\RaidCall.BR\rcplugin.exe FirewallRules: [{84F9A85B-1CD2-48C9-B9F4-CC9168B482A8}] => (Allow) C:\Program Files (x86)\RaidCall.BR\rcplugin.exe FirewallRules: [{A03E64D7-2733-4E6C-A16E-58F6DF230362}] => (Allow) C:\Program Files (x86)\RaidCall.BR\rcplugin.exe FirewallRules: [{9AEACC43-233F-4076-9335-89056570485A}] => (Allow) C:\Program Files (x86)\RaidCall.BR\rcplugin.exe FirewallRules: [TCP Query User{63CE61E0-A37F-4A87-9C78-50B805EBD1B7}C:\program files (x86)\steam\steamapps\common\cryptic studios\neverwinter\live\gameclient.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\cryptic studios\neverwinter\live\gameclient.exe FirewallRules: [UDP Query User{292AADC2-41DD-4B16-A388-05C6D8D84FA0}C:\program files (x86)\steam\steamapps\common\cryptic studios\neverwinter\live\gameclient.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\cryptic studios\neverwinter\live\gameclient.exe FirewallRules: [{22FB37F8-6307-4EE0-BB4A-CBEC13731D53}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{418AF828-E12F-41F3-836C-E040E6A8D6AA}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{50808862-EB58-4F9A-8FDD-64FEE5388238}C:\users\usuario\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\usuario\appdata\local\akamai\netsession_win.exe FirewallRules: [UDP Query User{2C206600-2146-4AAC-B319-A3178ACFEF81}C:\users\usuario\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\usuario\appdata\local\akamai\netsession_win.exe FirewallRules: [TCP Query User{21BD771D-43E6-44B1-ABF1-E16BBA44F537}C:\users\usuario\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\usuario\appdata\local\akamai\netsession_win.exe FirewallRules: [UDP Query User{4F6F990E-BC41-4378-9020-77E5B966D552}C:\users\usuario\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\usuario\appdata\local\akamai\netsession_win.exe FirewallRules: [{008EEF28-C1F8-4D94-B4DD-B41F71979627}] => (Allow) C:\Program Files (x86)\RaidCall.BR\rcplugin.exe FirewallRules: [{A1DD3A79-62BF-4A91-B899-46E346EA96A9}] => (Allow) C:\Program Files (x86)\RaidCall.BR\rcplugin.exe FirewallRules: [{36C32CDC-D4DF-424B-BF36-F12459F71980}] => (Allow) C:\Program Files (x86)\RaidCall.BR\raidcall.exe FirewallRules: [{312F426A-7BCF-4102-BB1F-D8BC37EDD5AA}] => (Allow) C:\Program Files (x86)\RaidCall.BR\raidcall.exe FirewallRules: [{28B7D1DC-A8D4-4D6C-97A9-9D14262C61F9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [{6D3D9348-DFAE-443A-807A-2AA514BA405E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe FirewallRules: [TCP Query User{7964F31D-4E9E-491C-A006-6306658027A1}C:\users\usuario\appdata\local\skypeplugin\7.12.0.55\pluginhost.exe] => (Allow) C:\users\usuario\appdata\local\skypeplugin\7.12.0.55\pluginhost.exe FirewallRules: [UDP Query User{4E1E9CBC-2D6B-42B5-8A3E-245E68DE4840}C:\users\usuario\appdata\local\skypeplugin\7.12.0.55\pluginhost.exe] => (Allow) C:\users\usuario\appdata\local\skypeplugin\7.12.0.55\pluginhost.exe FirewallRules: [TCP Query User{4201AB94-9181-4B07-833F-72F8908595DC}C:\program files (x86)\hi-rez studios\hirezgames\paladins\binaries\win32\paladins.exe] => (Allow) C:\program files (x86)\hi-rez studios\hirezgames\paladins\binaries\win32\paladins.exe FirewallRules: [UDP Query User{ED4E4135-5DD5-4C68-B634-807AB4A000BC}C:\program files (x86)\hi-rez studios\hirezgames\paladins\binaries\win32\paladins.exe] => (Allow) C:\program files (x86)\hi-rez studios\hirezgames\paladins\binaries\win32\paladins.exe FirewallRules: [{ED642305-1B24-435E-A5D9-7AF8CCE2B5B7}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{2CFB5706-7FBE-42CA-993C-DCBDF624F882}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [{DF7E2B15-418D-46F6-A2EF-635362D678F7}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe FirewallRules: [TCP Query User{C4AD7EDE-9C9B-4127-A260-A11D757ECA0C}C:\users\usuario\appdata\local\programs\lnv\stremio\stremio.exe] => (Allow) C:\users\usuario\appdata\local\programs\lnv\stremio\stremio.exe FirewallRules: [UDP Query User{1DFC9AFB-076B-4A55-92FC-CC866E8F2C30}C:\users\usuario\appdata\local\programs\lnv\stremio\stremio.exe] => (Allow) C:\users\usuario\appdata\local\programs\lnv\stremio\stremio.exe FirewallRules: [TCP Query User{02ADB12D-FF64-423D-94ED-7508D6608847}C:\users\usuario\downloads\survivors viy\survivors viy\viy new one english multiplayer 2.exe] => (Allow) C:\users\usuario\downloads\survivors viy\survivors viy\viy new one english multiplayer 2.exe FirewallRules: [UDP Query User{724589B8-5097-4DFC-8D87-CFB17B0AA0BA}C:\users\usuario\downloads\survivors viy\survivors viy\viy new one english multiplayer 2.exe] => (Allow) C:\users\usuario\downloads\survivors viy\survivors viy\viy new one english multiplayer 2.exe FirewallRules: [TCP Query User{6C56733F-7F26-480A-B6D3-972289C7FFEB}C:\gravity\metal assault\_mas.exe] => (Allow) C:\gravity\metal assault\_mas.exe FirewallRules: [UDP Query User{DB873741-E695-4413-8791-011B226D0627}C:\gravity\metal assault\_mas.exe] => (Allow) C:\gravity\metal assault\_mas.exe FirewallRules: [TCP Query User{593D4989-E28A-496D-A689-3B9AB302C193}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [UDP Query User{4A5898C8-5C41-4D2A-8649-CE8DEBFD3D4C}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe FirewallRules: [{C0C37197-22D5-4ED0-8A6C-EFA2DC349C43}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Gloria Victis\gv.exe FirewallRules: [{BA3AA5C3-00D1-4CBD-8E25-A7D45E6C6D40}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Gloria Victis\gv.exe FirewallRules: [{B7CD87BB-9C84-416E-AE37-FF6919CA29F4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe FirewallRules: [{2C32FC50-2FE4-417E-89C8-78C9B2CB87FC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe FirewallRules: [{749F9DF1-EB26-4572-9392-69971ADF00F5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Victor Vran\VictorVranSteam.exe FirewallRules: [{A65AD822-F39C-4032-9DB9-ACEB8F22A181}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Victor Vran\VictorVranSteam.exe FirewallRules: [TCP Query User{F23A6356-6F60-49F2-95B2-2A74BDE560F3}C:\program files (x86)\steam\steamapps\common\riders of icarus\bin64\launcher.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\riders of icarus\bin64\launcher.exe FirewallRules: [UDP Query User{C10A4B4D-BA79-4C6F-B8A9-E6F4525BFA4D}C:\program files (x86)\steam\steamapps\common\riders of icarus\bin64\launcher.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\riders of icarus\bin64\launcher.exe FirewallRules: [{728750D8-64DE-4919-B4CA-4A1F617A40B3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\EasyAntiCheat\EasyAntiCheat.exe FirewallRules: [{99BC8BCD-03B9-4CF2-8A2F-4518EA127764}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\EasyAntiCheat\EasyAntiCheat.exe FirewallRules: [{FEE1B9E5-8A5E-4504-8065-5BD48F19D343}] => (Allow) C:\Users\Usuario\AppData\Local\MyComGames\MyComGames.exe FirewallRules: [{D7363B08-8CDA-4EA7-B6E2-120B34C9FB8F}] => (Allow) C:\Users\Usuario\AppData\Local\MyComGames\MyComGames.exe FirewallRules: [{22BB1F78-0ED4-4B01-82D8-395A51ADCFE5}] => (Allow) C:\Users\Usuario\AppData\Roaming\Nox\bin\Nox.exe FirewallRules: [{6A043E11-240B-4D0A-97C3-041A4A20C336}] => (Allow) C:\Program Files\Bignox\BigNoxVM\RTNoxVMHandle.exe FirewallRules: [TCP Query User{066D0E12-27BF-492D-A86E-CE4924718339}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [UDP Query User{3F318275-765C-4D0C-8C91-104B0401837B}C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_91\bin\javaw.exe FirewallRules: [TCP Query User{94D368E3-98AF-4A83-A390-308388E125F4}C:\users\usuario\desktop\launcher\client\tal.exe] => (Allow) C:\users\usuario\desktop\launcher\client\tal.exe FirewallRules: [UDP Query User{61539582-5512-40FF-937F-B3A1D972638D}C:\users\usuario\desktop\launcher\client\tal.exe] => (Allow) C:\users\usuario\desktop\launcher\client\tal.exe FirewallRules: [TCP Query User{BC58D524-E8AC-4929-9350-B5918CEC5E81}C:\users\usuario\downloads\zombie night terrorbybusterbrgr\zombie night terrorbybusterbrgr\znt.exe] => (Allow) C:\users\usuario\downloads\zombie night terrorbybusterbrgr\zombie night terrorbybusterbrgr\znt.exe FirewallRules: [UDP Query User{176AE7C4-6FD6-4B11-A9B1-6D5539F4DC73}C:\users\usuario\downloads\zombie night terrorbybusterbrgr\zombie night terrorbybusterbrgr\znt.exe] => (Allow) C:\users\usuario\downloads\zombie night terrorbybusterbrgr\zombie night terrorbybusterbrgr\znt.exe FirewallRules: [{1C418E26-531D-47F3-936C-3BF0D317BDAE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TreeOfLife\client\client.exe FirewallRules: [{C426E764-E2C7-4CEE-8721-D6B82C2F2DE4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TreeOfLife\client\client.exe FirewallRules: [{ED3B5AD0-27EA-48C3-8A0B-306E69E7E2FF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TreeOfLife\ptr\client\client.exe FirewallRules: [{95AEC95B-96B6-4DB6-842A-C2E58EA0561A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\TreeOfLife\ptr\client\client.exe FirewallRules: [{9CAC7AF1-EFF9-4702-A93B-40297E48845A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BattleriteBeta\Battlerite.exe FirewallRules: [{2BEB3204-F722-4B82-897C-DA9BDA898248}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\BattleriteBeta\Battlerite.exe FirewallRules: [{7F7B5236-012D-4647-AE48-74A17F1EC582}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{9CE2B444-0F1D-4B3F-9065-681B45A89296}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Paladins\Binaries\Win32\HirezBridge.exe FirewallRules: [{E9914461-ED58-4096-92C5-CFB1A65D1244}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Paladins\Binaries\Win32\HirezBridge.exe FirewallRules: [TCP Query User{26C56B67-1A75-4B67-9595-20A756162D1C}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe FirewallRules: [UDP Query User{A2EAC99A-31B4-4C79-B1B8-D28A8586AF74}C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\paladins\binaries\win32\paladins.exe FirewallRules: [{23F45690-75E8-4740-BCA1-EBF553B17716}] => (Allow) LPort=49193 FirewallRules: [{DD4E6C4C-E42F-4A5A-94BE-074A1EE5E823}] => (Allow) LPort=5000 ==================== Pontos de Restauração ========================= 21-09-2016 10:46:59 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 21-09-2016 10:47:29 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 21-09-2016 10:48:15 DirectX instalado 29-09-2016 00:08:34 Ponto de Verificação Agendado 29-09-2016 11:43:14 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 29-09-2016 11:45:09 Windows Update 29-09-2016 11:53:32 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 29-09-2016 11:54:38 Windows Update 29-09-2016 11:56:42 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 29-09-2016 12:12:52 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 29-09-2016 12:14:30 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 29-09-2016 12:17:19 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 29-09-2016 12:52:42 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 ==================== Dispositivos Apresentando Falhas No Gerenciador ============= Name: Baidu NetDefense Description: Baidu NetDefense Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: Bndef Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. Name: Baidu Protect Description: Baidu Protect Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1} Manufacturer: Service: Bprotect Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24) Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed. Devices stay in this state if they have been prepared for removal. After you remove the device, this error disappears.Remove the device, and this error should be resolved. ==================== Erros no Log de eventos: ========================= Erros em Aplicativos: ================== Error: (09/28/2016 01:26:57 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: O programa Albion-Online.exe versão 5.4.0.23386 parou de interagir com o Windows e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique o histórico de problemas no painel de controle da Central de Ações. ID de Processo: 1268 Hora de Início: 01d2199c6829a76f Hora de Término: 232 Caminho do Aplicativo: C:\Program Files (x86)\AlbionOnline\game\Albion-Online.exe Id do Relatório: 5bb9b1f6-8598-11e6-9700-80ee7379e05c Error: (09/27/2016 11:05:06 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome de aplicativo com falha: AlbionLauncher.exe, versão: 1.0.0.1, carimbo de hora: 0x5783b5cc Nome do módulo de falhas: Qt5Widgets.dll, versão: 5.4.0.0, carimbo de hora: 0x5481edfe Código de exceção: 0xc0000005 Deslocamento com falha: 0x000070a3 Identificação do processo com falha: 0x10a8 Hora de início do aplicativo com falha: 0x01d2192cb33b3e09 Caminho do aplicativo com falha: C:\Program Files (x86)\AlbionOnline\launcher\AlbionLauncher.exe FCaminho do módulo de falhas: C:\Program Files (x86)\AlbionOnline\launcher\Qt5Widgets.dll Identificação do Relatório: f96dfa46-851f-11e6-8738-80ee7379e05c Error: (09/25/2016 02:23:59 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome de aplicativo com falha: rads_user_kernel.exe, versão: 0.0.0.0, carimbo de hora: 0x4e65c1ac Nome do módulo de falhas: rads_user_kernel.exe, versão: 0.0.0.0, carimbo de hora: 0x4e65c1ac Código de exceção: 0xc0000005 Deslocamento com falha: 0x000b8554 Identificação do processo com falha: 0x1720 Hora de início do aplicativo com falha: 0x01d216ed00dc5dcc Caminho do aplicativo com falha: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe FCaminho do módulo de falhas: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Identificação do Relatório: 42e2ecac-82e0-11e6-94fc-80ee7379e05c Error: (09/24/2016 01:56:33 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: O programa ts3client_win64.exe versão 3.0.19.4 parou de interagir com o Windows e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique o histórico de problemas no painel de controle da Central de Ações. ID de Processo: 1124 Hora de Início: 01d216842761a79c Hora de Término: 4 Caminho do Aplicativo: C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe Id do Relatório: d446565a-8277-11e6-95d6-80ee7379e05c Error: (09/23/2016 11:25:34 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: O programa ts3client_win64.exe versão 3.0.19.4 parou de interagir com o Windows e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique o histórico de problemas no painel de controle da Central de Ações. ID de Processo: 96c Hora de Início: 01d21607e3781b64 Hora de Término: 15 Caminho do Aplicativo: C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe Id do Relatório: 2687a5b4-81fe-11e6-96a7-80ee7379e05c Error: (09/23/2016 11:06:48 PM) (Source: MsiInstaller) (EventID: 1041) (User: AUTORIDADE NT) Description: Falha ao iniciar uma transação do Windows InstallerASU_MSI_TRAN. Erro 1603 ao iniciar a transação. Error: (09/20/2016 01:50:15 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome de aplicativo com falha: AlbionLauncher.exe, versão: 1.0.0.1, carimbo de hora: 0x5783b5cc Nome do módulo de falhas: Qt5Widgets.dll, versão: 5.4.0.0, carimbo de hora: 0x5481edfe Código de exceção: 0xc0000005 Deslocamento com falha: 0x000070a3 Identificação do processo com falha: 0xc04 Hora de início do aplicativo com falha: 0x01d2135f075e852f Caminho do aplicativo com falha: C:\Program Files (x86)\AlbionOnline\launcher\AlbionLauncher.exe FCaminho do módulo de falhas: C:\Program Files (x86)\AlbionOnline\launcher\Qt5Widgets.dll Identificação do Relatório: 4cf72478-7f52-11e6-afe5-80ee7379e05c Error: (09/18/2016 09:06:48 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome de aplicativo com falha: AlbionLauncher.exe, versão: 1.0.0.1, carimbo de hora: 0x5783b5cc Nome do módulo de falhas: Qt5Widgets.dll, versão: 5.4.0.0, carimbo de hora: 0x5481edfe Código de exceção: 0xc0000005 Deslocamento com falha: 0x000070a3 Identificação do processo com falha: 0xb20 Hora de início do aplicativo com falha: 0x01d211f21d8da8a5 Caminho do aplicativo com falha: C:\Program Files (x86)\AlbionOnline\launcher\AlbionLauncher.exe FCaminho do módulo de falhas: C:\Program Files (x86)\AlbionOnline\launcher\Qt5Widgets.dll Identificação do Relatório: f5061901-7dfc-11e6-92fc-80ee7379e05c Error: (09/18/2016 01:22:53 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: O programa ts3client_win64.exe versão 3.0.19.4 parou de interagir com o Windows e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique o histórico de problemas no painel de controle da Central de Ações. ID de Processo: 12b8 Hora de Início: 01d2114dcaaea883 Hora de Término: 17 Caminho do Aplicativo: C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe Id do Relatório: 8a46514b-7d57-11e6-95b4-80ee7379e05c Error: (09/18/2016 01:20:49 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome de aplicativo com falha: rads_user_kernel.exe, versão: 0.0.0.0, carimbo de hora: 0x4e65c1ac Nome do módulo de falhas: rads_user_kernel.exe, versão: 0.0.0.0, carimbo de hora: 0x4e65c1ac Código de exceção: 0xc0000005 Deslocamento com falha: 0x000b8554 Identificação do processo com falha: 0x16dc Hora de início do aplicativo com falha: 0x01d2116406958ffd Caminho do aplicativo com falha: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe FCaminho do módulo de falhas: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Identificação do Relatório: 46b2976b-7d57-11e6-95b4-80ee7379e05c Erros de Sistema: ============= Error: (09/29/2016 12:50:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Windows Presentation Foundation Font Cache 3.0.0.0 devido ao seguinte erro: O serviço não respondeu à requisição de início ou controle em tempo hábil. Error: (09/29/2016 12:50:17 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Tempo limite esgotado (30000 milissegundos) ao aguardar a conexão do serviço Windows Presentation Foundation Font Cache 3.0.0.0. Error: (09/29/2016 12:49:41 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Falha ao carregar o(s) seguinte(s) driver(s) de início do sistema ou de inicialização: Bnbase Bndef Bprotect Error: (09/29/2016 12:49:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Update Greener Web devido ao seguinte erro: O serviço não respondeu à requisição de início ou controle em tempo hábil. Error: (09/29/2016 12:49:10 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Tempo limite esgotado (30000 milissegundos) ao aguardar a conexão do serviço Update Greener Web. Error: (09/29/2016 12:47:25 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: AUTORIDADE NT) Description: Falha na inicialização do Módulo de Extensibilidade de WLAN. Caminho do Módulo: C:\Windows\system32\Rtlihvs.dll Código de Erro: 126 Error: (09/29/2016 12:15:39 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: O servidor {E60687F7-01A1-40AA-86AC-DB1CBF673334} não se registrou com o DCOM dentro do tempo limite requerido. Error: (09/29/2016 11:55:32 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: AUTORIDADE NT) Description: Falha na Instalação: o Windows não pôde instalar a seguinte atualização com o erro 0x80004005: Atualização para o Windows (KB2999226). Error: (09/29/2016 11:46:38 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: AUTORIDADE NT) Description: Falha na Instalação: o Windows não pôde instalar a seguinte atualização com o erro 0x80004005: Atualização para o Windows (KB2999226). Error: (09/29/2016 11:23:14 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10000) (User: AUTORIDADE NT) Description: Falha na inicialização do Módulo de Extensibilidade de WLAN. Caminho do Módulo: C:\Windows\system32\Rtlihvs.dll Código de Erro: 126 CodeIntegrity: =================================== Date: 2016-02-10 14:44:34.925 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2016-02-10 14:44:34.847 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2014-08-10 14:50:06.369 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Level Up! Games\Ragnarok\npkcrypt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2014-08-10 14:50:06.270 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Level Up! Games\Ragnarok\npkcrypt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2014-08-10 14:50:05.804 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Level Up! Games\Ragnarok\npkcrypt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2014-08-10 14:50:05.706 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Level Up! Games\Ragnarok\npkcrypt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2014-08-10 14:34:13.013 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Level Up! Games\Ragnarok\npkcrypt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2014-08-10 14:34:12.910 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Level Up! Games\Ragnarok\npkcrypt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2014-08-10 14:34:12.478 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Level Up! Games\Ragnarok\npkcrypt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. Date: 2014-08-10 14:34:12.377 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Level Up! Games\Ragnarok\npkcrypt.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source. ==================== Informações da Memória =========================== Processador: Intel(R) Core(TM) i5-3210M CPU @ 2.50GHz Percentagem de memória em uso: 67% RAM física total: 3542.14 MB RAM física disponível: 1162.37 MB Virtual Total: 7082.48 MB Virtual disponível: 4360.27 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:297.99 GB) (Free:88.51 GB) NTFS ==================== MBR & Tabela de Partições ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: EC465B00) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS) ==================== Fim de Addition.txt ============================