Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 02-12-2016 Executado por USER (administrador) em USER-PC (03-12-2016 09:03:14) Executando a partir de C:\Users\USER\Desktop Perfis Carregados: USER (Perfis Disponíveis: USER) Platform: Windows 7 Professional (X64) Idioma: Português (Brasil) Internet Explorer Versão 8 (Navegador padrão: Chrome) Modo da Inicialização: Normal Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (GAS Tecnologia) C:\Program Files (x86)\GbPlugin\GbpSv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe (FirebirdSQL Project) C:\Program Files (x86)\Firebird\Firebird_2_0\bin\fbguard.exe (Kurupira.net) C:\Windows\svcproxy\SVCProxy.exe (@ByELDI) C:\Program Files\KMSpico\Service_KMS.exe (GAS Tecnologia LTDA) C:\Program Files\Diebold\Warsaw\core.exe (Kurupira.NET) C:\Program Files (x86)\Kurupira\WebFilter\kurupiraWF.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (Kurupira.NET) C:\Program Files (x86)\Kurupira\WebFilter\rcp.exe (GlavSoft LLC.) C:\Program Files (x86)\ShowMyPCService\tvnserver.exe (GAS Tecnologia LTDA) C:\Program Files\Diebold\Warsaw\core.exe (FirebirdSQL Project) C:\Program Files (x86)\Firebird\Firebird_2_0\bin\fbserver.exe (GAS Tecnologia) C:\Program Files (x86)\GbPlugin\GbpSv.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registro (Whitelisted) ==================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [Diebold - Warsaw] => C:\Program Files\Diebold\Warsaw\core.exe [925744 2016-06-22] (GAS Tecnologia LTDA) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-11-16] (AVAST Software) HKLM-x32\...\Run: [KurupiraNet] => C:\Program Files (x86)\Kurupira\WebFilter\kurupirawf.exe [7731928 2016-01-14] (Kurupira.NET) Winlogon\Notify\ GbPluginCef: C:\Program Files (x86)\GbPlugin\gbiehCef.dll [2016-08-10] (Caixa Economica Federal) HKU\S-1-5-21-3695910337-1769152937-2696825416-1000\...\Run: [KurupiraNet] => C:\Program Files (x86)\Kurupira\WebFilter\kurupirawf.exe [7731928 2016-01-14] (Kurupira.NET) HKU\S-1-5-21-3695910337-1769152937-2696825416-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9105112 2016-11-15] (Piriform Ltd) HKU\S-1-5-18\...\Run: [KurupiraNet] => C:\Program Files (x86)\Kurupira\WebFilter\kurupirawf.exe [7731928 2016-01-14] (Kurupira.NET) ShellExecuteHooks-x32: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399003} - C:\Program Files (x86)\GbPlugin\gbiehcef.dll [1903328 2016-08-10] (Caixa Economica Federal) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-10-18] (AVAST Software) ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Winsock: Catalog9 01 C:\Windows\system32\SVCProxy.dll Nenhum Arquivo Winsock: Catalog9 02 C:\Windows\system32\SVCProxy.dll Nenhum Arquivo Winsock: Catalog9 03 C:\Windows\system32\SVCProxy.dll Nenhum Arquivo Winsock: Catalog9 04 C:\Windows\system32\SVCProxy.dll Nenhum Arquivo Winsock: Catalog9 15 C:\Windows\system32\SVCProxy.dll Nenhum Arquivo Winsock: Catalog9-x64 01 C:\Windows\system32\SVCProxy64.dll [460288 2015-03-05] (Kurupira.net) Winsock: Catalog9-x64 02 C:\Windows\system32\SVCProxy64.dll [460288 2015-03-05] (Kurupira.net) Winsock: Catalog9-x64 03 C:\Windows\system32\SVCProxy64.dll [460288 2015-03-05] (Kurupira.net) Winsock: Catalog9-x64 04 C:\Windows\system32\SVCProxy64.dll [460288 2015-03-05] (Kurupira.net) Winsock: Catalog9-x64 15 C:\Windows\system32\SVCProxy64.dll [460288 2015-03-05] (Kurupira.net) Hosts: 127.0.0.1 validation.sls.microsoft.com Tcpip\Parameters: [DhcpNameServer] 200.225.197.34 200.225.197.37 Tcpip\..\Interfaces\{76F4F96D-DCB6-4E93-9855-482C23DE8F86}: [DhcpNameServer] 200.225.197.34 200.225.197.37 Tcpip\..\Interfaces\{E10371AA-7A1A-490D-A3A9-4FB3DCE10BF8}: [DhcpNameServer] 10.1.1.1 Internet Explorer: ================== HKU\S-1-5-21-3695910337-1769152937-2696825416-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pt-br/?ocid=iehp BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-10-30] (Microsoft Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24] (AVAST Software) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2016-10-30] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-10-30] (Microsoft Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-10-30] (Microsoft Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24] (AVAST Software) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2016-10-30] (Microsoft Corporation) BHO-x32: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540003} -> C:\Program Files (x86)\GbPlugin\gbiehcef.dll [2016-08-10] (Caixa Economica Federal) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-10-30] (Microsoft Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-10-30] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-10-30] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-10-30] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-10-30] (Microsoft Corporation) Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-13] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-13] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-13] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-13] (Microsoft Corporation) FireFox: ======== FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-11-22] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-10-30] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-10-30] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-10-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-10-18] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-09-30] (Adobe Systems Inc.) Chrome: ======= CHR Profile: C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default [2016-12-03] CHR Extension: (Google Apresentações) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-10-18] CHR Extension: (Google Docs) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-18] CHR Extension: (Google Drive) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-18] CHR Extension: (YouTube) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-18] CHR Extension: (Planilhas do Google) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-10-18] CHR Extension: (Documentos Google off-line) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-18] CHR Extension: (Avast Online Security) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-10-18] CHR Extension: (PConverter) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\kloelaifhaljljodenkodboiodogmdnf [2016-10-18] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-10-18] CHR Extension: (Gmail) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-18] CHR Extension: (Chrome Media Router) - C:\Users\USER\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-18] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Serviços (Whitelisted) ==================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-10-18] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [223600 2016-11-22] (AVAST Software) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3294912 2016-10-30] (Microsoft Corporation) R2 FirebirdGuardianDefaultInstance; C:\Program Files (x86)\Firebird\Firebird_2_0\bin\fbguard.exe [81920 2008-04-23] (FirebirdSQL Project) [Arquivo não assinado] R3 FirebirdServerDefaultInstance; C:\Program Files (x86)\Firebird\Firebird_2_0\bin\fbserver.exe [2015232 2008-04-23] (FirebirdSQL Project) [Arquivo não assinado] R2 GbpSv; C:\Program Files (x86)\GbPlugin\GbpSv.exe [631520 2016-08-10] (GAS Tecnologia) R2 KNet; C:\Windows\svcproxy\svcproxy.exe [4524752 2015-09-04] (Kurupira.net) R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [737984 2015-08-30] (@ByELDI) [Arquivo não assinado] S3 svcprocess; C:\Windows\svcproxy\svcprocess.exe [174800 2015-09-04] (Kurupira.NET) R2 tvnserver; C:\Program Files (x86)\ShowMyPCService\tvnserver.exe [815704 2016-05-09] (GlavSoft LLC.) R2 Warsaw Technology; C:\Program Files\Diebold\Warsaw\core.exe [925744 2016-06-22] (GAS Tecnologia LTDA) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-10-18] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-10-18] (AVAST Software) R3 aswNetNd6; C:\Windows\System32\DRIVERS\aswNetNd6.sys [28312 2016-11-22] (AVAST Software) R1 aswNetSec; C:\Windows\system32\drivers\aswNetSec.sys [453192 2016-11-22] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-10-18] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-10-18] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-10-18] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-10-18] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-10-18] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-18] (AVAST Software) R3 GBPRCM; C:\Program Files (x86)\GbPlugin\gbprcm64.sys [29912 2016-08-10] (GAS Tecnologia) S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [926824 2011-04-08] (Realtek Semiconductor Corporation ) R3 Warsaw_PP; C:\Program Files (x86)\GbPlugin\wsftprp64.sys [24792 2016-08-10] (GAS Tecnologia LTDA) R4 WinDivert1.1; C:\Program Files\Diebold\Warsaw\WinDivert64.sys [38104 2015-07-07] (Basil) R1 wsddfac; C:\Windows\System32\drivers\wsddfac.sys [101080 2016-12-03] (GAS Tecnologia) R1 wsddpp; C:\Windows\system32\drivers\wsddpp.sys [103640 2015-03-18] (GAS Tecnologia) S1 gbpddfac; system32\drivers\gbpddfac64.sys [X] S0 gbpddreg; system32\drivers\gbpddreg64.sys [X] ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Três Meses Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-12-03 08:59 - 2016-12-03 09:03 - 00015538 _____ C:\Users\USER\Desktop\FRST.txt 2016-12-03 08:59 - 2016-12-03 09:03 - 00000000 ____D C:\FRST 2016-12-03 08:59 - 2016-12-03 08:58 - 02411520 _____ (Farbar) C:\Users\USER\Desktop\FRST64.exe 2016-12-03 08:58 - 2016-12-03 08:58 - 02411520 _____ (Farbar) C:\Users\USER\Downloads\FRST64.exe 2016-12-03 08:43 - 2016-12-03 08:44 - 01034556 _____ C:\Users\USER\Downloads\Windows6.1-KB2999226-x64.msu 2016-12-03 08:43 - 2016-12-03 08:43 - 00111848 _____ C:\Users\USER\AppData\Local\GDIPFONTCACHEV1.DAT 2016-12-01 07:04 - 2016-12-01 07:04 - 00434576 _____ C:\Windows\system32\FNTCACHE.DAT 2016-11-30 15:51 - 2016-11-30 15:51 - 08576448 _____ (Piriform Ltd) C:\Users\USER\Downloads\ccsetup524.exe 2016-11-30 15:51 - 2016-11-30 15:51 - 00002786 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2016-11-30 15:51 - 2016-11-30 15:51 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk 2016-11-30 15:51 - 2016-11-30 15:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2016-11-30 15:51 - 2016-11-30 15:51 - 00000000 ____D C:\Program Files\CCleaner 2016-11-30 15:20 - 2016-11-30 15:20 - 00019431 _____ C:\Users\USER\Downloads\trenas 57840.xml 2016-11-30 15:11 - 2016-11-30 15:11 - 00007887 _____ C:\Users\USER\Downloads\gran disco 21915.xml 2016-11-30 15:02 - 2016-11-30 15:02 - 00000115 _____ C:\Users\USER\Desktop\Baixar xml.url 2016-11-30 14:54 - 2016-11-30 14:54 - 00001059 _____ C:\Users\USER\Desktop\NewAdm.lnk 2016-11-29 15:23 - 2016-11-29 15:23 - 00000726 _____ C:\Users\USER\Desktop\FECHAMENTO DO CAIXA - Atalho.lnk 2016-11-22 07:41 - 2016-11-22 07:41 - 00001922 _____ C:\Users\Public\Desktop\Avast Internet Security.lnk 2016-11-22 07:41 - 2016-11-22 07:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2016-11-22 07:39 - 2016-11-22 07:39 - 00453192 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNetSec.sys 2016-11-22 07:39 - 2016-11-22 07:39 - 00028312 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNetNd6.sys 2016-11-22 07:39 - 2016-10-18 14:24 - 00391496 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2016-11-01 12:11 - 2016-11-01 12:11 - 00045403 _____ C:\Users\USER\Downloads\imgres.htm 2016-10-28 10:16 - 2016-10-28 10:16 - 00000000 ____D C:\Windows\system32\appmgmt 2016-10-26 10:24 - 2016-10-26 10:24 - 07194312 _____ (Microsoft Corporation) C:\Users\USER\Downloads\vcredist_x64.exe 2016-10-26 10:24 - 2016-10-26 10:24 - 06503984 _____ (Microsoft Corporation) C:\Users\USER\Downloads\vcredist_x86.exe 2016-10-26 10:24 - 2016-10-26 10:24 - 01420840 _____ (Microsoft Corporation) C:\Users\USER\Downloads\vcredist_arm.exe 2016-10-26 10:19 - 2016-10-26 10:19 - 00001079 _____ C:\Users\USER\Desktop\VendasFB.lnk 2016-10-26 10:16 - 2016-10-26 10:16 - 00213904 _____ (Microsoft Corporation) C:\Users\USER\Downloads\vs_community__df731163b5ad494093431e0a96fe7930.exe 2016-10-26 10:14 - 2016-10-26 10:25 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache 2016-10-26 10:14 - 2016-10-26 10:25 - 00000000 ____D C:\ProgramData\Package Cache 2016-10-26 10:12 - 2016-10-26 10:13 - 14572000 _____ (Microsoft Corporation) C:\Users\USER\Downloads\vc_redist.x64.exe 2016-10-25 15:58 - 2016-12-02 08:46 - 00000000 ____D C:\Windows\system32\MRT 2016-10-25 15:58 - 2016-10-25 15:58 - 143495576 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-10-25 15:56 - 2016-06-25 14:03 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\EOSNotify.exe 2016-10-25 15:56 - 2015-03-19 01:07 - 05503416 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-10-25 15:56 - 2015-03-19 00:57 - 03963320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2016-10-25 15:56 - 2015-03-19 00:57 - 03908024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2016-10-25 15:56 - 2014-09-14 22:44 - 03195392 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-10-25 15:56 - 2013-03-19 03:54 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-10-25 15:56 - 2013-03-19 02:53 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2016-10-25 15:56 - 2013-03-19 01:19 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-10-25 15:56 - 2011-04-09 04:58 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2016-10-25 15:56 - 2011-04-09 03:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2016-10-25 13:31 - 2016-10-25 13:32 - 00024378 _____ C:\Users\USER\Downloads\31161005547064000120550010000569301000569303.xml 2016-10-24 08:49 - 2016-12-03 07:15 - 00101080 _____ (GAS Tecnologia) C:\Windows\system32\Drivers\wsddfac.sys 2016-10-24 08:49 - 2016-10-24 08:49 - 00001024 _____ C:\.rnd 2016-10-24 08:49 - 2016-10-24 08:49 - 00000000 ___HD C:\Program Files (x86)\GAS Tecnologia 2016-10-24 08:49 - 2016-10-24 08:49 - 00000000 ___HD C:\Program Files (x86)\Diebold 2016-10-24 08:49 - 2016-10-24 08:49 - 00000000 ____D C:\Program Files\Diebold 2016-10-24 08:49 - 2015-03-18 10:23 - 00103640 ____N (GAS Tecnologia) C:\Windows\system32\Drivers\wsddpp.sys 2016-10-24 08:48 - 2016-12-03 07:15 - 00000000 ____D C:\Users\Todos os Usuários\GbPlugin 2016-10-24 08:48 - 2016-12-03 07:15 - 00000000 ____D C:\ProgramData\GbPlugin 2016-10-24 08:48 - 2016-12-03 07:15 - 00000000 ____D C:\Program Files (x86)\GbPlugin 2016-10-24 08:48 - 2016-10-24 08:48 - 00000000 ____D C:\Users\Todos os Usuários\GAS Tecnologia 2016-10-24 08:48 - 2016-10-24 08:48 - 00000000 ____D C:\ProgramData\GAS Tecnologia 2016-10-24 08:47 - 2016-10-24 08:50 - 00000000 ____D C:\Users\Todos os Usuários\Temp 2016-10-24 08:47 - 2016-10-24 08:50 - 00000000 ____D C:\ProgramData\Temp 2016-10-24 08:47 - 2016-10-24 08:48 - 05520590 _____ (GAS Tecnologia ) C:\Users\USER\Downloads\Não confirmado 716258.crdownload 2016-10-24 08:47 - 2016-10-24 08:47 - 02891312 _____ (CAIXA) C:\Users\USER\Downloads\GBPCEF.exe 2016-10-20 16:06 - 2016-10-20 16:06 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2016-10-20 14:55 - 2016-10-20 14:55 - 00000000 ____D C:\Users\USER\AppData\LocalLow\Temp 2016-10-20 14:21 - 2016-10-20 14:21 - 00120377 _____ C:\Users\USER\Downloads\Comparação Nexoos CDB - Reinvestimentos.xlsx 2016-10-20 14:21 - 2016-10-20 14:21 - 00120377 _____ C:\Users\USER\Downloads\Comparação Nexoos CDB - Reinvestimentos (1).xlsx 2016-10-19 14:23 - 2016-10-19 14:23 - 00000000 ____D C:\Users\USER\Documents\Modelos Personalizados do Office 2016-10-18 18:11 - 2016-11-30 15:52 - 00000000 ____D C:\Windows\Panther 2016-10-18 16:06 - 2016-10-18 16:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firebird 2.0 2016-10-18 16:06 - 2016-10-18 16:06 - 00000000 ____D C:\Program Files (x86)\Firebird 2016-10-18 16:06 - 2008-04-23 08:45 - 00393216 _____ (FirebirdSQL Project) C:\Windows\SysWOW64\GDS32.DLL 2016-10-18 16:01 - 2016-10-18 16:02 - 00000000 ____D C:\Program Files (x86)\ShowMyPCService 2016-10-18 16:01 - 2016-10-18 16:01 - 02076064 _____ C:\Users\USER\Downloads\ShowMyPC3500.exe 2016-10-18 16:01 - 2016-10-18 16:01 - 00001285 _____ C:\Users\USER\Desktop\ShowMyPC.lnk 2016-10-18 15:15 - 2010-06-29 15:22 - 00403968 _____ (Software 2000 Limited) C:\Windows\system32\HP1006LM.DLL 2016-10-18 15:15 - 2010-01-13 12:43 - 00080399 _____ C:\Windows\system32\WRes1200.txt 2016-10-18 15:15 - 2010-01-13 12:43 - 00001071 _____ C:\Windows\system32\W600dpi.txt 2016-10-18 15:15 - 2010-01-13 12:42 - 00080399 _____ C:\Windows\system32\HRes600.txt 2016-10-18 15:15 - 2010-01-13 12:42 - 00080399 _____ C:\Windows\system32\HRes1200.txt 2016-10-18 15:15 - 2010-01-13 12:41 - 00064512 _____ C:\Windows\system32\HPPLVS.dll 2016-10-18 14:37 - 2016-10-18 14:37 - 00000000 ____D C:\Windows\pss 2016-10-18 14:34 - 2016-12-03 07:15 - 00012080 _____ C:\Windows\SysWOW64\SVCProxyOff.ini 2016-10-18 14:34 - 2016-12-03 07:15 - 00012080 _____ C:\Windows\system32\SVCProxyOff.ini 2016-10-18 14:34 - 2015-03-05 21:30 - 00460288 _____ (Kurupira.net) C:\Windows\system32\SVCProxy64.dll 2016-10-18 14:34 - 2015-03-05 21:29 - 00354304 _____ (Kurupira.net) C:\Windows\SysWOW64\SVCProxy.dll 2016-10-18 14:33 - 2016-12-03 07:15 - 00000000 ___HD C:\Windows\svcproxy 2016-10-18 14:33 - 2016-10-18 14:33 - 00000000 ____D C:\Users\Todos os Usuários\Kurupira 2016-10-18 14:33 - 2016-10-18 14:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kurupira 2016-10-18 14:33 - 2016-10-18 14:33 - 00000000 ____D C:\ProgramData\Kurupira 2016-10-18 14:33 - 2016-10-18 14:33 - 00000000 ____D C:\Program Files (x86)\Kurupira 2016-10-18 14:33 - 2011-05-11 04:32 - 00032768 _____ () C:\Windows\SysWOW64\VBDelegator.dll 2016-10-18 14:33 - 2011-05-06 16:33 - 01867264 _____ (Osen Kusnadi) C:\Windows\SysWOW64\osenvistasuite2010.ocx 2016-10-18 14:33 - 2011-05-06 16:03 - 01342464 _____ (Osen Kusnadi) C:\Windows\SysWOW64\MySQLite2010.dll 2016-10-18 14:33 - 2011-04-29 10:42 - 00361472 _____ (Osen Kusnadi) C:\Windows\SysWOW64\osenvistasuite2010.dll 2016-10-18 14:33 - 2009-12-09 10:27 - 02187264 _____ (Chilkat Software, Inc.) C:\Windows\SysWOW64\ChilkatMail_v7_9.dll 2016-10-18 14:33 - 2009-12-02 13:30 - 00145944 _____ (Desaware Inc.) C:\Windows\SysWOW64\dwshengine80.dll 2016-10-18 14:33 - 2009-01-20 03:20 - 00258048 _____ (InfoSoft Global (P) Ltd.) C:\Windows\SysWOW64\FusionCharts.ocx 2016-10-18 14:33 - 2008-10-10 13:36 - 00128840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswinsck.ocx 2016-10-18 14:33 - 2008-05-01 14:46 - 00187392 _____ (Desaware Inc.) C:\Windows\SysWOW64\dweasy80.OCX 2016-10-18 14:33 - 2004-10-17 03:32 - 00299008 _____ (xp-style-menu.com) C:\Windows\SysWOW64\XpNetMenu.ocx 2016-10-18 14:33 - 2004-03-09 01:00 - 00212240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RICHTX32.OCX 2016-10-18 14:33 - 2004-02-23 03:00 - 00078848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msbind.dll 2016-10-18 14:33 - 1998-09-11 10:14 - 00021504 _____ () C:\Windows\SysWOW64\WBCustomizer.dll 2016-10-18 14:33 - 1998-04-14 10:51 - 00034304 _____ (Microsoft) C:\Windows\SysWOW64\NTSVC.ocx 2016-10-18 14:32 - 2016-10-18 14:32 - 00000000 ____D C:\Users\USER\Downloads\kurupira_webfilter_setup 2016-10-18 14:29 - 2016-10-18 14:32 - 16915701 _____ C:\Users\USER\Downloads\kurupira_webfilter_setup.zip 2016-10-18 14:26 - 2016-10-18 14:26 - 00000000 ____D C:\Users\USER\AppData\Roaming\AVAST Software 2016-10-18 14:25 - 2016-10-18 14:25 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software 2016-10-18 14:25 - 2016-10-18 14:25 - 00000000 ____D C:\Program Files\Common Files\AV 2016-10-18 14:24 - 2016-12-02 12:56 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2016-10-18 14:24 - 2016-10-18 14:26 - 00513632 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2016-10-18 14:24 - 2016-10-18 14:26 - 00293352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys 2016-10-18 14:24 - 2016-10-18 14:25 - 00969184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2016-10-18 14:24 - 2016-10-18 14:24 - 00992960 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2016-10-18 14:24 - 2016-10-18 14:24 - 00921280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2016-10-18 14:24 - 2016-10-18 14:24 - 00163416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2016-10-18 14:24 - 2016-10-18 14:24 - 00108816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2016-10-18 14:24 - 2016-10-18 14:24 - 00103064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2016-10-18 14:24 - 2016-10-18 14:24 - 00074544 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2016-10-18 14:24 - 2016-10-18 14:24 - 00053208 _____ (AVAST Software) C:\Windows\avastSS.scr 2016-10-18 14:24 - 2016-10-18 14:24 - 00037656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys 2016-10-18 14:21 - 2016-10-18 14:21 - 00000000 ____D C:\Users\Todos os Usuários\AVAST Software 2016-10-18 14:21 - 2016-10-18 14:21 - 00000000 ____D C:\ProgramData\AVAST Software 2016-10-18 14:21 - 2016-10-18 14:21 - 00000000 ____D C:\Program Files\AVAST Software 2016-10-18 14:12 - 2016-11-16 17:16 - 00000000 ____D C:\Users\USER\AppData\Local\Google 2016-10-18 14:12 - 2016-11-16 07:21 - 00002193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-10-18 14:12 - 2016-11-16 07:21 - 00002181 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-10-18 14:10 - 2016-12-03 08:15 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-10-18 14:10 - 2016-12-03 07:14 - 00001060 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-10-18 14:10 - 2016-10-18 14:12 - 00000000 ____D C:\Program Files (x86)\Google 2016-10-18 14:10 - 2016-10-18 14:10 - 00004060 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2016-10-18 14:10 - 2016-10-18 14:10 - 00003808 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2016-10-18 14:10 - 2016-07-26 14:24 - 00504488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2016-10-18 14:09 - 2016-10-18 14:10 - 00000000 ____D C:\Users\USER\AppData\Local\Deployment 2016-10-18 14:09 - 2016-10-18 14:09 - 00000000 ____D C:\Users\USER\AppData\Local\Apps\2.0 2016-10-18 14:08 - 2016-10-18 14:08 - 00000000 ____D C:\Users\USER\AppData\Local\CEF 2016-10-18 14:07 - 2016-11-10 07:17 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2016-10-18 14:07 - 2016-11-03 10:45 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2016-10-18 14:07 - 2016-10-18 14:07 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2016-10-18 14:07 - 2016-10-18 14:07 - 00000000 ____D C:\Users\USER\AppData\Roaming\Adobe 2016-10-18 14:07 - 2016-10-18 14:07 - 00000000 ____D C:\Users\USER\AppData\LocalLow\Adobe 2016-10-18 14:07 - 2016-10-18 14:07 - 00000000 ____D C:\Program Files (x86)\Adobe 2016-10-18 14:06 - 2016-10-18 14:08 - 00000000 ____D C:\Users\Todos os Usuários\Adobe 2016-10-18 14:06 - 2016-10-18 14:08 - 00000000 ____D C:\ProgramData\Adobe 2016-10-18 14:02 - 2016-10-18 14:08 - 00000000 ____D C:\Users\USER\AppData\Local\Adobe 2016-10-18 14:00 - 2016-10-18 14:01 - 00000000 ____D C:\Program Files\KMSpico 2016-10-18 14:00 - 2016-10-18 14:00 - 00003362 _____ C:\Windows\System32\Tasks\AutoPico Daily Restart 2016-10-18 14:00 - 2016-10-18 14:00 - 00000000 ____D C:\Users\USER\Intel 2016-10-18 14:00 - 2016-10-18 14:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico 2016-10-18 14:00 - 2010-12-06 00:16 - 00090112 _____ (Vestris Inc.) C:\Windows\system32\Vestris.ResourceLib.dll 2016-10-18 13:59 - 2016-10-18 13:59 - 00002125 _____ C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk 2016-10-18 13:59 - 2016-10-18 13:59 - 00002110 _____ C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk 2016-10-18 13:59 - 2016-10-18 13:59 - 00002110 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk 2016-10-18 13:59 - 2016-10-18 13:59 - 00002110 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk 2016-10-18 13:59 - 2016-10-18 13:59 - 00000000 ___RD C:\Users\USER\OneDrive 2016-10-18 13:59 - 2016-10-18 13:59 - 00000000 ____D C:\Users\Todos os Usuários\Microsoft OneDrive 2016-10-18 13:59 - 2016-10-18 13:59 - 00000000 ____D C:\ProgramData\Microsoft OneDrive 2016-10-18 13:59 - 2016-10-18 13:59 - 00000000 ____D C:\Program Files (x86)\Microsoft OneDrive 2016-10-18 13:56 - 2016-10-18 13:56 - 00002501 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk 2016-10-18 13:56 - 2016-10-18 13:56 - 00002459 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk 2016-10-18 13:56 - 2016-10-18 13:56 - 00002448 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk 2016-10-18 13:56 - 2016-10-18 13:56 - 00002413 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk 2016-10-18 13:56 - 2016-10-18 13:56 - 00002397 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk 2016-10-18 13:56 - 2016-10-18 13:56 - 00002394 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk 2016-10-18 13:56 - 2016-10-18 13:56 - 00002384 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk 2016-10-18 13:56 - 2016-10-18 13:56 - 00002380 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk 2016-10-18 13:56 - 2016-10-18 13:56 - 00002364 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk 2016-10-18 13:56 - 2016-10-18 13:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ferramentas do Microsoft Office 2016 2016-10-18 13:55 - 2016-11-18 08:55 - 00000000 ____D C:\Users\Todos os Usuários\regid.1991-06.com.microsoft 2016-10-18 13:55 - 2016-11-18 08:55 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2016-10-18 13:55 - 2016-10-18 13:55 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform 2016-10-18 13:53 - 2016-10-18 13:53 - 01804512 _____ C:\WindowsGABRIOLA.tt2 2016-10-18 13:52 - 2016-11-18 08:51 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2016-10-18 13:52 - 2016-10-18 13:52 - 00000000 ____D C:\Program Files\Microsoft Office 15 2016-10-18 13:46 - 2016-10-18 13:46 - 00116304 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll 2016-10-18 13:46 - 2016-10-18 13:46 - 00082544 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll 2016-10-18 13:45 - 2016-10-18 13:46 - 01035272 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2016-10-18 13:43 - 2016-10-18 13:43 - 00000000 ____D C:\Users\USER\AppData\Roaming\Easeware 2016-10-18 13:41 - 2016-10-19 11:14 - 01650340 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2016-10-18 13:38 - 2009-11-25 11:47 - 01942856 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2016-10-18 13:38 - 2009-11-25 11:47 - 01130824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2016-10-18 13:38 - 2009-11-25 11:47 - 00444752 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll 2016-10-18 13:38 - 2009-11-25 11:47 - 00320352 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe 2016-10-18 13:38 - 2009-11-25 11:47 - 00297808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscoree.dll 2016-10-18 13:38 - 2009-11-25 11:47 - 00295264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHost.exe 2016-10-18 13:38 - 2009-11-25 11:47 - 00109912 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll 2016-10-18 13:38 - 2009-11-25 11:47 - 00099176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationHostProxy.dll 2016-10-18 13:38 - 2009-11-25 11:47 - 00049472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netfxperf.dll 2016-10-18 13:38 - 2009-11-25 11:47 - 00048960 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll 2016-10-18 12:29 - 2012-06-02 20:19 - 02428952 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2016-10-18 12:29 - 2012-06-02 20:19 - 00701976 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2016-10-18 12:29 - 2012-06-02 20:19 - 00057880 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2016-10-18 12:29 - 2012-06-02 20:19 - 00044056 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2016-10-18 12:29 - 2012-06-02 20:19 - 00038424 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2016-10-18 12:29 - 2012-06-02 20:15 - 02622464 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2016-10-18 12:29 - 2012-06-02 20:15 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2016-10-18 12:29 - 2012-06-02 15:19 - 00186752 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2016-10-18 12:29 - 2012-06-02 15:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2016-10-18 12:27 - 2016-10-18 12:27 - 00000000 ____D C:\Users\USER\AppData\Roaming\WinRAR 2016-10-18 12:27 - 2016-10-18 12:27 - 00000000 ____D C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2016-10-18 12:27 - 2016-10-18 12:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2016-10-18 12:27 - 2016-10-18 12:27 - 00000000 ____D C:\Program Files\WinRAR 2016-10-18 12:27 - 2011-04-08 22:31 - 00926824 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\RTL8192cu.sys 2016-10-18 12:26 - 2016-10-18 12:26 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf 2016-10-18 12:19 - 2016-10-18 12:19 - 00001423 _____ C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-10-18 12:19 - 2016-10-18 12:19 - 00001389 _____ C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2016-10-18 12:18 - 2016-10-27 10:19 - 00000000 ____D C:\Users\USER\AppData\Local\VirtualStore 2016-10-18 12:18 - 2016-10-18 12:18 - 00000020 ___SH C:\Users\USER\ntuser.ini 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas músicas 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas imagens 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Meus vídeos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Histórico 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Dados de aplicativos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Usuário Padrão 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\Modelos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\Meus documentos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\Menu Iniciar 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\Documents\Minhas músicas 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\Documents\Minhas imagens 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\Documents\Meus vídeos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\Dados de aplicativos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\Configurações locais 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\AppData\Local\Histórico 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\AppData\Local\Dados de aplicativos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\Ambiente de rede 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\USER\Ambiente de impressão 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Todos os Usuários\Modelos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Todos os Usuários\Menu Iniciar 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Todos os Usuários\Favoritos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Todos os Usuários\Documentos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Todos os Usuários\Dados de aplicativos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Todos os Usuários 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Public\Documents\Minhas músicas 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Public\Documents\Minhas imagens 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Public\Documents\Meus vídeos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\Modelos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\Meus documentos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\Menu Iniciar 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\Documents\Minhas músicas 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\Documents\Minhas imagens 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\Documents\Meus vídeos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\Dados de aplicativos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\Configurações locais 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\AppData\Local\Histórico 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dados de aplicativos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\Ambiente de rede 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default\Ambiente de impressão 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default User\Documents\Minhas músicas 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default User\Documents\Minhas imagens 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default User\Documents\Meus vídeos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Histórico 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Dados de aplicativos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\ProgramData\Modelos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programas 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\ProgramData\Menu Iniciar 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\ProgramData\Favoritos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\ProgramData\Documentos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\ProgramData\Dados de aplicativos 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Program Files\Common Files\Sistema 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Program Files\Arquivos Comuns 2016-10-18 12:18 - 2016-10-18 12:18 - 00000000 _SHDL C:\Arquivos de Programas 2016-10-18 12:18 - 2009-07-14 05:45 - 00000000 ____D C:\Users\USER\AppData\Roaming\Media Center Programs 2016-10-18 12:14 - 2016-10-18 12:14 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2016-10-18 12:14 - 2016-10-18 12:14 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk 2016-10-07 22:52 - 2016-10-07 22:52 - 00443632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp140.dll 2016-10-07 22:52 - 2016-10-07 22:52 - 00394496 _____ (Microsoft Corporation) C:\Windows\system32\vccorlib140.dll 2016-10-07 22:52 - 2016-10-07 22:52 - 00334608 _____ (Microsoft Corporation) C:\Windows\system32\concrt140.dll 2016-10-07 22:52 - 2016-10-07 22:52 - 00089328 _____ (Microsoft Corporation) C:\Windows\system32\vcruntime140.dll 2016-10-07 22:52 - 2016-10-07 22:52 - 00085744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcruntime140.dll 2016-10-07 22:49 - 2016-10-07 22:49 - 00639728 _____ (Microsoft Corporation) C:\Windows\system32\msvcp140.dll 2016-10-07 22:49 - 2016-10-07 22:49 - 00244504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\concrt140.dll 2016-10-07 22:45 - 2016-10-07 22:45 - 00271112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vccorlib140.dll ==================== Três Meses Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-12-03 08:49 - 2009-07-14 02:45 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-12-03 08:49 - 2009-07-14 02:45 - 00014032 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-12-03 07:14 - 2009-07-14 03:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-12-02 08:40 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\system32\NDF 2016-12-02 08:36 - 2009-07-14 01:20 - 00000000 ____D C:\Windows\inf 2016-11-08 09:32 - 2009-07-14 01:20 - 00000000 __RHD C:\Users\Public\Libraries ==================== Bamital & volsnap ====================== (Não há correção automática para arquivos que não passaram na verificação.) C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente C:\Windows\explorer.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente C:\Windows\system32\services.exe => O arquivo é assinado digitalmente C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente C:\Windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente C:\Windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente LastRegBack: 2016-11-24 14:07 ==================== Fim de FRST.txt ============================