Resultado do exame Adicional Farbar Recovery Scan Tool (x64) Versão: 02.01.2018 Executado por SERVIDOR (08-01-2018 16:32:59) Executando a partir de C:\Users\SERVIDOR\Desktop Windows 7 Ultimate Service Pack 1 (X64) (2013-07-17 20:02:41) Modo da Inicialização: Normal ========================================================== ==================== Contas: ============================= Administrador (S-1-5-21-3111613574-2524581245-2586426736-500 - Administrator - Disabled) Convidado (S-1-5-21-3111613574-2524581245-2586426736-501 - Limited - Enabled) HomeGroupUser$ (S-1-5-21-3111613574-2524581245-2586426736-1007 - Limited - Enabled) SERVIDOR (S-1-5-21-3111613574-2524581245-2586426736-1000 - Administrator - Enabled) => C:\Users\SERVIDOR ==================== Central de Segurança ======================== (Se uma entrada for incluída na fixlist, será removida.) AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402} ==================== Programas Instalados ====================== (Somente os programas adwares com a indicação "Oculto" podem ser adicionados à fixlist para desocultá-los. Os programas adwares devem ser desinstalados manualmente.) Adobe Acrobat Reader DC - Português (HKLM-x32\...\{AC76BA86-7AD7-1046-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated) Adobe Flash Player 28 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 28.0.0.126 - Adobe Systems Incorporated) Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.126 - Adobe Systems Incorporated) Adobe Photoshop CS4 (HKLM-x32\...\Adobe_b741c3c52d3108664cedeb2b76f6d96) (Version: 11.0 - Adobe Systems Incorporated) Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.9.2322 - AVAST Software) Avira Phantom VPN (HKLM-x32\...\Avira Phantom VPN) (Version: 2.11.3.29834 - Avira Operations GmbH & Co. KG) Avira Software Updater (HKLM-x32\...\{591FD32E-4D97-44D6-84E5-84751E7A9859}) (Version: 2.0.4.31895 - Avira Operations GmbH & Co. KG) Bluetooth Win7 Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.2.0.83 - Atheros Communications) CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform) Componente de Segurança Bradesco (HKLM-x32\...\scpbrad) (Version: 1.0.0 - Banco Bradesco S.A.) Corel Graphics - Windows Shell Extension (HKLM\...\_{EBDC2D0D-1E26-4EF2-BB48-C7E18F7800C6}) (Version: 16.0.0.707 - Corel Corporation) Corel Graphics - Windows Shell Extension (HKLM\...\{EBDC2D0D-1E26-4EF2-BB48-C7E18F7800C6}) (Version: 16.0.707 - Corel Corporation) Hidden Corel Graphics - Windows Shell Extension 32 Bit (HKLM\...\{79899C6B-E315-4A3F-8904-02DEAB8D660D}) (Version: 16.0.707 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - BR (x64) (HKLM\...\{8EF2B1E1-4D7A-43FA-92C5-61DB6F0524C4}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - Capture (x64) (HKLM\...\{1967EF95-E00B-4669-8B1C-A589BE8BF24F}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - Common (x64) (HKLM\...\{35869A6C-BA31-4F23-B52D-BC1B1E41EC1B}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - Connect (x64) (HKLM\...\{96AAAB95-AEBE-437A-B7CA-37C7BE13FFE9}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - Custom Data (x64) (HKLM\...\{7386B5FA-8715-481D-821F-7785110506DF}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - Draw (x64) (HKLM\...\{27AE72A4-B217-4CDC-B82B-3311E9D7460E}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - Filters (x64) (HKLM\...\{E699230D-4B5E-411E-9F45-FF50789B18DD}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - FontNav (x64) (HKLM\...\{3933C06C-8239-432B-87FC-F2BDC5B49A10}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - IPM (HKLM\...\{B6DF7031-2843-44FD-9CAB-DECAB4257456}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - PHOTO-PAINT (x64) (HKLM\...\{D7C2687D-924E-4485-B367-C7D95CBF8DDD}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - Photozoom Plugin (x64) (HKLM\...\{2C72B5E4-AA34-4F1A-8C7E-468530F9F6A3}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - Redist (x64) (HKLM\...\{6099F026-0A98-4D40-9B3D-ED2123A8CBD0}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - Setup Files (x64) (HKLM\...\{BDBFAC49-8877-472F-876B-75ADB7DBC955}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - VBA (x64) (HKLM\...\{10762393-1B90-4AC2-AF1A-4C0C04AE303F}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - VideoBrowser (x64) (HKLM\...\{7B79AE44-9B76-4815-84E5-ACAC3F0F0278}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - VSTA (x64) (HKLM\...\{1E3A578C-0A7D-4820-990F-B7545C0B2303}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 - Writing Tools (x64) (HKLM\...\{DDE82E3D-20C4-48E1-AE1D-B1F10E42CA44}) (Version: 16.0 - Corel Corporation) Hidden CorelDRAW Graphics Suite X6 (64-Bit) (HKLM\...\_{BDBFAC49-8877-472F-876B-75ADB7DBC955}) (Version: 16.0.0.707 - Corel Corporation) CorelDRAW Graphics Suite X6 (x64) (HKLM\...\{CCE7423E-1D84-4CD3-9E32-220EC9358D97}) (Version: 16.0 - Corel Corporation) Hidden CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.1312.54 - CyberLink Corp.) Dell Digital Delivery (HKLM-x32\...\{31045ECE-019D-4DDF-A5C8-5C51A3FE50EE}) (Version: 1.7.4501.0 - Dell Products, LP) Dell System Detect (HKU\S-1-5-21-3111613574-2524581245-2586426736-1000\...\73f463568823ebbe) (Version: 6.5.0.6 - Dell) Dell Touchpad (HKLM\...\SynTPDeinstKey) (Version: 15.3.2.1 - Synaptics Incorporated) Dell WLAN and Bluetooth Client Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 9.0 - Dell Inc.) DigitalPersona Personal 4.01 (HKLM\...\{FC09380E-74BE-41F5-8353-E97113969040}) (Version: 4.01.3765 - DigitalPersona, Inc.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.84 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden hppLaserJetService (HKLM-x32\...\{178F0383-A2F1-427C-9881-6EACB8728C76}) (Version: 009.033.00905 - Hewlett-Packard) Hidden hppM125LaserJetService (HKLM-x32\...\{18D5B189-DBDD-4E57-A84B-58C7700E9BB0}) (Version: 001.032.00682 - Hewlett-Packard) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.1.41 - Intel Corporation) Java 7 Update 11 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417011FF}) (Version: 7.0.110 - Oracle) Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-3111613574-2524581245-2586426736-1000\...\OneDriveSetup.exe) (Version: 17.3.7131.1115 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation) Mozilla Firefox 56.0 (x86 pt-BR) (HKLM-x32\...\Mozilla Firefox 56.0 (x86 pt-BR)) (Version: 56.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 56.0.0.6478 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 12 (HKLM-x32\...\{560FC78C-A4B2-461D-9B47-820C1EEF87B8}) (Version: 12.0.02000 - Nero AG) Pacote de Compatibilidade para o sistema Office 2007 (HKLM-x32\...\{90120000-0020-0416-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) Pacote de Idiomas do Microsoft Visual Studio 2010 Tools for Office Runtime (x64) - Português (Brasil) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - PTB) (Version: 10.0.50903 - Microsoft Corporation) PDF Settings (HKLM-x32\...\{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}) (Version: 1.0 - Adobe Systems Incorporated) Hidden Photoshop Camera Raw (HKLM-x32\...\{C4418DF9-5B57-4C5D-ACC2-D6B1338CCE09}) (Version: 5.0 - Adobe Systems Incorporated) Hidden Platform (HKLM-x32\...\{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) Hidden PowerLine Utility (HKLM-x32\...\{A0384ECE-2017-4EA8-86C7-513ACB936BDF}) (Version: 1.1.830 - TP-LINK) Prerequisite installer (HKLM-x32\...\{3AAB08A3-F129-4BD5-B409-AE674F93759D}) (Version: 12.0.0002 - Nero AG) Hidden Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.17 - Qualcomm Atheros Inc.) Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.0.15 - Dell Inc.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.52.203.2012 - Realtek) Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.34.0 - Renesas Electronics Corporation) Hidden Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.34.0 - Renesas Electronics Corporation) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Skype™ 7.1 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.1.105 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-3111613574-2524581245-2586426736-1000\...\Spotify) (Version: 1.0.68.407.g6864aaaf - Spotify AB) ST Microelectronics 3 Axis Digital Accelerometer Solution (HKLM-x32\...\{9C24F411-9CA7-4A8A-91F3-F08A4A38EB31}) (Version: 4.11.0028 - ST Microelectronics) TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.90968 - TeamViewer) Update Manager (HKLM-x32\...\{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}) (Version: 4.60 - Corel Corporation) Hidden Validity Sensors DDK (HKLM\...\{10AAF056-7792-497A-ACAF-3BF002196574}) (Version: 4.3.33.0 - Validity Sensors, Inc.) VIA Gerenciador de dispositivo de plataforma (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) Warsaw 2.0.3.2 64 bits (HKLM\...\{20E60725-16C8-4FB9-8BC2-AF92C5F8D06D}_is1) (Version: 2.0.3.2 - GAS Tecnologia) Welcome App (Start-up experience) (HKLM-x32\...\{828175FA-7307-4DBF-95AD-9CEE086B6F45}) (Version: 12.0.14000 - Nero AG) Hidden WhatsApp (HKU\S-1-5-21-3111613574-2524581245-2586426736-1000\...\WhatsApp) (Version: 0.2.7315 - WhatsApp) WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies) WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) Wondershare Helper Compact 2.5.2 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.2 - Wondershare) ==================== Exame Personalizado CLSID (Whitelisted): ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) CustomCLSID: HKU\S-1-5-21-3111613574-2524581245-2586426736-1000_Classes\CLSID\{0783EB25-59F8-4F02-B6B0-F1D4349F0007}\InprocServer32 -> C:\Users\SERVIDOR\AppData\Local\GAS Tecnologia\GBBD\npsf_cef_64.dll (GAS Tecnologia) CustomCLSID: HKU\S-1-5-21-3111613574-2524581245-2586426736-1000_Classes\CLSID\{0783EB25-59F8-4F02-B6B1-F1D4349F0007}\InprocServer32 -> C:\Users\SERVIDOR\AppData\Local\GAS Tecnologia\GBBD\npsf_cef_64.dll (GAS Tecnologia) CustomCLSID: HKU\S-1-5-21-3111613574-2524581245-2586426736-1000_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\SERVIDOR\AppData\Local\Microsoft\OneDrive\17.3.6998.0830_1\amd64\FileCoAuthLib64.dll => Nenhum Arquivo ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-01-06] (AVAST Software) ContextMenuHandlers1: [Atheros] -> {B8952421-0E55-400B-94A6-FA858FC0A39F} => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvAppExt.dll [2011-05-20] (Atheros Commnucations) ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-01-06] (AVAST Software) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (Alexander Roshal) ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-01-06] (AVAST Software) ContextMenuHandlers3: [FTShellContext] -> {AFF81F7B-6942-40c4-AADA-7214EF7B6DD1} => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\ShellContextExt.dll [2011-05-20] (Atheros Commnucations) ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal) ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (Alexander Roshal) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2015-06-01] (Intel Corporation) ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-01-06] (AVAST Software) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-15] (Alexander Roshal) ==================== Tarefas Agendadas (Whitelisted) ============= (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) Task: {0A9D1664-6EF0-4E5B-8063-28932243E6B9} - System32\Tasks\Rerun Warsaw's CoreFixer => C:\Windows\TEMP\is-JHE37.tmp\corefixer.exe <==== ATENÇÃO Task: {1996C0B6-C031-4C11-96B1-1D9AB01C5775} - System32\Tasks\{DECB366F-E49C-40A5-AED3-F9CC9BCC5E64} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\RAMRush\unins000.exe" Task: {1B821831-F9EC-4588-917E-1EAE5549CFA6} - System32\Tasks\{4BAD9F16-72FA-41DF-A2FE-7AE6074AD3F2} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.) Task: {33EB637E-B010-418C-BA4B-144855EFB7CA} - System32\Tasks\{4E5F21E3-8E49-43A4-8C9D-2A47F08142EB} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.) Task: {4A713C22-078B-4062-BB5D-FB442C062693} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2018-01-08] (AVAST Software) Task: {68FA1167-D92F-4FA5-AEB1-C09FA4544AE0} - System32\Tasks\{21FDD2AC-37D8-44F0-8FBE-38644345040E} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-01-23] (Skype Technologies S.A.) Task: {6C1E2E46-2ED4-42E4-BDA9-1F4308712A57} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-01-06] (AVAST Software) Task: {756E8955-178F-4177-A9FF-9628CBB8D0E6} - System32\Tasks\R@1n-KMS\Office14ProPlus => wmic [Argument = path OfficeSoftwareProtectionProduct where (ID="6f327760-8c5c-417c-9b61-836a98287e0c") call Activate] Task: {8B611A63-243B-4648-BE91-113C7BFDEA00} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd) Task: {8E797AB7-8F90-406E-B40D-F984AD9C463C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {A4D5F339-5091-4355-A560-8390E2F77688} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated) Task: {B7FE13E2-902E-4F99-884C-EB3A65CBA503} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-12-12] (Adobe Systems Incorporated) Task: {D8E5FF1D-8991-4543-937F-B55635C79069} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe Task: {E2B7B601-D011-4B7C-9E2C-A1058BB7799A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.) Task: {FC92C314-0449-43B9-849C-F50E80893067} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe Task: {FDC18CB0-B9E6-48FA-91FC-94D142FE4250} - System32\Tasks\{754182E3-9BDD-46D4-A4AB-AE7A4EDFD6DD} => C:\Windows\system32\pcalua.exe -a C:\Users\SERVIDOR\Desktop\LGMobileSupportTool.exe -d C:\Users\SERVIDOR\Desktop (Se uma entrada for incluída na fixlist, o arquivo da tarefa (.job) será movido. O arquivo que está sendo executado pela tarefa não será movido.) Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe ==================== Atalhos & WMI ======================== (As entradas podem ser listadas para serem restauradas ou removidas.) ==================== Módulos Carregados (Whitelisted) ============== 2013-09-05 00:17 - 2013-09-05 00:17 - 004300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2017-04-26 11:05 - 2017-04-26 11:05 - 000026112 _____ () C:\Windows\KMS-R@1n.exe 2014-07-24 23:36 - 2014-07-24 23:36 - 000030208 _____ () C:\Windows\system32\LenovoSysCheck.dll 2018-01-06 20:36 - 2018-01-06 20:36 - 000067920 _____ () c:\Program Files\AVAST Software\Avast\x64\module_lifetime.dll 2018-01-06 20:36 - 2018-01-06 20:36 - 000067984 _____ () C:\Program Files\AVAST Software\Avast\x64\dll_loader.dll 2018-01-06 20:35 - 2018-01-06 20:35 - 000236840 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll 2018-01-06 20:36 - 2018-01-06 20:36 - 000902824 _____ () C:\Program Files\AVAST Software\Avast\x64\ffl2.dll 2018-01-06 20:36 - 2018-01-06 20:36 - 000349568 _____ () c:\Program Files\AVAST Software\Avast\x64\StreamBack.dll 2017-12-07 08:29 - 2017-12-06 02:24 - 004063064 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.84\libglesv2.dll 2017-12-07 08:29 - 2017-12-06 02:24 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.84\libegl.dll 2018-01-06 20:35 - 2018-01-06 20:35 - 000058016 _____ () C:\Program Files\AVAST Software\Avast\module_lifetime.dll 2018-01-06 20:35 - 2018-01-06 20:35 - 000057504 _____ () C:\Program Files\AVAST Software\Avast\dll_loader.dll 2018-01-06 20:35 - 2018-01-06 20:35 - 000206152 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll 2018-01-06 20:36 - 2018-01-06 20:36 - 000289272 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll 2018-01-06 20:36 - 2018-01-06 20:36 - 000196248 _____ () C:\Program Files\AVAST Software\Avast\network_notifications.dll 2018-01-08 14:55 - 2018-01-08 14:55 - 005768336 _____ () C:\Program Files\AVAST Software\Avast\defs\18010804\algo.dll 2018-01-06 20:36 - 2018-01-06 20:36 - 000745408 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll 2018-01-06 20:34 - 2018-01-06 20:34 - 000148936 _____ () C:\Program Files\AVAST Software\Avast\hns_tools.dll 2018-01-06 20:35 - 2018-01-06 20:35 - 000293944 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll 2017-09-22 11:25 - 2017-09-22 11:25 - 067109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2018-01-06 20:34 - 2018-01-06 20:34 - 000282560 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll 2013-07-18 09:07 - 2012-01-09 01:48 - 000541683 _____ () C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\sqlite3.dll 2011-10-26 09:57 - 2011-10-26 09:57 - 000102912 _____ () C:\Program Files (x86)\Dell Digital Delivery\ServiceTagPlusPlus.dll ==================== Alternate Data Streams (Whitelisted) ========= (Se uma entrada for incluída na fixlist, somente o ADS será removido.) AlternateDataStreams: C:\Program Files (x86)\GbPlugin:IncompleteStartProcessProtection.cnt [10] AlternateDataStreams: C:\Program Files (x86)\GbPlugin:u6eBQrM0Z2K3FKLVBMG8dY3IkKT2rqFO+Sf68h8fDg== [32] AlternateDataStreams: C:\Windows\System32:0E3C4079_Cef.gbp [2] AlternateDataStreams: C:\Windows\System32:45E2DABF_Cef.gbp [2] AlternateDataStreams: C:\Windows\system32\Drivers\gbpddfac64.sys:r0d3jo5 [20] AlternateDataStreams: C:\Windows\system32\Drivers\gbpddfac64.sys:X5ZN8aGvT4 [0] AlternateDataStreams: C:\Windows\system32\Drivers\wsddfac.sys:X5ZN8aGXs4 [2410] ==================== Modo de Segurança (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O valor "AlternateShell" será restaurado.) ==================== Associação (Whitelisted) =============== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido.) ==================== Internet Explorer confiável/restrito =============== (Se uma entrada for incluída na fixlist, será removida do Registro.) IE trusted site: HKU\.DEFAULT\...\caixa.gov.br -> hxxps://imagem.caixa.gov.br IE trusted site: HKU\S-1-5-21-3111613574-2524581245-2586426736-1000\...\caixa.gov.br -> hxxps://imagem.caixa.gov.br IE trusted site: HKU\S-1-5-21-3111613574-2524581245-2586426736-1000\...\caixa.gov.br -> imagem.caixa.gov.br IE trusted site: HKU\S-1-5-21-3111613574-2524581245-2586426736-1000\...\dell.com -> dell.com ==================== Hosts Conteúdo: =============================== (Se necessário, a diretiva Hosts: pode ser incluída na fixlist para redefinir o Hosts.) 2009-07-14 00:34 - 2009-06-10 19:00 - 000000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Outras Áreas ============================ (Atualmente não há nenhuma correção automática para esta seção.) HKU\S-1-5-21-3111613574-2524581245-2586426736-1000\Control Panel\Desktop\\Wallpaper -> DNS Servers: 8.8.8.8 - 8.8.4.4 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0) Firewall do Windows está habilitado. ==================== MSCONFIG/TASK MANAGER ítens desabilitados == MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices MSCONFIG\startupreg: electron.app.Deezer => C:\Users\SERVIDOR\AppData\Local\Programs\deezer-desktop\Deezer.exe MSCONFIG\startupreg: HotKeysCmds => "C:\Windows\system32\hkcmd.exe" MSCONFIG\startupreg: IgfxTray => "C:\Windows\system32\igfxtray.exe" MSCONFIG\startupreg: ISUSPM Startup => "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup MSCONFIG\startupreg: ISUSScheduler => "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start MSCONFIG\startupreg: Persistence => "C:\Windows\system32\igfxpers.exe" MSCONFIG\startupreg: PowerDVD12Agent => "C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe" MSCONFIG\startupreg: PowerDVD12DMREngine => "C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe" MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun MSCONFIG\startupreg: Spotify Web Helper => C:\Users\SERVIDOR\AppData\Roaming\Spotify\SpotifyWebHelper.exe --autostart MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe ==================== Regras do Firewall (Whitelisted) =============== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) FirewallRules: [{047A66A8-586D-4093-9732-0EFFFEDCF2AF}] => (Block) C:\Program Files (x86)\Microsoft Office\Office14\outlook.exe FirewallRules: [TCP Query User{665B64D7-2E4E-4FA5-96AB-1D3FBE50AD05}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe FirewallRules: [UDP Query User{B1B71610-9AB1-4055-A6FF-6616FEA229A2}C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe] => (Allow) C:\windows\microsoft.net\framework\v2.0.50727\vbc.exe FirewallRules: [{93296DC7-C35B-4CC6-AC4E-AB7BFBC23904}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [{63EC9B61-C894-4C56-B12A-7C2BF4EEF0D5}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe FirewallRules: [{0249EC45-8B20-44B3-AD9F-1E4B69688893}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe FirewallRules: [{60466794-500E-4B90-9424-AC22A3C96C6B}] => (Block) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe FirewallRules: [{5DDC840C-722D-48E4-BA7C-854A308D2AF0}] => (Block) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe FirewallRules: [{D6982BE1-E324-45AC-9622-4AE1BC193CDD}] => (Block) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe FirewallRules: [{D8BDACBF-9394-40D0-A438-B94E1891200B}] => (Block) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe FirewallRules: [{E6F16EFD-6693-415F-82CF-457528391E47}] => (Block) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe FirewallRules: [{F025F7CE-209C-406D-9604-08B4C76EEF91}] => (Block) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe FirewallRules: [{89BDD0FC-9E62-4F01-ADB3-82E8C25440A1}] => (Block) %ProgramFiles%\Corel\CorelDRAW Graphics Suite X6\Programs64\CorelDRW.exe FirewallRules: [{268605E2-854C-4053-8DA7-1D018DEB1B8E}] => (Block) %ProgramFiles%\Corel\CorelDRAW Graphics Suite X6\Programs64\CorelDRW.exe FirewallRules: [{D736E2E1-67F5-4E85-8E1D-F08647BA0901}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{D7538C45-8E4B-4137-AA38-FCDC526BD665}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{1734C978-C6D4-4C75-8771-750F78A3B00E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [TCP Query User{69AC59CF-AA69-4F79-8E58-7E4DC8E08D02}D:\powerline utility\powerline scan.exe] => (Allow) D:\powerline utility\powerline scan.exe FirewallRules: [UDP Query User{12A48AF1-75C6-4DB2-9E29-C4420A0B68F8}D:\powerline utility\powerline scan.exe] => (Allow) D:\powerline utility\powerline scan.exe FirewallRules: [TCP Query User{8E06B909-8FC4-4B9D-A718-60FB71102EBF}C:\users\servidor\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\servidor\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{DCB04FF2-230B-4C3C-B969-CBE6622AA772}C:\users\servidor\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\servidor\appdata\roaming\spotify\spotify.exe FirewallRules: [{DB9DFA16-A9D2-4407-BCB7-A542352D6C42}] => (Allow) C:\Windows\KMS-R@1n.exe FirewallRules: [{10FB5B6A-4ACF-4CE4-8D9B-6A78056FDE39}] => (Allow) C:\Windows\KMS-R@1n.exe FirewallRules: [{EFF468C3-6ABE-49DE-910F-D097565C7B51}] => (Allow) C:\Program Files\Diebold\Warsaw\core.exe FirewallRules: [{B43A5527-74AB-4B0D-B6B0-9AC5EB687646}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{E1F774EB-8EE8-4DF1-AE57-466523E2F61D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{917A9911-2804-49A4-A238-2A6C6951029E}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe FirewallRules: [{A3004C1E-D7DB-4B75-8F5E-0AE997CC4944}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe FirewallRules: [{22D50F32-5878-4938-8DC7-F2703F279EB6}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe ==================== Pontos de Restauração ========================= 10-12-2017 10:03:43 Ponto de Verificação Agendado 21-12-2017 10:54:04 Ponto de Verificação Agendado ==================== Dispositivos Apresentando Falhas No Gerenciador ============= Name: Dell Wireless 1702 Bluetooth v3.0+HS Description: Dell Wireless 1702 Bluetooth v3.0+HS Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974} Manufacturer: Atheros Communications Service: BTHUSB Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Erros no Log de eventos: ========================= Erros em Aplicativos: ================== Error: (01/08/2018 04:13:23 PM) (Source: ESENT) (EventID: 489) (User: ) Description: ccsetup538 (7196) Uma tentativa de abrir o arquivo "C:\Users\SERVIDOR\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat" para acesso somente leitura falhou com o erro de sistema 32 (0x00000020): "O arquivo já está sendo usado por outro processo. ". A operação para abrir o arquivo falhará com o erro -1032 (0xfffffbf8). Error: (12/10/2017 09:58:52 AM) (Source: Software Protection Platform Service) (EventID: 8208) (User: ) Description: Falha ao adquirir tíquete original (hr=0x80072EE7) para a identificação de modelo 66c92734-d682-4d71-983e-d6ec3f16059f Error: (12/10/2017 09:58:52 AM) (Source: Software Protection Platform Service) (EventID: 8200) (User: ) Description: Detalhes da falha na aquisição de licença. hr=0x80072EE7 Error: (12/10/2017 09:58:22 AM) (Source: Windows Activation Technologies) (EventID: 3) (User: ) Description: Falha de verificação de integridade: hr = 0x8004FE22, StatusIntegridade: 0x0000000000004C00 Error: (12/07/2017 09:58:32 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome de aplicativo com falha: WhatsApp_ExecutionStub.exe, versão: 0.2.6426.0, carimbo de hora: 0x5931cd5c Nome do módulo de falhas: WhatsApp_ExecutionStub.exe, versão: 0.2.6426.0, carimbo de hora: 0x5931cd5c Código de exceção: 0xc0000005 Deslocamento com falha: 0x00004729 Identificação do processo com falha: 0x1e9c Hora de início do aplicativo com falha: 0x01d36f52b1471311 Caminho do aplicativo com falha: C:\Users\SERVIDOR\AppData\Local\WhatsApp\app-0.2.6426\WhatsApp_ExecutionStub.exe FCaminho do módulo de falhas: C:\Users\SERVIDOR\AppData\Local\WhatsApp\app-0.2.6426\WhatsApp_ExecutionStub.exe Identificação do Relatório: f1ebea1c-db45-11e7-b2f4-14feb5a84761 Error: (12/03/2017 02:16:30 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Nome de aplicativo com falha: WINWORD.EXE, versão: 14.0.7190.5000, carimbo de hora: 0x59f560b0 Nome do módulo de falhas: oart.dll, versão: 14.0.7169.5000, carimbo de hora: 0x571774e3 Código de exceção: 0xc0000005 Deslocamento com falha: 0x001a0803 Identificação do processo com falha: 0x344 Hora de início do aplicativo com falha: 0x01d36b94ecc89b4d Caminho do aplicativo com falha: C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE FCaminho do módulo de falhas: C:\Program Files (x86)\Microsoft Office\Office14\oart.dll Identificação do Relatório: bce14c35-d7e0-11e7-942d-14feb5a84761 Erros de Sistema: ============= Error: (01/08/2018 04:24:43 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Falha ao carregar o(s) seguinte(s) driver(s) de início do sistema ou de inicialização: gbpddfac gbpddreg wsddfac Error: (01/08/2018 04:23:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Não foi possível iniciar o serviço Wondershare Application Framework Service devido ao seguinte erro: O sistema não pode encontrar o arquivo especificado. Error: (01/08/2018 04:15:20 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: O servidor {9B1F122C-2982-4E91-AA8B-E071D54F2A4D} não se registrou com o DCOM dentro do tempo limite requerido. Error: (01/08/2018 04:12:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: O serviço Avira Service Host foi finalizado inesperadamente. Isto aconteceu 1 vez(es). A seguinte ação corretiva será tomada em 10000 milissegundos: Reiniciar o serviço. Error: (01/08/2018 04:12:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: O serviço Avira Updater Service foi finalizado inesperadamente. Isto aconteceu 1 vez(es). A seguinte ação corretiva será tomada em 30000 milissegundos: Reiniciar o serviço. Error: (01/08/2018 04:03:26 PM) (Source: BROWSER) (EventID: 8032) (User: ) Description: O serviço localizador não pôde recuperar a lista de backup muitas vezes no transporte \Device\NetBT_Tcpip_{40DF4B04-62B3-42F8-A3D6-74805CDB2EAF}. O localizador reserva está finalizando. Error: (01/08/2018 04:03:22 PM) (Source: Schannel) (EventID: 4119) (User: AUTORIDADE NT) Description: O seguinte alerta fatal foi recebido: 40. Error: (01/08/2018 04:03:22 PM) (Source: Schannel) (EventID: 4119) (User: AUTORIDADE NT) Description: O seguinte alerta fatal foi recebido: 70. Error: (01/08/2018 03:45:10 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: O serviço Avira Real-Time Protection foi finalizado inesperadamente. Isto aconteceu 1 vez(es). A seguinte ação corretiva será tomada em 0 milissegundos: Reiniciar o serviço. Error: (01/08/2018 03:39:20 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Falha ao carregar o(s) seguinte(s) driver(s) de início do sistema ou de inicialização: gbpddfac gbpddreg wsddfac ==================== Informações da Memória =========================== Processador: Intel(R) Core(TM) i3-2350M CPU @ 2.30GHz Percentagem de memória em uso: 60% RAM física total: 3990.17 MB RAM física disponível: 1575.33 MB Virtual Total: 7978.52 MB Virtual disponível: 5342.73 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.56 GB) (Free:379.29 GB) NTFS ==================== MBR & Tabela de Partições ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 619C366F) Partition 1: (Active) - (Size=204 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=465.6 GB) - (Type=07 NTFS) ==================== Fim de Addition.txt ============================