PDA

View Full Version : Ezsurf.biz hijacked Chrome, not IE or Edge... and only for one windows 10 user



msdiniz
2015-12-14, 22:09
Hi, all.<br>
I'm having problems with ezsurf.biz on last 3 to 4 months, I guess; it captured startup page of Chrome, but not IE or Edge... and only for mine windows 10 user (Marcelo), not for the other user (Grazi).<br>
I have N360 and Malwarebytes, both full versions, and they cant detect any problem.<br>
I deleted all Chrome extensions and mine Chrome user... useless.<br>
I did a register backup with the tweaking.com tool.<br>
I hope someone can help with resolving these problems, below are my FRST &amp; aswMBR logs.<br>
TIA<br>
<br>
Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão:14-12-2015<br>
Executado por Marcelo (administrador) em MARCELO-CASA (14-12-2015 17:59:07)<br>
Executando a partir de D:\users\Marcelo\Downloads<br>
Perfis Carregados: Marcelo &amp; MSSQL$ADK (Perfis Disponíveis: Marcelo &amp; Grazi &amp; MSSQL$ADK &amp; Classic .NET AppPool &amp; .NET v4.5 &amp; DefaultAppPool &amp; .NET v2.0 &amp; .NET v4.5 Classic &amp; .NET v2.0 Classic)<br>
Platform: Windows 10 Pro Versão 1511 (X64) Idioma: Português (Brasil)<br>
Internet Explorer Versão 11 (Navegador padrão: Chrome)<br>
Modo da Inicialização: Normal<br>
Tutorial da Farbar Recovery Scan Tool: <a href="http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/" target="_blank">http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/</a><br>
<br>
==================== Processos (Whitelisted) =================<br>
<br>
(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)<br>
<br>
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe<br>
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe<br>
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe<br>
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe<br>
(ABBYY Production LLC) C:\Program Files (x86)\ABBYY PDF Transformer+\NetworkLicenseServer.exe<br>
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe<br>
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe<br>
(ABBYY InfoPoisk LLC) C:\Program Files (x86)\Common Files\ABBYY\ScreenshotReader\11.00\Licensing\NetworkLicenseServer.exe<br>
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe<br>
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe<br>
() C:\Program Files\GKrellM\bin\gkrellmd.exe<br>
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe<br>
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe<br>
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe<br>
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe<br>
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE<br>
(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\gbpsv.exe<br>
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe<br>
(Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe<br>
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe<br>
(SafeNet, Inc.) C:\Program Files\SafeNet\Authentication\SAC\x64\SACSrv.exe<br>
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe<br>
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe<br>
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe<br>
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe<br>
() C:\Program Files (x86)\Allway Sync\Bin\SyncService.exe<br>
(FirebirdSQL Project) C:\Program Files (x86)\Firebird\Firebird_2_0\bin\fb_inet_server.exe<br>
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDFSSvc.exe<br>
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe<br>
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe<br>
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe<br>
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe<br>
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe<br>
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdSvc.exe<br>
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe<br>
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe<br>
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe<br>
() C:\Program Files (x86)\QNAP\QVR\QVRService.exe<br>
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe<br>
(Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe<br>
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe<br>
() C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe<br>
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe<br>
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe<br>
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe<br>
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL11.ADK\MSSQL\Binn\sqlservr.exe<br>
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe<br>
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe<br>
(GAS Tecnologia LTDA) C:\Program Files\Diebold\Warsaw\core.exe<br>
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe<br>
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe<br>
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\n360.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler64.exe<br>
(Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe<br>
(Microsoft Corporation) C:\Windows\System32\dllhost.exe<br>
(Microsoft Corporation) C:\Windows\System32\vmms.exe<br>
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe<br>
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe<br>
() C:\Program Files (x86)\QNAP\Qfinder\iSCSIAgent.exe<br>
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe<br>
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ Power Control\PowerControlHelp.exe<br>
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Remote GO!\AssistTools\WiFi GO! Server.exe<br>
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe<br>
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe<br>
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe<br>
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe<br>
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\n360.exe<br>
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe<br>
(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\gbpsv.exe<br>
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe<br>
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe<br>
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe<br>
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe<br>
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe<br>
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe<br>
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Remote GO!\AsDLNAServerReal.exe<br>
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe<br>
(SafeNet, Inc.) C:\Program Files\SafeNet\Authentication\SAC\x64\SACMonitor.exe<br>
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe<br>
(Logitech, Inc.) C:\Program Files\Common Files\logishrd\KHAL3\KHALMNPR.exe<br>
(GAS Tecnologia LTDA) C:\Program Files\Diebold\Warsaw\core.exe<br>
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe<br>
() C:\Program Files (x86)\Allway Sync\Bin\syncappw.exe<br>
(Valve Corporation) D:\Steam\Steam.exe<br>
(Oracle Corporation) C:\Program Files (x86)\MySQL\MySQL Notifier 1.1.4\MySQLNotifier.exe<br>
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\ScanToPCActivationApp.exe<br>
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe<br>
(Notably Good Ltd) C:\Program Files (x86)\Affixa\AffixaTray.exe<br>
(Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe<br>
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe<br>
(WinZip Computing, S.L.) C:\Program Files\WinZip\WZQKPICK32.EXE<br>
(ABBYY Production LLC) C:\Program Files (x86)\ABBYY Screenshot Reader 11\ScreenshotReader.exe<br>
(CIGAM Software Corporativo) C:\Program Files (x86)\ERP CIGAM\CIGAM Boletos\CGBoletos.exe<br>
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe<br>
(QNAP) C:\Program Files (x86)\QNAP\myQNAPcloud Connect\NetworkDriveAgent.exe<br>
(Herman van Eijk) C:\Program Files (x86)\MCE Standby Tool\mst.exe<br>
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\HPNetworkCommunicator.exe<br>
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe<br>
(Google) C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe<br>
(ASUSTek Computer Inc.) C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe<br>
(Google) C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe<br>
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\apcsystray.exe<br>
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe<br>
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe<br>
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDTray.exe<br>
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe<br>
(Macrovision Europe Ltd.) C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe<br>
(Valve Corporation) D:\Steam\bin\steamwebhelper.exe<br>
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe<br>
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe<br>
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.0_none_95e4f9a171a1ad95\TiWorker.exe<br>
(Microsoft Corporation) C:\Windows\System32\SystemSettingsAdminFlows.exe<br>
Falha ao acessar processo -&gt; explorer.exe<br>
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe<br>
(Microsoft Corporation) C:\Windows\splwow64.exe<br>
(Tracker Software Products (Canada) Ltd.) C:\Program Files (x86)\ABBYY PDF Transformer+\pdfSaver5a.exe<br>
Falha ao acessar processo -&gt; WINWORD.EXE<br>
Falha ao acessar processo -&gt; explorer.exe<br>
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe<br>
() C:\Program Files\WindowsApps\Microsoft.Messaging_1.11.19004.0_x86__8wekyb3d8bbwe\SkypeHost.exe<br>
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe<br>
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe<br>
(SillySot Software) C:\Program Files\Iconoid\iconoid64.exe<br>
(Microsoft Corporation) C:\Windows\System32\dllhost.exe<br>
(Microsoft Corporation) C:\Windows\System32\dllhost.exe<br>
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE<br>
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe<br>
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe<br>
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\Evernote.exe<br>
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE<br>
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Microsoft Corporation) C:\Windows\System32\cmd.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\conathst.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(ESET) C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerApp.exe<br>
() C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe<br>
<br>
<br>
==================== Registro (Whitelisted) ===========================<br>
<br>
(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)<br>
<br>
HKLM\...\Run: [RTHDVCPL] =&gt; C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6827664 2012-08-07] (Realtek Semiconductor)<br>
HKLM\...\Run: [RtHDVBg_DTS] =&gt; C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-06] (Realtek Semiconductor)<br>
HKLM\...\Run: [Logitech Download Assistant] =&gt; C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch<br>
HKLM\...\Run: [ShadowPlay] =&gt; "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart<br>
HKLM\...\Run: [Samsung Link] =&gt; C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [607584 2015-03-18] (Copyright 2013 SAMSUNG)<br>
HKLM\...\Run: [SACMonitor] =&gt; C:\Program Files\SafeNet\Authentication\SAC\x64\SACMonitor.exe [2183312 2012-04-16] (SafeNet, Inc.)<br>
HKLM\...\Run: [NvBackend] =&gt; C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2757424 2015-11-12] (NVIDIA Corporation)<br>
HKLM\...\Run: [EvtMgr6] =&gt; C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.)<br>
HKLM\...\Run: [Diebold - Warsaw] =&gt; C:\Program Files\Diebold\Warsaw\core.exe [858424 2015-08-18] (GAS Tecnologia LTDA)<br>
HKLM\...\Run: [Acronis Scheduler2 Service] =&gt; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [570152 2014-08-14] (Acronis)<br>
HKLM\...\Run: [LogMeIn GUI] =&gt; C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [57928 2013-04-30] (LogMeIn, Inc.)<br>
HKLM-x32\...\Run: [] =&gt; [X]<br>
HKLM-x32\...\Run: [TrueImageMonitor.exe] =&gt; C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5343664 2015-07-20] (Acronis)<br>
HKLM-x32\...\Run: [Retail.SSR11] =&gt; C:\Program Files (x86)\ABBYY Screenshot Reader 11\ScreenshotReader.exe [1297936 2013-09-16] (ABBYY Production LLC)<br>
HKLM-x32\...\Run: [NUSB3MON] =&gt; C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)<br>
HKLM-x32\...\Run: [NetworkDriveAgent] =&gt; C:\Program Files (x86)\QNAP\myQNAPcloud Connect\NetworkDriveAgent.exe [1743592 2014-12-24] (QNAP)<br>
HKLM-x32\...\Run: [MCE Standby Tool] =&gt; C:\Program Files (x86)\MCE Standby Tool\mst.exe [1451008 2011-01-30] (Herman van Eijk)<br>
HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] =&gt; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2620728 2015-07-22] (Malwarebytes Corporation)<br>
HKLM-x32\...\Run: [HP Software Update] =&gt; C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)<br>
HKLM-x32\...\Run: [Google Desktop Search] =&gt; C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [30192 2013-08-15] (Google)<br>
HKLM-x32\...\Run: [Display] =&gt; C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe [284024 2012-01-24] (Schneider Electric)<br>
HKLM-x32\...\Run: [ASUS WiFi GO! FileTransfer Execute] =&gt; C:\Program Files (x86)\ASUS\AI Suite II\Remote GO!\AssistTools\WiFile\WiFileTransfer.exe [1391416 2013-06-21] (ASUSTeK Computer Inc.)<br>
HKLM-x32\...\Run: [ASUS AiChargerPlus Execute] =&gt; C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe [550272 2013-01-28] (ASUSTek Computer Inc.)<br>
HKLM-x32\...\Run: [AffixaPersonalSettings] =&gt; C:\Program Files (x86)\Affixa\AffixaHandler.exe [209272 2015-04-08] (Notably Good Ltd)<br>
HKLM-x32\...\Run: [AcronisTibMounterMonitor] =&gt; C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [691056 2015-07-20] (Acronis International GmbH)<br>
HKLM-x32\...\Run: [Acrobat Assistant 8.0] =&gt; C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe [620152 2006-10-23] (Adobe Systems Inc.)<br>
HKLM-x32\...\Run: [TkBellExe] =&gt; c:\program files (x86)\real\realplayer\Update\realsched.exe [295512 2013-12-04] (RealNetworks, Inc.)<br>
HKLM-x32\...\Run: [KiesTrayAgent] =&gt; C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2015-04-28] (Samsung Electronics Co., Ltd.)<br>
HKLM-x32\...\Run: [Dropbox] =&gt; C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [24952456 2015-12-08] (Dropbox, Inc.)<br>
HKLM-x32\...\Run: [VirtualCloneDrive] =&gt; C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)<br>
HKLM-x32\...\Run: [SDTray] =&gt; C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDTray.exe [4127488 2015-06-16] (Safer-Networking Ltd.)<br>
HKLM-x32\...\Run: [SunJavaUpdateSched] =&gt; C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)<br>
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)<br>
Winlogon\Notify\ GbPluginUni: C:\Program Files (x86)\GbPlugin\gbiehUni.dll [2015-07-06] (Banco Itaú Unibanco)<br>
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [Iconoid] =&gt; C:\Program Files\Iconoid\iconoid64.exe [313344 2010-08-21] (SillySot Software)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [Allway Sync] =&gt; C:\Program Files (x86)\Allway Sync\Bin\syncappw.exe [93488 2015-10-29] ()<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [Steam] =&gt; D:\Steam\steam.exe [3011152 2015-11-10] (Valve Corporation)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [MySQL Notifier] =&gt; C:\Program Files (x86)\MySQL\MySQL Notifier 1.1.4\MySqlNotifier.exe [762368 2013-07-05] (Oracle Corporation)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [KiesPDLR.exe] =&gt; C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [1015104 2015-04-28] (Samsung)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [HP Officejet Pro 8500 A910 (NET)] =&gt; C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [GoogleDriveSync] =&gt; C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22790776 2015-11-04] (Google)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [GarminExpressTrayApp] =&gt; C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2015-01-28] (Garmin Ltd or its subsidiaries)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [Affixa] =&gt; C:\Program Files (x86)\Affixa\AffixaTray.exe [643584 2015-04-08] (Notably Good Ltd)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [KiesPreload] =&gt; C:\Program Files (x86)\Samsung\Kies\Kies.exe [1566016 2015-04-28] (Samsung)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [Skype] =&gt; C:\Program Files (x86)\Skype\Phone\Skype.exe [53735968 2015-08-07] (Skype Technologies S.A.)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [SpybotPostWindows10UpgradeReInstall] =&gt; C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [Google Update] =&gt; C:\Users\Marcelo\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-10-30] (Google Inc.)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\Run: [Todoist] =&gt; C:\Users\Marcelo\AppData\Local\Todoist\WindowsDesktopApp\Todoist.exe [171080 2015-09-29] (Doist Ltd.)<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\RunOnce: [Uninstall C:\Users\Marcelo\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] =&gt; C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Marcelo\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\...\RunOnce: [Uninstall C:\Users\Marcelo\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1] =&gt; C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Marcelo\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1"<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\Control Panel\Desktop\\SCRNSAVE.EXE -&gt; C:\WINDOWS\system32\scrnsave.scr [31744 2015-10-30] (Microsoft Corporation)<br>
HKU\S-1-5-80-4287524181-3401991209-718407576-1481970793-3068686015\...\RunOnce: [WAB Migrate] =&gt; C:\Program Files\Windows Mail\wab.exe [517632 2015-10-30] (Microsoft Corporation)<br>
ShellExecuteHooks-x32: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399008} - C:\PROGRAM FILES (X86)\GbPlugin\gbiehuni.dll [1759992 2015-07-06] (Banco Itaú Unibanco)<br>
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -&gt; {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} =&gt; C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)<br>
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -&gt; {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} =&gt; C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)<br>
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -&gt; {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} =&gt; C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)<br>
ShellIconOverlayIdentifiers: [ OverlayExcluded] -&gt; {4433A54A-1AC8-432F-90FC-85F045CF383C} =&gt; C:\Program Files (x86)\Norton 360\Engine64\22.5.5.15\buShell.dll [2015-11-05] (Symantec Corporation)<br>
ShellIconOverlayIdentifiers: [ OverlayPending] -&gt; {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} =&gt; C:\Program Files (x86)\Norton 360\Engine64\22.5.5.15\buShell.dll [2015-11-05] (Symantec Corporation)<br>
ShellIconOverlayIdentifiers: [ OverlayProtected] -&gt; {476D0EA3-80F9-48B5-B70B-05E677C9C148} =&gt; C:\Program Files (x86)\Norton 360\Engine64\22.5.5.15\buShell.dll [2015-11-05] (Symantec Corporation)<br>
ShellIconOverlayIdentifiers: [ DropboxExt1] -&gt; {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers: [ DropboxExt2] -&gt; {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers: [ DropboxExt3] -&gt; {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers: [ DropboxExt4] -&gt; {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers: [ DropboxExt5] -&gt; {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers: [ DropboxExt6] -&gt; {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers: [ DropboxExt7] -&gt; {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers: [ DropboxExt8] -&gt; {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers: [ SkyDrive1] -&gt; {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =&gt; C:\Users\Marcelo\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64\FileSyncShell64.dll [2015-12-11] (Microsoft Corporation)<br>
ShellIconOverlayIdentifiers: [ SkyDrive2] -&gt; {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =&gt; C:\Users\Marcelo\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64\FileSyncShell64.dll [2015-12-11] (Microsoft Corporation)<br>
ShellIconOverlayIdentifiers: [ SkyDrive3] -&gt; {BBACC218-34EA-4666-9D7A-C78F2274A524} =&gt; C:\Users\Marcelo\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64\FileSyncShell64.dll [2015-12-11] (Microsoft Corporation)<br>
ShellIconOverlayIdentifiers: [AcronisSyncError] -&gt; {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} =&gt; C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2014-09-09] (Acronis)<br>
ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -&gt; {00F848DC-B1D4-4892-9C25-CAADC86A215D} =&gt; C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2014-09-09] (Acronis)<br>
ShellIconOverlayIdentifiers: [AcronisSyncOk] -&gt; {71573297-552E-46fc-BE3D-3DFAF88D47B7} =&gt; C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2014-09-09] (Acronis)<br>
ShellIconOverlayIdentifiers: [HardLinkMenu] -&gt; {0A479751-02BC-11d3-A855-0004AC2568AA} =&gt; C:\Program Files\LinkShellExtension\HardlinkShellExt.dll [2014-06-03] (Hermann Schinagl)<br>
ShellIconOverlayIdentifiers: [IconOverlayHardLink] -&gt; {0A479751-02BC-11d3-A855-0004AC2568DD} =&gt; C:\Program Files\LinkShellExtension\HardlinkShellExt.dll [2014-06-03] (Hermann Schinagl)<br>
ShellIconOverlayIdentifiers: [IconOverlaySymbolicLink] -&gt; {0A479751-02BC-11d3-A855-0004AC2568EE} =&gt; C:\Program Files\LinkShellExtension\HardlinkShellExt.dll [2014-06-03] (Hermann Schinagl)<br>
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -&gt; {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -&gt; {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -&gt; {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -&gt; {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -&gt; {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -&gt; {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -&gt; {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -&gt; {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -&gt; {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =&gt; C:\Users\Marcelo\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileSyncShell.dll [2015-12-11] (Microsoft Corporation)<br>
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -&gt; {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =&gt; C:\Users\Marcelo\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileSyncShell.dll [2015-12-11] (Microsoft Corporation)<br>
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -&gt; {BBACC218-34EA-4666-9D7A-C78F2274A524} =&gt; C:\Users\Marcelo\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileSyncShell.dll [2015-12-11] (Microsoft Corporation)<br>
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -&gt; {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -&gt; {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -&gt; {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =&gt; C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)<br>
ShellIconOverlayIdentifiers-x32: [HardLinkMenu] -&gt; {0A479751-02BC-11d3-A855-0004AC2568AA} =&gt; C:\Program Files\LinkShellExtension\32\HardlinkShellExt.dll [2014-06-03] (Hermann Schinagl)<br>
ShellIconOverlayIdentifiers-x32: [IconOverlayHardLink] -&gt; {0A479751-02BC-11d3-A855-0004AC2568DD} =&gt; C:\Program Files\LinkShellExtension\32\HardlinkShellExt.dll [2014-06-03] (Hermann Schinagl)<br>
ShellIconOverlayIdentifiers-x32: [IconOverlaySymbolicLink] -&gt; {0A479751-02BC-11d3-A855-0004AC2568EE} =&gt; C:\Program Files\LinkShellExtension\32\HardlinkShellExt.dll [2014-06-03] (Hermann Schinagl)<br>
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk [2013-08-14]<br>
ShortcutTarget: Adobe Acrobat Speed Launcher.lnk -&gt; C:\Windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe ()<br>
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Synchronizer.lnk [2013-08-14]<br>
ShortcutTarget: Adobe Acrobat Synchronizer.lnk -&gt; C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe ()<br>
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk [2013-08-15]<br>
ShortcutTarget: APC UPS Status.lnk -&gt; C:\Program Files (x86)\APC\PowerChute Personal Edition\Display.exe (Schneider Electric)<br>
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Quick Pick.lnk [2013-08-20]<br>
ShortcutTarget: WinZip Quick Pick.lnk -&gt; C:\Program Files\WinZip\WZQKPICK32.EXE (WinZip Computing, S.L.)<br>
Startup: C:\Users\Grazi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2014-12-21]<br>
ShortcutTarget: EvernoteClipper.lnk -&gt; C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)<br>
Startup: C:\Users\Grazi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteTray.lnk [2014-12-21]<br>
ShortcutTarget: EvernoteTray.lnk -&gt; C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)<br>
InternetURL: C:\Users\Marcelo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CIGAM Boletos.url -&gt; file:///C:\Program Files (x86)\ERP CIGAM\CIGAM Boletos\CGBoletos.exe<br>
Startup: C:\Users\Marcelo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2013-08-15]<br>
ShortcutTarget: EvernoteClipper.lnk -&gt; C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)<br>
Startup: C:\Users\Marcelo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteTray.lnk [2015-01-01]<br>
ShortcutTarget: EvernoteTray.lnk -&gt; C:\Program Files (x86)\Evernote\Evernote\EvernoteTray.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)<br>
Startup: C:\Users\Marcelo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitorar alertas de tinta - HP Officejet Pro 8500 A910 (Rede).lnk [2015-08-15]<br>
ShortcutTarget: Monitorar alertas de tinta - HP Officejet Pro 8500 A910 (Rede).lnk -&gt; C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\HPStatusBL.dll (Hewlett-Packard Co.)<br>
Startup: C:\Users\Marcelo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerChute.exe.lnk [2013-08-29]<br>
ShortcutTarget: PowerChute.exe.lnk -&gt; C:\Program Files (x86)\APC\PowerChute Personal Edition\PowerChute.exe (Schneider Electric)<br>
<br>
==================== Internet (Whitelisted) ====================<br>
<br>
(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)<br>
<br>
Winsock: Catalog5-x64 08 C:\Windows\system32\wlidnsp.dll [66048 2015-10-30] (Microsoft Corporation)<br>
Winsock: Catalog5-x64 09 C:\Windows\system32\wlidnsp.dll [66048 2015-10-30] (Microsoft Corporation)<br>
Hosts: Há mais de uma entrada no Hosts. Veja a seção Hosts do Addition.txt<br>
Tcpip\Parameters: [DhcpNameServer] 201.17.1.90 201.17.0.65<br>
Tcpip\..\Interfaces\{83b14409-9338-4711-aa61-ffe332fe7807}: [DhcpNameServer] 201.17.1.90 201.17.0.65<br>
<br>
Internet Explorer:<br>
==================<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com.br/<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie<br>
HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie<br>
SearchScopes: HKU\S-1-5-21-3919632497-1473999287-3719428057-1000 -&gt; DefaultScope {AB8E0A1C-25EF-49A6-A15D-F4DE1B9CFA83} URL = hxxps://www.google.com/search?q={searchTerms}<br>
SearchScopes: HKU\S-1-5-21-3919632497-1473999287-3719428057-1000 -&gt; {37A1CB8F-91AE-4CED-9B46-1F83FC36B8BB} URL = hxxp://www.google.com/search?hl=en&amp;q={searchTerms}<br>
SearchScopes: HKU\S-1-5-21-3919632497-1473999287-3719428057-1000 -&gt; {70D46D94-BF1E-45ED-B567-48701376298E} URL = hxxp://127.0.0.1:4664/search&amp;s=Vec0qmTC8rtxwowValP4_hwOmvc?q={searchTerms}<br>
SearchScopes: HKU\S-1-5-21-3919632497-1473999287-3719428057-1000 -&gt; {AB8E0A1C-25EF-49A6-A15D-F4DE1B9CFA83} URL = hxxps://www.google.com/search?q={searchTerms}<br>
BHO: Lync Browser Helper -&gt; {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -&gt; C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2015-11-01] (Microsoft Corporation)<br>
BHO: Norton Identity Protection -&gt; {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -&gt; C:\Program Files (x86)\Norton 360\Engine64\22.5.5.15\coIEPlg.dll [2015-11-05] (Symantec Corporation)<br>
BHO: Java(tm) Plug-In SSV Helper -&gt; {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -&gt; C:\Program Files\Java\jre1.8.0_65\bin\ssv.dll [2015-10-25] (Oracle Corporation)<br>
BHO: Skype Click to Call for Internet Explorer -&gt; {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -&gt; C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)<br>
BHO: Logitech SetPoint -&gt; {AF949550-9094-4807-95EC-D1C317803333} -&gt; C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)<br>
BHO: Sem Nome -&gt; {B4F3A835-0E21-4959-BA22-42B3008E02FF} -&gt; Nenhum Arquivo<br>
BHO: Microsoft OneDrive for Business Browser Helper -&gt; {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -&gt; C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2015-11-01] (Microsoft Corporation)<br>
BHO: Java(tm) Plug-In 2 SSV Helper -&gt; {DBC80044-A445-435b-BC74-9C25C1C588A9} -&gt; C:\Program Files\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-25] (Oracle Corporation)<br>
BHO-x32: Adobe PDF Reader Link Helper -&gt; {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -&gt; C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2012-09-23] (Adobe Systems Incorporated)<br>
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -&gt; {3049C3E9-B461-4BC5-8870-4C09146192CA} -&gt; C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2013-08-14] (RealDownloader)<br>
BHO-x32: Norton Identity Protection -&gt; {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -&gt; C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\coIEPlg.dll [2015-11-05] (Symantec Corporation)<br>
BHO-x32: Norton Vulnerability Protection -&gt; {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -&gt; C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\IPS\IPSBHO.DLL =&gt; Nenhum Arquivo<br>
BHO-x32: Evernote extension -&gt; {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -&gt; C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2015-12-01] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)<br>
BHO-x32: Adobe PDF Conversion Toolbar Helper -&gt; {AE7CD045-E861-484f-8273-0445EE161910} -&gt; C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-23] (Adobe Systems Incorporated)<br>
BHO-x32: Skype Click to Call for Internet Explorer -&gt; {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -&gt; C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)<br>
BHO-x32: Logitech SetPoint -&gt; {AF949550-9094-4807-95EC-D1C317803333} -&gt; C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)<br>
BHO-x32: Office Document Cache Handler -&gt; {B4F3A835-0E21-4959-BA22-42B3008E02FF} -&gt; C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)<br>
BHO-x32: GbIehObj Class -&gt; {C41A1C0E-EA6C-11D4-B1B8-444553540008} -&gt; C:\PROGRAM FILES (X86)\GBPLUGIN\gbiehuni.dll [2015-07-06] (Banco Itaú Unibanco)<br>
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\22.5.5.15\coIEPlg.dll [2015-11-05] (Symantec Corporation)<br>
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll [2006-10-23] (Adobe Systems Incorporated)<br>
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\coIEPlg.dll [2015-11-05] (Symantec Corporation)<br>
Toolbar: HKU\S-1-5-21-3919632497-1473999287-3719428057-1000 -&gt; Sem Nome - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - Nenhum Arquivo<br>
DPF: HKLM-x32 {721700FE-7F0E-49C5-BDED-CA92B7CB1245} hxxp://192.168.0.5/camclictrl.cab<br>
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-11-01] (Microsoft Corporation)<br>
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-11-01] (Microsoft Corporation)<br>
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-11-01] (Microsoft Corporation)<br>
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-11-01] (Microsoft Corporation)<br>
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)<br>
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)<br>
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)<br>
<br>
FireFox:<br>
========<br>
FF Plugin: @adobe.com/FlashPlayer -&gt; C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll [2015-12-10] ()<br>
FF Plugin: @garmin.com/GpsControl -&gt; C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)<br>
FF Plugin: @java.com/DTPlugin,version=11.65.2 -&gt; C:\Program Files\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-25] (Oracle Corporation)<br>
FF Plugin: @java.com/JavaPlugin,version=11.65.2 -&gt; C:\Program Files\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-25] (Oracle Corporation)<br>
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -&gt; C:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)<br>
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -&gt; C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)<br>
FF Plugin-x32: @adobe.com/FlashPlayer -&gt; C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-10] ()<br>
FF Plugin-x32: @D-Link.com/camclictrl -&gt; C:\Program Files (x86)\D-Link\Plugin\npCamCliCtrl.dll [2013-10-11] (D-Link Corp.)<br>
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -&gt; C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)<br>
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -&gt; C:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)<br>
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -&gt; C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)<br>
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -&gt; C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2015-11-01] (Microsoft Corporation)<br>
FF Plugin-x32: @nvidia.com/3DVision -&gt; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-11-24] (NVIDIA Corporation)<br>
FF Plugin-x32: @nvidia.com/3DVisionStreaming -&gt; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-11-24] (NVIDIA Corporation)<br>
FF Plugin-x32: @qnap.com/QVR -&gt; C:\Program Files (x86)\QNAP\QVR\npQVRHost.dll [2015-09-03] ( QNAP System, Inc)<br>
FF Plugin-x32: @real.com/nppl3260;version=16.0.3.51 -&gt; c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2013-12-04] (RealNetworks, Inc.)<br>
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -&gt; C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2013-08-14] (RealNetworks, Inc.)<br>
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.3 -&gt; C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2013-08-14] (RealNetworks, Inc.)<br>
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -&gt; C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2013-08-14] (RealNetworks, Inc.)<br>
FF Plugin-x32: @real.com/nprpplugin;version=16.0.3.51 -&gt; c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2013-12-04] (RealPlayer)<br>
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 -&gt; C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2013-08-14] (RealDownloader)<br>
FF Plugin-x32: @tools.google.com/Google Update;version=3 -&gt; C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)<br>
FF Plugin-x32: @tools.google.com/Google Update;version=9 -&gt; C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)<br>
FF Plugin-x32: Adobe Reader -&gt; C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)<br>
FF Plugin HKU\S-1-5-21-3919632497-1473999287-3719428057-1000: @tools.google.com/Google Update;version=3 -&gt; C:\Users\Marcelo\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)<br>
FF Plugin HKU\S-1-5-21-3919632497-1473999287-3719428057-1000: @tools.google.com/Google Update;version=9 -&gt; C:\Users\Marcelo\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)<br>
FF Plugin HKU\S-1-5-21-3919632497-1473999287-3719428057-1000: <a href="http://www.mydlink.com/Uplayer" target="_blank">www.mydlink.com/Uplayer</a> -&gt; C:\Users\Marcelo\AppData\Roaming\dlink\Uplayer\1.0.0.33\npUplayer.dll [2015-07-09] (D-LINK CORPORATION)<br>
FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.0.124\coFFAddon<br>
FF Extension: Norton Identity Safe - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.0.124\coFFAddon [2015-12-04] [não assinado]<br>
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext<br>
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-12-04] [não assinado]<br>
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt<br>
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-10-28] [não assinado]<br>
FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.0.124\coFFAddon<br>
<br>
Chrome: <br>
=======<br>
CHR HomePage: Profile 1 -&gt; hxxp://www.google.com.br/<br>
CHR StartupUrls: Profile 1 -&gt; "hxxps://mail.google.com/mail/u/0/?shva=1#inbox","hxxps://www.google.com/calendar/render?tab=mc","hxxps://mail.google.com/mail/u/0/?tab=cm#contacts","hxxps://www.todoist.com/","hxxp://www.uol.com.br/","hxxp://globoesporte.globo.com/","hxxp://magnatune.com/artists/albums/paternoster-cellosuites1/","hxxp://cbn.globoradio.globo.com/Player/playerAoVivoRJ.htm","hxxps://chrome.google.com/webstore/category/extensions?hl=pt-BR","hxxps://flipboard.com/","hxxp://www.google.com/"<br>
CHR DefaultSearchKeyword: Profile 1 -&gt; google.com.br_<br>
CHR Profile: C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default<br>
CHR Extension: (Google Drive) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-20]<br>
CHR Extension: (YouTube) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-27]<br>
CHR Extension: (Norton Security Toolbar) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2015-10-07]<br>
CHR Extension: (Google Search) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-26]<br>
CHR Extension: (Google Agenda) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2015-10-13]<br>
CHR Extension: (EXAME.com para Chrome) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjeomhheecfjcmhkncjhoedhchbahmpg [2015-09-15]<br>
CHR Extension: (Kindle Cloud Reader) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2015-09-15]<br>
CHR Extension: (Flow) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihgnmdcofnoffcdffjonphfgmenojooh [2015-09-15]<br>
CHR Extension: (YouTube) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijoffpmfcdnncgblkdnobhomnjnkofdm [2015-09-16]<br>
CHR Extension: (Online PDF Tools) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jddfpnmfhodaljeelokfceepbeapgbdn [2015-09-15]<br>
CHR Extension: (Clipular! Research, save &amp; share screenshot) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmjbgcjbgmcfgbgikmbdioggjlhjegpp [2015-09-15]<br>
CHR Extension: (conversor de moeda) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbhghjdcfghfhlogkgdklfgmpodeglno [2015-09-15]<br>
CHR Extension: (ShiftEdit) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcgmndephhjcabhhjfcmncnhbmgbkpij [2015-09-27]<br>
CHR Extension: (Codenvy) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lefigjbiimiemfhjmibbgemkpenelmag [2015-09-15]<br>
CHR Extension: (Google Maps) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-09-19]<br>
CHR Extension: (Google Search) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfpjmkngecpnnajkmdhplmeoelenkpgk [2015-09-16]<br>
CHR Extension: (PDF Cloud Tools) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjpieolhcmajmolkhbbeljknkcdcmffk [2015-09-15]<br>
CHR Extension: (Google Play Books) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2015-09-15]<br>
CHR Extension: (Conversor de Unidade Universal) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafkejlpknmikohhgdelefdeeieplkog [2015-09-15]<br>
CHR Extension: (Cloud9) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbdmccoknlfggadpfkmcpnamfnbkmkcp [2015-09-15]<br>
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-15]<br>
CHR Extension: (Picasa) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2015-09-15]<br>
CHR Extension: (RealtimeBoard) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\opfmbdmhambgleempeofcjjhjclimccg [2015-09-15]<br>
CHR Extension: (Booking.com) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pficdecjkdlnacnnbkociacmdbpmhdoc [2015-09-15]<br>
CHR Extension: (Gmail) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-15]<br>
CHR Profile: C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1<br>
CHR Extension: (Google Drive) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-14]<br>
CHR Extension: (YouTube) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-14]<br>
CHR Extension: (Norton Security Toolbar) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2015-12-14]<br>
CHR Extension: (Google Search) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-14]<br>
CHR Extension: (Google Agenda) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2015-12-14]<br>
CHR Extension: (Documentos Google off-line) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-14]<br>
CHR Extension: (EXAME.com para Chrome) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gjeomhheecfjcmhkncjhoedhchbahmpg [2015-12-14]<br>
CHR Extension: (Kindle Cloud Reader) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2015-12-14]<br>
CHR Extension: (Flow) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ihgnmdcofnoffcdffjonphfgmenojooh [2015-12-14]<br>
CHR Extension: (Norton Identity Safe) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-12-14]<br>
CHR Extension: (YouTube) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ijoffpmfcdnncgblkdnobhomnjnkofdm [2015-12-14]<br>
CHR Extension: (Online PDF Tools) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jddfpnmfhodaljeelokfceepbeapgbdn [2015-12-14]<br>
CHR Extension: (Clipular! Research, save &amp; share screenshot) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jmjbgcjbgmcfgbgikmbdioggjlhjegpp [2015-12-14]<br>
CHR Extension: (conversor de moeda) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lbhghjdcfghfhlogkgdklfgmpodeglno [2015-12-14]<br>
CHR Extension: (ShiftEdit) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lcgmndephhjcabhhjfcmncnhbmgbkpij [2015-12-14]<br>
CHR Extension: (Codenvy) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lefigjbiimiemfhjmibbgemkpenelmag [2015-12-14]<br>
CHR Extension: (Google Maps) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-12-14]<br>
CHR Extension: (Google Search) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mfpjmkngecpnnajkmdhplmeoelenkpgk [2015-12-14]<br>
CHR Extension: (PDF Cloud Tools) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mjpieolhcmajmolkhbbeljknkcdcmffk [2015-12-14]<br>
CHR Extension: (Google Play Books) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2015-12-14]<br>
CHR Extension: (Conversor de Unidade Universal) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nafkejlpknmikohhgdelefdeeieplkog [2015-12-14]<br>
CHR Extension: (Cloud9) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nbdmccoknlfggadpfkmcpnamfnbkmkcp [2015-12-14]<br>
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-14]<br>
CHR Extension: (Picasa) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2015-12-14]<br>
CHR Extension: (RealtimeBoard) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\opfmbdmhambgleempeofcjjhjclimccg [2015-12-14]<br>
CHR Extension: (Booking.com) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pficdecjkdlnacnnbkociacmdbpmhdoc [2015-12-14]<br>
CHR Extension: (Gmail) - C:\Users\Marcelo\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-14]<br>
CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\Exts\Chrome.crx [2015-11-30]<br>
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx<br>
CHR HKU\S-1-5-21-3919632497-1473999287-3719428057-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx<br>
CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\Exts\Chrome.crx [2015-11-30]<br>
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]<br>
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx<br>
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]<br>
<br>
==================== Serviços (Whitelisted) ========================<br>
<br>
(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)<br>
<br>
R2 ABBYY.Licensing.PDFTransformer.Classic.4.0; C:\Program Files (x86)\ABBYY PDF Transformer+\NetworkLicenseServer.exe [965848 2015-06-22] (ABBYY Production LLC)<br>
R2 ABBYY.Licensing.ScreenshotReader.Windows.11.0; C:\Program Files (x86)\Common Files\ABBYY\ScreenshotReader\11.00\Licensing\NetworkLicenseServer.exe [821048 2013-08-14] (ABBYY InfoPoisk LLC)<br>
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) [Arquivo não assinado]<br>
R2 APC Data Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe [21880 2012-01-24] (Schneider Electric)<br>
R2 APC UPS Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe [705912 2012-01-24] (Schneider Electric)<br>
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2012-06-01] ()<br>
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2012-06-01] (ASUSTeK Computer Inc.)<br>
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.)<br>
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.02.00\AsusFanControlService.exe [1632256 2012-11-09] (ASUSTeK Computer Inc.) [Arquivo não assinado]<br>
R2 BotkindSyncService; C:\Program Files (x86)\Allway Sync\Bin\SyncService.exe [182784 2015-10-29] () [Arquivo não assinado]<br>
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)<br>
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)<br>
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2869432 2015-11-01] (Microsoft Corporation)<br>
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-15] (Dropbox, Inc.)<br>
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-09-15] (Dropbox, Inc.)<br>
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [233328 2012-01-23] (DTS, Inc)<br>
R2 FirebirdServerDefaultInstance; C:\Program Files (x86)\Firebird\Firebird_2_0\bin\fb_inet_server.exe [1974272 2007-03-02] (FirebirdSQL Project) [Arquivo não assinado]<br>
R3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2013-08-14] (Macrovision Europe Ltd.) [Arquivo não assinado]<br>
R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [394752 2015-12-04] (Microsoft Corporation)<br>
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [Arquivo não assinado]<br>
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [517464 2015-01-28] (Garmin Ltd or its subsidiaries)<br>
R2 GbpSv; C:\Program Files (x86)\GbPlugin\gbpsv.exe [546104 2014-09-29] (GAS Tecnologia)<br>
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156400 2015-11-12] (NVIDIA Corporation)<br>
R2 gkrellmd; C:\Program Files\GKrellM\bin\gkrellmd.exe [75776 2010-10-13] () [Arquivo não assinado]<br>
S3 GoogleDesktopManager-051210-111108; C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe [30192 2013-08-15] (Google)<br>
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company)<br>
R2 HvHost; C:\Windows\System32\hvhostsvc.dll [61440 2015-12-04] (Microsoft Corporation)<br>
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [17408 2015-12-04] (Microsoft Corporation)<br>
R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [22744 2015-02-05] (Microsoft Corporation)<br>
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [376168 2014-10-31] (LogMeIn, Inc.)<br>
S4 LMIMaint; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [226152 2014-10-31] (LogMeIn, Inc.)<br>
S4 LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [407424 2013-04-30] (LogMeIn, Inc.)<br>
S2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [713016 2015-07-22] (Malwarebytes Corporation)<br>
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)<br>
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)<br>
R2 MSSQL$ADK; C:\Program Files (x86)\Microsoft SQL Server\MSSQL11.ADK\MSSQL\Binn\sqlservr.exe [206424 2012-02-11] (Microsoft Corporation)<br>
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4466688 2007-11-07] (Microsoft Corporation)<br>
R2 N360; C:\Program Files (x86)\Norton 360\Engine\22.5.5.15\N360.exe [282016 2015-11-20] (Symantec Corporation)<br>
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872688 2015-11-12] (NVIDIA Corporation)<br>
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8133424 2015-11-12] (NVIDIA Corporation)<br>
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5915440 2015-11-12] (NVIDIA Corporation)<br>
R2 QVRService; C:\Program Files (x86)\QNAP\QVR\QVRService.exe [73728 2015-09-03] () [Arquivo não assinado]<br>
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()<br>
R2 SACSrv; C:\Program Files\SafeNet\Authentication\SAC\x64\SACSrv.exe [10384 2012-04-16] (SafeNet, Inc.)<br>
R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [616288 2015-03-18] (Copyright 2013 SAMSUNG)<br>
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDFSSvc.exe [1750712 2015-06-16] (Safer-Networking Ltd.)<br>
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDUpdSvc.exe [2102496 2015-06-16] (Safer-Networking Ltd.)<br>
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search &amp; Destroy 2\SDWSCSvc.exe [224712 2015-07-24] (Safer-Networking Ltd.)<br>
S4 SQLAgent$ADK; C:\Program Files (x86)\Microsoft SQL Server\MSSQL11.ADK\MSSQL\Binn\SQLAGENT.EXE [438360 2012-02-11] (Microsoft Corporation)<br>
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)<br>
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [Arquivo não assinado]<br>
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)<br>
S3 Visual Studio Analyzer RPC bridge; C:\Program Files (x86)\Microsoft Visual Studio\Common\Tools\VS-Ent98\Vanalyzr\varpc.exe [34036 1998-06-06] (Microsoft Corporation) [Arquivo não assinado]<br>
S3 vmcompute; C:\Windows\system32\vmcompute.exe [1142272 2015-12-04] (Microsoft Corporation)<br>
R2 vmms; C:\Windows\system32\vmms.exe [14384128 2015-12-04] (Microsoft Corporation)<br>
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-07] (Microsoft Corporation)<br>
R2 Warsaw Technology; C:\Program Files\Diebold\Warsaw\core.exe [858424 2015-08-18] (GAS Tecnologia LTDA)<br>
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)<br>
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)<br>
S3 WMSVC; C:\Windows\system32\inetsrv\wmsvc.exe [12288 2015-12-04] (Microsoft Corporation)<br>
<br>
===================== Drivers (Whitelisted) ==========================<br>
<br>
(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)<br>
<br>
R3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTek Computer Inc.)<br>
R3 AKSIFDH; C:\Windows\system32\DRIVERS\aksifdh.sys [62632 2008-07-30] (Aladdin Knowledge Systems, Ltd.)<br>
S3 AKSUP; C:\Windows\system32\drivers\aksup.sys [44712 2008-07-30] (Aladdin Knowledge Systems, Ltd.)<br>
S3 ampa; C:\Windows\system32\ampa.sys [17008 2013-11-29] ()<br>
S3 ampa; C:\Windows\SysWOW64\ampa.sys [17008 2013-11-29] ()<br>
R0 asahci64; C:\Windows\System32\drivers\asahci64.sys [49760 2012-01-06] (Asmedia Technology)<br>
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()<br>
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2012-09-14] ()<br>
R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\BASHDefs\20151207.001\BHDrvx64.sys [1665608 2015-10-08] (Symantec Corporation)<br>
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1605050.00F\ccSetx64.sys [173808 2015-07-10] (Symantec Corporation)<br>
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [498512 2015-11-18] (Symantec Corporation)<br>
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [157520 2015-11-18] (Symantec Corporation)<br>
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [63064 2015-07-22] ()<br>
R0 file_tracker; C:\Windows\System32\DRIVERS\file_tracker.sys [296736 2014-09-22] (Acronis International GmbH)<br>
R1 hvservice; C:\Windows\System32\drivers\hvservice.sys [71008 2015-12-04] (Microsoft Corporation)<br>
R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\IPSDefs\20151211.001\IDSvia64.sys [767224 2015-12-04] (Symantec Corporation)<br>
R3 iKeyEnum; C:\Windows\system32\DRIVERS\ikeyenum.sys [16160 2010-07-08] (SafeNet, Inc.)<br>
R3 iKeyIFD; C:\Windows\system32\DRIVERS\ikeyifd.sys [22304 2010-07-08] (SafeNet, Inc.)<br>
R2 LMIInfo; C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [16056 2013-04-30] (LogMeIn, Inc.)<br>
S3 lunparser; C:\Windows\System32\drivers\lunparser.sys [22528 2015-12-04] (Microsoft Corporation)<br>
R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [109272 2015-06-18] (Malwarebytes Corporation)<br>
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)<br>
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2015-12-14] (Malwarebytes)<br>
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)<br>
R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\VirusDefs\20151214.002\ENG64.SYS [138488 2015-10-27] (Symantec Corporation)<br>
R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\VirusDefs\20151214.002\EX64.SYS [2148080 2015-10-27] (Symantec Corporation)<br>
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19760 2015-11-12] (NVIDIA Corporation)<br>
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)<br>
S3 OXUDIDRV; C:\Windows\system32\Drivers\OXUDIDRV_X64.sys [31280 2010-05-25] ()<br>
S3 passthruparser; C:\Windows\System32\drivers\passthruparser.sys [23552 2015-12-04] (Microsoft Corporation)<br>
S3 pcip; C:\Windows\System32\drivers\pcip.sys [44544 2015-12-04] (Microsoft Corporation)<br>
S3 pvhdparser; C:\Windows\System32\drivers\pvhdparser.sys [50176 2015-12-04] (Microsoft Corporation)<br>
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()<br>
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()<br>
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek )<br>
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation)<br>
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1605050.00F\SRTSP64.SYS [928496 2015-11-11] (Symantec Corporation)<br>
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1605050.00F\SRTSPX64.SYS [50936 2015-07-10] (Symantec Corporation)<br>
S3 STTub30; C:\Windows\System32\Drivers\STTub30.sys [44184 2015-10-29] (STMicroelectronics)<br>
R0 SymEFASI; C:\Windows\System32\drivers\N360x64\1605050.00F\SYMEFASI64.SYS [1621232 2015-11-11] (Symantec Corporation)<br>
S0 SymELAM; C:\Windows\System32\drivers\N360x64\1605050.00F\SymELAM.sys [24192 2015-07-10] (Symantec Corporation)<br>
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [111344 2015-07-26] (Symantec Corporation)<br>
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1605050.00F\Ironx64.SYS [297720 2015-07-10] (Symantec Corporation)<br>
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1605050.00F\SYMNETS.SYS [577768 2015-11-11] (Symantec Corporation)<br>
R3 Synth3dVsp; C:\Windows\System32\drivers\synth3dvsp.sys [101888 2015-12-04] (Microsoft Corporation)<br>
R2 tib; C:\Windows\System32\DRIVERS\tib.sys [1058632 2015-07-26] (Acronis International GmbH)<br>
S2 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [248648 2015-07-26] (Acronis International GmbH)<br>
S3 vhdparser; C:\Windows\System32\drivers\vhdparser.sys [26624 2015-12-04] (Microsoft Corporation)<br>
R2 VMSP; C:\Windows\System32\drivers\vmswitch.sys [976384 2015-12-04] (Microsoft Corporation)<br>
R0 vmsproxy; C:\Windows\System32\drivers\vmsproxy.sys [22016 2015-12-04] (Microsoft Corporation)<br>
S3 VMSVSF; C:\Windows\System32\drivers\vmswitch.sys [976384 2015-12-04] (Microsoft Corporation)<br>
S3 VMSVSP; C:\Windows\System32\drivers\vmswitch.sys [976384 2015-12-04] (Microsoft Corporation)<br>
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)<br>
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)<br>
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)<br>
R4 WinDivert1.1; C:\Program Files\Diebold\Warsaw\WinDivert64.sys [38104 2015-04-01] (Basil)<br>
S3 WinNat; C:\Windows\System32\drivers\winnat.sys [350720 2015-12-04] (Microsoft Corporation)<br>
U3 idsvc; não ImagePath<br>
U5 REALPLAYERUPDATESVC; não ImagePath<br>
<br>
==================== NetSvcs (Whitelisted) ===================<br>
<br>
(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)<br>
<br>
<br>
==================== Um Mês Criados arquivos e pastas ========<br>
<br>
(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)<br>
<br>
2015-12-14 17:57 - 2015-12-14 17:59 - 00000000 ____D C:\FRST<br>
2015-12-14 17:57 - 2015-12-14 17:57 - 00000207 _____ C:\WINDOWS\tweaking.com-regbackup-MARCELO-CASA-Windows-10-Pro-(64-bit).dat<br>
2015-12-14 17:57 - 2015-12-14 17:57 - 00000000 ____D C:\RegBackup<br>
2015-12-14 17:56 - 2015-12-14 17:56 - 00016681 _____ C:\WINDOWS\Tweaking.com - Registry Backup Setup Log.txt<br>
2015-12-14 17:56 - 2015-12-14 17:56 - 00002325 _____ C:\Users\Marcelo\Desktop\Tweaking.com - Registry Backup.lnk<br>
2015-12-14 17:56 - 2015-12-14 17:56 - 00000000 ____D C:\Users\Marcelo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tweaking.com<br>
2015-12-14 17:56 - 2015-12-14 17:56 - 00000000 ____D C:\Program Files (x86)\Tweaking.com<br>
2015-12-14 17:45 - 2015-12-14 17:45 - 00000000 ____D C:\Program Files (x86)\ESET<br>
2015-12-14 17:22 - 2015-12-09 22:26 - 00002363 _____ C:\Users\Marcelo\Desktop\Marcelo - Chrome.lnk<br>
2015-12-14 16:52 - 2015-12-14 16:52 - 00001371 _____ C:\Users\Marcelo\Desktop\Todoist.lnk<br>
2015-12-14 16:52 - 2015-12-14 16:52 - 00000000 ____D C:\Users\Marcelo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Todoist<br>
2015-12-14 16:52 - 2015-12-14 16:52 - 00000000 ____D C:\Users\Marcelo\AppData\Local\Todoist<br>
2015-12-14 16:52 - 2015-12-14 16:52 - 00000000 ____D C:\Users\Marcelo\AppData\Local\Doist_Ltd<br>
2015-12-11 14:29 - 2015-12-11 14:29 - 00002523 _____ C:\Users\Public\Desktop\Evernote.lnk<br>
2015-12-11 14:29 - 2015-12-11 14:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote<br>
2015-12-09 22:49 - 2015-12-09 22:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox<br>
2015-12-05 12:21 - 2015-12-05 12:21 - 00000000 ____D C:\WINDOWS\system32\SleepStudy<br>
2015-12-04 08:41 - 2015-12-04 08:41 - 00000000 ____D C:\Users\Marcelo\AppData\Local\ActiveSync<br>
2015-12-04 08:39 - 2015-12-04 08:39 - 00000020 ___SH C:\Users\Marcelo\ntuser.ini<br>
2015-12-04 05:19 - 2015-12-04 06:00 - 00000000 ___DC C:\WINDOWS\Panther<br>
2015-12-04 05:17 - 2015-12-04 05:17 - 00000000 ____D C:\Windows.old<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 24603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 22394880 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 16984064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 14384128 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmms.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 13376512 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 13017088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 12120064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 03670832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 02918808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 02587136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 02064384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 01998848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 01707008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 01126744 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 01036640 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00940888 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00798560 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00071008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00019808 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll<br>
2015-12-04 05:16 - 2015-12-04 05:16 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll<br>
2015-12-04 05:15 - 2015-12-04 05:15 - 00008192 _____ C:\WINDOWS\system32\config\userdiff<br>
2015-12-04 05:13 - 2015-12-04 05:13 - 00004096 _____ C:\WINDOWS\system32\config\VSMIDK<br>
2015-12-04 05:13 - 2015-12-04 05:13 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IIS<br>
2015-12-04 05:13 - 2015-12-04 05:13 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer<br>
2015-12-04 05:13 - 2015-12-04 05:13 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices<br>
2015-12-04 05:13 - 2015-12-04 05:13 - 00000000 ____D C:\WINDOWS\system32\msmq<br>
2015-12-04 05:13 - 2015-12-04 05:13 - 00000000 ____D C:\WINDOWS\system32\BestPractices<br>
2015-12-04 05:13 - 2015-12-04 05:13 - 00000000 ____D C:\WINDOWS\system32\0416<br>
2015-12-04 05:13 - 2015-12-04 05:13 - 00000000 ____D C:\Program Files\Reference Assemblies<br>
2015-12-04 05:13 - 2015-12-04 05:13 - 00000000 ____D C:\Program Files\MSBuild<br>
2015-12-04 05:13 - 2015-12-04 05:13 - 00000000 ____D C:\Program Files\Hyper-V<br>
2015-12-04 05:13 - 2015-12-04 05:13 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies<br>
2015-12-04 05:13 - 2015-12-04 05:13 - 00000000 ____D C:\inetpub<br>
2015-12-04 05:13 - 2015-12-04 04:31 - 00000000 ____D C:\Program Files (x86)\MSBuild<br>
2015-12-04 05:13 - 2015-10-23 18:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll<br>
2015-12-04 05:13 - 2015-10-23 18:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll<br>
2015-12-04 05:13 - 2015-10-23 18:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe<br>
2015-12-04 05:12 - 2015-10-23 18:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll<br>
2015-12-04 05:12 - 2015-10-23 18:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe<br>
2015-12-04 05:12 - 2015-10-23 18:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programas<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Histórico<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Dados de Aplicativos<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default\Modelos<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default\Meus Documentos<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default\Menu Iniciar<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default\Dados de Aplicativos<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default\Configurações Locais<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default\AppData\Local\Histórico<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dados de Aplicativos<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default\Ambiente de Rede<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default\Ambiente de Impressão<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programas<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Histórico<br>
2015-12-04 04:58 - 2015-12-04 04:58 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Dados de Aplicativos<br>
2015-12-04 04:56 - 2015-12-11 02:46 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT<br>
2015-12-04 04:43 - 2015-12-04 04:43 - 00000020 ___SH C:\Users\MSSQL$ADK\ntuser.ini<br>
2015-12-04 04:41 - 2015-12-04 04:41 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk<br>
2015-12-04 04:41 - 2015-12-04 04:41 - 00000000 ____D C:\Users\Usuário Padrão\AppData\Roaming\Media Center Programs<br>
2015-12-04 04:41 - 2015-12-04 04:41 - 00000000 ____D C:\Users\Usuário Padrão\AppData\Local\Microsoft Help<br>
2015-12-04 04:41 - 2015-12-04 04:41 - 00000000 ____D C:\Users\Usuário Padrão\AppData\Local\Google<br>
2015-12-04 04:41 - 2015-12-04 04:41 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs<br>
2015-12-04 04:41 - 2015-12-04 04:41 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help<br>
2015-12-04 04:41 - 2015-12-04 04:41 - 00000000 ____D C:\Users\Default\AppData\Local\Google<br>
2015-12-04 04:41 - 2015-12-04 04:41 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs<br>
2015-12-04 04:41 - 2015-12-04 04:41 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help<br>
2015-12-04 04:41 - 2015-12-04 04:41 - 00000000 ____D C:\Users\Default User\AppData\Local\Google<br>
2015-12-04 04:31 - 2015-12-04 04:31 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines<br>
2015-12-04 04:26 - 2015-12-04 04:42 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate<br>
2015-12-04 04:23 - 2015-12-04 08:42 - 00000000 ____D C:\Users\Marcelo<br>
2015-12-04 04:23 - 2015-12-04 04:57 - 00000000 ____D C:\Users\Grazi<br>
2015-12-04 04:23 - 2015-12-04 04:54 - 00000000 ____D C:\Users\Classic .NET AppPool<br>
2015-12-04 04:23 - 2015-12-04 04:54 - 00000000 ____D C:\Users\.NET v2.0 Classic<br>
2015-12-04 04:23 - 2015-12-04 04:53 - 00000000 ____D C:\Users\DefaultAppPool<br>
2015-12-04 04:23 - 2015-12-04 04:53 - 00000000 ____D C:\Users\.NET v4.5<br>
2015-12-04 04:23 - 2015-12-04 04:52 - 00000000 ____D C:\Users\.NET v2.0<br>
2015-12-04 04:23 - 2015-12-04 04:51 - 00000000 ____D C:\Users\.NET v4.5 Classic<br>
2015-12-04 04:23 - 2015-12-04 04:45 - 00000000 ____D C:\Users\MSSQL$ADK<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\MSSQL$ADK\Modelos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\MSSQL$ADK\Meus Documentos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\MSSQL$ADK\Menu Iniciar<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\MSSQL$ADK\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\MSSQL$ADK\Configurações Locais<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Start Menu\Programas<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\MSSQL$ADK\AppData\Local\Histórico<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\MSSQL$ADK\AppData\Local\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\MSSQL$ADK\Ambiente de Rede<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\MSSQL$ADK\Ambiente de Impressão<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Marcelo\Modelos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Marcelo\Meus Documentos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Marcelo\Menu Iniciar<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Marcelo\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Marcelo\Configurações Locais<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Marcelo\AppData\Roaming\Microsoft\Windows\Start Menu\Programas<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Marcelo\AppData\Local\Histórico<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Marcelo\AppData\Local\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Marcelo\Ambiente de Rede<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Marcelo\Ambiente de Impressão<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Grazi\Modelos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Grazi\Meus Documentos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Grazi\Menu Iniciar<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Grazi\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Grazi\Configurações Locais<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Grazi\AppData\Roaming\Microsoft\Windows\Start Menu\Programas<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Grazi\AppData\Local\Histórico<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Grazi\AppData\Local\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Grazi\Ambiente de Rede<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Grazi\Ambiente de Impressão<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Modelos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Meus Documentos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Menu Iniciar<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Configurações Locais<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programas<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Histórico<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Ambiente de Rede<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\DefaultAppPool\Ambiente de Impressão<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Classic .NET AppPool\Modelos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Classic .NET AppPool\Meus Documentos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Classic .NET AppPool\Menu Iniciar<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Classic .NET AppPool\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Classic .NET AppPool\Configurações Locais<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programas<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Classic .NET AppPool\AppData\Local\Histórico<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Classic .NET AppPool\AppData\Local\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Classic .NET AppPool\Ambiente de Rede<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\Classic .NET AppPool\Ambiente de Impressão<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5\Modelos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5\Meus Documentos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5\Menu Iniciar<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5\Configurações Locais<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programas<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5\AppData\Local\Histórico<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5\AppData\Local\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5\Ambiente de Rede<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5\Ambiente de Impressão<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5 Classic\Modelos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5 Classic\Meus Documentos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5 Classic\Menu Iniciar<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5 Classic\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5 Classic\Configurações Locais<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programas<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5 Classic\AppData\Local\Histórico<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5 Classic\AppData\Local\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5 Classic\Ambiente de Rede<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v4.5 Classic\Ambiente de Impressão<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0\Modelos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0\Meus Documentos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0\Menu Iniciar<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0\Configurações Locais<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programas<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0\AppData\Local\Histórico<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0\AppData\Local\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0\Ambiente de Rede<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0\Ambiente de Impressão<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0 Classic\Modelos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0 Classic\Meus Documentos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0 Classic\Menu Iniciar<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0 Classic\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0 Classic\Configurações Locais<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programas<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0 Classic\AppData\Local\Histórico<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0 Classic\AppData\Local\Dados de Aplicativos<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0 Classic\Ambiente de Rede<br>
2015-12-04 04:23 - 2015-12-04 04:23 - 00000000 _SHDL C:\Users\.NET v2.0 Classic\Ambiente de Impressão<br>
2015-12-04 04:22 - 2015-12-11 14:30 - 02376140 _____ C:\WINDOWS\system32\PerfStringBackup.INI<br>
2015-12-04 04:22 - 2015-12-04 04:22 - 02034332 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI<br>
2015-12-04 04:21 - 2015-12-04 04:31 - 00000000 ____D C:\Program Files\Common Files\logishrd<br>
2015-12-04 04:21 - 2015-12-04 04:21 - 00018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys<br>
2015-12-04 04:21 - 2015-12-04 04:21 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_SensorsSimulatorDriver_01_11_00.Wdf<br>
2015-12-04 04:21 - 2015-12-04 04:21 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM<br>
2015-12-04 04:21 - 2015-12-04 04:21 - 00000000 ____D C:\Program Files\Realtek<br>
2015-12-04 04:20 - 2015-12-04 04:43 - 00370696 _____ C:\WINDOWS\system32\FNTCACHE.DAT<br>
2015-12-04 04:20 - 2015-12-04 04:43 - 00000000 ____D C:\Users\Todos os Usuários\NVIDIA<br>
2015-12-04 04:20 - 2015-12-04 04:43 - 00000000 ____D C:\ProgramData\NVIDIA<br>
2015-12-04 04:20 - 2015-12-04 04:32 - 00000000 ____D C:\Users\Todos os Usuários\NVIDIA Corporation<br>
2015-12-04 04:20 - 2015-12-04 04:32 - 00000000 ____D C:\ProgramData\NVIDIA Corporation<br>
2015-12-04 04:20 - 2015-12-04 04:31 - 00000000 ____D C:\Program Files\NVIDIA Corporation<br>
2015-12-04 04:20 - 2015-12-04 04:31 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation<br>
2015-12-04 04:20 - 2015-11-24 17:32 - 06358648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll<br>
2015-12-04 04:20 - 2015-11-24 17:32 - 02983032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll<br>
2015-12-04 04:20 - 2015-11-24 17:32 - 02554672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll<br>
2015-12-04 04:20 - 2015-11-24 17:32 - 00938616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe<br>
2015-12-04 04:20 - 2015-11-24 17:32 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll<br>
2015-12-04 04:20 - 2015-11-24 17:32 - 00062768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll<br>
2015-12-04 04:20 - 2015-11-23 18:35 - 06049858 _____ C:\WINDOWS\system32\nvcoproc.bin<br>
2015-12-04 04:20 - 2015-10-30 05:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll<br>
2015-12-02 18:37 - 2013-06-26 18:05 - 00226744 _____ (Micromed Biotecnologia Ltda.) C:\WINDOWS\SysWOW64\MMDSCP.dll<br>
2015-12-01 20:26 - 2015-12-01 20:26 - 00002223 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk<br>
2015-12-01 20:26 - 2015-11-24 16:42 - 00102704 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe<br>
2015-12-01 20:23 - 2015-11-25 22:34 - 11228488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 42913912 _____ C:\WINDOWS\system32\nvcompiler.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 37882672 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 22345336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 18487360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 18389624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 16561320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 15933400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 15839392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 14844304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 13533416 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 12870384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 12040952 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 03540360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 03126800 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 02876536 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 02496816 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 01905272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435906.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 01572496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 01564792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435906.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00877872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00861816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00689784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00673912 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00539464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00445400 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00205456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00177416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00155976 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00151368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00039240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll<br>
2015-12-01 20:23 - 2015-11-24 21:07 - 00034494 _____ C:\WINDOWS\system32\nvinfo.pb<br>
2015-12-01 13:06 - 2015-12-04 04:42 - 00000000 ____D C:\Users\Marcelo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplicativo Itaú<br>
2015-11-26 20:33 - 2015-11-26 20:33 - 00000000 ___DL C:\Users\Todos os Usuários\Package Cache<br>
2015-11-26 20:33 - 2015-11-26 20:33 - 00000000 ___DL C:\ProgramData\Package Cache<br>
2015-11-26 16:51 - 2015-12-04 04:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Folder Size<br>
2015-11-26 16:51 - 2015-11-26 16:51 - 00001124 _____ C:\Users\Marcelo\Desktop\Folder Size.lnk<br>
2015-11-26 16:51 - 2015-11-26 16:51 - 00000000 ____D C:\Users\Todos os Usuários\MindGems<br>
2015-11-26 16:51 - 2015-11-26 16:51 - 00000000 ____D C:\ProgramData\MindGems<br>
2015-11-26 16:51 - 2015-11-26 16:51 - 00000000 ____D C:\Program Files (x86)\Folder Size<br>
2015-11-22 14:09 - 2015-11-16 01:54 - 01905456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435900.dll<br>
2015-11-22 14:09 - 2015-11-16 01:54 - 01564792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435900.dll<br>
2015-11-22 14:07 - 2015-11-12 16:37 - 00112712 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll<br>
2015-11-17 23:09 - 2015-11-26 17:31 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk<br>
2015-11-17 23:09 - 2015-11-17 23:09 - 00002137 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk<br>
2015-11-14 01:58 - 2015-11-14 01:58 - 00000877 _____ C:\Users\Marcelo\Desktop\Steam.exe.lnk<br>
<br>
==================== Um Mês Modificados arquivos e pastas ========<br>
<br>
(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)<br>
<br>
2015-12-14 17:57 - 2015-10-30 04:28 - 00000000 ____D C:\Windows<br>
2015-12-14 17:48 - 2015-09-15 23:43 - 00001048 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job<br>
2015-12-14 17:42 - 2015-10-30 20:32 - 00001112 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3919632497-1473999287-3719428057-1000UA.job<br>
2015-12-14 17:42 - 2015-10-30 20:32 - 00001060 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3919632497-1473999287-3719428057-1000Core.job<br>
2015-12-14 17:40 - 2014-02-02 01:16 - 00000902 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job<br>
2015-12-14 17:38 - 2013-08-15 01:08 - 00004182 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{EE067CFD-7726-43B7-B927-6D762F2BD2ED}<br>
2015-12-14 17:25 - 2013-08-15 00:32 - 00001102 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job<br>
2015-12-14 15:47 - 2015-10-01 19:07 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton 360<br>
2015-12-14 14:51 - 2015-02-02 09:46 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys<br>
2015-12-14 12:48 - 2015-04-09 19:31 - 00000000 ____D C:\Program Files (x86)\Affixa<br>
2015-12-14 10:53 - 2013-08-15 00:45 - 00000000 _____ C:\WINDOWS\Path.idx<br>
2015-12-14 10:23 - 2013-08-15 00:53 - 00001640 _____ C:\WINDOWS\MB.idx<br>
2015-12-14 10:00 - 2015-09-15 23:11 - 00000414 _____ C:\WINDOWS\Tasks\Allway Sync_{4DECC64D2D0B616FB06E6AEDC6D65E89}.job<br>
2015-12-14 09:00 - 2014-12-03 19:35 - 00000388 _____ C:\WINDOWS\Tasks\Allway Sync_{449BCC86312B1EEA3A71EAE5662C34AA}.job<br>
2015-12-14 05:25 - 2013-08-15 00:32 - 00001098 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job<br>
2015-12-14 04:13 - 2015-10-30 05:24 - 00000000 ____D C:\WINDOWS\AppReadiness<br>
2015-12-13 11:21 - 2015-10-30 05:24 - 00000000 ____D C:\WINDOWS\system32\NDF<br>
2015-12-13 11:21 - 2013-08-27 13:15 - 00000000 ____D C:\Users\Marcelo\AppData\Local\ElevatedDiagnostics<br>
2015-12-13 01:19 - 2015-10-30 05:24 - 00000000 ___HD C:\Program Files\WindowsApps<br>
2015-12-12 22:48 - 2015-09-15 23:43 - 00001044 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job<br>
2015-12-12 08:58 - 2015-10-30 05:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports<br>
2015-12-11 16:40 - 2014-12-03 17:10 - 00000000 ____D C:\Program Files (x86)\TeamViewer<br>
2015-12-11 14:30 - 2015-10-30 17:11 - 00987028 _____ C:\WINDOWS\system32\prfh0416.dat<br>
2015-12-11 14:30 - 2015-10-30 17:11 - 00232754 _____ C:\WINDOWS\system32\prfc0416.dat<br>
2015-12-11 14:30 - 2015-10-30 05:21 - 00000000 ____D C:\WINDOWS\INF<br>
2015-12-11 14:20 - 2015-10-30 05:11 - 00000000 ____D C:\WINDOWS\CbsTemp<br>
2015-12-11 08:44 - 2015-08-17 19:07 - 00002433 _____ C:\Users\Marcelo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk<br>
2015-12-11 08:40 - 2013-12-04 08:39 - 00003590 _____ C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3919632497-1473999287-3719428057-1000<br>
2015-12-11 08:40 - 2013-12-04 08:39 - 00003530 _____ C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3919632497-1473999287-3719428057-1000<br>
2015-12-10 20:51 - 2013-08-15 02:01 - 00000000 ____D C:\Users\Todos os Usuários\Microsoft Help<br>
2015-12-10 20:51 - 2013-08-15 02:01 - 00000000 ____D C:\ProgramData\Microsoft Help<br>
2015-12-10 20:49 - 2015-04-07 13:35 - 00000000 ____D C:\ProgramData

Satchfan
2015-12-16, 08:46
Hello msdiniz and welcome to Safer Networking Forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:


please follow all instructions in the order posted
please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
if you don't understand something, please don't hesitate to ask for clarification before proceeding
the fixes are specific to your problem and should only be used for this issue on this machine.
please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here (https://toolslib.net/downloads/finish/1/) and save it to your desktop.


run AdwCleaner
when it has finished, select Clean
if it asks to reboot, allow the reboot
on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool (http://thisisudax.org/downloads/JRT.exe) to your desktop.


shut down your protection software now to avoid potential conflicts.
run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
the tool will open and start scanning your system
please be patient as this can take a while to complete depending on your system's specifications
on completion, a log (JRT.txt) is saved to your desktop and will automatically open
post the contents of JRT.txt into your next message.

===================================================

Run Farbar Recovery Scan Tool

Please run FRST again and post the new log plus the Addition.txt log which was also produced with the first run of FRST.

Logs to include with next post:

AdwCleaner log
JRT.txt
Frst.txt
Addition.txt

Thanks

Satchfan

Satchfan
2015-12-20, 10:07
Hi

It has been several days since I replied to your request for help with your computer problems.

Please let me know if you are having problems and still need help.

Thanks

Satchfan

Satchfan
2015-12-21, 17:46
Due to inactivity, this thread will now be closed.

If it has been three days or more since your last post and the helper assisting you posted a response to that post to which you did not reply , your topic will not be re-opened.

If you still require help, please start a new topic and include a new FRST log with a link to your previous thread. Please do not add any logs that might have been requested in the closed topic as you will be starting fresh.