Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 20-05-2017 Executado por CASA (administrador) em CASA-PC (21-05-2017 21:08:01) Executando a partir de C:\Users\CASA\Downloads Perfis Carregados: CASA (Perfis Disponíveis: CASA) Platform: Windows 7 Ultimate (X64) Idioma: Português (Brasil) Internet Explorer Versão 8 (Navegador padrão: Chrome) Modo da Inicialização: Normal Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registro (Whitelisted) ==================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [296216 2015-09-25] (Intel Corporation) HKU\S-1-5-21-510531075-749168698-4211684673-1000\...\MountPoints2: {08071d49-3e71-11e7-aac3-806e6f6e6963} - E:\setup.exe ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Tcpip\Parameters: [DhcpNameServer] 192.168.7.4 Tcpip\..\Interfaces\{458CD514-E49C-4C16-833E-9882267427EB}: [DhcpNameServer] 192.168.7.4 Internet Explorer: ================== SearchScopes: HKU\S-1-5-21-510531075-749168698-4211684673-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-13] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-13] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-13] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-13] (Microsoft Corporation) FireFox: ======== FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-21] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-21] (Google Inc.) Chrome: ======= CHR Profile: C:\Users\CASA\AppData\Local\Google\Chrome\User Data\Default [2017-05-21] CHR Extension: (Google Apresentações) - C:\Users\CASA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-05-21] CHR Extension: (Google Docs) - C:\Users\CASA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-05-21] CHR Extension: (Google Drive) - C:\Users\CASA\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-05-21] CHR Extension: (YouTube) - C:\Users\CASA\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-05-21] CHR Extension: (Planilhas do Google) - C:\Users\CASA\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-05-21] CHR Extension: (Documentos Google off-line) - C:\Users\CASA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-21] CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\CASA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-05-21] CHR Extension: (Gmail) - C:\Users\CASA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-05-21] CHR Extension: (Chrome Media Router) - C:\Users\CASA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-21] ==================== Serviços (Whitelisted) ==================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-13] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) ==================== Um Mês Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2017-05-22 00:01 - 2017-05-21 19:22 - 00000000 ____D C:\Windows\Panther 2017-05-21 22:22 - 2017-05-21 22:22 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-05-21 22:22 - 2017-05-21 19:26 - 00000000 ____D C:\Program Files (x86)\Realtek 2017-05-21 22:22 - 2015-12-22 17:02 - 00116304 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll 2017-05-21 22:21 - 2015-09-25 07:17 - 00805616 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3xhc.sys 2017-05-21 22:21 - 2015-09-25 07:17 - 00394992 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hub.sys 2017-05-21 22:20 - 2017-05-21 22:20 - 00000000 ____D C:\Program Files (x86)\Intel 2017-05-21 22:20 - 2017-05-21 22:20 - 00000000 ____D C:\Intel 2017-05-21 21:08 - 2017-05-21 21:08 - 00005779 _____ C:\Users\CASA\Downloads\FRST.txt 2017-05-21 21:07 - 2017-05-21 21:08 - 00000000 ____D C:\FRST 2017-05-21 21:06 - 2017-05-21 21:07 - 02429952 _____ (Farbar) C:\Users\CASA\Downloads\FRST64 (1).exe 2017-05-21 21:06 - 2017-05-21 21:06 - 02429952 _____ (Farbar) C:\Users\CASA\Downloads\FRST64.exe 2017-05-21 21:03 - 2017-05-21 21:05 - 14572000 _____ (Microsoft Corporation) C:\Users\CASA\Downloads\vc_redist.x64.exe 2017-05-21 21:03 - 2017-05-21 21:03 - 01034556 _____ C:\Users\CASA\Downloads\Windows6.1-KB2999226-x64 (1).msu 2017-05-21 21:00 - 2017-05-21 21:02 - 02786824 _____ (DLL-Files.com Client ) C:\Users\CASA\Downloads\clientsetup_d-0.exe 2017-05-21 20:59 - 2017-05-21 20:59 - 01034556 _____ C:\Users\CASA\Downloads\Windows6.1-KB2999226-x64.msu 2017-05-21 20:24 - 2017-05-21 21:05 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache 2017-05-21 20:24 - 2017-05-21 21:05 - 00000000 ____D C:\ProgramData\Package Cache 2017-05-21 20:23 - 2017-05-21 20:23 - 00000000 ____D C:\Users\CASA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kodi 2017-05-21 20:23 - 2017-05-21 20:23 - 00000000 ____D C:\Program Files (x86)\Kodi 2017-05-21 20:20 - 2017-05-21 20:20 - 83845508 _____ (XBMC-Foundation) C:\Users\CASA\Downloads\Baixaki_kodi.exe 2017-05-21 20:01 - 2017-05-21 20:01 - 01784926 _____ C:\Users\CASA\Downloads\WLOADER - TPG.zip 2017-05-21 20:01 - 2017-05-21 20:01 - 01784926 _____ C:\Users\CASA\Downloads\WLOADER - TPG (2).zip 2017-05-21 20:01 - 2017-05-21 20:01 - 01784926 _____ C:\Users\CASA\Downloads\WLOADER - TPG (1).zip 2017-05-21 20:01 - 2017-05-21 20:01 - 00000000 ____D C:\Users\CASA\Downloads\WLOADER - TPG (2) 2017-05-21 19:59 - 2017-05-21 19:59 - 00000000 ____D C:\3afc37f9b720a8b453c2e2 2017-05-21 19:57 - 2017-05-21 19:57 - 01878253 _____ (Program Stub ) C:\Users\CASA\Downloads\Baixaki_kodi_3686374235.exe 2017-05-21 19:49 - 2017-05-21 19:59 - 33273108 _____ C:\Users\CASA\Downloads\Intel(R)_ME_11.0_Consumer_11.0.0.1194 (1).zip 2017-05-21 19:47 - 2017-05-21 19:52 - 02588291 _____ C:\Users\CASA\Downloads\Chipset_10.1.1.13_Public.zip 2017-05-21 19:47 - 2017-05-21 19:47 - 09871455 _____ C:\Users\CASA\Downloads\Realtek RTL8111H.zip 2017-05-21 19:47 - 2017-05-21 19:47 - 05415167 _____ C:\Users\CASA\Downloads\Intel_USB_3.0_xHC_Driver_Skylake_MR2_PV_4.0.2.42.zip 2017-05-21 19:29 - 2017-05-21 19:29 - 00002265 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-05-21 19:29 - 2017-05-21 19:29 - 00002253 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-05-21 19:28 - 2017-05-21 19:40 - 00000000 ____D C:\Users\CASA\AppData\Local\Google 2017-05-21 19:28 - 2017-05-21 19:29 - 00000000 ____D C:\Program Files (x86)\Google 2017-05-21 19:28 - 2017-05-21 19:28 - 00003500 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2017-05-21 19:28 - 2017-05-21 19:28 - 00003372 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2017-05-21 19:28 - 2017-05-21 19:28 - 00000000 ____D C:\Users\CASA\AppData\Local\Deployment 2017-05-21 19:28 - 2017-05-21 19:28 - 00000000 ____D C:\Users\CASA\AppData\Local\Apps\2.0 2017-05-21 19:26 - 2015-12-22 17:02 - 01026304 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2017-05-21 19:26 - 2015-12-22 17:02 - 00082544 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll 2017-05-21 19:24 - 2017-05-21 19:24 - 00057560 _____ C:\Users\CASA\AppData\Local\GDIPFONTCACHEV1.DAT 2017-05-21 19:23 - 2017-05-21 19:23 - 00001419 _____ C:\Users\CASA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2017-05-21 19:23 - 2017-05-21 19:23 - 00001385 _____ C:\Users\CASA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk 2017-05-21 19:22 - 2017-05-21 19:23 - 00000000 ____D C:\Users\CASA 2017-05-21 19:22 - 2017-05-21 19:22 - 00000020 ___SH C:\Users\CASA\ntuser.ini 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas músicas 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas imagens 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Meus vídeos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Histórico 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Dados de aplicativos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Usuário Padrão 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Todos os Usuários\Modelos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Todos os Usuários\Menu Iniciar 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Todos os Usuários\Favoritos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Todos os Usuários\Documentos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Todos os Usuários\Dados de aplicativos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Todos os Usuários 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Public\Documents\Minhas músicas 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Public\Documents\Minhas imagens 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Public\Documents\Meus vídeos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\Modelos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\Meus documentos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\Menu Iniciar 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\Documents\Minhas músicas 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\Documents\Minhas imagens 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\Documents\Meus vídeos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\Dados de aplicativos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\Configurações locais 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\AppData\Local\Histórico 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dados de aplicativos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\Ambiente de rede 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default\Ambiente de impressão 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default User\Documents\Minhas músicas 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default User\Documents\Minhas imagens 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default User\Documents\Meus vídeos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Histórico 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Dados de aplicativos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\Modelos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\Meus documentos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\Menu Iniciar 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\Documents\Minhas músicas 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\Documents\Minhas imagens 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\Documents\Meus vídeos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\Dados de aplicativos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\Configurações locais 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\AppData\Roaming\Microsoft\Windows\Start Menu\Programas 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\AppData\Local\Histórico 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\AppData\Local\Dados de aplicativos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\Ambiente de rede 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Users\CASA\Ambiente de impressão 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\ProgramData\Modelos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programas 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\ProgramData\Menu Iniciar 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\ProgramData\Favoritos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\ProgramData\Documentos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\ProgramData\Dados de aplicativos 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Program Files\Common Files\Sistema 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Program Files\Arquivos Comuns 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 _SHDL C:\Arquivos de Programas 2017-05-21 19:22 - 2017-05-21 19:22 - 00000000 ____D C:\Users\CASA\AppData\Local\VirtualStore 2017-05-21 19:22 - 2009-07-14 04:45 - 00000000 ____D C:\Users\CASA\AppData\Roaming\Media Center Programs 2017-05-21 19:03 - 2017-05-21 19:03 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk 2017-05-21 19:03 - 2017-05-21 19:03 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk ==================== Um Mês Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2017-05-22 00:00 - 2009-07-14 02:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2017-05-21 20:08 - 2009-07-14 01:45 - 00017136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-05-21 20:08 - 2009-07-14 01:45 - 00017136 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-05-21 20:07 - 2009-07-29 13:08 - 00654272 _____ C:\Windows\system32\prfh0416.dat 2017-05-21 20:07 - 2009-07-29 13:08 - 00124724 _____ C:\Windows\system32\prfc0416.dat 2017-05-21 20:07 - 2009-07-14 02:13 - 01491932 _____ C:\Windows\system32\PerfStringBackup.INI 2017-05-21 20:07 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\inf 2017-05-21 20:02 - 2009-07-14 02:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-05-21 19:23 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\rescache 2017-05-21 19:22 - 2009-07-14 00:20 - 00000000 ____D C:\Program Files\Windows NT 2017-05-21 19:05 - 2009-07-14 01:45 - 00274824 _____ C:\Windows\system32\FNTCACHE.DAT 2017-05-21 19:03 - 2009-07-14 02:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2017-05-21 19:03 - 2009-07-14 00:20 - 00000000 ____D C:\Windows\system32\sysprep 2017-05-21 19:02 - 2009-07-14 04:46 - 00000000 ____D C:\Windows\CSC ==================== Bamital & volsnap ====================== (Não há correção automática para arquivos que não passaram na verificação.) C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\wininit.exe => O arquivo é assinado digitalmente C:\Windows\explorer.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente C:\Windows\system32\services.exe => O arquivo é assinado digitalmente C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente C:\Windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente C:\Windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente C:\Windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente LastRegBack: 2017-05-21 19:44 ==================== Fim de FRST.txt ============================