Resultado do exame Adicional Farbar Recovery Scan Tool (x86) Versão: 18-07-2017 Executado por Camila (21-07-2017 11:45:02) Executando a partir de C:\Users\Camila\Downloads Microsoft Windows 7 Ultimate (X86) (2014-08-26 18:57:58) Modo da Inicialização: Normal ========================================================== ==================== Contas: ============================= Administrador (S-1-5-21-1991832834-588285413-1918845543-500 - Administrator - Disabled) Camila (S-1-5-21-1991832834-588285413-1918845543-1000 - Administrator - Enabled) => C:\Users\Camila Convidado (S-1-5-21-1991832834-588285413-1918845543-501 - Limited - Enabled) => C:\Users\Convidado ==================== Central de Segurança ======================== (Se uma entrada for incluída na fixlist, será removida.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Programas Instalados ====================== (Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.) Adobe Acrobat Reader DC - Português (HKLM\...\{AC76BA86-7AD7-1046-7B44-AC0F074E4100}) (Version: 17.009.20058 - Adobe Systems Incorporated) Assistente de Início de Sessão do Windows Live (HKLM\...\{28DA1AA2-07F2-4451-A28B-A6A01A9CE8E9}) (Version: 5.000.818.5 - Microsoft Corporation) Atheros Driver Installation Program (HKLM\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Atheros) Atualização do produto Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0416-0000-0000000FF1CE}_ENTERPRISE_{717C9095-8AAE-41CB-B046-BD6E8399F4F3}) (Version: - Microsoft) Atualização do produto Microsoft Office Outlook 2007 Help (KB963677) (HKLM\...\{90120000-001A-0416-0000-0000000FF1CE}_ENTERPRISE_{5016CB22-B9A7-44FB-AA72-AF28B27B15EA}) (Version: - Microsoft) Atualização do produto Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0416-0000-0000000FF1CE}_ENTERPRISE_{BE3A7C0C-0081-4694-B5F9-980DD66BDDF8}) (Version: - Microsoft) Atualização do produto Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0416-0000-0000000FF1CE}_ENTERPRISE_{7297E3A9-FCD4-4E0E-A306-7A90359E50E3}) (Version: - Microsoft) AutoCAD 2010 - English (HKLM\...\{5783F2D7-8001-0409-0002-0060B0CE6BBA}) (Version: 18.0.55.0 - Autodesk) Hidden AutoCAD 2010 - English (HKLM\...\AutoCAD 2010 - English) (Version: 18.0.55.0 - Autodesk) AutoCAD 2010 Language Pack - English (HKLM\...\{5783F2D7-8001-0409-1002-0060B0CE6BBA}) (Version: 18.0.55.0 - Autodesk) Hidden Autodesk Design Review 2010 (HKLM\...\{55D9E026-DCB0-46FF-B60A-68B972228CF6}) (Version: 10.0.0.108 - Autodesk, Inc.) Hidden Autodesk Design Review 2010 (HKLM\...\Autodesk Design Review 2010) (Version: 10.0.0.108 - Autodesk, Inc.) Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 17.5.2303 - AVAST Software) Ferramenta de Carregamento do Windows Live (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) FormatFactory 3.3.5.0 (HKLM\...\FormatFactory) (Version: 3.3.5.0 - Format Factory) Galeria de Fotografias do Windows Live (HKLM\...\{B37F12C4-1ED6-4E72-99CD-8D9415FE6A06}) (Version: 14.0.8081.709 - Microsoft Corporation) Hidden GIMP 2.8.20 (HKLM\...\GIMP-2_is1) (Version: 2.8.20 - The GIMP Team) Google Chrome (HKLM\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.) Google SketchUp Pro 8 (HKLM\...\{3AB65E95-37D6-4DD7-8862-29AED3AFD54B}) (Version: 3.0.3117 - Google, Inc.) Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden Google Update Helper (HKLM\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden Guardião - Itaú 30 horas (HKLM\...\{70e5f739-1d2a-40ae-bbc9-4b3e6af4c831}_is1) (Version: 3.10.0.1 - ) HP LaserJet Professional P1100-P1560-P1600 Series (HKLM\...\HP LaserJet Professional P1100-P1560-P1600 Series) (Version: - ) Intel(R) Processor Graphics (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3372 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Módulo de Proteção - Banco Santander (Brasil) S.A. (HKLM\...\{83033d93-48d0-48fc-9c5b-82e57e7e0dd6}_is1) (Version: 3.12.1.2 - ) MPC-HC 1.7.7 (HKLM\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.7.7 - MPC-HC Team) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 7 Ultra Edition (HKLM\...\{CF097717-F174-4144-954A-FBC4BF301046}) (Version: 7.02.9753 - Nero AG) PhotoScape (HKLM\...\PhotoScape) (Version: - ) Reimage Repair (HKLM\...\Reimage Repair) (Version: 1.8.6.6 - Reimage) <==== ATENÇÃO SafeZone Stable 3.55.2393.609 (HKLM\...\SafeZone 3.55.2393.609) (Version: 3.55.2393.609 - Avast Software) Hidden Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.63.0 - Samsung Electronics Co., Ltd.) Suplemento Microsoft Salvar como PDF ou XPS para programas do Microsoft Office 2007 (HKLM\...\{90120000-00B2-0416-0000-0000000FF1CE}) (Version: 12.0.4518.1019 - Microsoft Corporation) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) V-Ray for SketchUp (HKLM\...\V-Ray for SketchUp 1.48.89) (Version: 1.48.89 - ASGVIS) Warsaw 1.16.0.89 32 bits (HKLM\...\{20E60725-16C8-4FB9-8BC2-AF92C5F8D06D}_is1) (Version: 1.16.0.89 - GAS Tecnologia) Weather Lite 2.0.1.5000183 (HKLM\...\WeatherTool) (Version: 2.0.1.5000183 - ShenZhen Qianhailewang Technology Co,.Ltd) Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live Sync (HKLM\...\{34795BBE-39E4-41B6-997A-B88FD7306562}) (Version: 14.0.8089.726 - Microsoft Corporation) WinRAR 5.40 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) ==================== Exame Personalizado CLSID (Whitelisted): ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{00B7E0AB-817A-44AD-A04B-D1148D524136}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{0783EB25-59F8-4F02-B6B0-F1D4349F0001}\InprocServer32 -> C:\Users\Camila\AppData\Local\GAS Tecnologia\GBBD\npsf_abn.dll (GAS Tecnologia) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{0783EB25-59F8-4F02-B6B0-F1D4349F0013}\InprocServer32 -> C:\Users\Camila\AppData\Local\GAS Tecnologia\GBBD\npsf_uni.dll (GAS Tecnologia) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{0783EB25-59F8-4F02-B6B1-F1D4349F0001}\InprocServer32 -> C:\Users\Camila\AppData\Local\GAS Tecnologia\GBBD\npsf_abn.dll (GAS Tecnologia) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{0783EB25-59F8-4F02-B6B1-F1D4349F0013}\InprocServer32 -> C:\Users\Camila\AppData\Local\GAS Tecnologia\GBBD\npsf_uni.dll (GAS Tecnologia) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{6D7AE628-FF41-4CD3-91DD-34825BB1A251}\localserver32 -> C:\Program Files\AutoCAD 2010\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{7C6E29BC-8B8B-4C3D-859E-AF6CD158BE0F}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{88D969C0-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{88D969C1-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{88D969C2-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{88D969C3-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{88D969C4-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{88D969C5-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{88D969C6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{88D969C8-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{88D969C9-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{88D969CA-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{88D969D6-F192-11D4-A65F-0040963251E5}\InprocServer32 -> C:\Windows\system32\msxml4.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\AutoCAD 2010\acad.exe (Autodesk, Inc.) CustomCLSID: HKU\S-1-5-21-1991832834-588285413-1918845543-1000_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\AutoCAD 2010\acadficn.dll (Autodesk, Inc.) ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-07-20] (AVAST Software) ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2009-02-09] (Autodesk, Inc.) ShellIconOverlayIdentifiers: [BaiduAntivirusIconLock] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CC} => C:\Program Files\Baidu Security\Baidu Antivirus\BavShx.dll -> Nenhum Arquivo ContextMenuHandlers01: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2009-02-09] (Autodesk) ContextMenuHandlers01: [Autodesk.DWF.ContextMenu] -> {6C18531F-CA85-45F7-8278-FF33CF0A5964} => C:\Program Files\Common Files\Autodesk Shared\DWF Common\DWFShellExtension.dll [2009-01-13] (Autodesk, Inc.) ContextMenuHandlers01: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-07-20] (AVAST Software) ContextMenuHandlers01: [Baidu_Scan] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CB} => C:\Program Files\Baidu Security\Baidu Antivirus\BavShx.dll -> Nenhum Arquivo ContextMenuHandlers01: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll [2007-06-28] (Nero AG) ContextMenuHandlers01: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal) ContextMenuHandlers02: [Baidu_Scan] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CB} => C:\Program Files\Baidu Security\Baidu Antivirus\BavShx.dll -> Nenhum Arquivo ContextMenuHandlers03: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-07-20] (AVAST Software) ContextMenuHandlers04: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal) ContextMenuHandlers05: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2014-08-26] (Intel Corporation) ContextMenuHandlers06: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2017-07-20] (AVAST Software) ContextMenuHandlers06: [Baidu_Scan] -> {0A93904A-BB1E-4a0c-9753-B57B9AE272CB} => C:\Program Files\Baidu Security\Baidu Antivirus\BavShx.dll -> Nenhum Arquivo ContextMenuHandlers06: [WinRAR] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal) ==================== Tarefas Agendadas (Whitelisted) ============= (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) Task: {6393A0EF-1975-48E7-974B-B7BBF0AEA9C0} - System32\Tasks\avastBCLRestartS-1-5-21-1991832834-588285413-1918845543-1000 => C:\Program Files\Google\Chrome\Application\chrome.exe Task: {6888B3BD-69FD-498D-807B-B1C40996D65F} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-07-20] (AVAST Software) Task: {6AD9DA0C-49E1-4232-83E9-A96921647CA0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {75E53446-31CD-4F3C-BDBE-2DFE5BAC2881} - System32\Tasks\{5F064F67-EE39-4988-B978-A2B405E94E4F} => C:\Windows\system32\pcalua.exe -a "F:\arquivos do HD BACKUP\PROGRAMAS\, corel + prhotoshop + autocad\autocad 2010\AutoCAD_2010_English_SLD_Win_32bit.exe" -d "F:\arquivos do HD BACKUP\PROGRAMAS\, corel + prhotoshop + autocad\autocad 2010" Task: {7B807C13-BFD2-4FA4-9B5D-C3AB9FFBF1BF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {A38E516C-CDB9-4133-806D-5C374157C040} - System32\Tasks\Reimage Reminder => C:\Program Files\Reimage\Reimage Repair\ReimageReminder.exe [2017-07-03] (Reimage ltd.) <==== ATENÇÃO Task: {A4790E05-C469-4DC2-9F51-3020F8E676C0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {B5640079-DA70-45A5-BA38-D13520D02624} - System32\Tasks\Microsoft\Windows\Setup\EOSNotify => C:\Windows\system32\EOSNotify.exe [2016-06-25] (Microsoft Corporation) Task: {D8738C2E-CF20-408E-9618-7165A6111465} - System32\Tasks\SafeZone scheduled Autoupdate 1496862016 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-06-13] (Avast Software) Task: {E9DAEF1D-A2AC-494C-BC73-ACC3D32627BC} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [2017-05-14] (Reimage®) <==== ATENÇÃO (Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.) ==================== Atalhos & WMI ======================== (As entradas podem ser listadas para serem restauradas ou removidas.) ShortcutWithArgument: C:\Users\Camila\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Pessoa 2 - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1" ==================== Módulos Carregados (Whitelisted) ============== 2017-07-20 13:29 - 2017-07-20 13:29 - 00170224 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2017-07-20 13:29 - 2017-07-20 13:29 - 00192664 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll 2017-07-20 13:29 - 2017-07-20 13:29 - 00224256 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2017-07-21 10:24 - 2017-07-21 10:24 - 05784064 _____ () C:\Program Files\AVAST Software\Avast\defs\17072100\algo.dll 2017-07-20 13:29 - 2017-07-20 13:29 - 00689272 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2017-07-20 13:29 - 2017-07-20 13:29 - 00231664 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll 2017-02-03 09:58 - 2011-04-02 15:03 - 00151552 _____ () C:\Windows\System32\HP1100LM.DLL 2017-02-03 09:59 - 2011-04-02 15:03 - 00069632 _____ () C:\Windows\system32\spool\PRTPROCS\W32X86\HP1100PP.DLL 2017-03-31 01:01 - 2017-03-31 01:01 - 00149136 _____ () C:\Program Files\WeatherTool\2.0.1.5000183\WeatherService.exe 2017-03-31 01:01 - 2017-03-31 01:01 - 00575120 _____ () C:\Program Files\WeatherTool\2.0.1.5000183\Updata.dll 2017-07-20 13:29 - 2017-07-20 13:29 - 00134928 _____ () c:\Program Files\AVAST Software\Avast\vaarclient.dll 2017-03-31 01:01 - 2017-03-31 01:01 - 01021072 _____ () C:\Program Files\WeatherTool\2.0.1.5000183\WeatherEntryDll.dll 2017-07-20 13:29 - 2017-07-20 13:29 - 01065936 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll 2017-07-05 11:32 - 2017-07-05 11:32 - 67109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2017-07-20 13:29 - 2017-07-20 13:29 - 00292920 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2017-06-29 12:55 - 2017-06-22 23:21 - 02877272 _____ () C:\Program Files\Google\Chrome\Application\59.0.3071.115\libglesv2.dll 2017-06-29 12:55 - 2017-06-22 23:21 - 00086360 _____ () C:\Program Files\Google\Chrome\Application\59.0.3071.115\libegl.dll 2010-08-26 17:24 - 2010-08-26 17:24 - 01597440 _____ () C:\Program Files\Google\Google SketchUp 8\IGCore.dll 2010-08-26 17:24 - 2010-08-26 17:24 - 01724416 _____ () C:\Program Files\Google\Google SketchUp 8\IGSg.dll 2010-08-26 17:24 - 2010-08-26 17:24 - 00778240 _____ () C:\Program Files\Google\Google SketchUp 8\IGAttrs.dll 2010-08-26 17:24 - 2010-08-26 17:24 - 03362816 _____ () C:\Program Files\Google\Google SketchUp 8\IGGfx.dll 2010-08-26 17:24 - 2010-08-26 17:24 - 00380928 _____ () C:\Program Files\Google\Google SketchUp 8\IGUtils.dll 2010-08-26 17:24 - 2010-08-26 17:24 - 00819200 _____ () C:\Program Files\Google\Google SketchUp 8\IGMath.dll 2010-08-26 17:31 - 2010-08-26 17:31 - 00192512 _____ () C:\Program Files\Google\Google SketchUp 8\alchemyext.dll 2010-08-26 17:23 - 2010-08-26 17:23 - 00892998 _____ () C:\Program Files\Google\Google SketchUp 8\msvcrt-ruby18.dll 2014-08-27 15:37 - 2010-07-09 18:08 - 00015872 _____ () C:\Program Files\Google\Google SketchUp 8\Plugins\RubyWinFunc.so 2014-08-27 15:37 - 2010-07-09 18:11 - 00110592 _____ () C:\ProgramData\ASGVIS\VfS\RubyToPython.so 2014-08-27 15:37 - 2009-11-17 18:45 - 02109440 _____ () C:\Program Files\Google\Google SketchUp 8\QtCore4.dll 2014-08-27 15:37 - 2010-07-09 18:12 - 01036288 _____ () C:\ProgramData\ASGVIS\VfS\VfSbin2xml.so 2014-08-27 15:38 - 2009-11-17 17:15 - 01191936 _____ () C:\ProgramData\ASGVIS\Python26\Lib\site-packages\PyQt4\QtCore.pyd 2014-08-27 15:38 - 2009-11-17 17:02 - 00069632 _____ () C:\ProgramData\ASGVIS\Python26\Lib\site-packages\sip.pyd 2014-08-27 15:38 - 2009-11-17 17:33 - 04513792 _____ () C:\ProgramData\ASGVIS\Python26\Lib\site-packages\PyQt4\QtGui.pyd 2014-08-27 15:38 - 2009-11-17 18:57 - 07495680 _____ () C:\ProgramData\ASGVIS\Python26\Lib\site-packages\PyQt4\QtGui4.dll 2014-08-27 15:38 - 2009-04-07 17:50 - 00057344 _____ () C:\ProgramData\ASGVIS\Python26\DLLS\_socket.pyd 2014-08-27 15:38 - 2009-07-30 19:26 - 00018432 _____ () C:\ProgramData\ASGVIS\Python26\Lib\site-packages\Ft\Xml\Lib\XmlString.pyd 2014-08-27 15:38 - 2009-04-07 17:50 - 00139264 _____ () C:\ProgramData\ASGVIS\Python26\DLLS\pyexpat.pyd 2014-08-27 15:38 - 2009-07-30 19:27 - 00007680 _____ () C:\ProgramData\ASGVIS\Python26\Lib\site-packages\Ft\Lib\_win32con.pyd 2014-08-27 15:38 - 2009-07-30 19:26 - 00015872 _____ () C:\ProgramData\ASGVIS\Python26\Lib\site-packages\Ft\Xml\Lib\cStreamWriter.pyd 2014-08-27 15:38 - 2009-07-30 19:27 - 00294912 _____ () C:\ProgramData\ASGVIS\Python26\Lib\site-packages\Ft\Xml\cDomlettec.pyd 2014-08-27 15:38 - 2009-11-17 17:33 - 00007168 _____ () C:\ProgramData\ASGVIS\Python26\Lib\site-packages\PyQt4\Qt.pyd 2014-08-27 15:37 - 2010-07-09 18:11 - 01257472 _____ () C:\ProgramData\ASGVIS\VfS\PyVRay.pyd 2014-08-27 15:37 - 2010-06-02 17:23 - 00009728 _____ () C:\ProgramData\ASGVIS\VfS\Win32HookMsgProc.pyd 2014-08-27 15:37 - 2009-10-09 10:29 - 00073728 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_AAFilters.dll 2014-08-27 15:37 - 2010-04-19 10:59 - 00069632 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_ASGVISNode.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BakeView.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 01495040 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BitmapBuffer.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00077824 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFBlinn.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00114688 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFBump.dll 2014-08-27 15:37 - 2010-03-24 19:39 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFDiffuse.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFGlass.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFLayered.dll 2014-08-27 15:37 - 2010-03-24 19:39 - 00061440 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFLight.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00061440 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFMirror.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFPhong.dll 2014-08-27 15:37 - 2010-07-07 20:36 - 00069632 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFReflection.dll 2014-08-27 15:37 - 2010-03-24 19:39 - 00077824 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFRefraction.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00094208 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFSampled.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00663552 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFSimbiont.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00069632 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFSSS.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00094208 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_BRDFSSS2.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_cameradome.dll 2014-08-27 15:37 - 2010-05-07 17:10 - 00073728 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_CameraPhysical.dll 2014-08-27 15:37 - 2010-03-24 19:38 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_GeomInfinitePlane.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00237568 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_GeomMeshFile.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00221184 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_GeomMeshTest.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00118784 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_GeomParticleInstance.dll 2014-08-27 15:37 - 2010-07-07 20:36 - 00077824 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_GeomPlane.dll 2014-08-27 15:37 - 2010-07-07 20:36 - 00073728 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_GeomSphere.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00221184 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_GeomStaticDisplacedMesh.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00192512 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_GeomStaticMesh.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00385024 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_GeomStaticNurbs.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00241664 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_GeomStaticSmoothedMesh.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_Instancer.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_LightAmbient.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00081920 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_LightDirect.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00110592 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_LightDome.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00098304 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_LightIES.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00081920 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_LightOmni.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00122880 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_LightRectangle.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00098304 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_LightSphere.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00086016 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_LightSpot.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00061440 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MayaLightDirect.dll 2014-08-27 15:37 - 2010-03-24 19:39 - 00061440 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_Mtl2Sided.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00061440 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlAlphaContribution.dll 2014-08-27 15:37 - 2010-06-02 16:50 - 00073728 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlAngleBlend.dll 2014-08-27 15:37 - 2010-06-30 19:06 - 00086016 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlASGVIS.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00114688 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlBump.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlDiffuse.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlDoubleSided.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00061440 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlLayeredBRDF.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlMaterialID.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlMulti.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlOverride.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00061440 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlRenderStats.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlRoundEdges.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlSingleBRDF.dll 2014-08-27 15:37 - 2010-05-17 18:25 - 00049152 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlSkp2Sided.dll 2014-08-27 15:37 - 2010-06-25 17:04 - 00073728 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlToon.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00094208 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_MtlWrapper.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00114688 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_NewGI.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_Node.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00094208 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_RenderChannelColor.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00073728 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_RenderChannelMultiMatte.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00069632 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_RenderView.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 01761280 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_RTEngine.dll 2014-08-27 15:37 - 2010-03-24 19:39 - 00131072 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_Settings.dll 2014-08-27 15:37 - 2010-03-24 19:38 - 00049152 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_SettingsDR.dll 2014-08-27 15:37 - 2010-03-24 19:38 - 00061440 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_SettingsImageFilter.dll 2014-08-27 15:37 - 2010-03-24 19:39 - 00094208 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_SettingsRenderChannels.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00114688 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_sunsky.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexAColor.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00098304 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexBitmap.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexBlend.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00098304 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexBulge.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00114688 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexCellular.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00102400 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexChecker.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00061440 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexClamp.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00102400 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexCloth.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexDirt.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_texedges.dll 2014-08-27 15:37 - 2010-03-24 19:39 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexFresnel.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00106496 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexGranite.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00102400 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexGrid.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexInvert.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00094208 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexLayered.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00106496 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexLeather.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00102400 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexMarble.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00335872 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexMax.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00212992 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexMaya.dll 2014-08-27 15:37 - 2010-03-24 19:38 - 00069632 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexNoise.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_texparticle.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00110592 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexRamp.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00077824 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexRemap.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00098304 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexRock.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00143360 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexSampler.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00098304 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexSnow.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexUVW.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexWater.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00102400 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexWood.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 01310720 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_TexXSI.dll 2014-08-27 15:37 - 2010-03-24 19:38 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_UVWGenChannel.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_UVWGenEnvironment.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_UVWGenExplicit.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_UVWGenObject.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_UVWGenPlanarWorld.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00098304 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_UVWGenProjection.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00065536 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_VolumeFog.dll 2014-08-27 15:37 - 2009-10-09 10:29 - 00057344 _____ () C:\ProgramData\ASGVIS\VfS\vrayplugins\vray_VolumeMulti.dll ==================== Alternate Data Streams (Whitelisted) ========= (Se uma entrada for incluída na fixlist, somente o ADS será removido.) AlternateDataStreams: C:\Program Files\GbPlugin:IncompleteStartProcessProtection.cnt [8] AlternateDataStreams: C:\Program Files\GbPlugin:u6eBQrM0Z2K3FKLVBMG8dY3IkKT2rqFO+Sf68h8fDg== [32] AlternateDataStreams: C:\Windows\System32:96A12C7C_Abn.gbp [2] AlternateDataStreams: C:\Windows\System32:96A12C7C_Bb.gbp [2] AlternateDataStreams: C:\Windows\System32:96A12C7C_Cef.gbp [2] AlternateDataStreams: C:\Windows\System32:96A12C7C_Uni.gbp [2] AlternateDataStreams: C:\Windows\system32\drivers:GbpKmAp.lst [718] AlternateDataStreams: C:\Windows\system32\Drivers\wsddfac.sys:X5ZN8aGXs4 [2174] AlternateDataStreams: C:\ProgramData\GbPlugin:IncompleteStartGbprcm.cnt [10] AlternateDataStreams: C:\Users\Todos os Usuários\GbPlugin:IncompleteStartGbprcm.cnt [10] ==================== Modo de Segurança (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O valor "AlternateShell" será restaurado.) ==================== Associação (Whitelisted) =============== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido.) HKU\S-1-5-21-1991832834-588285413-1918845543-1000\Software\Classes\.scr: AutoCADScriptFile => C:\Windows\system32\notepad.exe "%1" ==================== Internet Explorer confiável/restrito =============== (Se uma entrada for incluída na fixlist, será removida do Registro.) IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\bancobrasil.com.br -> hxxps://www14.bancobrasil.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\bancoreal.com.br -> hxxp://www.bancoreal.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\bancosantander.com.br -> hxxp://www.bancosantander.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\bancosantander.com.br -> hxxps://www.bancosantander.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\bb.com.br -> hxxps://seg.bb.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\caixa.gov.br -> hxxps://imagem.caixa.gov.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\itau.com.br -> hxxps://bankline.itau.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\itau.com.br -> bankline.itau.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\itaupersonnalite.com.br -> hxxp://www.itaupersonnalite.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\realsecureweb.com.br -> hxxps://www.realsecureweb.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\santander.com.br -> www.santander.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\santander.com.br -> hxxp://www.santander.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\santanderempresarial.com.br -> www.santanderempresarial.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\santanderempresarial.com.br -> hxxp://www.santanderempresarial.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\santandernet.com.br -> www.santandernet.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\santandernet.com.br -> hxxps://www.santandernet.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\santandernetibe.com.br -> www.santandernetibe.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\santandernetibe.com.br -> hxxps://www.santandernetibe.com.br IE trusted site: HKU\S-1-5-21-1991832834-588285413-1918845543-1000\...\secureweb.com.br -> hxxps://www.secureweb.com.br ==================== Hosts Conteúdo: =============================== (Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.) 2009-07-13 23:04 - 2017-06-27 18:15 - 00000822 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Outras Áreas ============================ (Atualmente não há nenhuma correção automática para esta seção.) HKU\S-1-5-21-1991832834-588285413-1918845543-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Camila\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Firewall do Windows está habilitado. ==================== MSCONFIG/TASK MANAGER ítens desabilitados == MSCONFIG\Services: cphs => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: ICCS => 3 MSCONFIG\startupreg: HotKeysCmds => "C:\Windows\system32\hkcmd.exe" MSCONFIG\startupreg: IgfxTray => "C:\Windows\system32\igfxtray.exe" MSCONFIG\startupreg: Persistence => "C:\Windows\system32\igfxpers.exe" ==================== Regras do Firewall (Whitelisted) =============== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) FirewallRules: [{4803A0A9-0980-42B9-A6D6-102C15549303}] => (Allow) C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe FirewallRules: [TCP Query User{15140803-7140-4BBB-9219-E0E55CD16B16}C:\program files\google\google sketchup 8\sketchup.exe] => (Allow) C:\program files\google\google sketchup 8\sketchup.exe FirewallRules: [UDP Query User{E73F8DC8-F42C-40A0-B6A3-B412AD9938F8}C:\program files\google\google sketchup 8\sketchup.exe] => (Allow) C:\program files\google\google sketchup 8\sketchup.exe FirewallRules: [{8506CDDF-EB03-408D-B199-F02232FDBA5F}] => (Block) C:\program files\google\google sketchup 8\sketchup.exe FirewallRules: [{A8A2FB78-8274-48CD-9B29-F6CE13AEF3D8}] => (Block) C:\program files\google\google sketchup 8\sketchup.exe FirewallRules: [{0BEE50B1-146F-43DA-9CD6-63CCD4BF4992}] => (Allow) C:\Program Files\baidu\SparkSafe\Spark.exe FirewallRules: [{94B1BDC2-AD2F-473D-B5E7-725C6760B299}] => (Allow) C:\Program Files\baidu\SparkSafe\Spark.exe FirewallRules: [{B281459A-6EB5-456E-8BD7-2B8EFB033AEC}] => (Allow) C:\Program Files\baidu\SparkSafe\CrashReport.exe FirewallRules: [{E7C95DB2-1E95-4086-9DAB-893981EADD63}] => (Allow) C:\Program Files\baidu\SparkSafe\CrashReport.exe FirewallRules: [{737CA09D-BEF0-4BD4-9BAF-BFCF20BB46EE}] => (Allow) C:\Program Files\baidu\SparkSafe\bdtray.exe FirewallRules: [{795F0193-D90D-46A6-A5AE-9BE9F039DFDC}] => (Allow) C:\Program Files\baidu\SparkSafe\bdtray.exe FirewallRules: [{37EDBCFD-6467-4692-9B02-30852CDD22A5}] => (Allow) C:\Program Files\baidu\SparkSafe\CrashUL.exe FirewallRules: [{C1564097-9203-4D7E-BB60-93F7DE36C789}] => (Allow) C:\Program Files\baidu\SparkSafe\CrashUL.exe FirewallRules: [{18C5BC73-0F17-4B89-9463-4915BB3A0B04}] => (Allow) C:\Program Files\Diebold\Warsaw\core.exe FirewallRules: [{6BDC8353-FFF5-4AFB-8515-03B9BED1A01E}] => (Allow) C:\Program Files\baidu\Spark\Spark.exe FirewallRules: [{A60BF2CF-095B-4B24-B655-833B8AA1C5EA}] => (Allow) C:\Program Files\baidu\Spark\Spark.exe FirewallRules: [{152DBD54-F91F-414C-828D-E669865609BC}] => (Allow) C:\Program Files\baidu\Spark\bdtray.exe FirewallRules: [{D172D4E3-DC7F-4F97-974B-51619638A116}] => (Allow) C:\Program Files\baidu\Spark\bdtray.exe FirewallRules: [{42F22210-D689-453A-BA07-673B32FD304B}] => (Allow) C:\Program Files\Battle.net\Battle.net.exe FirewallRules: [{C27048D9-9286-4EFB-BA6B-4A0DB1382BF6}] => (Allow) C:\Program Files\Battle.net\Battle.net.exe FirewallRules: [{731F123D-D684-4637-8A3B-F558123D6744}] => (Allow) C:\Program Files\Hearthstone\Hearthstone.exe FirewallRules: [{4E65051D-87E2-4D8B-90B0-59CC05F3D0FA}] => (Allow) C:\Program Files\Hearthstone\Hearthstone.exe FirewallRules: [{E928A659-0042-43D4-9812-2B2118D64B33}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe FirewallRules: [{E580A251-A787-42E1-AFC7-007585D1CFA7}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.609\SZBrowser.exe FirewallRules: [{8C3CCBAA-0A01-47D7-B1F0-0272BB55D4AD}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.609_0\SZBrowser.exe ==================== Pontos de Restauração ========================= 27-10-2016 17:41:34 Ponto de Verificação Agendado 07-11-2016 18:13:57 Windows Update 08-11-2016 13:41:16 Windows Update 09-11-2016 18:21:23 Windows Update 10-11-2016 12:18:14 Windows Update 10-11-2016 17:46:26 Windows Update 11-11-2016 08:36:27 Windows Update 11-11-2016 08:47:17 Windows Update 11-11-2016 22:01:33 Windows Update 14-11-2016 10:14:06 Windows Update 21-11-2016 11:04:36 Ponto de Verificação Agendado 13-12-2016 17:43:27 Ponto de Verificação Agendado 15-12-2016 11:27:06 Windows Update 27-12-2016 10:08:27 Ponto de Verificação Agendado 03-01-2017 13:56:11 Ponto de Verificação Agendado 11-01-2017 15:26:36 Ponto de Verificação Agendado 22-01-2017 15:44:06 Ponto de Verificação Agendado 28-01-2017 22:58:31 Instalação de Pacote de Driver de Dispositivo: Diebold Network Monitor Serviço de Rede 04-02-2017 23:00:20 Ponto de Verificação Agendado 15-02-2017 15:41:02 Ponto de Verificação Agendado 01-03-2017 14:55:33 Ponto de Verificação Agendado 10-03-2017 13:00:24 Ponto de Verificação Agendado 09-06-2017 02:19:25 Ponto de Verificação Agendado 10-06-2017 10:10:37 Windows Update 21-06-2017 22:19:09 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 ==================== Dispositivos Apresentando Falhas No Gerenciador ============= Name: Teredo Tunneling Pseudo-Interface Description: Adaptador de Túnel Teredo da Microsoft Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. Name: Controlador de barramento SM Description: Controlador de barramento SM Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Controlador de comunicação PCI simples Description: Controlador de comunicação PCI simples Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Erros no Log de eventos: ========================= Erros em Aplicativos: ================== Error: (07/21/2017 10:43:18 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: O programa Setup.exe versão 10.0.30319.1 parou de interagir com o Windows e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique o histórico de problemas no painel de controle da Central de Ações. ID de Processo: ea4 Hora de Início: 01d30225b46ed047 Hora de Término: 13 Caminho do Aplicativo: D:\a43b616799c0641cedccce257b\Setup.exe Id do Relatório: Error: (07/20/2017 01:21:25 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: O programa Setup.exe versão 10.0.30319.1 parou de interagir com o Windows e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique o histórico de problemas no painel de controle da Central de Ações. ID de Processo: 5d4 Hora de Início: 01d3016cb4235a42 Hora de Término: 7 Caminho do Aplicativo: D:\a1cb14dfd14d8086080d\Setup.exe Id do Relatório: Error: (07/20/2017 12:10:38 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: O programa setup.exe versão 10.0.30319.1 parou de interagir com o Windows e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique o histórico de problemas no painel de controle da Central de Ações. ID de Processo: ae0 Hora de Início: 01d3015a6f0ee32c Hora de Término: 23 Caminho do Aplicativo: C:\Users\Camila\AppData\Local\Temp\sketchup_install\setup.exe Id do Relatório: Error: (07/18/2017 10:54:01 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome de aplicativo com falha: Explorer.EXE, versão: 6.1.7600.16385, carimbo de hora: 0x4a5bc60d Nome do módulo de falhas: ThumbsUp.dll, versão: 8.0.3117.0, carimbo de hora: 0x4c76f9ac Código de exceção: 0xc0000005 Deslocamento com falha: 0x0007acc4 Identificação do processo com falha: 0xe40 Hora de início do aplicativo com falha: 0x01d2ffc72524d661 Caminho do aplicativo com falha: C:\Windows\Explorer.EXE FCaminho do módulo de falhas: C:\Program Files\Google\Google SketchUp 8\LayOut\ThumbsUp.dll Identificação do Relatório: 8d3f8c57-6bc0-11e7-a46a-24f5aa555005 Error: (07/16/2017 01:09:26 AM) (Source: EventSystem) (EventID: 4621) (User: ) Description: O Sistema de Eventos COM+ não pôde remover o EventSystem.EventSubscription objeto {1052D246-11EF-4B7F-AE48-EDDE249F6923}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. Nome do objeto: Explorer Descrição do objeto: O HRESULT foi 80040206. Error: (07/14/2017 11:02:33 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: O programa SketchUp.exe versão 8.0.3117.0 parou de interagir com o Windows e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique o histórico de problemas no painel de controle da Central de Ações. ID de Processo: 1344 Hora de Início: 01d2fca9704b7479 Hora de Término: 16 Caminho do Aplicativo: C:\Program Files\Google\Google SketchUp 8\SketchUp.exe Id do Relatório: 0ac1187a-689d-11e7-a37e-24f5aa555005 Error: (07/14/2017 11:02:29 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: O programa SketchUp.exe versão 8.0.3117.0 parou de interagir com o Windows e foi fechado. Para ver se há mais informações disponíveis sobre o problema, verifique o histórico de problemas no painel de controle da Central de Ações. ID de Processo: ff0 Hora de Início: 01d2fca943023b68 Hora de Término: 159 Caminho do Aplicativo: C:\Program Files\Google\Google SketchUp 8\SketchUp.exe Id do Relatório: 0b8f19de-689d-11e7-a37e-24f5aa555005 Error: (07/12/2017 12:30:46 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1511) (User: Camila-PC) Description: O Windows não pode localizar o perfil local e está fazendo seu logon com um perfil temporário. As alterações que você fizer nesse perfil serão perdidas quando você fizer logoff. Error: (07/12/2017 12:30:46 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1515) (User: Camila-PC) Description: O Windows fez o backup deste perfil de usuário. O Windows tentará usar automaticamente esse perfil na próxima vez em que o usuário fizer logon. Error: (07/12/2017 12:30:46 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1502) (User: Camila-PC) Description: O Windows não pode carregar o perfil armazenado localmente. As possíveis causas do erro são direitos de segurança insuficientes ou um perfil local corrompido. DETALHE - O arquivo já está sendo usado por outro processo. Erros de Sistema: ============= Error: (07/21/2017 10:50:17 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Gbpddreg svc devido ao seguinte erro: O sistema não pode encontrar o arquivo especificado. Error: (07/21/2017 10:50:17 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Gbpddreg svc devido ao seguinte erro: O sistema não pode encontrar o arquivo especificado. Error: (07/21/2017 10:49:31 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Gbpddreg svc devido ao seguinte erro: O sistema não pode encontrar o arquivo especificado. Error: (07/21/2017 10:48:55 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Falha ao carregar o(s) seguinte(s) driver(s) de início do sistema ou de inicialização: gbpddreg Error: (07/21/2017 10:48:53 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Update Faster Light devido ao seguinte erro: O sistema não pode encontrar o arquivo especificado. Error: (07/21/2017 10:47:20 AM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: O serviço Windows Update não foi desligado corretamente após receber um controle de pré-desligamento. Error: (07/21/2017 10:32:12 AM) (Source: atapi) (EventID: 11) (User: ) Description: O driver detectou um erro de controlador em \Device\Ide\IdePort0. Error: (07/21/2017 10:29:50 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Gbpddreg svc devido ao seguinte erro: O sistema não pode encontrar o arquivo especificado. Error: (07/21/2017 10:29:49 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Gbpddreg svc devido ao seguinte erro: O sistema não pode encontrar o arquivo especificado. Error: (07/21/2017 10:26:24 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Gbpddreg svc devido ao seguinte erro: O sistema não pode encontrar o arquivo especificado. CodeIntegrity: =================================== Date: 2016-10-05 22:14:06.704 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wsddpp.sys because the set of per-page image hashes could not be found on the system. Date: 2016-10-05 22:14:01.649 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system. Date: 2016-10-05 07:10:00.331 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wsddpp.sys because the set of per-page image hashes could not be found on the system. Date: 2016-10-05 07:09:57.367 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system. Date: 2016-10-04 19:23:42.658 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wsddpp.sys because the set of per-page image hashes could not be found on the system. Date: 2016-10-04 19:23:38.914 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system. Date: 2016-10-03 19:55:39.970 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wsddpp.sys because the set of per-page image hashes could not be found on the system. Date: 2016-10-03 19:55:37.084 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system. Date: 2016-10-03 19:50:15.034 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\wsddpp.sys because the set of per-page image hashes could not be found on the system. Date: 2016-10-03 19:50:11.322 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system. ==================== Informações da Memória =========================== Processador: Intel(R) Celeron(R) CPU 1007U @ 1.50GHz Percentagem de memória em uso: 80% RAM física total: 1915.93 MB RAM física disponível: 375.12 MB Virtual Total: 3831.87 MB Virtual disponível: 1969.94 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:172.69 GB) (Free:54.97 GB) NTFS Drive d: () (Fixed) (Total:292.97 GB) (Free:272.75 GB) NTFS ==================== MBR & Tabela de Partições ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 7A0FDC7B) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=172.7 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=293 GB) - (Type=07 NTFS) ==================== Fim de Addition.txt ============================