Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 15-03-2017 Executado por Claudio (administrador) em CLAUDIO-PC (09-04-2017 07:49:26) Executando a partir de C:\Users\Claudio\AppData\Local\Temp\scoped_dir2072_17031 Perfis Carregados: Claudio & postgres (Perfis Disponíveis: Claudio & postgres & DefaultAppPool) Platform: Windows 7 Professional Service Pack 1 (X64) Idioma: Português (Brasil) Internet Explorer Versão 9 (Navegador padrão: Opera) Modo da Inicialização: Normal Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (Luis Cobian, CobianSoft) C:\Program Files (x86)\Cobian Backup 11\cbService.exe (Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe (Mediafour Corporation) C:\Program Files\Mediafour\MacDrive 9\MacDrive9Service.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Mediafour Corporation) C:\Program Files\Mediafour\MacDrive 9\MacDrive.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATII4E.EXE (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Luis Cobian, CobianSoft) C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe (PostgreSQL Global Development Group) C:\PostgreSQL8.4.5\bin\pg_ctl.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe (PostgreSQL Global Development Group) C:\PostgreSQL8.4.5\bin\postgres.exe (PostgreSQL Global Development Group) C:\PostgreSQL8.4.5\bin\postgres.exe (PostgreSQL Global Development Group) C:\PostgreSQL8.4.5\bin\postgres.exe (PostgreSQL Global Development Group) C:\PostgreSQL8.4.5\bin\postgres.exe (PostgreSQL Global Development Group) C:\PostgreSQL8.4.5\bin\postgres.exe (PostgreSQL Global Development Group) C:\PostgreSQL8.4.5\bin\postgres.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser_crashreporter.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe () C:\Program Files\AVAST Software\Avast\AvastNM.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe (Avast Software) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe ==================== Registro (Whitelisted) ==================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-07-29] (Realtek Semiconductor) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10775584 2010-07-29] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-07-29] (Realtek Semiconductor) HKLM\...\Run: [MacDrive 9 application] => C:\Program Files\Mediafour\MacDrive 9\MacDrive.exe [505856 2011-08-15] (Mediafour Corporation) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-04-06] (AVAST Software) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595992 2016-03-20] (Oracle Corporation) HKLM-x32\...\Run: [Cobian Backup 11 interface] => C:\Program Files (x86)\Cobian Backup 11\cbInterface.exe [4407808 2013-03-07] (Luis Cobian, CobianSoft) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-1515203375-3869413919-2955012471-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [718208 2010-03-16] (Microsoft Corporation) HKU\S-1-5-21-1515203375-3869413919-2955012471-1000\...\Run: [EPLTarget\P0000000000000002] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATII4E.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1515203375-3869413919-2955012471-1001\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATII4E.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION) ShellIconOverlayIdentifiers: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX64.dll -> Nenhum Arquivo ShellIconOverlayIdentifiers: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX64.dll -> Nenhum Arquivo ShellIconOverlayIdentifiers: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX64.dll -> Nenhum Arquivo ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-04-06] (AVAST Software) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-04-06] (AVAST Software) ShellIconOverlayIdentifiers: [MacDriveVolumeIcon] -> {6B21AF46-EE37-40D0-A707-C06C17D06CE9} => C:\Program Files\Mediafour\MacDrive 9\MDVolumeIcons.dll [2011-07-13] (Mediafour Corporation) ShellIconOverlayIdentifiers: [MacDriveVolumeIconReadOnly] -> {E9BC4DCA-0A4E-4C65-9D40-621C9D0CDC5F} => C:\Program Files\Mediafour\MacDrive 9\MDVolumeIcons.dll [2011-07-13] (Mediafour Corporation) ShellIconOverlayIdentifiers-x32: [ MEGA (Pending)] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX32.dll -> Nenhum Arquivo ShellIconOverlayIdentifiers-x32: [ MEGA (Synced)] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX32.dll -> Nenhum Arquivo ShellIconOverlayIdentifiers-x32: [ MEGA (Syncing)] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX32.dll -> Nenhum Arquivo ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{155EB9E8-893E-4B52-A675-71B0C0AEBFF3}: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{F2C09FE2-091E-434F-BA80-3E0F4D61A67C}: [DhcpNameServer] 8.8.8.8 Internet Explorer: ================== HKU\S-1-5-21-1515203375-3869413919-2955012471-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pt-br/?ocid=iehp HKU\S-1-5-21-1515203375-3869413919-2955012471-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/pt-br/?ocid=iehp SearchScopes: HKU\S-1-5-21-1515203375-3869413919-2955012471-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1515203375-3869413919-2955012471-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_77\bin\ssv.dll [2016-04-12] (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-06] (AVAST Software) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-04-12] (Oracle Corporation) BHO-x32: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-04-12] (Oracle Corporation) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-06] (AVAST Software) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-04-12] (Oracle Corporation) Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION) FireFox: ======== FF DefaultProfile: hpgyiyg6.default FF ProfilePath: C:\Users\Claudio\AppData\Roaming\Mozilla\Firefox\Profiles\hpgyiyg6.default [2016-07-02] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-12-29] FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-12-29] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on FF Extension: (E-Web Print) - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2016-07-22] [não assinado] FF Plugin: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-12] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-12] (Oracle Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-17] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-17] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-17] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2017-01-17] (Foxit Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-12] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-12] (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-29] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-29] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-01-17] (Adobe Systems Inc.) Chrome: ======= CHR DefaultProfile: Default CHR HomePage: Default -> hxxp://www.google.com CHR Profile: C:\Users\Claudio\AppData\Local\Google\Chrome\User Data\Default [2017-03-03] CHR Extension: (Avast SafePrice) - C:\Users\Claudio\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-01-05] CHR Extension: (Avast Online Security) - C:\Users\Claudio\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-03-03] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Claudio\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-03] CHR Extension: (Chrome Media Router) - C:\Users\Claudio\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-03] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx ==================== Serviços (Whitelisted) ==================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7398336 2017-04-06] (AVAST Software s.r.o.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [261712 2017-04-06] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [310496 2017-04-06] (AVAST Software) R2 CobianBackup11; C:\Program Files (x86)\Cobian Backup 11\cbService.exe [1131008 2013-03-07] (Luis Cobian, CobianSoft) [Arquivo não assinado] R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation) R2 FoxitReaderService; C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe [1659592 2017-02-24] (Foxit Software Inc.) R2 MacDrive9Service; C:\Program Files\Mediafour\MacDrive 9\MacDrive9Service.exe [179712 2011-07-13] (Mediafour Corporation) [Arquivo não assinado] S2 MASMonitorService; C:\Program Files (x86)\StatSoft\MAS\MASMonitorService.exe [593336 2010-11-04] (StatSoft, Inc.) R2 postgresql-8.4; C:\PostgreSQL8.4.5\bin\pg_ctl.exe [66048 2010-10-03] (PostgreSQL Global Development Group) [Arquivo não assinado] S2 STATISTICA License Manager; C:\Program Files (x86)\StatSoft\FLEXlm\lmgrd.exe [1500424 2010-11-04] (Acresso Software Inc.) S2 WebSTATISTICA; C:\Program Files (x86)\StatSoft\WebSTATISTICA\WebSTAT.exe [473528 2010-11-04] (StatSoft, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [309272 2017-03-16] (AVAST Software s.r.o.) R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-03-16] (AVAST Software s.r.o.) R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334600 2017-03-16] (AVAST Software s.r.o.) R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-03-16] (AVAST Software s.r.o.) S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-03-16] (AVAST Software) R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [32088 2017-03-16] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [126600 2017-03-16] (AVAST Software) R3 aswNetNd6; C:\Windows\System32\DRIVERS\aswNetNd6.sys [29432 2017-02-09] (AVAST Software) R1 aswNetSec; C:\Windows\system32\drivers\aswNetSec.sys [461640 2017-03-16] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [100640 2017-03-16] (AVAST Software) R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-03-16] (AVAST Software) R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [993608 2017-03-16] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [548928 2017-03-21] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [162528 2017-03-16] (AVAST Software) R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [337592 2017-03-16] (AVAST Software) R1 CBDisk; C:\Windows\system32\drivers\CBDisk.sys [70344 2011-05-06] (EldoS Corporation) S1 hwinterface; C:\Windows\SysWOW64\Drivers\hwinterface.sys [3026 2017-04-06] (Logix4u) [Arquivo não assinado] R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [30960 2015-05-29] (Intel Corporation) R3 int0800; C:\Windows\System32\DRIVERS\flashud.sys [51712 2009-09-09] (Intel Corporation) R0 MDFSYSNT; C:\Windows\System32\Drivers\MDFSYSNT.sys [316080 2011-08-24] (Mediafour Corporation) R0 MDPMGRNT; C:\Windows\System32\DRIVERS\MDPMGRNT.SYS [32936 2011-05-09] (Mediafour Corporation) R3 ROCKEYNT; C:\Windows\System32\DRIVERS\Rockey4.sys [36904 2016-06-30] (Feitian Technologies Co., Ltd.) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um Mês Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2017-04-09 07:49 - 2017-04-09 07:49 - 00000000 ____D C:\FRST 2017-04-09 07:47 - 2017-04-09 07:48 - 02424832 _____ (Farbar) C:\Users\Claudio\Downloads\FRST64.exe 2017-04-09 07:37 - 2017-04-09 07:37 - 01034556 _____ C:\Users\Claudio\Downloads\Windows6.1-KB2999226-x64 (1).msu 2017-04-09 07:31 - 2017-04-09 07:31 - 00003630 _____ C:\Users\Claudio\Downloads\api-ms-win-crt-runtime-l1-1-0.zip 2017-04-09 07:17 - 2017-04-09 07:17 - 00000000 ___HT C:\Windows\wusa.lock 2017-04-09 07:17 - 2017-04-09 07:17 - 00000000 ____D C:\d6cced806495a4cbadb026a420993e 2017-04-09 07:08 - 2017-04-09 07:08 - 00000000 ____D C:\Users\Todos os Usuários\SWCUTemp 2017-04-09 07:08 - 2017-04-09 07:08 - 00000000 ____D C:\ProgramData\SWCUTemp 2017-04-08 22:38 - 2017-04-08 22:38 - 00629006 _____ C:\Users\Claudio\Downloads\Windows6.1-KB2999226-x86.msu 2017-04-08 22:26 - 2017-04-08 22:26 - 01034556 _____ C:\Users\Claudio\Downloads\Windows6.1-KB2999226-x64.msu 2017-04-08 22:26 - 2017-04-08 22:26 - 00000000 ____D C:\f9810893851ff44ba917 2017-04-08 22:17 - 2017-04-08 22:20 - 00003370 _____ C:\Windows\System32\Tasks\DllKitPRO 2017-04-08 22:17 - 2017-04-08 22:17 - 00000000 ____D C:\Users\Claudio\AppData\Local\{003ACA6A-C058-424D-B955-A82DE5375C64} 2017-04-08 22:15 - 2017-04-08 22:15 - 00904176 _____ C:\Users\Claudio\Desktop\dllkit-setup.exe 2017-04-08 22:05 - 2017-04-08 22:05 - 00000000 ____D C:\Users\Claudio\.gvsig-scripting 2017-04-08 22:04 - 2017-04-08 22:06 - 00000000 ____D C:\Users\Claudio\gvSIG 2017-04-08 18:33 - 2017-04-08 18:33 - 00001640 _____ C:\Users\Public\Desktop\GRASS GIS 6.4.4.lnk 2017-04-08 18:33 - 2017-04-08 18:33 - 00001609 _____ C:\Users\Public\Desktop\MSYS Shell.lnk 2017-04-08 18:33 - 2017-04-08 18:33 - 00001601 _____ C:\Users\Public\Desktop\Monteverdi.lnk 2017-04-08 15:59 - 2017-04-08 15:59 - 00165376 _____ C:\Users\Claudio\Downloads\João Carlos Madella 08-04-2017.xls 2017-04-08 15:56 - 2017-04-08 15:56 - 00094720 _____ C:\Users\Claudio\Downloads\Fernando Magno 08-04-2017.xls 2017-04-08 15:08 - 2017-04-08 15:10 - 00000000 ____D C:\osgeo 2017-04-08 15:02 - 2017-04-08 15:02 - 00711136 _____ C:\Users\Claudio\Desktop\osgeo4w-setup-x86.exe 2017-04-07 22:00 - 2017-04-07 22:43 - 299907695 _____ C:\Users\Claudio\Downloads\QGIS-OSGeo4W-2.14.13-2-Setup-x86.exe 2017-04-07 21:57 - 2017-04-08 18:29 - 00000000 ____D C:\OSGeo4W 2017-04-07 21:55 - 2017-04-07 21:55 - 00711136 _____ C:\Users\Claudio\Downloads\osgeo4w-setup-x86.exe 2017-04-07 21:44 - 2017-04-07 21:44 - 00000000 ____D C:\Users\Public\Desktop\OSGeo4W 2017-04-07 21:43 - 2017-04-08 22:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OSGeo4W 2017-04-07 21:24 - 2017-04-08 14:26 - 00000000 ____D C:\Users\Claudio\.designer 2017-04-07 21:03 - 2017-04-08 15:03 - 00000000 ____D C:\Users\Public\Desktop\QGIS 2.14 2017-04-07 18:51 - 2017-04-07 18:51 - 00262144 _____ C:\Windows\Minidump\040717-29920-01.dmp 2017-04-07 17:49 - 2017-04-07 17:49 - 00000000 ____D C:\a7906bc6e70692e6c9d49426e447e6c9 2017-04-07 17:46 - 2017-04-08 18:32 - 00001612 _____ C:\Users\Public\Desktop\GRASS GIS 7.2.0.lnk 2017-04-07 17:38 - 2017-04-08 14:00 - 00000000 ____D C:\Program Files\QGIS 2.14 2017-04-07 16:57 - 2017-04-07 16:57 - 00000000 ____D C:\Users\Claudio\AppData\Roaming\Notepad++ 2017-04-07 16:57 - 2017-04-07 16:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++ 2017-04-07 16:57 - 2017-04-07 16:57 - 00000000 ____D C:\Program Files\Notepad++ 2017-04-07 16:56 - 2017-04-07 16:56 - 02974456 _____ C:\Users\Claudio\Downloads\npp.7.3.3.Installer.x64.exe 2017-04-07 16:05 - 2017-04-07 16:05 - 01857024 _____ C:\Users\Claudio\Downloads\geoestat.ppt 2017-04-07 15:54 - 2017-04-07 16:42 - 379727876 _____ C:\Users\Claudio\Downloads\QGIS-OSGeo4W-2.14.13-2-Setup-x86_64.exe 2017-04-06 06:42 - 2017-04-06 06:42 - 00399944 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2017-04-04 23:17 - 2017-04-04 23:18 - 00344064 _____ C:\Users\Claudio\Documents\Database26.accdb 2017-04-04 12:11 - 2017-04-04 12:11 - 00332845 _____ C:\Users\Claudio\Downloads\rel_mon_29_03-17_prudente.pdf 2017-04-04 11:49 - 2017-04-04 11:49 - 00345516 _____ C:\Users\Claudio\Downloads\rel_mon_30_03-17_paraiso.pdf 2017-04-04 10:25 - 2017-04-04 10:25 - 00086632 _____ C:\Users\Claudio\Downloads\20170404_092527_IPNI_NOVODRISMILHO.xlsx 2017-04-04 10:12 - 2017-04-04 10:12 - 00086236 _____ C:\Users\Claudio\Downloads\20170404_091152_IPNI_NOVODRISMILHO.xlsx 2017-04-04 10:08 - 2017-04-04 10:08 - 00137193 _____ C:\Users\Claudio\Downloads\FOLIAR.pdf 2017-04-04 07:53 - 2017-04-04 07:53 - 00344064 _____ C:\Users\Claudio\Documents\Database25.accdb 2017-04-04 07:50 - 2017-04-04 07:51 - 00344064 _____ C:\Users\Claudio\Documents\Database24.accdb 2017-04-04 07:35 - 2017-04-04 07:36 - 00344064 _____ C:\Users\Claudio\Documents\Database23.accdb 2017-04-03 11:38 - 2017-04-03 11:38 - 00073728 _____ C:\Users\Claudio\Downloads\Aguetoni_Análise de Solo_Pivot01 e 04_Cláudio_2017_2.xls 2017-04-03 06:43 - 2017-04-03 06:43 - 00001623 _____ C:\Users\Claudio\Desktop\DADOS_AMOSTRAS_SEDE_GAMELEIRA_17 - Atalho.lnk 2017-04-03 06:30 - 2017-04-03 06:30 - 00001656 _____ C:\Users\Claudio\Desktop\Map_Pivo04_17 - Atalho.lnk 2017-04-03 06:30 - 2017-04-03 06:30 - 00001457 _____ C:\Users\Claudio\Desktop\Graficos_Nutrientes_th01 - Atalho.lnk 2017-04-03 06:19 - 2017-04-03 06:19 - 00001358 _____ C:\Users\Claudio\Desktop\Map_A2 - Atalho.lnk 2017-04-03 06:01 - 2017-04-03 06:01 - 00001379 _____ C:\Users\Claudio\Desktop\Esquema_Trabalho_2014_Resumido - Atalho.lnk 2017-04-02 10:10 - 2017-04-02 10:16 - 11879939 _____ C:\Users\Claudio\Downloads\epidemiologiaecontroledasdoenasnomilho-141031092843-conversion-gate01 (1).pptx 2017-04-02 10:04 - 2017-04-02 10:11 - 11879939 _____ C:\Users\Claudio\Downloads\epidemiologiaecontroledasdoenasnomilho-141031092843-conversion-gate01.pptx 2017-04-02 09:48 - 2017-04-02 09:53 - 26962432 _____ C:\Users\Claudio\Downloads\tratamentodesementeseplantio-160302002404.ppt 2017-04-02 09:38 - 2017-04-02 09:38 - 00124113 _____ C:\Users\Claudio\Downloads\13-40-1-PB.pdf 2017-03-30 23:55 - 2017-03-30 23:55 - 00344064 _____ C:\Users\Claudio\Documents\Database22.accdb 2017-03-30 21:58 - 2017-03-30 21:58 - 00066048 _____ C:\Users\Claudio\Downloads\Pivos_01_04_Aguitoni_17 (1).xls 2017-03-30 21:31 - 2017-03-30 21:31 - 00141312 _____ C:\Users\Claudio\Downloads\Dinamerico S. Aguitoni-01 (1).xls 2017-03-28 13:45 - 2017-03-28 13:45 - 00187851 _____ C:\Users\Claudio\Downloads\PRODUTOS_KIMBERLIT_Soja_Milho_17_18.pdf 2017-03-27 19:28 - 2017-03-27 19:28 - 00000000 ____D C:\Users\Todos os Usuários\Foxit Software 2017-03-27 19:28 - 2017-03-27 19:28 - 00000000 ____D C:\ProgramData\Foxit Software 2017-03-27 19:27 - 2017-03-27 19:27 - 00001355 _____ C:\Users\Public\Desktop\Foxit Reader.lnk 2017-03-27 19:27 - 2017-03-27 19:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader 2017-03-27 19:27 - 2017-03-27 19:27 - 00000000 ____D C:\Program Files (x86)\Foxit Software 2017-03-26 20:49 - 2017-03-26 20:49 - 00373454 _____ C:\Users\Claudio\Downloads\Contrato_Serviços_Mapeamento_PANAMA_2016 (1).pdf 2017-03-25 21:35 - 2017-03-25 21:35 - 00240936 _____ C:\Users\Claudio\Downloads\rel_mon_23_03-17_prudente.pdf 2017-03-24 21:07 - 2017-03-24 21:08 - 00344064 _____ C:\Users\Claudio\Documents\Database21.accdb 2017-03-21 06:18 - 2017-03-21 06:18 - 01228407 _____ C:\Users\Claudio\Downloads\rel_mon_18_03-17_hamonia.pptx 2017-03-21 05:53 - 2017-03-21 05:53 - 00001075 _____ C:\Users\Claudio\Desktop\PIXresizer.lnk 2017-03-21 05:53 - 2017-03-21 05:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PIXresizer 2017-03-21 05:53 - 2017-03-21 05:53 - 00000000 ____D C:\Program Files (x86)\PIXresizer 2017-03-21 05:53 - 2007-04-15 01:05 - 00991232 _____ (Viscom Software ) C:\Windows\SysWOW64\imageviewer2.ocx 2017-03-21 05:53 - 2002-08-29 20:00 - 01703936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdiplus.dll 2017-03-21 05:53 - 2000-07-09 19:15 - 00106496 _____ (Marco Bellinaso) C:\Windows\SysWOW64\mbprgbar.ocx 2017-03-21 05:53 - 2000-05-02 00:02 - 00110592 _____ (Common Controls Replacement Project (CCRP)) C:\Windows\SysWOW64\ccrpbds6.dll 2017-03-21 05:53 - 1999-09-16 10:04 - 00151552 _____ (Domenico Statuto - CCRP) C:\Windows\SysWOW64\ccrpfd6.ocx 2017-03-21 05:53 - 1996-01-12 01:00 - 00200704 _____ (Sheridan Software Systems, Inc.) C:\Windows\SysWOW64\threed32.ocx 2017-03-21 05:52 - 2017-03-21 05:52 - 03436220 _____ C:\Users\Claudio\Downloads\PIXresizer.zip 2017-03-19 18:27 - 2017-03-19 18:27 - 00093184 _____ C:\Users\Claudio\Downloads\Jair Borges da Silva.xls 2017-03-19 18:26 - 2017-03-19 18:26 - 00173568 _____ C:\Users\Claudio\Downloads\Fernando Magno.xls 2017-03-18 22:48 - 2017-03-18 22:48 - 00000000 ____D C:\Users\Claudio\AppData\Roaming\DuckLink 2017-03-18 22:46 - 2017-03-18 22:47 - 06142695 _____ (DuckLink Software ) C:\Users\Claudio\Downloads\Install_DuckCapture_Standard.exe 2017-03-18 05:32 - 2017-03-18 05:32 - 00013618 _____ C:\Users\Claudio\Downloads\gmapsupp_v1702.zip.rar 2017-03-17 23:14 - 2017-03-18 00:08 - 346191857 _____ C:\Users\Claudio\Downloads\gmapsupp_v1702.zip 2017-03-17 23:06 - 2017-03-17 23:06 - 00013559 _____ C:\Users\Claudio\Downloads\gmapsupp_v1702.zip.torrent 2017-03-17 23:04 - 2017-03-17 23:04 - 00000000 ____D C:\Users\Claudio\AppData\Local\Mega Limited 2017-03-17 22:00 - 2017-03-17 22:01 - 00344064 _____ C:\Users\Claudio\Documents\Database20.accdb 2017-03-17 20:41 - 2017-03-17 20:42 - 00344064 _____ C:\Users\Claudio\Documents\Database19.accdb 2017-03-17 20:33 - 2017-03-17 20:33 - 00344064 _____ C:\Users\Claudio\Documents\Database18.accdb 2017-03-16 06:50 - 2017-03-16 06:50 - 00000000 ____D C:\Users\TEMP\AppData\Roaming\AVAST Software 2017-03-16 06:47 - 2017-03-16 12:54 - 00000000 ____D C:\Users\TEMP 2017-03-15 06:48 - 2017-03-15 06:49 - 00344064 _____ C:\Users\Claudio\Documents\Database17.accdb 2017-03-15 00:44 - 2017-03-15 00:44 - 00202986 _____ C:\Users\Claudio\Downloads\CAMINHAMENTO_DIA_CAMPO.pdf 2017-03-15 00:38 - 2017-03-15 00:38 - 00202087 _____ C:\Users\Claudio\Downloads\CAMINHAMENTO_DIA_CAMPO_AT (1).pdf 2017-03-15 00:37 - 2017-03-15 00:37 - 00202087 _____ C:\Users\Claudio\Downloads\CAMINHAMENTO_DIA_CAMPO_AT.pdf 2017-03-14 22:15 - 2017-03-14 22:15 - 00820058 _____ C:\Users\Claudio\Downloads\rel_mon_01_03-17_paraiso.pdf 2017-03-14 22:14 - 2017-03-14 22:15 - 01064370 _____ C:\Users\Claudio\Downloads\rel_mon_01_03-17_prudente (1).pdf 2017-03-14 22:14 - 2017-03-14 22:14 - 00809497 _____ C:\Users\Claudio\Downloads\rel_mon_01_03_17_franco.pdf 2017-03-14 21:15 - 2017-03-14 21:16 - 00916834 _____ C:\Users\Claudio\Downloads\rel_mon_08_03-17_grupo_prudente.pdf 2017-03-14 21:15 - 2017-03-14 21:15 - 01199820 _____ C:\Users\Claudio\Downloads\rel_mon_08_03_17_ivair.pdf 2017-03-14 21:15 - 2017-03-14 21:15 - 00666783 _____ C:\Users\Claudio\Downloads\rel_mon_08_03_17_paraiso.pdf 2017-03-13 21:12 - 2017-03-13 21:13 - 00344064 _____ C:\Users\Claudio\Documents\Database16.accdb 2017-03-13 21:01 - 2017-03-13 21:01 - 00344064 _____ C:\Users\Claudio\Documents\Database15.accdb 2017-03-13 06:07 - 2017-03-13 06:07 - 00013401 _____ C:\Users\Claudio\Downloads\CAMINHAMENTO_DIA_CAMPO (3).xlsx 2017-03-13 06:05 - 2017-03-13 06:05 - 00018901 _____ C:\Users\Claudio\Downloads\CAMINHAMENTO_DIA_CAMPO (2).xlsx 2017-03-13 06:04 - 2017-03-13 06:05 - 00013317 _____ C:\Users\Claudio\Downloads\CAMINHAMENTO_DIA_CAMPO (1).xlsx 2017-03-13 06:02 - 2017-03-13 06:04 - 00013220 _____ C:\Users\Claudio\Downloads\CAMINHAMENTO_DIA_CAMPO.xlsx ==================== Um Mês Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2017-04-09 07:44 - 2009-07-14 01:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-04-09 07:44 - 2009-07-14 01:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-04-09 07:09 - 2016-04-23 11:16 - 00000000 ____D C:\PG_data 2017-04-09 07:07 - 2009-07-14 02:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-04-08 22:18 - 2016-06-16 23:44 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2017-04-08 22:05 - 2016-04-12 14:06 - 00000000 ____D C:\Users\Claudio 2017-04-08 16:05 - 2009-07-14 02:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2017-04-08 13:56 - 2016-04-12 20:45 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache 2017-04-08 13:56 - 2016-04-12 20:45 - 00000000 ____D C:\ProgramData\Package Cache 2017-04-07 18:51 - 2016-05-06 22:31 - 00000000 ____D C:\Windows\Minidump 2017-04-07 18:50 - 2016-05-06 22:31 - 511498630 _____ C:\Windows\MEMORY.DMP 2017-04-07 15:55 - 2016-04-12 15:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-04-06 21:06 - 2016-04-12 15:54 - 00002193 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-04-06 20:49 - 2010-11-21 06:37 - 00785868 _____ C:\Windows\system32\prfh0416.dat 2017-04-06 20:49 - 2010-11-21 06:37 - 00175002 _____ C:\Windows\system32\prfc0416.dat 2017-04-06 20:49 - 2009-07-14 02:13 - 01847966 _____ C:\Windows\system32\PerfStringBackup.INI 2017-04-06 20:49 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\inf 2017-04-06 06:42 - 2017-02-09 15:15 - 00004172 _____ C:\Windows\System32\Tasks\Avast Emergency Update 2017-04-06 06:34 - 2016-04-12 21:20 - 00003026 _____ (Logix4u) C:\Windows\SysWOW64\Drivers\hwinterface.sys 2017-04-04 21:50 - 2016-04-12 20:46 - 00000000 ____D C:\Users\Claudio\.qgis2 2017-04-04 21:50 - 2016-04-12 20:46 - 00000000 ____D C:\Users\Claudio\.matplotlib 2017-04-03 18:37 - 2016-04-23 15:55 - 00013030 _____ C:\PDOXUSRS.NET 2017-03-28 13:42 - 2016-04-12 16:12 - 00000000 ____D C:\Users\Claudio\AppData\Roaming\Foxit Software 2017-03-27 19:28 - 2016-04-12 16:11 - 00000000 ____D C:\Users\Todos os Usuários\Foxit ContentPlatform 2017-03-27 19:28 - 2016-04-12 16:11 - 00000000 ____D C:\ProgramData\Foxit ContentPlatform 2017-03-21 23:26 - 2016-04-12 16:12 - 00548928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2017-03-20 19:25 - 2016-12-12 23:05 - 00000000 ____D C:\Program Files\QGIS 2.18 2017-03-20 19:24 - 2016-04-12 16:09 - 00000000 ____D C:\Program Files (x86)\Hard Disk Sentinel 2017-03-17 00:07 - 2016-04-12 16:21 - 00003902 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1460488860 2017-03-16 21:45 - 2009-07-14 02:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2017-03-16 06:48 - 2009-07-14 01:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2017-03-16 06:45 - 2016-04-12 16:12 - 00337592 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys 2017-03-16 06:43 - 2016-04-12 16:20 - 00032088 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2017-03-16 06:43 - 2016-04-12 16:12 - 00993608 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2017-03-16 06:43 - 2016-04-12 16:12 - 00547904 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.148965753413704 2017-03-16 06:43 - 2016-04-12 16:12 - 00337592 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.148965753997306 2017-03-16 06:43 - 2016-04-12 16:12 - 00162528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2017-03-16 06:43 - 2016-04-12 16:12 - 00126600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2017-03-16 06:43 - 2016-04-12 16:12 - 00100640 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2017-03-16 06:43 - 2016-04-12 16:12 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys 2017-03-16 06:43 - 2016-04-12 16:12 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys 2017-03-16 06:42 - 2017-02-09 15:14 - 00334600 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys 2017-03-16 06:42 - 2017-02-09 15:14 - 00309272 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys 2017-03-16 06:42 - 2017-02-09 15:14 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys 2017-03-16 06:42 - 2017-02-09 15:14 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys 2017-03-16 06:42 - 2016-10-29 13:38 - 00461640 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNetSec.sys 2017-03-14 20:43 - 2016-06-16 23:44 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-03-14 20:43 - 2016-06-16 23:44 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-03-14 20:43 - 2016-06-16 23:44 - 00004530 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-03-14 20:43 - 2016-06-16 23:44 - 00004384 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-03-14 20:43 - 2016-06-16 23:44 - 00000000 ____D C:\Windows\system32\Macromed ==================== Arquivos na raiz de alguns diretórios ======= 2016-04-12 14:41 - 2016-04-12 14:41 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Alguns arquivos em TEMP: ==================== 2015-11-11 14:47 - 2015-11-11 14:47 - 0511488 _____ () C:\Users\Claudio\AppData\Local\Temp\ACIS.dll 2016-07-13 19:22 - 2016-07-13 19:22 - 0003584 _____ () C:\Users\Claudio\AppData\Local\Temp\agsurbee.dll 2016-09-09 19:06 - 2016-09-09 19:06 - 2903395 _____ (Estatcamp ) C:\Users\Claudio\AppData\Local\Temp\AS653c1da5-e15f-40e8-9698-1d57f00c90e3.exe 2016-04-12 16:11 - 2016-04-12 16:11 - 0034308 _____ () C:\Users\Claudio\AppData\Local\Temp\bassmod.dll 2017-03-27 19:25 - 2015-09-28 10:45 - 4990656 _____ (Foxit Corporation) C:\Users\Claudio\AppData\Local\Temp\FoxitUpdater.exe 2017-02-02 20:38 - 2010-06-20 22:42 - 0046456 _____ (Sony Electronics, Inc) C:\Users\Claudio\AppData\Local\Temp\GLF2F1F.EXE 2017-02-02 20:38 - 2003-05-02 15:13 - 0151552 _____ () C:\Users\Claudio\AppData\Local\Temp\GLF39DA.EXE 2016-07-02 07:22 - 2010-06-20 22:42 - 0046456 _____ (Sony Electronics, Inc) C:\Users\Claudio\AppData\Local\Temp\GLF5268.EXE 2016-07-02 07:22 - 2003-05-02 15:13 - 0151552 _____ () C:\Users\Claudio\AppData\Local\Temp\GLF593C.EXE 2016-07-02 07:41 - 2003-05-02 15:13 - 0151552 _____ () C:\Users\Claudio\AppData\Local\Temp\GLF763C.EXE 2017-02-02 20:23 - 2003-05-02 15:13 - 0151552 _____ () C:\Users\Claudio\AppData\Local\Temp\GLF83.EXE 2016-06-30 11:35 - 2010-06-20 22:42 - 0046456 _____ (Sony Electronics, Inc) C:\Users\Claudio\AppData\Local\Temp\GLFA135.EXE 2016-06-30 11:35 - 2003-05-02 15:13 - 0151552 _____ () C:\Users\Claudio\AppData\Local\Temp\GLFAC1F.EXE 2016-07-02 07:45 - 2010-06-20 23:42 - 0046456 _____ (Sony Electronics, Inc) C:\Users\Claudio\AppData\Local\Temp\GLFD4E0.EXE 2016-07-02 07:45 - 2003-05-02 16:13 - 0151552 _____ () C:\Users\Claudio\AppData\Local\Temp\GLFDAE9.EXE 2017-02-02 20:23 - 2010-06-20 22:42 - 0046456 _____ (Sony Electronics, Inc) C:\Users\Claudio\AppData\Local\Temp\GLFEBBA.EXE 2016-09-30 20:43 - 2016-09-30 20:44 - 0741440 _____ (Oracle Corporation) C:\Users\Claudio\AppData\Local\Temp\jre-8u101-windows-au.exe 2016-10-30 12:39 - 2016-10-30 12:39 - 0737856 _____ (Oracle Corporation) C:\Users\Claudio\AppData\Local\Temp\jre-8u111-windows-au.exe 2016-07-11 14:46 - 2016-07-11 14:46 - 0005632 _____ () C:\Users\Claudio\AppData\Local\Temp\lehnelq3.dll 2016-09-25 17:27 - 2005-05-03 17:37 - 0032768 _____ () C:\Users\Claudio\AppData\Local\Temp\shutdown1474835272.exe 2016-04-12 16:50 - 2016-04-12 16:52 - 42743928 _____ (Skype Technologies S.A.) C:\Users\Claudio\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap ====================== (Não há correção automática para arquivos que não passaram na verificação.) C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente C:\Windows\explorer.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente C:\Windows\system32\services.exe => O arquivo é assinado digitalmente C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente C:\Windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente C:\Windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente LastRegBack: 2016-09-25 02:22 ==================== Fim de FRST.txt ============================