Resultado do exame da Farbar Recovery Scan Tool (FRST) (x86) Versão: 12-02-2017 Executado por Computador (administrador) em COMPUTADOR-PC (12-02-2017 20:57:39) Executando a partir de C:\Users\Computador\Downloads Perfis Carregados: Computador (Perfis Disponíveis: Computador) Platform: Microsoft Windows 7 Ultimate (X86) Idioma: Português (Brasil) Internet Explorer Versão 9 (Navegador padrão: Chrome) Modo da Inicialização: Normal Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (GAS Tecnologia) C:\Program Files\GbPlugin\gbpsv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avguard.exe () C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe (GAS Tecnologia LTDA) C:\Program Files\Diebold\Warsaw\core.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe (Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (GAS Tecnologia) C:\Program Files\GbPlugin\gbpsv.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avshadow.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Antivirus\avgnt.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\RPDS\Bin\rpsystray.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (RealNetworks, Inc.) C:\Program Files\Real\RealDownloader\realupgrade.exe () C:\Program Files\Real\RealDownloader\downloader2.exe (Oracle Corporation) C:\Program Files\Java\jre1.8.0_111\bin\javaw.exe (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.) C:\Program Files\Real\RealDownloader\recordingmanager.exe (CopySpider Software ) C:\Users\Computador\Downloads\copyspider-setup.exe () C:\Users\Computador\AppData\Local\Temp\is-J63TC.tmp\copyspider-setup.tmp (CopySpider Software ) C:\Users\Computador\Downloads\copyspider-setup.exe () C:\Users\Computador\AppData\Local\Temp\is-61S3I.tmp\copyspider-setup.tmp (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\LogonUI.exe (Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe ==================== Registro (Whitelisted) ==================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\Antivirus\avgnt.exe [917576 2016-12-06] (Avira Operations GmbH & Co. KG) Winlogon\Notify\ GbPluginBb: C:\Program Files\GbPlugin\gbieh.dll [2016-09-28] (Banco do Brasil) HKU\S-1-5-21-2531994756-4072431436-2826721706-1000\...\MountPoints2: {5d877445-5c74-11e5-b6d8-0024e8927386} - F:\Setup.exe HKU\S-1-5-21-2531994756-4072431436-2826721706-1000\...\MountPoints2: {7b4885c5-881a-11e6-b36d-c982904b7125} - F:\setup.exe HKU\S-1-5-21-2531994756-4072431436-2826721706-1000\...\MountPoints2: {a22b0c98-18b5-11e6-a1b0-ba34d8e06ac6} - F:\LGAutoRun.exe ShellExecuteHooks: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399F83} - C:\PROGRAM FILES\GbPlugin\gbieh.dll [1947872 2016-09-28] (Banco do Brasil) ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => -> Nenhum Arquivo ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => -> Nenhum Arquivo ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => -> Nenhum Arquivo ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => -> Nenhum Arquivo ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => -> Nenhum Arquivo ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => -> Nenhum Arquivo ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => -> Nenhum Arquivo ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => -> Nenhum Arquivo ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Nenhum Arquivo ShellIconOverlayIdentifiers: [BaiduAntivirusIconLock] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CC} => -> Nenhum Arquivo Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealTimes.lnk [2017-01-08] ShortcutTarget: RealTimes.lnk -> C:\Program Files\Real\RealPlayer\RPDS\Bin\rpsystray.exe (RealNetworks, Inc.) GroupPolicy: Restrição ? <======= ATENÇÃO CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Hosts: Há mais de uma entrada no Hosts. Veja a seção Hosts do Addition.txt Tcpip\Parameters: [DhcpNameServer] 187.17.52.1 187.17.52.2 8.8.8.8 Tcpip\..\Interfaces\{AAC37604-4493-42BE-809B-135C9473DD91}: [DhcpNameServer] 187.17.52.1 187.17.52.2 8.8.8.8 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-2531994756-4072431436-2826721706-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://br.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_bxinw_16_40¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtByCyD0EtDzy0CzzyC0B0A0Czz0AtN0D0Tzu0StCyBtAyDtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1ByDtN1L1G1B1V1N2Y1L1Qzu2SyDtB0CtByE0FyD0CtGtDtD0D0AtGyB0CzzzytGtD0B0AzytGyEtDtB0CyCyE0CzytAtB0D0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtA0FtDzztAzy0BtGyDyD0AyDtGyEyDtB0AtG0ByDtDyCtGyB0Azy0C0EyB0AtBzytBtCyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEtDzz%26cr%3D2077998756%26a%3Dwbf_bxinw_16_40%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate SearchScopes: HKLM -> DefaultScope valor está ausente SearchScopes: HKLM -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxps://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-4b01449e&q={searchTerms} SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_bxinw_16_40¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtByCyD0EtDzy0CzzyC0B0A0Czz0AtN0D0Tzu0StCyBtAyDtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1ByDtN1L1G1B1V1N2Y1L1Qzu2SyDtB0CtByE0FyD0CtGtDtD0D0AtGyB0CzzzytGtD0B0AzytGyEtDtB0CyCyE0CzytAtB0D0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtA0FtDzztAzy0BtGyDyD0AyDtGyEyDtB0AtG0ByDtDyCtGyB0Azy0C0EyB0AtBzytBtCyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEtDzz%26cr%3D2077998756%26a%3Dwbf_bxinw_16_40%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms} SearchScopes: HKLM -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_17_06_mnn_ir_17_01¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutDtDtByCyD0EtDzy0CzzyC0B0A0Czz0AtN0D0Tzu0StCzzyCyDtN1L2XzutAtFtByCtFyEtFyDtBtN1L1Czu1M1Q1CtAtCtFtCyEtFtDtN1L1G1B1V1N2Y1L1Qzu2StD0EzzzyyBtC0DtCtGtC0BtCyBtGtB0AtA0DtGyEyD0A0FtGyCtByByBtBtB0FyBtD0EyD0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtA0FtDzztAzy0BtGyDyD0AyDtGyEyDtB0AtG0ByDtDyCtGyB0Azy0C0EyB0AtBzytBtCyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCzytByB%26cr%3D1747432301%26a%3Dhdr_s_17_06_mnn_ir_17_01%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms} SearchScopes: HKU\S-1-5-21-2531994756-4072431436-2826721706-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2531994756-4072431436-2826721706-1000 -> {26080cad-4adc-49ac-8c63-eda16e595cbd} URL = hxxps://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-4b01449e&q={searchTerms} SearchScopes: HKU\S-1-5-21-2531994756-4072431436-2826721706-1000 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_bxinw_16_40¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtByCyD0EtDzy0CzzyC0B0A0Czz0AtN0D0Tzu0StCyBtAyDtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1ByDtN1L1G1B1V1N2Y1L1Qzu2SyDtB0CtByE0FyD0CtGtDtD0D0AtGyB0CzzzytGtD0B0AzytGyEtDtB0CyCyE0CzytAtB0D0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtA0FtDzztAzy0BtGyDyD0AyDtGyEyDtB0AtG0ByDtDyCtGyB0Azy0C0EyB0AtBzytBtCyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEtDzz%26cr%3D2077998756%26a%3Dwbf_bxinw_16_40%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms} SearchScopes: HKU\S-1-5-21-2531994756-4072431436-2826721706-1000 -> {94AABAF0-CFF6-4A31-8AE0-9F207EE164FB} URL = hxxps://br.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default SearchScopes: HKU\S-1-5-21-2531994756-4072431436-2826721706-1000 -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=elm&hsimp=yhs-001&type=hdr_s_17_06_mnn_ir_17_01¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1QzutDtDtByCyD0EtDzy0CzzyC0B0A0Czz0AtN0D0Tzu0StCzzyCyDtN1L2XzutAtFtByCtFyEtFyDtBtN1L1Czu1M1Q1CtAtCtFtCyEtFtDtN1L1G1B1V1N2Y1L1Qzu2StD0EzzzyyBtC0DtCtGtC0BtCyBtGtB0AtA0DtGyEyD0A0FtGyCtByByBtBtB0FyBtD0EyD0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtA0FtDzztAzy0BtGyDyD0AyDtGyEyDtB0AtG0ByDtDyCtGyB0Azy0C0EyB0AtBzytBtCyC2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtCzytByB%26cr%3D1747432301%26a%3Dhdr_s_17_06_mnn_ir_17_01%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms} BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files\Real\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2016-11-11] (RealDownloader) BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-12-23] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation) BHO: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540000} -> C:\PROGRAM FILES\GBPLUGIN\gbieh.dll [2016-09-28] (Banco do Brasil) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-12-23] (Oracle Corporation) DPF: {CAFEEFAC-0018-0000-0051-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_51-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinstall-1_8_0_51-windows-i586.cab Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Computador\AppData\Roaming\Mozilla\Firefox\Profiles\lPGrmy98.default [2017-02-12] FF DefaultSearchEngine: Mozilla\Firefox\Profiles\lPGrmy98.default -> Yahoo! Powered FF SelectedSearchEngine: Mozilla\Firefox\Profiles\lPGrmy98.default -> Yahoo! Powered FF Homepage: Mozilla\Firefox\Profiles\lPGrmy98.default -> hxxps://www.bing.com/search?FORM=INCOH1&PC=IC04&PTAG=ICO-4b01449e FF Keyword.URL: Mozilla\Firefox\Profiles\lPGrmy98.default -> user_pref("keyword.URL", true); FF Extension: (Avira Browser Safety) - C:\Users\Computador\AppData\Roaming\Mozilla\Firefox\Profiles\lPGrmy98.default\Extensions\abs@avira.com.xpi [2017-02-11] FF Extension: (SEOquake) - C:\Users\Computador\AppData\Roaming\Mozilla\Firefox\Profiles\lPGrmy98.default\Extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}.xpi [2017-01-17] FF Extension: (Video DownloadHelper) - C:\Users\Computador\AppData\Roaming\Mozilla\Firefox\Profiles\lPGrmy98.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2017-01-07] FF SearchPlugin: C:\Users\Computador\AppData\Roaming\Mozilla\Firefox\Profiles\lPGrmy98.default\searchplugins\yahoo! powered.xml [2016-10-01] FF HKU\S-1-5-21-2531994756-4072431436-2826721706-1000\...\Firefox\Extensions: [{87F8774F-B485-47E2-A755-A40A8A5E886C}] - C:\Users\Computador\AppData\Local\GAS Tecnologia\GBBD\bb\xpi => não encontrado (a) FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-12-23] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-12-23] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [Nenhum Arquivo] FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation) FF Plugin: @real.com/nppl3260;version=18.1.6.161 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2017-01-08] (RealNetworks, Inc.) FF Plugin: @real.com/nprpplugin;version=18.1.6.161 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpplugin.dll [2017-01-08] (RealPlayer) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2012-10-01] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2016-12-17] (Adobe Systems Inc.) StartMenuInternet: FIREFOX.EXE - firefox.exe Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxp://www.search.ask.com/?gct=hp CHR StartupUrls: Default -> "hxxp://www.google.com.br/" CHR DefaultSearchURL: Default -> hxxp://www.search.ask.com/web?q={searchTerms} CHR DefaultSearchKeyword: Default -> search.ask.com CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li=ff&q={searchTerms} CHR Profile: C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Default [2017-02-12] CHR Extension: (SEOquake) - C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Default\Extensions\akdgnmcogleenhbclghghlkkdndkjdjc [2017-01-12] CHR Extension: (Search Manager) - C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Default\Extensions\bahkljhhdeciiaodlkppoonappfnheoi [2017-02-04] CHR Extension: (TVPlusNewtab) - C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfdhgilbkpomgbinopjomfjooamjgeef [2016-11-15] CHR Extension: (SEO Site Tools, Site Analysis) - C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Default\Extensions\femogmcmjpjkokoojcljkpfdifkpbbpp [2017-01-24] CHR Extension: (Segurança do navegador Avira) - C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-09-21] CHR Extension: (Seen On Screen) - C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbnedkgemidblchdmcaikjjlppklpiep [2016-11-15] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-18] CHR Extension: (Seen On Screen) - C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Default\Extensions\oioaodifhhhfoijgdnpdfehmmkhjnjml [2016-10-26] CHR Extension: (Chrome Media Router) - C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-09] CHR Extension: (TV Hero) - C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmbigmnnjhhimblppkcabpnjmibphfmg [2016-11-01] CHR Extension: (Screen Addict) - C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Default\Extensions\poiapofmfcplmniafohaldhfddbacheo [2016-11-01] CHR Profile: C:\Users\Computador\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-01-03] CHR HKLM\...\Chrome\Extension: [ehlceeijggpdgfcefmipcmdelickjgfg] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [kpdmjodecdegfglgaapafjleomjjlpnh] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [npdicihegicnhaangkdmcgbjceoemeoo] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-2531994756-4072431436-2826721706-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ehlceeijggpdgfcefmipcmdelickjgfg] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-2531994756-4072431436-2826721706-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx ==================== Serviços (Whitelisted) ==================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) "Warsaw Technology" => serviço foi desbloqueado. <===== ATENÇÃO S2 AntiVirMailService; C:\Program Files\Avira\Antivirus\avmailc7.exe [1089592 2016-12-06] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\Antivirus\sched.exe [476736 2016-12-06] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\Antivirus\avguard.exe [476736 2016-12-06] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\Antivirus\avwebg7.exe [1490296 2016-12-06] (Avira Operations GmbH & Co. KG) R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [372272 2016-12-29] (Avira Operations GmbH & Co. KG) R2 GbpSv; C:\Program Files\GbPlugin\gbpsv.exe [631520 2016-09-28] (GAS Tecnologia) R2 RealPlayerUpdateSvc; C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe [35104 2016-11-11] () R2 RealTimes Desktop Service; C:\Program Files\Real\RealPlayer\RPDS\Bin\rpdsvc.exe [987408 2017-01-08] (RealNetworks, Inc.) R2 Warsaw Technology; C:\Program Files\Diebold\Warsaw\core.exe [792624 2016-11-11] (GAS Tecnologia LTDA) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R3 acpials; C:\Windows\System32\DRIVERS\acpials.sys [7680 2009-07-13] (Microsoft Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119208 2016-12-06] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [140840 2016-12-06] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37896 2016-12-06] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [60088 2016-12-06] (Avira Operations GmbH & Co. KG) R0 avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [30672 2016-12-06] (Avira Operations GmbH & Co. KG) R0 GbpKm; C:\Windows\System32\drivers\gbpkm.sys [49496 2015-08-26] (GAS Tecnologia) R1 ndisrd; C:\Windows\System32\DRIVERS\gbpndisrdn.sys [29400 2015-11-29] (GAS Tecnologia) R1 wsddfac; C:\Windows\System32\drivers\wsddfac.sys [22744 2017-02-09] (GAS Tecnologia) R1 wsddntf; C:\Windows\System32\DRIVERS\wsddntf.sys [31864 2016-11-11] (GAS Tecnologia) R1 wsddpp; C:\Windows\system32\drivers\wsddpp.sys [22624 2016-11-11] (GAS Tecnologia) R3 wsddprm; C:\Windows\system32\drivers\wsddprm.sys [22624 2016-11-11] (GAS Tecnologia) U0 aswVmm; não ImagePath S3 CT_QUALCOMM_U_drv; system32\DRIVERS\CT_QUALCOMM_U_drv.sys [X] S0 gbpddreg; system32\drivers\gbpddreg32.sys [X] ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Três Meses Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2017-02-12 20:57 - 2017-02-12 20:58 - 00022379 _____ C:\Users\Computador\Downloads\FRST.txt 2017-02-12 20:56 - 2017-02-12 20:57 - 00000000 ____D C:\FRST 2017-02-12 20:47 - 2017-02-12 20:47 - 01763328 _____ (Farbar) C:\Users\Computador\Downloads\FRST.exe 2017-02-12 17:58 - 2017-02-12 18:00 - 27169484 _____ (CopySpider Software ) C:\Users\Computador\Downloads\CopySpider-Setup-v1.2.0.exe 2017-02-12 10:32 - 2017-02-12 10:32 - 00000000 ____D C:\Users\Computador\AppData\Local\{A21FEE26-02C6-4E7F-BAB1-54141B66ABE2} 2017-02-12 10:00 - 2017-02-12 10:00 - 00036546 _____ C:\Users\Computador\Downloads\online (1).html 2017-02-12 09:59 - 2017-02-12 09:59 - 00036546 _____ C:\Users\Computador\Downloads\online.html 2017-02-11 13:51 - 2017-02-11 13:51 - 00157617 _____ C:\Users\Computador\Desktop\RESERVA DE ITA.pdf 2017-02-11 13:44 - 2017-02-11 13:44 - 00192732 _____ C:\Users\Computador\Downloads\Cartão de Embarque - GOL-ita.pdf 2017-02-11 12:59 - 2017-02-11 12:59 - 00139453 _____ C:\Users\Computador\Desktop\4125-15656-1-PB.pdf 2017-02-11 12:28 - 2017-02-11 12:28 - 00160434 _____ C:\Users\Computador\Desktop\12-LuizGMarinoni.pdf 2017-02-11 11:58 - 2017-02-11 11:58 - 11337116 _____ C:\Users\Computador\Desktop\situação juridica.pdf 2017-02-11 11:24 - 2017-02-11 11:24 - 01898504 _____ C:\Users\Computador\Downloads\Apostila LFG - Direito Processual Civil.pdf 2017-02-08 07:28 - 2017-02-08 07:28 - 00193377 _____ C:\Users\Computador\Desktop\Cartão de embarque 2 - GOL- ita.pdf 2017-02-08 07:25 - 2017-02-08 07:25 - 00192732 _____ C:\Users\Computador\Desktop\Cartão de Embarque - GOL-ita.pdf 2017-02-08 07:15 - 2017-02-12 20:15 - 00000286 _____ C:\Windows\Tasks\{40329473-3A59-783A-486C-337DC4BAA971}.job 2017-02-08 07:14 - 2017-02-08 07:15 - 00000000 ____D C:\Users\Computador\AppData\Local\{8CE3BABF-A84B-D607-C5D3-F3EFE1BB0F77} 2017-02-08 06:01 - 2017-02-12 20:31 - 00000286 _____ C:\Windows\Tasks\{3C640506-924D-4B71-91A2-F2A31FC245F4}.job 2017-02-05 22:19 - 2017-02-05 22:19 - 00000000 ____D C:\Users\Computador\AppData\Local\{D5A758A6-6EA4-4517-A1D8-779B546545E8} 2017-02-05 20:51 - 2017-02-05 21:11 - 00000000 ____D C:\DIREITO ADMINISTRATIVO 2017-02-04 10:27 - 2017-02-04 10:27 - 00601317 _____ C:\Users\Computador\Desktop\exame da oab.pdf 2017-01-31 06:56 - 2017-01-31 06:56 - 00141829 _____ C:\Users\Computador\Desktop\boleto-pos-daniel1.pdf 2017-01-31 06:56 - 2017-01-31 06:56 - 00139646 _____ C:\Users\Computador\Desktop\boleto - pos - elizene1.pdf 2017-01-23 22:37 - 2017-01-23 22:37 - 00176529 _____ C:\Users\Computador\Downloads\Comunicado.pdf 2017-01-22 11:43 - 2017-01-22 11:43 - 06883827 _____ C:\Users\Computador\Desktop\História da Bahia_ final_ 18_06_13.pdf 2017-01-22 11:36 - 2017-01-22 11:41 - 09224197 _____ C:\Users\Computador\Downloads\bahia_1798.pdf 2017-01-20 09:51 - 2017-01-20 09:51 - 00125323 _____ C:\Users\Computador\Downloads\ELIZENE SILVA_MENSAL - PORTAL.pdf 2017-01-19 16:53 - 2017-01-19 16:53 - 00690080 _____ (Dropbox, Inc.) C:\Users\Computador\Downloads\DropboxInstaller.exe 2017-01-18 16:17 - 2017-01-18 16:17 - 00007605 _____ C:\Users\Computador\AppData\Local\Resmon.ResmonCfg 2017-01-17 18:07 - 2017-01-17 18:07 - 00000000 ____D C:\Windows\pss 2017-01-17 10:21 - 2017-01-17 10:21 - 00055145 _____ C:\Users\Computador\Desktop\historico-Elizene.pdf 2017-01-17 10:20 - 2017-01-17 10:20 - 00040762 _____ C:\Users\Computador\Desktop\comprovante de matricula Elizene.pdf 2017-01-17 10:17 - 2017-01-17 10:17 - 00057986 _____ C:\Users\Computador\Desktop\historico-Daniel.pdf 2017-01-17 10:15 - 2017-01-17 10:15 - 00041086 _____ C:\Users\Computador\Desktop\comprovante de matricula.pdf 2017-01-16 11:16 - 2016-12-06 17:04 - 00018760 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\ssmdrv.sys 2017-01-16 11:15 - 2016-12-06 17:04 - 00030672 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avusbflt.sys 2017-01-16 11:15 - 2016-12-06 17:03 - 00140840 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2017-01-16 11:15 - 2016-12-06 17:03 - 00119208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2017-01-16 11:15 - 2016-12-06 17:03 - 00060088 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2017-01-16 11:15 - 2016-12-06 17:03 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2017-01-16 10:03 - 2017-01-16 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2017-01-16 10:03 - 2017-01-16 10:03 - 00001170 _____ C:\Users\Public\Desktop\Avira Connect.lnk 2017-01-16 10:01 - 2017-01-16 11:15 - 00000000 ____D C:\Users\Todos os Usuários\Avira 2017-01-16 10:01 - 2017-01-16 11:15 - 00000000 ____D C:\ProgramData\Avira 2017-01-16 10:01 - 2017-01-16 11:15 - 00000000 ____D C:\Program Files\Avira 2017-01-16 09:54 - 2017-01-16 09:56 - 04581024 _____ (Avira Operations GmbH & Co. KG) C:\Users\Computador\Downloads\avira_ptbr_av_587cc27989e43__ws.exe 2017-01-14 17:47 - 2017-01-14 17:47 - 00015305 _____ C:\Users\Computador\Downloads\BilheteEletrônico_5408665401 (1).pdf 2017-01-14 07:11 - 2017-01-14 07:11 - 00000969 _____ C:\Users\Public\Desktop\CCleaner.lnk 2017-01-14 07:11 - 2017-01-14 07:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2017-01-14 07:10 - 2017-01-14 07:11 - 00000000 ____D C:\Program Files\CCleaner 2017-01-14 07:03 - 2017-01-14 07:09 - 08803648 _____ (Piriform Ltd) C:\Users\Computador\Downloads\ccsetup525.exe 2017-01-12 12:09 - 2017-01-12 12:09 - 00433694 _____ C:\Users\Computador\Downloads\Procuração BA.pdf 2017-01-12 12:09 - 2017-01-12 12:09 - 00192748 _____ C:\Users\Computador\Downloads\900364763.pdf 2017-01-11 20:47 - 2017-01-11 20:47 - 00000000 ____D C:\Users\Usuário Padrão\AppData\Roaming\RealNetworks 2017-01-11 20:47 - 2017-01-11 20:47 - 00000000 ____D C:\Users\Default\AppData\Roaming\RealNetworks 2017-01-11 20:47 - 2017-01-11 20:47 - 00000000 ____D C:\Users\Default User\AppData\Roaming\RealNetworks 2017-01-10 17:23 - 2017-01-10 17:23 - 00115305 _____ C:\Users\Computador\Downloads\Adverbio preposição e conjunção.pdf 2017-01-10 17:19 - 2017-01-10 17:19 - 00298438 _____ C:\Users\Computador\Downloads\Aula 08 - Preposição e Conjunção.pdf 2017-01-09 09:34 - 2017-01-09 09:34 - 00002079 _____ C:\Users\Computador\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton Product Installer.lnk 2017-01-09 09:34 - 2017-01-09 09:34 - 00002071 _____ C:\Users\Computador\Desktop\Norton Product Installer.lnk 2017-01-08 20:51 - 2017-01-08 20:51 - 00001415 _____ C:\Users\Public\Desktop\Norton Security Scan.LNK 2017-01-08 20:51 - 2017-01-08 20:51 - 00000000 ____D C:\Windows\system32\Drivers\NSS 2017-01-08 20:51 - 2017-01-08 20:51 - 00000000 ____D C:\Users\Todos os Usuários\NortonInstaller 2017-01-08 20:51 - 2017-01-08 20:51 - 00000000 ____D C:\Users\Todos os Usuários\Norton 2017-01-08 20:51 - 2017-01-08 20:51 - 00000000 ____D C:\ProgramData\NortonInstaller 2017-01-08 20:51 - 2017-01-08 20:51 - 00000000 ____D C:\ProgramData\Norton 2017-01-08 20:51 - 2017-01-08 20:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security Scan 2017-01-08 20:51 - 2017-01-08 20:51 - 00000000 ____D C:\Program Files\NortonInstaller 2017-01-08 20:51 - 2017-01-08 20:51 - 00000000 ____D C:\Program Files\Norton Security Scan 2017-01-08 20:44 - 2017-01-08 20:44 - 00001188 _____ C:\Users\Public\Desktop\RealPlayer (RealTimes).lnk 2017-01-08 20:44 - 2017-01-08 20:44 - 00000000 ____D C:\Users\Computador\AppData\Roaming\RealNetworks 2017-01-08 20:43 - 2017-01-08 20:43 - 00000000 ____D C:\Users\Todos os Usuários\RealNetworks 2017-01-08 20:43 - 2017-01-08 20:43 - 00000000 ____D C:\ProgramData\RealNetworks 2017-01-08 20:40 - 2017-01-08 20:40 - 00207752 _____ (RealNetworks, Inc.) C:\Windows\system32\rmoc3260.dll 2017-01-08 20:40 - 2017-01-08 20:40 - 00000000 ____D C:\Program Files\Common Files\xing shared 2017-01-08 20:38 - 2017-01-08 20:38 - 00285576 _____ (Progressive Networks) C:\Windows\system32\pncrt.dll 2017-01-08 20:37 - 2017-01-08 20:37 - 00512392 _____ (Microsoft Corporation) C:\Windows\system32\msvcp71.dll 2017-01-08 20:37 - 2017-01-08 20:37 - 00360840 _____ (Microsoft Corporation) C:\Windows\system32\msvcr71.dll 2017-01-08 20:36 - 2017-02-12 09:08 - 00000568 ____H C:\Windows\Tasks\Norton Product InstallerIdle.job 2017-01-08 20:36 - 2017-01-08 20:36 - 00000000 ____D C:\Users\Computador\AppData\Local\Real 2017-01-08 15:14 - 2017-01-23 22:25 - 00000000 ____D C:\Users\Computador\Desktop\imprimir 2017-01-07 16:05 - 2017-01-07 16:05 - 00139240 _____ C:\Users\Computador\Desktop\Pacto são jose de costa rica.pdf 2017-01-07 16:01 - 2017-01-07 16:02 - 00050063 _____ C:\Users\Computador\Desktop\declaraçoa dos direitos humanos.pdf 2017-01-07 10:31 - 2017-01-07 10:32 - 00000000 ____D C:\Users\Computador\Downloads\direito tributario 2017-01-07 10:30 - 2017-01-07 10:30 - 00000000 ____D C:\Users\Computador\Downloads\processo civil 2017-01-07 10:27 - 2017-01-07 10:29 - 00000000 ____D C:\Users\Computador\Downloads\ingles fcc 2017-01-07 10:25 - 2017-01-07 10:26 - 00000000 ____D C:\Users\Computador\Downloads\raciocinio logico 2017-01-07 10:05 - 2017-02-12 19:04 - 00000000 ____D C:\Nova pasta 2017-01-07 09:37 - 2017-01-07 09:37 - 00015305 _____ C:\Users\Computador\Downloads\BilheteEletrônico_5408665401.pdf 2017-01-06 08:51 - 2017-01-06 08:51 - 00678387 _____ C:\Users\Computador\Downloads\79-303-1-PB.pdf 2017-01-03 07:32 - 2017-01-03 07:38 - 00000000 ____D C:\Users\Computador\Downloads\Windows_7_todas.as.versoes_x86_ou_x64_pt-BR 2017-01-03 07:21 - 2017-01-03 07:21 - 00002493 _____ C:\Users\Computador\Desktop\Windows 7 USB DVD Download Tool.lnk 2017-01-03 07:21 - 2017-01-03 07:21 - 00000000 ____D C:\Users\Computador\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool 2017-01-03 07:21 - 2017-01-03 07:21 - 00000000 ____D C:\Users\Computador\AppData\Local\Apps\Windows 7 USB DVD Download Tool 2017-01-03 07:17 - 2017-01-03 07:17 - 02721168 _____ (Microsoft Corporation) C:\Users\Computador\Downloads\Windows7-USB-DVD-Download-Tool-Installer-en-US.exe 2016-12-28 13:37 - 2016-12-28 14:09 - 00014268 _____ C:\Users\Computador\Desktop\RESUMO DE GEOGRAFIA- CFO.docx 2016-12-28 07:56 - 2017-02-12 08:50 - 00000000 ____D C:\Users\Todos os Usuários\{7CCAB9A9-F688-336F-704E-AD2DEA0C26E3} 2016-12-28 07:56 - 2017-02-12 08:50 - 00000000 ____D C:\ProgramData\{7CCAB9A9-F688-336F-704E-AD2DEA0C26E3} 2016-12-27 11:43 - 2016-12-27 11:43 - 00016980 _____ C:\Users\Computador\Desktop\LEI COMPLEMENTAR Nº 97 - MILITAR.docx 2016-12-27 11:19 - 2016-12-27 11:19 - 00011711 _____ C:\Users\Computador\Documents\PROTOCOLO - TIM.docx 2016-12-27 10:49 - 2016-11-11 14:37 - 00031864 _____ (GAS Tecnologia) C:\Windows\system32\Drivers\wsddntf.sys 2016-12-27 10:49 - 2016-11-11 14:37 - 00022624 ____N (GAS Tecnologia) C:\Windows\system32\Drivers\wsddprm.sys 2016-12-27 10:49 - 2016-11-11 14:37 - 00022624 ____N (GAS Tecnologia) C:\Windows\system32\Drivers\wsddpp.sys 2016-12-27 10:49 - 2016-11-11 14:37 - 00008811 _____ C:\Windows\system32\Drivers\wsddntf.cat 2016-12-27 10:49 - 2016-11-11 14:37 - 00002708 _____ C:\Windows\system32\Drivers\wsddntf.inf 2016-12-27 10:48 - 2017-02-09 11:41 - 00022744 _____ (GAS Tecnologia) C:\Windows\system32\Drivers\wsddfac.sys 2016-12-23 20:35 - 2016-12-23 20:35 - 00136601 _____ C:\Users\Computador\Desktop\boleto-pos-daniel.pdf 2016-12-23 20:29 - 2016-12-23 20:30 - 00135886 _____ C:\Users\Computador\Desktop\boleto - pos - elizene.pdf 2016-12-23 15:06 - 2016-12-23 15:06 - 00000000 ____D C:\Program Files\Common Files\Java 2016-12-23 14:39 - 2017-02-12 20:40 - 00000902 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-12-20 10:24 - 2016-12-20 10:24 - 00101559 _____ C:\Users\Computador\Downloads\artigo_sobre_crimes_propriamente_e_impropriamente_militares.pdf 2016-12-20 10:00 - 2017-02-11 09:45 - 00000000 ____D C:\Users\Computador\AppData\LocalLow\Mozilla 2016-12-20 07:50 - 2017-02-09 11:40 - 00000000 ____D C:\Program Files\Mozilla Firefox 2016-12-19 08:54 - 2016-12-19 08:54 - 00050026 _____ C:\Users\Computador\Desktop\LEI 8457- MILITAR.docx 2016-12-19 08:51 - 2016-12-19 08:51 - 00023537 _____ C:\Users\Computador\Desktop\LEI 8457- MILITAR.pdf 2016-12-18 15:56 - 2017-02-08 07:12 - 00000274 _____ C:\Users\Computador\AppData\Roaming\WB.CFG 2016-12-16 10:33 - 2016-12-16 10:33 - 01048576 ___SH C:\Windows\system32\config\COMPONENTS{83d26929-1345-11e5-9583-0024e8927386}.TxR.2.regtrans-ms 2016-12-16 10:33 - 2016-12-16 10:33 - 01048576 ___SH C:\Windows\system32\config\COMPONENTS{83d26929-1345-11e5-9583-0024e8927386}.TxR.1.regtrans-ms 2016-12-16 10:33 - 2016-12-16 10:33 - 01048576 ___SH C:\Windows\system32\config\COMPONENTS{83d26929-1345-11e5-9583-0024e8927386}.TxR.0.regtrans-ms 2016-12-16 10:33 - 2016-12-16 10:33 - 00065536 ___SH C:\Windows\system32\config\COMPONENTS{83d26929-1345-11e5-9583-0024e8927386}.TxR.blf 2016-12-16 10:30 - 2017-02-12 08:50 - 00000000 ____D C:\Users\Todos os Usuários\{9B625E01-1120-D4C7-97E6-4A850DA4C14B} 2016-12-16 10:30 - 2017-02-12 08:50 - 00000000 ____D C:\ProgramData\{9B625E01-1120-D4C7-97E6-4A850DA4C14B} 2016-12-16 10:29 - 2017-02-08 21:15 - 00000000 ____D C:\Users\Computador\AppData\Local\UpdateTask 2016-12-16 07:59 - 2016-12-27 14:05 - 00037597 _____ C:\Users\Computador\Desktop\Competência da polícia judiciária militar.docx 2016-12-16 07:59 - 2016-12-16 07:59 - 00012454 ____H C:\Users\Computador\Desktop\~WRL2525.tmp 2016-12-16 07:59 - 2016-12-16 07:59 - 00000162 ____H C:\Users\Computador\Desktop\~$mpetência da polícia judiciária militar.docx 2016-12-16 07:17 - 2016-12-16 07:18 - 00000000 ____D C:\Users\Computador\AppData\OICE_15_974FA576_32C1D314_3762 2016-12-16 07:16 - 2016-12-16 07:16 - 00934603 _____ C:\Users\Computador\Downloads\CÓDIGO DE PROCESSO PENAL MILITAR (2).pdf 2016-12-16 07:16 - 2016-12-16 07:16 - 00108587 _____ C:\Users\Computador\Downloads\APLICABILIDADE DO CÓDIGO PENAL MILITAR E CÓDIGO DO PROCESSO PENAL MILITAR AOS POLICIAIS MILITARES..docx 2016-12-16 06:38 - 2016-12-16 06:39 - 00000000 ____D C:\Users\Computador\Desktop\celular de Dani 2016-12-16 05:58 - 2016-12-16 05:58 - 01358172 _____ C:\Users\Computador\Desktop\Apostila Solução Direito Penal Militar e Direito Processual Penal Militar.pdf 2016-12-16 05:58 - 2016-12-16 05:58 - 00694722 _____ C:\Users\Computador\Downloads\Direito Processual e Penal Militar - Renato Brasileiro.pdf 2016-12-16 05:57 - 2016-12-16 05:57 - 01565464 _____ C:\Users\Computador\Downloads\Apostila Solução Direito Penal Militar e Direito Processual Penal Militar.pdf 2016-12-16 05:57 - 2016-12-16 05:57 - 00535704 _____ C:\Users\Computador\Downloads\direito penal militar e processual militar penal.pdf 2016-12-15 22:14 - 2016-12-15 22:14 - 00107748 _____ C:\Users\Computador\Desktop\direito_penal_militar_e_processual_militar_penal1.pdf 2016-12-15 22:13 - 2016-12-15 22:13 - 00105636 _____ C:\Users\Computador\Downloads\DIREITO PROCESSUAL PENAL MILITAR.pdf 2016-12-15 22:11 - 2016-12-15 22:11 - 00535704 _____ C:\Users\Computador\Desktop\direito_penal_militar_e_processual_militar_penal.pdf 2016-12-13 15:49 - 2016-12-13 15:49 - 00011715 _____ C:\Users\Computador\Desktop\Redação.docx 2016-12-13 15:11 - 2016-12-13 15:11 - 00024976 _____ C:\Users\Computador\Downloads\processo de Anildo (4).docx 2016-12-13 15:04 - 2016-12-13 15:05 - 00000000 ____D C:\Users\Computador\AppData\OICE_15_974FA576_32C1D314_216A 2016-12-13 13:57 - 2016-12-13 15:17 - 00041073 _____ C:\Users\Computador\Desktop\processo de Eudelides.docx 2016-12-13 10:02 - 2016-12-13 13:58 - 00018298 _____ C:\Users\Computador\Downloads\TABELA DOS VALORES PAGOS (1).xlsx 2016-12-13 09:51 - 2016-12-13 09:51 - 00355321 _____ C:\Users\Computador\Desktop\edital da ufba.pdf 2016-12-13 08:59 - 2016-12-13 08:59 - 04728237 _____ C:\Users\Computador\Desktop\PROPOSTA DE ADESÃO.pdf 2016-12-11 21:46 - 2016-12-11 21:46 - 01355330 _____ C:\Users\Computador\Documents\analise_combinatoria_raciocinio_logico.pdf 2016-12-09 06:31 - 2017-01-07 14:04 - 00000000 ____D C:\Users\Computador\Desktop\atividades 2016-12-09 06:26 - 2016-12-09 06:27 - 00000000 ____D C:\Users\Computador\Desktop\ingles - cfo 2016-12-09 06:25 - 2005-10-05 08:20 - 00073577 _____ C:\Users\Computador\Desktop\ingles aula 0.pdf 2016-12-09 06:22 - 2016-12-09 06:22 - 00934156 _____ C:\Users\Computador\Downloads\Inglês para Concurso.zip 2016-12-09 06:20 - 2016-12-09 06:20 - 05078606 _____ C:\Users\Computador\Downloads\Gramática da Língua Inglesa (1).pdf 2016-12-09 06:20 - 2016-12-09 06:20 - 00823353 _____ C:\Users\Computador\Downloads\Ingles Instrumental-apostila para estudo (2).pdf 2016-12-08 20:12 - 2016-12-08 20:18 - 21828392 _____ C:\Users\Computador\Downloads\Ingles Instrumental.pdf 2016-12-08 20:12 - 2016-12-08 20:14 - 05078606 _____ C:\Users\Computador\Downloads\Inglês-gramática.pdf 2016-12-08 20:11 - 2016-12-08 20:11 - 00272384 _____ C:\Users\Computador\Downloads\Apostila Completa de Inglês Técnico.doc 2016-12-08 20:05 - 2016-12-08 20:05 - 00823353 _____ C:\Users\Computador\Downloads\Ingles Instrumental-apostila para estudo (1).pdf 2016-12-08 19:34 - 2016-12-08 19:38 - 04368384 _____ C:\Users\Computador\Downloads\apostila ingles instrumental.doc 2016-12-08 19:33 - 2016-12-08 19:38 - 05078606 _____ C:\Users\Computador\Downloads\Gramática da Língua Inglesa.pdf 2016-12-08 19:33 - 2016-12-08 19:34 - 00823353 _____ C:\Users\Computador\Downloads\Ingles Instrumental-apostila para estudo.pdf 2016-12-08 10:00 - 2016-12-08 10:00 - 00042133 _____ C:\Users\Computador\Documents\novoacordo2 (1).pdf 2016-12-08 07:31 - 2016-12-08 07:31 - 01460666 _____ C:\Users\Computador\Downloads\IMG_20161102_125939167 (1).jpg 2016-12-08 06:56 - 2016-12-08 06:56 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_avusbflt_01011.Wdf 2016-12-06 09:26 - 2016-12-06 09:26 - 00000165 ____H C:\Users\Computador\Documents\~$estudo do CFO.xlsx 2016-12-04 14:20 - 2016-12-04 14:21 - 26971584 _____ (CopySpider Software ) C:\Users\Computador\Downloads\CopySpider-Setup-v1.1.17-RC2 (2).exe 2016-12-04 10:16 - 2016-12-04 10:16 - 00062976 _____ C:\Users\Computador\Downloads\POESIAS- AVOZ NO PAPEL.doc 2016-12-03 21:24 - 2016-12-03 21:24 - 00011351 _____ C:\Users\Computador\Downloads\atividade da pos - Daniel (1).docx 2016-12-03 19:28 - 2016-12-04 06:24 - 00015970 _____ C:\Users\Computador\Downloads\atividade da pos - Elizene.docx 2016-11-30 08:38 - 2016-12-04 11:08 - 00000000 ____D C:\Users\Computador\AppData\Local\IIIQF 2016-11-30 08:32 - 2016-11-30 08:35 - 07040152 _____ (Solvusoft Corporation ) C:\Users\Computador\Downloads\Setup_DriverDoc_2016.exe 2016-11-29 10:46 - 2017-01-08 20:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks 2016-11-29 10:44 - 2017-01-08 20:44 - 00000000 ____D C:\Program Files\Real 2016-11-29 10:44 - 2017-01-08 20:38 - 00000000 ____D C:\Users\Todos os Usuários\Real 2016-11-29 10:44 - 2017-01-08 20:38 - 00000000 ____D C:\ProgramData\Real 2016-11-29 10:41 - 2017-01-24 17:06 - 00000000 ____D C:\Users\Computador\AppData\Roaming\Real 2016-11-29 10:38 - 2016-11-29 10:40 - 39174576 _____ (RealNetworks, Inc.) C:\Users\Computador\Downloads\RealPlayer_br.exe 2016-11-27 08:31 - 2016-11-27 08:42 - 00000000 ____D C:\Users\Computador\Desktop\ORIGEM 2016-11-27 06:19 - 2016-12-04 15:39 - 00000000 ____D C:\Users\Computador\Documents\Nova pasta 2016-11-23 15:49 - 2016-11-23 15:49 - 00018322 _____ C:\Users\Computador\Downloads\TABELA DOS VALORES PAGOS.xlsx 2016-11-23 11:09 - 2016-11-23 11:09 - 00043520 _____ C:\Users\Computador\Downloads\curriculum - ELIZENE S. SANTOS.doc 2016-11-23 11:00 - 2016-11-23 11:00 - 00025600 _____ C:\Users\Computador\Downloads\Curriculum vitae.doc 2016-11-23 10:52 - 2016-11-23 10:52 - 00037888 _____ C:\Users\Computador\Downloads\CV ELIZENE S. SANTOS.doc 2016-11-21 15:34 - 2016-11-21 15:34 - 00000000 ____D C:\Users\Computador\AppData\Local\{D42061CD-3961-4F66-846F-ECE88EAE5F7E} 2016-11-19 07:26 - 2017-01-17 17:58 - 00000000 ____D C:\Users\Computador\AppData\Local\PlutoTV 2016-11-19 07:25 - 2016-11-19 07:25 - 00001799 _____ C:\Users\Computador\Desktop\PlutoTV.lnk 2016-11-19 07:21 - 2016-11-19 07:25 - 00000000 ____D C:\Users\Computador\AppData\Roaming\Pluto TV 2016-11-19 07:14 - 2016-11-19 07:14 - 00000000 ____D C:\Users\Public\Documents\Guid 2016-11-19 07:14 - 2016-11-19 07:14 - 00000000 ____D C:\Users\Public\Documents\Baidu 2016-11-17 19:52 - 2016-11-17 19:52 - 01580008 _____ ( ) C:\Users\Computador\Downloads\VDownloader_Setup (1).VIR 2016-11-17 19:30 - 2016-11-19 06:50 - 00000000 ____D C:\Users\Computador\AppData\Local\{1AC35162-1FF4-41B0-90A3-D87A43BC6920} 2016-11-16 09:54 - 2016-11-16 09:54 - 00056349 _____ C:\Users\Computador\Desktop\fluxograma de daniel.pdf 2016-11-15 18:05 - 2016-11-15 18:05 - 08312330 _____ C:\Users\Computador\Downloads\Mapas Mentais de Direito Tributário.pdf 2016-11-15 18:05 - 2016-11-15 18:05 - 01439744 _____ C:\Users\Computador\Downloads\RESUMO DIREITO TRIBUTÁRIO ESQUEMATIZADO (1).doc 2016-11-15 18:04 - 2016-11-15 18:04 - 01427456 _____ C:\Users\Computador\Downloads\DIREITO -TRIBUTARIO 1700 EXERCICIOS COM GABARITO (1).doc ==================== Três Meses Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2017-02-12 20:48 - 2009-07-14 01:34 - 00009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-02-12 20:48 - 2009-07-14 01:34 - 00009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-02-12 20:40 - 2016-09-11 11:24 - 00000000 ____D C:\Program Files\CopySpider 2017-02-12 17:34 - 2014-11-23 09:49 - 00000000 ____D C:\FFOutput 2017-02-12 10:37 - 2014-11-18 16:22 - 01635826 _____ C:\Windows\system32\PerfStringBackup.INI 2017-02-12 10:37 - 2009-07-17 15:48 - 00706008 _____ C:\Windows\system32\prfh0416.dat 2017-02-12 10:37 - 2009-07-17 15:48 - 00147848 _____ C:\Windows\system32\prfc0416.dat 2017-02-12 10:37 - 2009-07-13 23:37 - 00000000 ____D C:\Windows\inf 2017-02-11 06:42 - 2016-09-16 17:37 - 00000000 ____D C:\Users\Computador\Desktop\Pos graduação 2017-02-09 11:42 - 2015-07-23 09:55 - 00000000 ____D C:\Users\Todos os Usuários\GbPlugin 2017-02-09 11:42 - 2015-07-23 09:55 - 00000000 ____D C:\ProgramData\GbPlugin 2017-02-09 11:41 - 2009-07-14 01:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-02-09 11:40 - 2016-09-15 14:34 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2017-02-08 07:14 - 2016-10-01 17:44 - 00001475 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk 2017-02-08 07:14 - 2016-10-01 17:44 - 00000372 __RSH C:\Users\Todos os Usuários\ntuser.pol 2017-02-08 07:14 - 2016-10-01 17:44 - 00000372 __RSH C:\ProgramData\ntuser.pol 2017-02-08 06:17 - 2016-09-15 14:43 - 00000000 ____D C:\Users\Computador\dwhelper 2017-02-08 06:07 - 2014-11-18 16:34 - 00002345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-02-08 06:07 - 2014-11-18 16:34 - 00002127 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-01-19 21:28 - 2016-06-19 17:48 - 00021450 _____ C:\Users\Computador\Documents\estudo do CFO.xlsx 2017-01-17 17:54 - 2014-12-28 12:38 - 00000000 ____D C:\Users\Todos os Usuários\AVAST Software 2017-01-17 17:54 - 2014-12-28 12:38 - 00000000 ____D C:\ProgramData\AVAST Software 2017-01-17 17:10 - 2014-11-20 18:06 - 00000000 ____D C:\Users\Computador\AppData\Local\VDownloader 2017-01-17 14:51 - 2015-06-12 17:05 - 00000000 ____D C:\Users\Computador\AppData\Roaming\MPC-HC 2017-01-16 09:57 - 2015-10-08 09:43 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache 2017-01-16 09:57 - 2015-10-08 09:43 - 00000000 ____D C:\ProgramData\Package Cache 2017-01-14 11:23 - 2015-06-02 09:07 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk 2017-01-14 10:41 - 2014-12-06 10:50 - 00000000 ____D C:\Windows\Minidump 2017-01-14 07:38 - 2015-03-20 14:22 - 00000000 ____D C:\Program Files\Java 2017-01-14 07:37 - 2015-03-20 14:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java ==================== Arquivos na raiz de alguns diretórios ======= 2014-11-20 18:06 - 2010-01-26 09:11 - 0444283 _____ () C:\Program Files\Common Files\WinPcapNmap.exe 2016-10-01 17:44 - 2016-10-01 17:44 - 0019784 _____ () C:\Users\Computador\AppData\Roaming\Samogipamefo 2016-12-18 15:56 - 2017-02-08 07:12 - 0000274 _____ () C:\Users\Computador\AppData\Roaming\WB.CFG 2015-06-20 16:07 - 2015-06-20 16:07 - 0003584 _____ () C:\Users\Computador\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2017-01-18 16:17 - 2017-01-18 16:17 - 0007605 _____ () C:\Users\Computador\AppData\Local\Resmon.ResmonCfg 2014-12-06 11:13 - 2015-01-11 07:49 - 0000227 _____ () C:\ProgramData\bc.ini Arquivos para serem movidos ou deletados: ==================== C:\Windows\Tasks\{3C640506-924D-4B71-91A2-F2A31FC245F4}.job C:\Windows\Tasks\{40329473-3A59-783A-486C-337DC4BAA971}.job ==================== Bamital & volsnap ====================== (Não há correção automática para arquivos que não passaram na verificação.) C:\Windows\explorer.exe => O arquivo é assinado digitalmente C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente C:\Windows\system32\services.exe => O arquivo é assinado digitalmente C:\Windows\system32\User32.dll => MD5 é legítimo C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente LastRegBack: 2017-02-08 22:58 ==================== Fim de FRST.txt ============================