Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 05-02-2017 Executado por Odye (administrador) em DESKTOP-AGAKLJ1 (10-02-2017 11:53:45) Executando a partir de C:\Users\Odye\Downloads Perfis Carregados: Odye (Perfis Disponíveis: Odye) Platform: Windows 10 Home Single Language Versão 1607 (X64) Idioma: Português (Brasil) Internet Explorer Versão 11 (Navegador padrão: Edge) Modo da Inicialização: Normal Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe () C:\Windows\System32\igfxTray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.105.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe ==================== Registro (Whitelisted) ==================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8512760 2015-08-04] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-08-04] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2857128 2015-01-09] (Synaptics Incorporated) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [205512 2017-02-10] (AVAST Software) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-02-10] (AVAST Software) ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{d37ae798-3c66-4130-afd3-b98d5dc6dc67}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== FireFox: ======== FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-10] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-02-10] (Google Inc.) Chrome: ======= CHR Profile: C:\Users\Odye\AppData\Local\Google\Chrome\User Data\Default [2017-02-10] CHR Extension: (Google Apresentações) - C:\Users\Odye\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-02-10] CHR Extension: (Google Docs) - C:\Users\Odye\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-02-10] CHR Extension: (Google Drive) - C:\Users\Odye\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-02-10] CHR Extension: (YouTube) - C:\Users\Odye\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-02-10] CHR Extension: (Planilhas do Google) - C:\Users\Odye\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-02-10] CHR Extension: (Documentos Google off-line) - C:\Users\Odye\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-02-10] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Odye\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-10] CHR Extension: (Gmail) - C:\Users\Odye\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-02-10] CHR Extension: (Chrome Media Router) - C:\Users\Odye\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-10] ==================== Serviços (Whitelisted) ==================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7142136 2017-02-10] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [262736 2017-02-10] (AVAST Software) R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373744 2016-11-01] (Intel Corporation) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [312056 2015-08-04] (Realtek Semiconductor) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [309784 2017-02-10] (AVAST Software s.r.o.) R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [189768 2017-02-10] (AVAST Software s.r.o.) R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [334600 2017-02-10] (AVAST Software s.r.o.) R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [48528 2017-02-10] (AVAST Software s.r.o.) S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [38296 2017-02-10] (AVAST Software) R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [32088 2017-02-10] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [126088 2017-02-10] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [100640 2017-02-10] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [74680 2017-02-10] (AVAST Software) R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [991496 2017-02-10] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [547904 2017-02-10] (AVAST Software) S2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [162528 2017-02-10] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [337080 2017-02-10] (AVAST Software) S3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [23760 2015-02-26] (Dell Computer Corporation) S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [23312 2015-02-26] (Dell Computer Corporation) R3 DellRbtn; C:\WINDOWS\System32\drivers\DellRbtn.sys [10752 2013-01-24] (OSR Open Systems Resources, Inc.) S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus.sys [129152 2016-04-25] (Samsung Electronics Co., Ltd.) S3 dot4; C:\WINDOWS\System32\drivers\Dot4.sys [151968 2012-09-25] (Windows (R) Win 7 DDK provider) S3 iaLPSS_GPIO; C:\WINDOWS\System32\drivers\iaLPSS_GPIO.sys [35832 2014-06-03] (Intel Corporation) S3 iaLPSS_I2C; C:\WINDOWS\System32\drivers\iaLPSS_I2C.sys [120312 2014-06-03] (Intel Corporation) S3 iaLPSS_SPI; C:\WINDOWS\System32\drivers\iaLPSS_SPI.sys [100856 2014-06-03] (Intel Corporation) S3 iaLPSS_UART2; C:\WINDOWS\System32\drivers\iaLPSS_UART2.sys [143864 2014-06-03] (Intel Corporation) R3 MEIx64; C:\WINDOWS\System32\drivers\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation) S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek ) S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [412400 2015-08-05] (Realsil Semiconductor Corporation) S3 ssudcdf; C:\WINDOWS\System32\drivers\ssudcdf.sys [36608 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 ssuddmgr; C:\WINDOWS\System32\drivers\ssuddmgr.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 ssudobex; C:\WINDOWS\System32\drivers\ssudobex.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [64640 2016-04-25] (QUALCOMM Incorporated) S3 ssudrmnet; C:\WINDOWS\System32\drivers\ssudrmnet.sys [70400 2014-01-22] (DEVGURU Co., LTD.) S3 ssudserd; C:\WINDOWS\System32\drivers\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 ss_conn_usb_driver; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver.sys [26368 2014-01-22] (DEVGURU Co., LTD.) R3 SynRMIHID; C:\WINDOWS\System32\drivers\SynRMIHID.sys [42664 2015-01-09] (Synaptics Incorporated) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um Mês Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2017-02-10 11:51 - 2017-02-10 11:52 - 00017812 _____ C:\Users\Odye\Downloads\Addition.txt 2017-02-10 11:50 - 2017-02-10 11:53 - 00010549 _____ C:\Users\Odye\Downloads\FRST.txt 2017-02-10 11:50 - 2017-02-10 11:53 - 00000000 ____D C:\FRST 2017-02-10 11:49 - 2017-02-10 11:49 - 02421248 _____ (Farbar) C:\Users\Odye\Downloads\FRST64.exe 2017-02-10 11:47 - 2017-02-10 11:47 - 01763328 _____ (Farbar) C:\Users\Odye\Downloads\Não confirmado 961928.crdownload 2017-02-10 11:46 - 2017-02-10 11:46 - 01753984 _____ (Farbar) C:\Users\Odye\Downloads\Não confirmado 916746.crdownload 2017-02-10 11:40 - 2017-02-10 11:40 - 00000000 ____D C:\Users\Todos os Usuários\SWCUTemp 2017-02-10 11:03 - 2017-02-10 11:03 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job 2017-02-10 10:33 - 2017-02-10 10:33 - 00004028 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1486733585 2017-02-10 10:33 - 2017-02-10 10:33 - 00001090 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk 2017-02-10 10:32 - 2017-02-10 10:32 - 00000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software 2017-02-10 10:32 - 2017-02-10 10:32 - 00000000 ____D C:\Program Files\Common Files\AV 2017-02-10 10:31 - 2017-02-10 10:31 - 00032088 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys 2017-02-10 10:27 - 2017-02-10 10:27 - 00003994 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update 2017-02-10 10:27 - 2017-02-10 10:27 - 00001969 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2017-02-10 10:27 - 2017-02-10 10:27 - 00000000 ____D C:\Users\Odye\AppData\Roaming\AVAST Software 2017-02-10 10:27 - 2017-02-10 10:27 - 00000000 ____D C:\Users\Odye\AppData\Local\CEF 2017-02-10 10:26 - 2017-02-10 10:27 - 00337080 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswvmm.sys 2017-02-10 10:26 - 2017-02-10 10:25 - 00547904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2017-02-10 10:26 - 2017-02-10 10:25 - 00162528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys 2017-02-10 10:26 - 2017-02-10 10:25 - 00126088 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2017-02-10 10:26 - 2017-02-10 10:25 - 00100640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2017-02-10 10:26 - 2017-02-10 10:25 - 00074680 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2017-02-10 10:26 - 2017-02-10 10:25 - 00038296 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys 2017-02-10 10:26 - 2017-02-10 10:24 - 00991496 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2017-02-10 10:26 - 2017-02-10 10:23 - 00334600 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys 2017-02-10 10:26 - 2017-02-10 10:23 - 00309784 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys 2017-02-10 10:26 - 2017-02-10 10:23 - 00189768 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys 2017-02-10 10:26 - 2017-02-10 10:23 - 00048528 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys 2017-02-10 10:25 - 2017-02-10 10:25 - 00398408 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2017-02-10 10:19 - 2017-02-10 10:31 - 00000000 ____D C:\Program Files\AVAST Software 2017-02-10 10:17 - 2017-02-10 10:31 - 00000000 ____D C:\Users\Todos os Usuários\AVAST Software 2017-02-10 09:43 - 2017-02-10 09:43 - 00002332 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-02-10 09:41 - 2017-02-10 11:23 - 00000000 ____D C:\Users\Odye\AppData\Local\Google 2017-02-10 09:41 - 2017-02-10 09:50 - 00003586 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2017-02-10 09:41 - 2017-02-10 09:50 - 00003462 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2017-02-10 09:41 - 2017-02-10 09:43 - 00000000 ____D C:\Program Files (x86)\Google 2017-02-10 09:40 - 2017-02-10 09:40 - 00000000 ____D C:\Users\Odye\AppData\Local\MicrosoftEdge 2017-02-09 20:06 - 2017-02-09 16:41 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe 2017-02-09 20:04 - 2017-02-09 20:06 - 00000000 ____D C:\WINDOWS\system32\MRT 2017-02-09 20:04 - 2017-02-09 20:04 - 135657872 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2017-02-09 19:44 - 2017-02-09 19:46 - 00412276 _____ C:\WINDOWS\Minidump\020917-26875-01.dmp 2017-02-09 19:44 - 2017-02-09 19:44 - 604240525 _____ C:\WINDOWS\MEMORY.DMP 2017-02-09 19:44 - 2017-02-09 19:44 - 00000000 ____D C:\WINDOWS\Minidump 2017-02-09 15:26 - 2017-02-09 15:26 - 00000000 ____D C:\Users\Odye\AppData\Local\Comms 2017-02-09 15:07 - 2017-02-09 15:07 - 00000000 ____D C:\Program Files (x86)\Intel 2017-02-09 14:53 - 2017-02-09 14:53 - 00003288 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2 2017-02-09 14:48 - 2017-02-09 14:48 - 00000000 ____D C:\Users\Odye\AppData\Roaming\Skype 2017-02-09 14:43 - 2017-02-09 14:53 - 00002368 _____ C:\Users\Odye\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-02-09 14:40 - 2017-02-09 14:40 - 00000000 ____D C:\Users\Todos os Usuários\Microsoft OneDrive 2017-02-09 14:38 - 2017-02-09 14:38 - 00000000 ____D C:\Users\Odye\AppData\Local\Publishers 2017-02-09 14:37 - 2017-02-09 20:12 - 00000000 ____D C:\Users\Odye\AppData\Local\Packages 2017-02-09 14:37 - 2017-02-09 14:37 - 00000000 ____D C:\Users\Odye\AppData\Roaming\Adobe 2017-02-09 14:37 - 2017-02-09 14:37 - 00000000 ____D C:\Users\Odye\AppData\Local\VirtualStore 2017-02-09 14:37 - 2017-02-09 14:37 - 00000000 ____D C:\Users\Odye\AppData\Local\TileDataLayer 2017-02-09 14:36 - 2017-02-09 20:48 - 00000000 ____D C:\Users\Odye\AppData\Local\ConnectedDevicesPlatform 2017-02-09 14:36 - 2017-02-09 14:36 - 00000020 ___SH C:\Users\Odye\ntuser.ini 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas Músicas 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas Imagens 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Meus Vídeos 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Histórico 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Dados de Aplicativos 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Usuário Padrão 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Todos os Usuários\Modelos 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Todos os Usuários\Menu Iniciar 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Todos os Usuários\Documentos 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Todos os Usuários\Dados de Aplicativos 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Todos os Usuários 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Public\Documents\Minhas Músicas 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Public\Documents\Minhas Imagens 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Public\Documents\Meus Vídeos 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\Modelos 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\Meus Documentos 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\Menu Iniciar 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\Documents\Minhas Músicas 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\Documents\Minhas Imagens 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\Documents\Meus Vídeos 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\Dados de Aplicativos 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\Configurações Locais 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\AppData\Local\Histórico 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dados de Aplicativos 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\Ambiente de Rede 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Users\Default\Ambiente de Impressão 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Program Files\Common Files\Sistema 2017-02-09 14:35 - 2017-02-09 14:35 - 00000000 _SHDL C:\Program Files\Arquivos Comuns 2017-02-09 14:34 - 2017-02-10 11:45 - 01913732 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-02-09 14:34 - 2017-02-09 14:34 - 00009946 _____ C:\Users\Odye\Desktop\Aplicativos Removidos.html 2017-02-09 14:26 - 2017-02-10 11:01 - 00000000 ____D C:\Users\Odye 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\Modelos 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\Meus Documentos 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\Menu Iniciar 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\Documents\Minhas Músicas 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\Documents\Minhas Imagens 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\Documents\Meus Vídeos 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\Dados de Aplicativos 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\Configurações Locais 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\AppData\Local\Histórico 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\AppData\Local\Dados de Aplicativos 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\Ambiente de Rede 2017-02-09 14:26 - 2017-02-09 14:26 - 00000000 _SHDL C:\Users\Odye\Ambiente de Impressão 2017-02-09 14:19 - 2017-02-10 11:40 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2017-02-09 14:19 - 2017-02-09 15:06 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat 2017-02-09 14:19 - 2017-02-09 14:19 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf 2017-02-09 14:19 - 2017-02-09 14:19 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf 2017-02-09 14:19 - 2017-02-09 14:19 - 00000000 ____D C:\Program Files\Common Files\Atheros 2017-02-09 14:19 - 2017-02-09 14:19 - 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin 2017-02-09 14:19 - 2016-11-01 23:05 - 00103952 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL 2017-02-09 14:19 - 2016-11-01 23:05 - 00099848 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL 2017-02-09 14:18 - 2017-02-09 14:18 - 01019725 _____ C:\WINDOWS\system32\Drivers\rtwavesskdy.dat 2017-02-09 14:18 - 2017-02-09 14:18 - 00455936 _____ C:\WINDOWS\system32\Drivers\rtwavesmapro.dat 2017-02-09 14:18 - 2017-02-09 14:18 - 00031095 _____ C:\WINDOWS\system32\Drivers\rtwavesEFX.dat 2017-02-09 14:18 - 2017-02-09 14:18 - 00020691 _____ C:\WINDOWS\system32\Drivers\rtwavesmaprocap.dat 2017-02-09 14:18 - 2017-02-09 14:18 - 00010945 _____ C:\WINDOWS\system32\Drivers\rtwavesMFX.dat 2017-02-09 14:18 - 2017-02-09 14:18 - 00003218 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_PushButton 2017-02-09 14:18 - 2017-02-09 14:18 - 00000000 ____H C:\Users\Todos os Usuários\DP45977C.lfl 2017-02-09 14:18 - 2017-02-09 14:18 - 00000000 ____D C:\WINDOWS\system32\SRSLabs 2017-02-09 14:18 - 2017-02-09 14:18 - 00000000 ____D C:\Program Files\Intel 2017-02-09 14:17 - 2017-02-09 14:17 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2017-02-09 14:17 - 2017-02-09 14:17 - 00000000 ____D C:\Program Files\Realtek 2017-02-09 14:15 - 2016-07-16 08:41 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll 2017-02-09 14:14 - 2017-02-09 14:14 - 00000000 ____D C:\Users\Todos os Usuários\USOShared 2017-02-09 14:13 - 2017-02-10 11:39 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-02-09 14:12 - 2017-02-10 10:57 - 00000000 ____D C:\WINDOWS\system32\SleepStudy 2017-02-09 14:12 - 2017-02-09 22:20 - 00194496 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2017-02-09 14:10 - 2017-02-09 14:36 - 00000000 ___DC C:\WINDOWS\Panther 2017-02-09 14:10 - 2017-02-09 14:10 - 00000000 ____D C:\WINDOWS\InfusedApps 2017-02-09 14:09 - 2017-02-09 15:43 - 00000000 ____D C:\Windows.old 2017-02-09 14:09 - 2017-02-09 14:12 - 00000000 ____D C:\WINDOWS\ServiceProfiles 2017-02-09 14:09 - 2017-02-09 14:09 - 00008192 _____ C:\WINDOWS\system32\config\userdiff 2017-02-09 14:04 - 2017-02-09 14:04 - 00000000 ____D C:\WINDOWS\SysWOW64\sda 2017-02-09 14:04 - 2017-02-09 14:04 - 00000000 ____D C:\Program Files\Synaptics 2017-02-09 14:00 - 2017-02-09 14:00 - 00000000 ____D C:\WINDOWS\Setup 2017-02-09 13:57 - 2017-02-09 13:57 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2017-02-09 13:57 - 2017-02-09 13:57 - 00000000 ____D C:\WINDOWS\OCR 2017-02-09 13:57 - 2017-02-09 13:57 - 00000000 ____D C:\Program Files\Reference Assemblies 2017-02-09 13:57 - 2017-02-09 13:57 - 00000000 ____D C:\Program Files\MSBuild 2017-02-09 13:57 - 2017-02-09 13:57 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2017-02-09 13:57 - 2017-02-09 13:57 - 00000000 ____D C:\Program Files (x86)\MSBuild 2017-02-09 13:56 - 2017-02-10 11:45 - 00809338 _____ C:\WINDOWS\system32\prfh0416.dat 2017-02-09 13:56 - 2017-02-10 11:45 - 00176232 _____ C:\WINDOWS\system32\prfc0416.dat 2017-02-09 13:56 - 2017-02-09 13:54 - 00328278 _____ C:\WINDOWS\system32\prfi0416.dat 2017-02-09 13:56 - 2017-02-09 13:54 - 00040752 _____ C:\WINDOWS\system32\prfd0416.dat 2017-02-09 13:55 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm 2017-02-09 13:55 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN 2017-02-09 13:55 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep 2017-02-09 13:55 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr 2017-02-09 13:55 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts 2017-02-09 13:55 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\SysWOW64\0409 2017-02-09 13:55 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\system32\winrm 2017-02-09 13:55 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\system32\WCN 2017-02-09 13:55 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\system32\slmgr 2017-02-09 13:55 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts 2017-02-09 13:55 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\system32\0409 2017-02-09 13:55 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\DigitalLocker 2017-02-09 13:50 - 2016-12-22 20:13 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2017-02-09 13:50 - 2016-12-22 20:13 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2017-02-09 13:48 - 2017-02-10 10:27 - 00000000 ___HD C:\Program Files\WindowsApps 2017-02-09 13:48 - 2017-02-10 10:27 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-02-09 13:48 - 2017-02-10 09:41 - 00000000 ____D C:\WINDOWS\appcompat 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ___SD C:\WINDOWS\system32\F12 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ___SD C:\WINDOWS\system32\dsc 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ___RD C:\Program Files\Windows Defender 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\SysWOW64\setup 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\system32\Sysprep 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\system32\setup 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\system32\oobe 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\system32\migwiz 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\system32\Dism 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\system32\appraiser 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\ShellExperiences 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\Provisioning 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\bcastdvr 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2017-02-09 13:48 - 2017-02-09 22:17 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2017-02-09 13:48 - 2017-02-09 22:15 - 00015425 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml 2017-02-09 13:48 - 2017-02-09 14:41 - 00000000 ____D C:\WINDOWS\rescache 2017-02-09 13:48 - 2017-02-09 14:35 - 00000000 ____D C:\Program Files\Windows NT 2017-02-09 13:48 - 2017-02-09 14:34 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase 2017-02-09 13:48 - 2017-02-09 14:30 - 00000000 ____D C:\Users\Todos os Usuários\regid.1991-06.com.microsoft 2017-02-09 13:48 - 2017-02-09 14:26 - 00000000 ____D C:\WINDOWS\system32\spool 2017-02-09 13:48 - 2017-02-09 14:26 - 00000000 ____D C:\WINDOWS\system32\FxsTmp 2017-02-09 13:48 - 2017-02-09 14:21 - 00000000 ___RD C:\WINDOWS\PrintDialog 2017-02-09 13:48 - 2017-02-09 14:21 - 00000000 ___RD C:\WINDOWS\MiracastView 2017-02-09 13:48 - 2017-02-09 14:14 - 00000000 ____D C:\Users\Todos os Usuários\USOPrivate 2017-02-09 13:48 - 2017-02-09 14:09 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template 2017-02-09 13:48 - 2017-02-09 13:57 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI 2017-02-09 13:48 - 2017-02-09 13:57 - 00000000 ____D C:\WINDOWS\SystemApps 2017-02-09 13:48 - 2017-02-09 13:57 - 00000000 ____D C:\WINDOWS\system32\MUI 2017-02-09 13:48 - 2017-02-09 13:55 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2017-02-09 13:48 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\SysWOW64\Com 2017-02-09 13:48 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2017-02-09 13:48 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\system32\Com 2017-02-09 13:48 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\PolicyDefinitions 2017-02-09 13:48 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\IME 2017-02-09 13:48 - 2017-02-09 13:55 - 00000000 ____D C:\WINDOWS\Help 2017-02-09 13:48 - 2017-02-09 13:55 - 00000000 ____D C:\Program Files\Common Files\System 2017-02-09 13:48 - 2017-02-09 13:55 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 __SHD C:\Program Files\Windows Sidebar 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 __RSD C:\WINDOWS\Media 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 __RHD C:\Users\Public\Libraries 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ___SD C:\WINDOWS\system32\Nui 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ___SD C:\WINDOWS\system32\Configuration 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ___RD C:\WINDOWS\Offline Web Pages 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\Web 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\Vss 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\tracing 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\TAPI 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\ras 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\IME 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SystemResources 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\WinMetadata 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\winevt 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\ras 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\ProximityToast 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\PointOfService 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\NDF 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\MsDtc 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\Ipmi 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\InputMethod 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\inetsrv 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\IME 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\icsxml 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\ias 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\downlevel 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\DDFs 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\config\Journal 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\Bthprops 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\AppLocker 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\System 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SKB 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\security 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\schemas 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\SchCache 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\Resources 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\Registration 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\PLA 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\Performance 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\ModemLogs 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\L2Schemas 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\InputMethod 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\Globalization 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\GameBarPresenceWriter 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\Cursors 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\Branding 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\addins 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\Users\Todos os Usuários\Comms 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\Program Files\Windows Portable Devices 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\Program Files\Windows Multimedia Platform 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\Program Files\Common Files\Services 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\Program Files (x86)\Windows NT 2017-02-09 13:48 - 2017-02-09 13:48 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2017-02-09 13:48 - 2017-02-09 13:43 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll 2017-02-09 13:48 - 2017-02-09 13:43 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat 2017-02-09 13:48 - 2017-02-09 13:43 - 00215943 _____ C:\WINDOWS\system32\dssec.dat 2017-02-09 13:48 - 2017-02-09 13:43 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll 2017-02-09 13:48 - 2017-02-09 13:43 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services 2017-02-09 13:48 - 2017-02-09 13:43 - 00004096 _____ C:\WINDOWS\system32\config\VSMIDK 2017-02-09 13:48 - 2017-02-09 13:43 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam 2017-02-09 13:48 - 2017-02-09 13:43 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol 2017-02-09 13:48 - 2017-02-09 13:43 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json 2017-02-09 13:48 - 2017-02-09 13:43 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT 2017-02-09 13:48 - 2017-02-09 13:43 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT 2017-02-09 13:48 - 2017-02-09 13:43 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks 2017-02-09 13:48 - 2017-02-09 13:42 - 00000219 _____ C:\WINDOWS\system.ini 2017-02-09 13:48 - 2017-02-09 13:42 - 00000092 _____ C:\WINDOWS\win.ini 2017-02-09 13:45 - 2017-02-10 10:26 - 00000000 ____D C:\WINDOWS\INF 2017-02-09 13:28 - 2017-02-09 20:04 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-02-09 13:22 - 2017-02-10 11:39 - 00786432 _____ C:\WINDOWS\system32\config\BBI 2017-02-09 13:22 - 2017-02-10 10:29 - 00032768 _____ C:\WINDOWS\system32\config\ELAM 2017-02-09 13:22 - 2017-02-09 22:17 - 00000000 ____D C:\WINDOWS\servicing 2017-02-09 13:22 - 2017-02-09 14:07 - 00000000 ____D C:\$WINDOWS.~BT 2017-02-09 13:22 - 2017-02-09 13:48 - 00000000 ____D C:\WINDOWS\system32\SMI 2017-02-08 17:39 - 2017-02-08 17:39 - 00000000 ___HD C:\$AV_ASW 2017-02-08 16:24 - 2017-02-09 13:14 - 00000000 _____ C:\Users\Public\Documents\report.dat 2017-02-08 16:24 - 2017-02-08 22:36 - 00000000 _____ C:\Users\Public\Documents\temp.dat 2017-02-08 15:43 - 2017-02-08 16:24 - 83209902 _____ C:\Users\Odye\Downloads\Duetos_Novo_Tempo-_Volume_4_2014_Playback.zip 2017-02-08 15:43 - 2017-02-08 15:45 - 41597852 _____ C:\Users\Odye\Downloads\Duetos_Novo_Tempo-_Volume_4_2014.zip 2017-02-03 14:50 - 2017-02-08 23:03 - 00000000 ____D C:\Users\Odye\AppData\LocalLow\Mozilla 2017-02-03 14:48 - 2017-02-03 14:48 - 00245584 _____ C:\Users\Odye\Downloads\Firefox Setup Stub 51.0.1.exe 2017-01-30 13:13 - 2017-01-30 13:21 - 00000002 _____ C:\END 2017-01-30 00:08 - 2017-01-30 00:08 - 03117001 _____ C:\Users\Odye\Downloads\AT O2016 PN.rar 2017-01-29 22:26 - 2017-02-09 12:11 - 00000000 ____D C:\Users\Odye\Documents\Office 2016 32 e 64 2017-01-28 21:27 - 2017-02-09 12:11 - 00000000 ____D C:\Users\Odye\Desktop\Office 2016 Online 2017-01-28 21:26 - 2017-01-28 21:26 - 62024136 _____ C:\Users\Odye\Downloads\Office 2016 Online.rar 2017-01-26 15:18 - 2016-12-21 04:43 - 04130440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2017-01-26 15:18 - 2016-12-21 04:42 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2017-01-26 15:18 - 2016-12-21 04:06 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2017-01-26 15:18 - 2016-12-21 01:40 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll 2017-01-26 15:18 - 2016-12-21 01:40 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe 2017-01-26 15:18 - 2016-12-21 01:39 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe 2017-01-26 15:18 - 2016-12-21 01:22 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll 2017-01-26 15:18 - 2016-12-14 01:48 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll 2017-01-26 15:18 - 2016-12-14 01:38 - 17188864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll 2017-01-26 15:17 - 2016-12-21 05:08 - 00245600 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll 2017-01-26 15:17 - 2016-12-21 05:08 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll 2017-01-26 15:17 - 2016-12-21 04:49 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll 2017-01-26 15:17 - 2016-12-21 04:46 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2017-01-26 15:17 - 2016-12-21 04:43 - 01454504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll 2017-01-26 15:17 - 2016-12-21 04:43 - 01071736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll 2017-01-26 15:17 - 2016-12-21 04:43 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2017-01-26 15:17 - 2016-12-21 04:42 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll 2017-01-26 15:17 - 2016-12-21 04:42 - 01702392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2017-01-26 15:17 - 2016-12-21 04:42 - 01300600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2017-01-26 15:17 - 2016-12-21 04:41 - 01600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll 2017-01-26 15:17 - 2016-12-21 04:15 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2017-01-26 15:17 - 2016-12-21 04:14 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe 2017-01-26 15:17 - 2016-12-21 04:09 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll 2017-01-26 15:17 - 2016-12-21 04:08 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll 2017-01-26 15:17 - 2016-12-21 04:08 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll 2017-01-26 15:17 - 2016-12-21 04:08 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe 2017-01-26 15:17 - 2016-12-21 04:07 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll 2017-01-26 15:17 - 2016-12-21 04:06 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe 2017-01-26 15:17 - 2016-12-21 04:05 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll 2017-01-26 15:17 - 2016-12-21 04:05 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll 2017-01-26 15:17 - 2016-12-21 04:05 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll 2017-01-26 15:17 - 2016-12-21 04:01 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2017-01-26 15:17 - 2016-12-21 03:59 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll 2017-01-26 15:17 - 2016-12-21 03:59 - 00883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll 2017-01-26 15:17 - 2016-12-21 03:58 - 23678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2017-01-26 15:17 - 2016-12-21 03:56 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll 2017-01-26 15:17 - 2016-12-21 03:56 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll 2017-01-26 15:17 - 2016-12-21 03:55 - 08129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2017-01-26 15:17 - 2016-12-21 03:55 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2017-01-26 15:17 - 2016-12-21 03:54 - 05511680 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll 2017-01-26 15:17 - 2016-12-21 03:53 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe 2017-01-26 15:17 - 2016-12-21 03:53 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll 2017-01-26 15:17 - 2016-12-21 03:51 - 08075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll 2017-01-26 15:17 - 2016-12-21 03:51 - 05611008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2017-01-26 15:17 - 2016-12-21 03:50 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2017-01-26 15:17 - 2016-12-21 03:49 - 04149248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2017-01-26 15:17 - 2016-12-21 03:49 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2017-01-26 15:17 - 2016-12-21 03:49 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2017-01-26 15:17 - 2016-12-21 03:47 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll 2017-01-26 15:17 - 2016-12-21 02:59 - 00218976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll 2017-01-26 15:17 - 2016-12-21 02:09 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll 2017-01-26 15:17 - 2016-12-21 02:02 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2017-01-26 15:17 - 2016-12-21 02:02 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2017-01-26 15:17 - 2016-12-21 02:02 - 01360464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll 2017-01-26 15:17 - 2016-12-21 02:01 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll 2017-01-26 15:17 - 2016-12-21 01:46 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe 2017-01-26 15:17 - 2016-12-21 01:43 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll 2017-01-26 15:17 - 2016-12-21 01:41 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll 2017-01-26 15:17 - 2016-12-21 01:41 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2017-01-26 15:17 - 2016-12-21 01:40 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll 2017-01-26 15:17 - 2016-12-21 01:40 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll 2017-01-26 15:17 - 2016-12-21 01:39 - 01300480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll 2017-01-26 15:17 - 2016-12-21 01:38 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll 2017-01-26 15:17 - 2016-12-21 01:35 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2017-01-26 15:17 - 2016-12-21 01:35 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll 2017-01-26 15:17 - 2016-12-21 01:34 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2017-01-26 15:17 - 2016-12-21 01:33 - 19413504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2017-01-26 15:17 - 2016-12-21 01:32 - 19417600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2017-01-26 15:17 - 2016-12-21 01:30 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll 2017-01-26 15:17 - 2016-12-21 01:30 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll 2017-01-26 15:17 - 2016-12-21 01:26 - 01155072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll 2017-01-26 15:17 - 2016-12-21 01:25 - 07469056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll 2017-01-26 15:17 - 2016-12-21 01:25 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe 2017-01-26 15:17 - 2016-12-21 01:24 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2017-01-26 15:17 - 2016-12-14 02:41 - 01235296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2017-01-26 15:17 - 2016-12-14 02:41 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2017-01-26 15:17 - 2016-12-14 02:34 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2017-01-26 15:17 - 2016-12-14 02:33 - 01356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2017-01-26 15:17 - 2016-12-14 02:23 - 00404832 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll 2017-01-26 15:17 - 2016-12-14 02:21 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2017-01-26 15:17 - 2016-12-14 02:19 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe 2017-01-26 15:17 - 2016-12-14 02:17 - 00319288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll 2017-01-26 15:17 - 2016-12-14 02:14 - 01694712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll 2017-01-26 15:17 - 2016-12-14 02:14 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2017-01-26 15:17 - 2016-12-14 02:01 - 01557808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll 2017-01-26 15:17 - 2016-12-14 02:01 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2017-01-26 15:17 - 2016-12-14 02:01 - 00076984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll 2017-01-26 15:17 - 2016-12-14 01:46 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll 2017-01-26 15:17 - 2016-12-14 01:46 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2017-01-26 15:17 - 2016-12-14 01:43 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScDeviceEnum.dll 2017-01-26 15:17 - 2016-12-14 01:42 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll 2017-01-26 15:17 - 2016-12-14 01:42 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll 2017-01-26 15:17 - 2016-12-14 01:42 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSCard.dll 2017-01-26 15:17 - 2016-12-14 01:41 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2017-01-26 15:17 - 2016-12-14 01:40 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll 2017-01-26 15:17 - 2016-12-14 01:40 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll 2017-01-26 15:17 - 2016-12-14 01:40 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll 2017-01-26 15:17 - 2016-12-14 01:39 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll 2017-01-26 15:17 - 2016-12-14 01:38 - 13869056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll 2017-01-26 15:17 - 2016-12-14 01:38 - 00213504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll 2017-01-26 15:17 - 2016-12-14 01:37 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll 2017-01-26 15:17 - 2016-12-14 01:36 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll 2017-01-26 15:17 - 2016-12-14 01:36 - 00539648 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2017-01-26 15:17 - 2016-12-14 01:36 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll 2017-01-26 15:17 - 2016-12-14 01:35 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2017-01-26 15:17 - 2016-12-14 01:35 - 00600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll 2017-01-26 15:17 - 2016-12-14 01:35 - 00553984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll 2017-01-26 15:17 - 2016-12-14 01:32 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll 2017-01-26 15:17 - 2016-12-14 01:26 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2017-01-26 15:17 - 2016-12-14 01:26 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2017-01-26 15:17 - 2016-12-14 01:25 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll 2017-01-26 15:17 - 2016-12-14 01:24 - 01005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll 2017-01-26 15:17 - 2016-12-14 01:24 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2017-01-26 15:17 - 2016-12-14 01:23 - 03134976 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll 2017-01-26 15:17 - 2016-12-14 01:23 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll 2017-01-26 15:17 - 2016-12-14 01:22 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll 2017-01-26 15:17 - 2016-12-14 01:22 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2017-01-26 15:17 - 2016-12-14 01:22 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2017-01-26 15:17 - 2016-12-14 01:22 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2017-01-26 15:17 - 2016-12-14 01:21 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2017-01-26 15:17 - 2016-11-02 09:01 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2017-01-26 15:17 - 2016-11-02 08:00 - 00534096 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2017-01-26 15:17 - 2016-11-02 07:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll 2017-01-26 15:17 - 2016-11-02 07:22 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2017-01-26 15:17 - 2016-11-02 07:21 - 00942080 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2017-01-26 15:17 - 2016-08-02 01:30 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll 2017-01-26 15:16 - 2016-12-21 05:04 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2017-01-26 15:16 - 2016-12-21 04:42 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll 2017-01-26 15:16 - 2016-12-21 04:37 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe 2017-01-26 15:16 - 2016-12-21 04:13 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll 2017-01-26 15:16 - 2016-12-21 04:12 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll 2017-01-26 15:16 - 2016-12-21 04:10 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll 2017-01-26 15:16 - 2016-12-21 04:09 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll 2017-01-26 15:16 - 2016-12-21 04:08 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll 2017-01-26 15:16 - 2016-12-21 04:08 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll 2017-01-26 15:16 - 2016-12-21 04:08 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll 2017-01-26 15:16 - 2016-12-21 04:06 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll 2017-01-26 15:16 - 2016-12-21 04:06 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll 2017-01-26 15:16 - 2016-12-21 04:00 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll 2017-01-26 15:16 - 2016-12-21 03:57 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll 2017-01-26 15:16 - 2016-12-21 03:53 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2017-01-26 15:16 - 2016-12-21 03:51 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2017-01-26 15:16 - 2016-12-21 02:02 - 01277344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2017-01-26 15:16 - 2016-12-21 02:02 - 01201872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2017-01-26 15:16 - 2016-12-21 02:02 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll 2017-01-26 15:16 - 2016-12-21 01:27 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll 2017-01-26 15:16 - 2016-12-21 01:24 - 05061120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2017-01-26 15:16 - 2016-12-21 01:24 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll 2017-01-26 15:16 - 2016-12-21 01:24 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll 2017-01-26 15:16 - 2016-12-21 01:22 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2017-01-26 15:16 - 2016-12-14 02:18 - 00715104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2017-01-26 15:16 - 2016-12-14 02:18 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys 2017-01-26 15:16 - 2016-12-14 02:14 - 00089416 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll 2017-01-26 15:16 - 2016-12-14 02:08 - 00341344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll 2017-01-26 15:16 - 2016-12-14 02:06 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe 2017-01-26 15:16 - 2016-12-14 01:45 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys 2017-01-26 15:16 - 2016-12-14 01:42 - 00352768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll 2017-01-26 15:16 - 2016-12-14 01:40 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll 2017-01-26 15:16 - 2016-12-14 01:40 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll 2017-01-26 15:16 - 2016-12-14 01:39 - 00837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll 2017-01-26 15:16 - 2016-12-14 01:39 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll 2017-01-26 15:16 - 2016-12-14 01:38 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll 2017-01-26 15:16 - 2016-12-14 01:35 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2017-01-26 15:16 - 2016-12-14 01:32 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll 2017-01-26 15:16 - 2016-12-14 01:22 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2017-01-26 15:16 - 2016-12-14 01:22 - 00707584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll 2017-01-23 14:41 - 2017-01-23 14:41 - 02751791 _____ C:\Users\Odye\Documents\Marcos.mp4 2017-01-23 14:39 - 2017-01-23 14:39 - 00441961 _____ C:\Users\Odye\Documents\Ivan1.mp4 2017-01-22 17:12 - 2017-01-26 13:18 - 00000000 ____D C:\Users\Odye\AppData\LocalLow\uTorrent 2017-01-16 16:00 - 2017-01-16 16:00 - 00096604 _____ C:\Users\Odye\Documents\Creche.zip 2017-01-16 13:10 - 2017-01-16 13:10 - 00175322 _____ C:\Users\Odye\Documents\Candeias.zip 2017-01-14 20:58 - 2017-01-14 20:58 - 03367676 _____ C:\Users\Odye\Documents\WhatsApp Video 2017-01-14 at 19.25.13.mp4 2017-01-14 20:00 - 2017-01-14 20:01 - 00252084 _____ C:\Users\Odye\Downloads\FaturaHipercard-12-2016.pdf 2017-01-13 10:20 - 2017-01-13 10:27 - 00000000 ____D C:\Users\Odye\Documents\Candeias 2017-01-13 10:20 - 2017-01-13 10:27 - 00000000 ____D C:\Users\Odye\Desktop\Candeias ==================== Um Mês Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2017-02-10 11:40 - 2016-04-21 19:32 - 00000000 __SHD C:\Users\Odye\IntelGraphicsProfiles 2017-02-09 22:24 - 2016-11-14 20:09 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-02-09 14:53 - 2016-04-21 19:36 - 00000000 ___RD C:\Users\Odye\OneDrive 2017-02-09 13:36 - 2016-07-16 03:04 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2017-02-09 13:33 - 2016-07-16 03:04 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe ==================== Arquivos na raiz de alguns diretórios ======= 2017-02-09 14:18 - 2017-02-09 14:18 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap ====================== (Não há correção automática para arquivos que não passaram na verificação.) C:\WINDOWS\system32\winlogon.exe => O arquivo é assinado digitalmente C:\WINDOWS\system32\wininit.exe => O arquivo é assinado digitalmente C:\WINDOWS\explorer.exe => O arquivo é assinado digitalmente C:\WINDOWS\SysWOW64\explorer.exe => O arquivo é assinado digitalmente C:\WINDOWS\system32\svchost.exe => O arquivo é assinado digitalmente C:\WINDOWS\SysWOW64\svchost.exe => O arquivo é assinado digitalmente C:\WINDOWS\system32\services.exe => O arquivo é assinado digitalmente C:\WINDOWS\system32\User32.dll => O arquivo é assinado digitalmente C:\WINDOWS\SysWOW64\User32.dll => O arquivo é assinado digitalmente C:\WINDOWS\system32\userinit.exe => O arquivo é assinado digitalmente C:\WINDOWS\SysWOW64\userinit.exe => O arquivo é assinado digitalmente C:\WINDOWS\system32\rpcss.dll => O arquivo é assinado digitalmente C:\WINDOWS\system32\dnsapi.dll => O arquivo é assinado digitalmente C:\WINDOWS\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente C:\WINDOWS\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente LastRegBack: 2017-02-09 14:12 ==================== Fim de FRST.txt ============================