Arquivado

Este tópico foi arquivado e está fechado para novas respostas.

maricris

Análise log HijackThis

19 posts neste tópico

Segue log para análise:

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:59:35, on 11/05/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal
 
Running processes:
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\AVG\AVG2013\avgui.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\user\Downloads\HijackThis.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.greatresults.info/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\coIEPlg.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\IPS\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Auxiliar de Conexão do Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: G-Buster Browser Defense Banco Real - {C41A1C0E-EA6C-11D4-B1B8-444553540007} - C:\PROGRAM FILES (X86)\GBPLUGIN\gbiehabn.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll" (file missing)
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\coIEPlg.dll
O4 - HKLM\..\Run: [bCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [NokiaPCInternetAccess] "C:\Program Files (x86)\Nokia\PC Internet Access\NPCIA.exe" /b
O4 - HKCU\..\Run: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-18\..\Run: [Norton Download Manager{NF22-B22-4abb-B07C-C084B04B4F12}] C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe /m (User 'SISTEMA')
O4 - HKUS\.DEFAULT\..\Run: [Norton Download Manager{NF22-B22-4abb-B07C-C084B04B4F12}] C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe /m (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Exibir ou ocultar HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: wwws.realsecureweb.com.br
O15 - Trusted Zone: www.santander.com.br
O15 - Trusted Zone: www.santanderempresarial.com.br
O15 - Trusted Zone: www.santandernet.com.br
O15 - Trusted Zone: wwws.santandernet.com.br
O15 - Trusted Zone: wwws2.santandernet.com.br
O15 - Trusted Zone: www.santandernetibe.com.br
O15 - Trusted Zone: www.secureweb.com.br
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\progra~2\browse~1\sprote~1.dll
O20 - Winlogon Notify:  GbPluginAbn - C:\Program Files (x86)\GbPlugin\gbiehAbn.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
O23 - Service: Watchdog do AVG (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Gbp Service (GbpSv) - GAS Tecnologia - C:\PROGRA~2\GbPlugin\GbpSv.exe
O23 - Service: Serviço do Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Serviço do Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Management (MCLIENT) - Symantec Corporation - C:\Program Files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
 
--
End of file - 11987 bytes
 

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Baixe o Malwarebytes' Anti-Malware (MBAM) ou aqui.

Salve ou imprima estas instruções:

Dê um duplo-clique no mbam-setup.exe, escolha a linguagem e na instalação, aceite todas as opções padrão.

Verifique se as caixas Atualizar Malwarebytes Anti-Malware e Executar Malwarebytes Anti-Malware estão marcadas e clique então, em Concluir.

Se houver atualizações a serem feitas, serão baixadas e instaladas.

Ao final da atualização, com o programa aberto, marque Verificação Rápida e clique no botão Verificar.

Começará então o exame. Aguarde, pois pode demorar.

Ao acabar o exame, clique em OK, depois no botão Mostrar Resultados para ver o relatório.

Se houver ítens encontrados, certifique-se de que, estão todos marcados e clique no botão Remover.

Ao final da desinfecção, abrirá o Bloco de notas com um Log e poderá aparecer um aviso se quer reiniciar o PC. (Ver Nota abaixo)

O Log é automaticamente salvo pelo MBAM e para vê-lo, clique na aba Logs na janela principal do Programa.

NOTA: Se o MBAM encontrar arquivos que não consiga remover, poderá ter de reiniciar o PC (talvez mais de uma vez). Faça isso imediatamente, ao ser perguntado se quer reiniciar

Selecione, copie e cole o conteúdo do Log do MBAM na sua próxima resposta + um novo Log do HijackThis .



MVP Mr.Million

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

O PC está infectado....



MVP Mr.Million

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Segue log para analise:

 

 

Malwarebytes Anti-Malware (Trial) 1.75.0.1300
www.malwarebytes.org
 
Versão da Base de Dados:  v2013.05.15.06
 
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16540
user :: VERA-PC [administrador]
 
Proteção: Permitir
 
15/05/2013 09:25:03
mbam-log-2013-05-15 (09-25-03).txt
 
Tipo de Verificação:  Verificação Rápida 
Opções de verificações ativadas: Memória | Inicialização | Registro | Sistema de arquivos  | Heurística/Extra | Heurística/Shuriken | PUP | PUM
Opções de verificação desativadas: P2P
Objetos escaneados:  212990
Tempo decorrido: 3 minuto(s), 13 segundo(s)
 
Processos de Memória Detectados: 0
(Não foram detectados ítens maliciosos)
 
Módulos de Memória Detectados: 0
(Não foram detectados ítens maliciosos)
 
Chaves de Registro Detectadas: 0
(Não foram detectados ítens maliciosos)
 
Valores de Registro Detectadas: 0
(Não foram detectados ítens maliciosos)
 
Itens de Dados no Registro Detectadas: 0
(Não foram detectados ítens maliciosos)
 
Pastas Detectadas: 0
(Não foram detectados ítens maliciosos)
 
Arquivos Detectados: 0
(Não foram detectados ítens maliciosos)
 
(fim)
 
 
Obrigada

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ok, continuando...

Desabilite o seu Antivírus, AntiSpyware e Firewall para não haver conflitos. Mantenha-os desativados até terminar as instruções.

Download ComboFix

Salve no seu Desktop ( Para que a Ferramenta seja executada corretamente é necessário que esteja no Desktop (Área de trabalho)

Feche todas as janelas e programas.

É necessário estar conectado durante o procedimento com o ComboFix;

Execute o combofix.exe, tecle "Sim" para prosseguir. Aguarde, pois é um pouco demorado.

OBS: Caso não queira que seja instalado o Console de Recuperação do Windows, clique em "Não" e depois concorde para que a verificação prossiga.

Ao ser instalado o Console, na Inicialização do Sistema será apresentada a tela para Seleção dos Sistemas Operacionais.

Mais informações sobre o Console: http://support.micro...kb/307654/pt-br

O ComboFix reiniciará o PC automaticamente para completar o processo de remoção. Caso isso não aconteça, reinicie manualmente.

Quando acabar, será gerado um Log, que estará em C:\ComboFix.txt. Selecione, copie e cole o conteúdo do ComboFix.txt na sua próxima resposta + um novo Log do HijackThis .

IMPORTANTE: Não use o mouse nem o teclado quando o ComboFix estiver rodando. Para parar ou sair do ComboFix, tecle "N".

OBS 2: Não execute o ComboFix mais do que uma vez. Isso irá sobreescrever o Log e dificultará a remoção do(s) malware(s)

Caso ocorra algum erro, reinicie o computador em Modo Seguro (pressione a tecla F8 intermitentemente, ou F5 em alguns casos, durante a inicialização) e repita o procedimento.



MVP Mr.Million

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Oi, na verdade a unica coisa que eu nao consegui fazer foi salvar no desktop o programa, no que eu cliquei ele ja salvou e rodou automaticamente, então nao faço ideia de onde ele foi salvo.... 
De qualquer forma segue o novo LOG apresentado:

 

 

ComboFix 13-05-18.04 - user 20/05/2013   9:30.1.2 - x64
Microsoft Windows 7 Professional   6.1.7601.1.1252.55.1046.18.4061.1831 [GMT -3:00]
Executando de: c:\users\user\Downloads\ComboFix.exe
AV: AVG antivírus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: AVG antivírus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Norton 360 *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Criado um novo ponto de restauração
.
.
(((((((((((((((((((((((((((((((((((((   Outras Exclusões   )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\boost_interprocess\20130520082008.375199
c:\programdata\boost_interprocess\20130520082008.375199\Nobu64AgentService
c:\programdata\boost_interprocess\20130520082008.375199\Nobu64TrayIcon
c:\programdata\Browase2saaVE
c:\programdata\Browase2saaVE\51657c37b6639.tlb
c:\programdata\Browase2saaVE\settings.ini
c:\programdata\Browase2saaVE\uninstall.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\Browase2saaVE
c:\programdata\Microsoft\Windows\Start Menu\Programs\Browase2saaVE\Browase2saaVE.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\Browase2saaVE\Uninstall.lnk
c:\windows\SysWow64\drivers\ati4irxx.sys
.
.
((((((((((((((((   Arquivos/Ficheiros criados de 2013-04-20 to 2013-05-20  ))))))))))))))))))))))))))))
.
.
2013-05-20 12:35 . 2013-05-20 12:35 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-05-20 12:33 . 2013-05-20 12:33 0 ----a-w- c:\windows\SysWow64\drivers\clbdriver.sys
2013-05-15 12:23 . 2013-05-15 12:23 -------- d-----w- c:\users\user\AppData\Roaming\Malwarebytes
2013-05-15 12:23 . 2013-05-15 12:23 -------- d-----w- c:\programdata\Malwarebytes
2013-05-15 12:23 . 2013-05-15 12:23 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-05-15 12:23 . 2013-04-04 17:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-05-15 12:23 . 2013-05-15 12:23 -------- d-----w- c:\users\user\AppData\Local\Programs
2013-05-11 14:50 . 2013-05-11 14:50 -------- d-----w- c:\program files\CCleaner
2013-05-10 12:25 . 2013-05-10 12:25 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software
2013-04-30 21:41 . 2013-04-30 21:41 -------- d-----w- c:\users\user\AppData\Roaming\AVG
2013-04-30 21:40 . 2013-04-30 21:42 -------- d-----w- c:\programdata\AVG
2013-04-30 21:40 . 2013-04-30 21:40 -------- d-sh--w- c:\programdata\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-04-25 13:16 . 2013-05-02 18:32 -------- d-----w- c:\program files (x86)\SimpleSpeedy
2013-04-24 12:46 . 2013-04-12 14:45 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
.
.
.
(((((((((((((((((((((((((((((((((((((   Relatório Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-15 21:11 . 2012-10-20 15:26 75016696 ----a-w- c:\windows\system32\MRT.exe
2013-05-15 15:32 . 2012-06-05 19:22 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-15 15:32 . 2012-06-05 19:22 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-13 12:12 . 2011-03-28 21:36 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-04-13 05:49 . 2013-05-15 12:21 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-15 12:21 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-15 12:21 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-15 12:21 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-15 12:21 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-15 12:21 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-03-29 05:53 . 2013-03-29 05:53 246072 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
2013-03-21 06:08 . 2013-03-21 06:08 240952 ----a-w- c:\windows\system32\drivers\avgtdia.sys
2013-03-19 06:04 . 2013-04-10 12:16 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 05:46 . 2013-04-10 12:16 43520 ----a-w- c:\windows\system32\csrsrv.dll
2013-03-19 05:04 . 2013-04-10 12:16 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04 . 2013-04-10 12:16 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47 . 2013-04-10 12:16 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll
2013-03-19 03:06 . 2013-04-10 12:16 112640 ----a-w- c:\windows\system32\smss.exe
2013-02-23 14:56 . 2013-02-23 14:56 310688 ----a-w- c:\windows\system32\javaws.exe
2013-02-23 14:56 . 2013-02-23 14:56 188832 ----a-w- c:\windows\system32\javaw.exe
2013-02-23 14:56 . 2013-02-23 14:56 188320 ----a-w- c:\windows\system32\java.exe
2013-02-23 14:56 . 2013-02-23 14:56 108448 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-02-23 14:56 . 2012-10-26 12:24 963488 ----a-w- c:\windows\system32\deployJava1.dll
2013-02-23 14:56 . 2012-10-26 12:24 1085344 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-02-23 14:53 . 2013-02-23 14:53 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-02-23 14:53 . 2012-06-05 19:22 861088 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2013-02-23 14:53 . 2012-06-05 19:22 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll
.
.
((((((((((((((((((((((((((   Pontos de Carregamento do Registro   )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por padrão não são apresentadas. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2012-08-20 14:17 220608 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2012-08-20 14:17 220608 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2012-08-20 14:17 220608 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaPCInternetAccess"="c:\program files (x86)\Nokia\PC Internet Access\NPCIA.exe" [2009-09-22 544768]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-04-19 18678376]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"AVG_UI"="c:\program files (x86)\AVG\AVG2013\avgui.exe" [2013-04-29 4408368]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Norton Download Manager{NF22-B22-4abb-B07C-C084B04B4F12}"="c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe" [2012-10-11 143928]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginAbn]
2012-12-04 17:21 1718256 ----a-w- c:\program files (x86)\GbPlugin\gbiehabn.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [x]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2013\avgidsagent.exe [2013-04-25 4936752]
R2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-02-28 161384]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 25928]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Serviço de Tecnologias de Ativação do Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-06-05 1255736]
S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys [2013-02-08 71480]
S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys [2013-02-08 311096]
S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys [2013-02-08 116536]
S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys [2013-02-08 45880]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\1403010.016\SYMDS64.SYS [2013-01-22 493656]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\1403010.016\SYMEFA64.SYS [2013-01-31 1139800]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys [2013-03-29 246072]
S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys [2013-02-08 206136]
S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys [2013-03-21 240952]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130502.001\BHDrvx64.sys [2013-04-12 1390680]
S1 ccSet_MCLIENT;Norton Management Settings Manager;c:\windows\system32\drivers\MCLIENTx64\0302000.013\ccSetx64.sys [2012-10-04 168096]
S1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360x64\1403010.016\ccSetx64.sys [2012-11-16 168096]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130517.001\IDSvia64.sys [2013-01-18 513184]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\1403010.016\Ironx64.SYS [2012-11-16 224416]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360x64\1403010.016\SYMNETS.SYS [2013-01-31 432800]
S2 avgwd;Watchdog do AVG;c:\program files (x86)\AVG\AVG2013\avgwdsvc.exe [2013-04-18 283136]
S2 GbpSv;Gbp Service;c:\progra~2\GbPlugin\GbpSv.exe [2012-12-04 527856]
S2 MCLIENT;Norton Management;c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe [2012-10-11 143928]
S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe [2012-12-24 144520]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-08-31 2754984]
S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-01-18 138912]
S3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-08-21 320040]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ   hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-10 17:18 1642448 ----a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Conteúdo da pasta 'Tarefas Agendadas'
.
2013-05-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-05 15:32]
.
2013-05-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-05 13:51]
.
2013-05-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-05 13:51]
.
2013-05-20 c:\windows\Tasks\schedule!3036567561.job
- c:\programdata\BetterSoft\OptimizerPro\OptimizerPro.exe [2013-04-10 19:58]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2012-08-20 14:17 244672 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2012-08-20 14:17 244672 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2012-08-20 14:17 244672 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-30 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-30 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-30 411672]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - LocalService
FontCache
.
------- Scan Suplementar -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://websearch.greatresults.info/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: &Enviar para o OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: E&xportar para o Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
Trusted Zone: agentware.net
Trusted Zone: realsecureweb.com.br\wwws
Trusted Zone: sabre.com
Trusted Zone: santander.com.br\www
Trusted Zone: santanderempresarial.com.br\www
Trusted Zone: santandernet.com.br\www
Trusted Zone: santandernet.com.br\wwws
Trusted Zone: santandernet.com.br\wwws2
Trusted Zone: santandernetibe.com.br\www
Trusted Zone: secureweb.com.br\www
TCP: DhcpNameServer = 192.168.0.1 192.168.0.1 192.168.0.1
.
- - - - ORFÃOS REMOVIDOS - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-{C3F3165C-74D3-6FDB-3274-14FDA8698CFA} - c:\programdata\Browase2saaVE\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MCLIENT]
"ImagePath"="\"c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe\" /s \"MCLIENT\" /m \"c:\program files (x86)\Norton Management\Engine\3.2.0.19\diMaster.dll\" /prefetch:1"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360]
"ImagePath"="\"c:\program files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Engine\20.3.1.22\diMaster.dll\" /prefetch:1"
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Tempo para conclusão: 2013-05-20  09:37:54
ComboFix-quarantined-files.txt  2013-05-20 12:37
.
Pré-execução: 445.172.645.888 bytes disponíveis
Pós execução: 444.802.957.312 bytes disponíveis
.
- - End Of File - - 29935F8783BE593E3468BD07467F691A
 

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Nunca use dois Antivírus juntos....Eles geram Conflitos, Instabilidades e Lentidão no PC, em suma um desastre completo. Dois antivírus instalados no computador competem entre si e abrem brecha para que a funcionalidade de um anule a proteção do outro.

Desinstale um, reinicie e faça/poste um novo Log para exame.



MVP Mr.Million

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Oi, então eu sabia disso dos antivírus, o que eu não tinha percebido é que os dois estavam ativos no meu computador ao mesmo tempo hehehe. Obrigada pela ajuda, segue o novo LOG:

 

 

a seComboFix 13-05-20.01 - user 21/05/2013   9:49.2.2 - x64
Microsoft Windows 7 Professional   6.1.7601.1.1252.55.1046.18.4061.1914 [GMT -3:00]
Executando de: c:\users\user\Downloads\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton 360 *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton 360 *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((   Outras Exclusões   )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\boost_interprocess\20130521092731.375199
c:\programdata\boost_interprocess\20130521092731.375199\Nobu64AgentService
c:\programdata\boost_interprocess\20130521092731.375199\Nobu64TrayIcon
.
.
((((((((((((((((   Arquivos/Ficheiros criados de 2013-04-21 to 2013-05-21  ))))))))))))))))))))))))))))
.
.
2013-05-21 13:00 . 2013-05-21 13:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-05-21 13:00 . 2013-05-21 13:00 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{99555C0C-A462-4CAA-AD6E-377D2D9F1FC4}\offreg.dll
2013-05-20 12:33 . 2013-05-20 12:33 0 ----a-w- c:\windows\SysWow64\drivers\clbdriver.sys
2013-05-15 12:23 . 2013-05-15 12:23 -------- d-----w- c:\users\user\AppData\Roaming\Malwarebytes
2013-05-15 12:23 . 2013-05-15 12:23 -------- d-----w- c:\programdata\Malwarebytes
2013-05-15 12:23 . 2013-05-15 12:23 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2013-05-15 12:23 . 2013-04-04 17:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-05-15 12:23 . 2013-05-15 12:23 -------- d-----w- c:\users\user\AppData\Local\Programs
2013-05-11 14:50 . 2013-05-11 14:50 -------- d-----w- c:\program files\CCleaner
2013-05-10 12:25 . 2013-05-10 12:25 -------- d-----w- c:\users\Default\AppData\Roaming\TuneUp Software
2013-04-30 21:41 . 2013-04-30 21:41 -------- d-----w- c:\users\user\AppData\Roaming\AVG
2013-04-30 21:40 . 2013-04-30 21:42 -------- d-----w- c:\programdata\AVG
2013-04-30 21:40 . 2013-04-30 21:40 -------- d-sh--w- c:\programdata\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-04-25 13:16 . 2013-05-02 18:32 -------- d-----w- c:\program files (x86)\SimpleSpeedy
2013-04-24 12:46 . 2013-04-12 14:45 1656680 ----a-w- c:\windows\system32\drivers\ntfs.sys
.
.
.
(((((((((((((((((((((((((((((((((((((   Relatório Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-05-15 21:11 . 2012-10-20 15:26 75016696 ----a-w- c:\windows\system32\MRT.exe
2013-05-15 15:32 . 2012-06-05 19:22 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-15 15:32 . 2012-06-05 19:22 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-13 12:12 . 2011-03-28 21:36 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-04-13 05:49 . 2013-05-15 12:21 135168 ----a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49 . 2013-05-15 12:21 350208 ----a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49 . 2013-05-15 12:21 308736 ----a-w- c:\windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49 . 2013-05-15 12:21 111104 ----a-w- c:\windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45 . 2013-05-15 12:21 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45 . 2013-05-15 12:21 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-03-19 06:04 . 2013-04-10 12:16 5550424 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 05:46 . 2013-04-10 12:16 43520 ----a-w- c:\windows\system32\csrsrv.dll
2013-03-19 05:04 . 2013-04-10 12:16 3968856 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04 . 2013-04-10 12:16 3913560 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47 . 2013-04-10 12:16 6656 ----a-w- c:\windows\SysWow64\apisetschema.dll
2013-03-19 03:06 . 2013-04-10 12:16 112640 ----a-w- c:\windows\system32\smss.exe
2013-02-23 14:56 . 2013-02-23 14:56 310688 ----a-w- c:\windows\system32\javaws.exe
2013-02-23 14:56 . 2013-02-23 14:56 188832 ----a-w- c:\windows\system32\javaw.exe
2013-02-23 14:56 . 2013-02-23 14:56 188320 ----a-w- c:\windows\system32\java.exe
2013-02-23 14:56 . 2013-02-23 14:56 108448 ----a-w- c:\windows\system32\WindowsAccessBridge-64.dll
2013-02-23 14:56 . 2012-10-26 12:24 963488 ----a-w- c:\windows\system32\deployJava1.dll
2013-02-23 14:56 . 2012-10-26 12:24 1085344 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-02-23 14:53 . 2013-02-23 14:53 95648 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-02-23 14:53 . 2012-06-05 19:22 861088 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2013-02-23 14:53 . 2012-06-05 19:22 782240 ----a-w- c:\windows\SysWow64\deployJava1.dll
.
.
((((((((((((((((((((((((((   Pontos de Carregamento do Registro   )))))))))))))))))))))))))))))))))))))))
.
.
*Nota* entradas vazias e legítimas por padrão não são apresentadas. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2012-08-20 14:17 220608 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2012-08-20 14:17 220608 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2012-08-20 14:17 220608 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\SkyDriveShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaPCInternetAccess"="c:\program files (x86)\Nokia\PC Internet Access\NPCIA.exe" [2009-09-22 544768]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-04-19 18678376]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Norton Download Manager{NF22-B22-4abb-B07C-C084B04B4F12}"="c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe" [2012-10-11 143928]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2010-5-28 276328]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ GbPluginAbn]
2012-12-04 17:21 1718256 ----a-w- c:\program files (x86)\GbPlugin\gbiehabn.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
"HP Software Update"=c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe"
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
.
R0 GbpKm;Gbp KernelMode;c:\windows\system32\drivers\gbpkm.sys [x]
R2 BBSvc;BingBar Service;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\BBSvc.exe [2012-02-10 193816]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe [2013-02-28 161384]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Serviço de Tecnologias de Ativação do Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2012-06-05 1255736]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\1403010.016\SYMDS64.SYS [2013-01-22 493656]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\1403010.016\SYMEFA64.SYS [2013-01-31 1139800]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\BASHDefs\20130515.001\BHDrvx64.sys [2013-04-12 1390680]
S1 ccSet_MCLIENT;Norton Management Settings Manager;c:\windows\system32\drivers\MCLIENTx64\0302000.013\ccSetx64.sys [2012-10-04 168096]
S1 ccSet_N360;Norton 360 Settings Manager;c:\windows\system32\drivers\N360x64\1403010.016\ccSetx64.sys [2012-11-16 168096]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.2.0.19\Definitions\IPSDefs\20130517.001\IDSvia64.sys [2013-01-18 513184]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\1403010.016\Ironx64.SYS [2012-11-16 224416]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360x64\1403010.016\SYMNETS.SYS [2013-01-31 432800]
S2 GbpSv;Gbp Service;c:\progra~2\GbPlugin\GbpSv.exe [2012-12-04 527856]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512]
S2 MCLIENT;Norton Management;c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe [2012-10-11 143928]
S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe [2012-12-24 144520]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-08-31 2754984]
S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-01-18 138912]
S3 k57nd60a;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [2009-08-21 320040]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 25928]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ   hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-10 17:18 1642448 ----a-w- c:\program files (x86)\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Conteúdo da pasta 'Tarefas Agendadas'
.
2013-05-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-05 15:32]
.
2013-05-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-05 13:51]
.
2013-05-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-06-05 13:51]
.
2013-05-21 c:\windows\Tasks\schedule!3036567561.job
- c:\programdata\BetterSoft\OptimizerPro\OptimizerPro.exe [2013-04-10 19:58]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2012-08-20 14:17 244672 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2012-08-20 14:17 244672 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2012-08-20 14:17 244672 ----a-w- c:\users\user\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-03-30 166424]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-03-30 391192]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-03-30 411672]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - LocalService
FontCache
.
------- Scan Suplementar -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://websearch.greatresults.info/
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: &Enviar para o OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: E&xportar para o Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
Trusted Zone: agentware.net
Trusted Zone: realsecureweb.com.br\wwws
Trusted Zone: sabre.com
Trusted Zone: santander.com.br\www
Trusted Zone: santanderempresarial.com.br\www
Trusted Zone: santandernet.com.br\www
Trusted Zone: santandernet.com.br\wwws
Trusted Zone: santandernet.com.br\wwws2
Trusted Zone: santandernetibe.com.br\www
Trusted Zone: secureweb.com.br\www
TCP: DhcpNameServer = 192.168.0.1 192.168.0.1 192.168.0.1
.
- - - - ORFÃOS REMOVIDOS - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
AddRemove-{C3F3165C-74D3-6FDB-3274-14FDA8698CFA} - c:\programdata\Browase2saaVE\uninstall.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MCLIENT]
"ImagePath"="\"c:\program files (x86)\Norton Management\Engine\3.2.0.19\ccSvcHst.exe\" /s \"MCLIENT\" /m \"c:\program files (x86)\Norton Management\Engine\3.2.0.19\diMaster.dll\" /prefetch:1"
--
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\N360]
"ImagePath"="\"c:\program files (x86)\Norton 360\Engine\20.3.1.22\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Engine\20.3.1.22\diMaster.dll\" /prefetch:1"
.
--------------------- CHAVES DO REGISTRO BLOQUEADAS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_7_700_202_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_7_700_202.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Tempo para conclusão: 2013-05-21  10:19:33
ComboFix-quarantined-files.txt  2013-05-21 13:19
ComboFix2.txt  2013-05-20 12:37
.
Pré-execução: 443.938.390.016 bytes disponíveis
Pós execução: 445.885.661.184 bytes disponíveis
.
- - End Of File - - 5A3B2DDD890F80950E9EB2BED850EAB7
 
Fico no aguardo e muito obrigada mais uma vez.
 

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Desabilite o seu Antivírus, AntiSpyware e Firewall para não haver conflitos. Mantenha-os desativados até terminar as instruções

Download bouton-telecharger.png Salve-o no Desktop. (Área de Trabalho)

Execute o adwcleaner.exe

OBS: Usuários do Windows Vista ou do Windows 7, clicar com o botão direito do mouse no arquivo e selecionar:Executar como administrador

AdwCleanerCustom-1.jpg

Clique [Delete]

Salve o Log criado.

Donload 1268r49.png Salve no seu Desktop (Área de trabalho).

Dê um duplo-clique para executar o Junkware Removal Tool (JRT)

* No Windows Vista e Windows 7:

Clique com o botão direito do mouse sobre o JRT.exe e selecione run_as_adm1.png

A Ferramenta começará o exame do seu Sistema. Tenha paciência pois pode demorar um pouco, dependendo da quantidades de ítens a serem examinados.

Ao final, um Log se abrirá e salvo no Desktop com o nome de JRT.txt.

Selecione, copie e cole o conteúdo deste Log na sua próxima resposta + o Log do AdwCleaner e um novo Log do HijackThis.



MVP Mr.Million

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Bom dia, segue LOGS conforme solicitado:

 

1° - adwcleaner

 

 

# AdwCleaner v2.301 - Relatório criado em 22/05/2013 às 09:36:33
# Atualizado em 16/05/2013 por Xplode
# Sistema Operacional : Windows 7 Professional Service Pack 1 (64 bits)
# Usuário : user - VERA-PC
# Modo de Boot : Normal
# Executado de : C:\Users\user\Desktop\adwcleaner.exe
# Opção [Remover]
 
 
***** [serviços] *****
 
 
***** [Arquivos/Pastas] *****
 
Pasta Removido : C:\Program Files (x86)\WebSearch
Pasta Removido : C:\ProgramData\InstallMate
Pasta Removido : C:\ProgramData\SoftSafe
Removido Durante o reboot : C:\ProgramData\BetterSoft
Removido Durante o reboot : C:\ProgramData\boost_interprocess
 
***** [Registro] *****
 
Chave Removida : HKCU\Software\AppDataLow\SProtector
Chave Removida : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Chave Removida : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Chave Removida : HKLM\SOFTWARE\Classes\TypeLib\{AC329328-7EC4-4C34-B672-0A2B90CB9B00}
Chave Removida : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Chave Removida : HKLM\Software\SP Global
Chave Removida : HKLM\Software\SProtector
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{14F35FFC-522A-4DD1-A07E-6B8B65C6891E}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Chave Removida : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}
Chave Removida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OptimizerPro
 
***** [Navegadores] *****
 
-\\ Internet Explorer v10.0.9200.16576
 
Substituído : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://websearch.greatresults.info/ --> hxxp://www.google.com
 
-\\ Google Chrome v26.0.1410.64
 
*************************
 
AdwCleaner[s1].txt - [1984 octets] - [22/05/2013 09:36:33]
 
########## EOF - C:\AdwCleaner[s1].txt - [2044 octets] ##########
 
 
2° - JRT 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 7 Professional x64
Ran by user on 22/05/2013 at  9:42:27,71
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] "C:\ProgramData\bettersoft"
Failed to delete: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\Users\user\AppData\Roaming\pdfforge"
Successfully deleted: [Folder] "C:\Program Files (x86)\SimpleSpeedy"
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{00A1F99D-6D76-4CE8-8FC6-4C5EC1049435}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{02370986-9ACD-4092-8219-97EE096F469D}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{05CC04DF-6E6E-48EC-BC1B-6CC47C553301}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{0648F324-AA48-4CF3-97B2-7BC07477614F}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{06AD671D-2CE7-4D88-833D-BF92CD3C64B0}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{073ACAAE-1430-4213-8BE2-1844F12F9FB2}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{09454823-464F-4D1F-AA75-BCDAE26B2F0E}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{11C980FB-AD65-4880-A12A-63DDF6470FEA}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{17FE841F-8722-45D1-B053-8BFD2BD6364F}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{1B648BC0-9A53-4921-B205-5FAA8D94AD14}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{1BD49E96-ABF4-4C34-A136-53E759C96EEB}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{1CB7BA56-F4A6-4914-A551-52F95F781BC0}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{1E7EA140-69F7-4855-B046-785B058D23F9}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{1F03984F-867D-4FB8-ADAC-52633F733C27}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{1FB18B5D-BCA7-4D5B-B6E0-B8E17ACC5B8B}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{2283553E-BFA8-4FA4-A38E-03DB9FCFCBEB}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{24733C79-CAE2-4ECC-B939-5D267B412D0F}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{24AA3A39-F20B-4554-A6E7-6E549DEE6D70}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{25564269-396E-438A-B33C-58A2203FE1EE}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{26F23199-9478-44B3-A270-A3D4FC42D0FB}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{2816324B-1519-4C44-A101-6EF17D5EC800}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{29F681AF-1DF1-4256-A24A-877F30ECAC34}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{2A22F19E-D8A4-49CD-B3F3-DA4986D7A430}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{2ACC7DDE-1132-4387-9CC0-A9CCF1A640D1}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{2B282917-A396-4A43-97FF-F364BC65D078}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{2C62EBB1-AC46-463B-AD9D-90D705C0807D}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{2C95813C-1A92-467C-AF3F-EB303A812CBC}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{2D15F96D-1DBF-4985-BEDB-CA3E865F5C47}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{2DD9FFB5-39F0-4355-A7B0-DCCC0AB72764}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{32ADD56D-67CC-4F40-81E7-9FD3CED8AB11}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{3436190B-9762-4437-B4F5-C2C57A3EB18E}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{35D00B3A-CDC2-419B-BF0A-E26FAFB35B65}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{35DD4B02-86DE-46AA-8F7A-F6E0109053FC}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{35F38CB5-C5D8-4C34-819B-729438B2074C}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{36DE2A60-C25F-43FF-A670-7FBE615EBA5C}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{37FAB02B-0BBF-4007-B4F1-CA0DD49C58B7}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{3C9A9884-D97F-446A-B891-36342DFD2FBE}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{424745D3-F949-4BA4-AF97-A7F02D7E5458}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{43F615C6-59F4-49AB-88B5-8B952922FC39}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{4421FE16-DD55-41C6-8219-072AE2A894B6}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{44F6A7A5-AC87-4B96-B94D-6CC7D62E15FF}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{4B5D1149-86EF-4F04-A2B6-749CB956A047}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{4D021DE8-C33B-43A4-BF46-4624992A6422}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{4ED71176-39C4-464D-AD3B-506D997611A9}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{5272241E-F25B-44C0-8EB6-6970FB9CF226}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{5522AAE6-14FB-48A5-B474-4C6B53CDD93F}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{55E17252-0D40-416E-BAFE-54DD5B4738E6}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{58C4DB41-57B5-42C9-970E-11B58CFEB0A5}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{5B905A72-BA74-4D07-BDA9-68EF1F180B73}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{5E1C78DA-E093-4817-9993-B7C5D6E50EF8}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{5F5B1DE5-D64E-4051-AE12-D30936390A7E}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{60723320-4FF2-4E9D-9B61-EE113317A57D}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{650C3F0B-AC39-49A5-867A-5FE6C2593DF5}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{6523F07B-83CC-45EC-BE9C-A7D5DF838D2D}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{666CC7EC-6AD7-4F3B-A3FB-A8224B151F62}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{68277D8B-46A7-4A2A-8E27-33A7EC0A8542}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{688986F4-67DF-44DA-B593-CF4AA3C84884}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{6ACFB761-615D-4E99-8798-89030EED084E}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{6C1545C3-3002-463A-BE7A-A8FD92167203}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{6FC33B24-3711-4008-B8CB-A9A1122E339B}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{704EE3E8-0E37-4626-AFD7-B926303E2C20}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{722D7E62-2939-426B-9F78-4A5AF1931FAC}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{7300D689-10A8-43E5-9612-1D27D4FB8383}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{780D9B2E-B556-486F-87FB-C0574654E05A}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{7815B7A7-EE5B-473A-8CEF-B863E33881CC}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{79EEA729-0B35-4DB3-86DE-7CE8C0A15E5D}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{7A2A20DE-0CB7-4A9B-9AC9-B613A63DF298}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{7A8647EA-C97D-4280-A05B-DD40309D9B2E}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{7DF0C898-3679-4844-BC0C-7EC8490F621A}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{7E5990BC-59D7-41AF-9124-FA9B91E62BDD}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{807FAB3D-7A92-44E6-BCEB-77751CCFBCF7}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{82921958-01E2-4222-A397-0360B86ED8A7}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{837ADB97-D056-4288-A60F-B1ADBE2E4632}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{8683B318-4B75-436D-BFAC-F47545265D89}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{888A8398-C660-42F4-87E1-9F0F4F3AC821}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{88A87CA0-70EF-4751-B079-49674C934A84}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{8A46BA2C-DF93-4DAF-8286-EA02BB5D4E1D}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{8B04F13D-79AB-4A60-BE7C-A262781B11A6}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{8F0D0B6B-4B62-4AC2-A4B5-58DC82253231}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{8FE65A24-5C1F-4B64-AF23-BF34DC5CAAF3}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{9195FE83-4747-43AD-9BBF-F9C0EDB6FC87}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{91EF7DC4-7D5B-4BDF-9AE0-CC217F0EF92D}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{926B7301-6F74-451B-8005-E12893E46065}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{95D2B720-1DA7-4AD5-90AE-5E955F672E2A}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{96BBF063-6A30-4E17-8C5A-01B08A1F3E81}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{9789D5B8-5A51-4D63-B5E0-6F621D17778A}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{9B10CA44-969C-4DE2-B896-9EB35D316637}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{9BC3DB49-AD2F-472D-87E4-B870E43DE054}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{9E54BF05-33AB-4271-B17F-97191BD9D255}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{9F42C34F-0F5D-4BAC-8E02-28A1B5D1B855}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{A2866201-F510-45E6-8318-6A08BF0911FD}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{A889448B-1723-4715-B707-625A7FFFDC4C}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{A9A01390-12FD-40E3-A4B0-8E44B998E43B}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{B1913130-FDB6-4DBA-AAFA-9A12DCE56632}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{B192D63A-AA8B-4D03-937C-2A5E6F6844DD}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{B224E994-3E83-4F1C-A930-54E0CFC80E35}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{B646311A-3ED6-4E38-A580-6E814396E308}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{B9CBF080-039D-4F57-83B9-096EF0EDDEBC}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{BC265A2F-50D4-432F-BAAC-B2B87DA500AD}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{BD0942BB-918A-4A7A-BCD7-6952432D2720}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{BD2CF57C-F228-4B46-9F25-3DA6AD6588EA}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{BD504E23-D97F-42C6-B8AA-EECB5EE5860D}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{BF2865E6-8B12-483A-9D15-AA1A0DD68B99}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{BF5BF641-47FC-47A4-9F6A-0D1B8472F106}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{BFEFD3B7-080B-4E46-A3FB-5E90279E3215}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{C38E088F-B7BD-4014-8FAE-2B3CCBF533AE}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{C3A8106D-C990-4E02-9672-04D273DC802A}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{C3C68339-4F45-445F-8643-90592ECA66D7}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{C5D66D4A-DC83-4446-9C2F-B3D64BA6E964}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{C6F67D58-7F33-41DC-8DCD-F3130874FFAC}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{C7A8BEB9-CE11-4A26-A93A-C92165BC0F58}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{CE125368-4BAE-4A13-A74C-F7698C757418}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{CEF05065-0C81-494C-8424-190EB6E45DB5}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{D01B4909-074D-42DC-91C6-F29264325F45}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{D0FC13D0-023A-4E9E-889E-55CDB0FC4013}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{D1EB111C-D3DE-45D7-BE30-5CDE0222B57B}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{D266F48A-FC7F-47B0-B658-E990F43EEFA4}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{D2BC466E-E3A1-44D7-A527-749F2336BAF2}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{D35571DE-4EC8-4A5F-811F-FDBD3538A33C}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{D4C36747-927F-41C9-800B-81DC5D2F03CC}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{D57FDFF9-D4AB-49C8-9BB1-246A404961B6}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{DA34DA86-7CF3-478A-9B6D-082E1D0F52B9}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{DAD1935D-2166-439D-A8DE-BA43CD0250E3}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{DBF8FD6B-3E8D-4298-8200-84002C5FF53B}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{E0A2E0BB-C326-4161-9E92-63DBD40BDBA2}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{E4784657-36C8-4504-AF42-991A7E51FA24}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{E57F06C6-F8C8-49C5-909F-F1A6411E591C}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{E6591BA9-509C-4910-8142-550919F73849}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{E9D57B5A-2B44-4123-BCDE-AAE9B0A2D5E1}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{EBE2EC44-94B8-4926-9B27-D76C7D56A716}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{EC09288D-D8B6-42B6-986B-D56009E9E380}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{EDD6C947-EFD0-47E0-8844-378A5C8417BB}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{F108A509-52B1-42D0-8B54-71A50717B9FD}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{F1822FBB-2FCF-40CF-A545-B9C722A3C7EE}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{F4635374-2691-4360-A182-74C4CF609E58}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{F537C886-4D91-4461-8EEC-FC238AB4E962}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{F557B125-1048-45C5-99C1-62CD712E7F5B}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{F7D04E03-C00B-4623-870D-1D5DCD540D61}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{F84D2E9E-5361-42F9-9C59-04996D90A13A}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{FA39DDE3-B2E8-4FAF-9C9E-3FBF666DFA44}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{FA7ED786-76DD-43B3-A504-005D37600317}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{FCE6602E-538C-41F8-B2DC-A6614F787C19}
Successfully deleted: [Empty Folder] C:\Users\user\appdata\local\{FE5ED4A3-46B0-42E5-BFFC-5577F11BF09E}
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22/05/2013 at  9:50:11,22
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 

Obrigada

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Ok, o PC está limpo

Finalizando.......

Renomeie o ComboFix para Uninstall, execute-o e aguarde a remoção da Ferramenta.

Limpe a Restauração do Sistema, criando um Ponto de Restauração do sistema limpo.

Clique com o botão direito do mouse em cima do MEU COMPUTADOR > Propiedades > Proteção do Sistema > Configurar > Excluir.

Ainda em Proteção do Sistema > Criar.



MVP Mr.Million

0

Compartilhar este post


Link para o post
Compartilhar em outros sites

Oi bom dia, 

Obrigada pela ajuda, mas o meu Google Chrome continua mostrando uns links estranhos, tipo propagandas de emagrecimento, umas palavras ficam sublinhadas e quando eu coloco o mouse encima abre um popup com mais propaganda e continuam aparecendo uns barners meio "pornos/freaks", eu não sei como explicar melhor, desculpa...É que eu não consigo mandar, uma imagem da minha tela pra você ver.

Tem mais alguma coisa que eu poça fazer ou vou ter que conviver com essas coisas? hehehe

Eu desinstalei e instalei de novo só pra ver se não era isso também na nada mudou.

 

Enfim muito obrigada pela ajuda.

0

Compartilhar este post


Link para o post
Compartilhar em outros sites
    • 10 Mensagens
    • 106 Visualizações
    • 11 Mensagens
    • 1001 Visualizações
    • 12 Mensagens
    • 90 Visualizações
    • 12 Mensagens
    • 189 Visualizações
    • 9 Mensagens
    • 118 Visualizações

  • Postagens Recentes

    • Solicitação de análise de log
      a partir de C:\Users\Geicy\Desktop
      Perfis Carregados: Geicy (Perfis Disponíveis: Geicy)
      Platform: Windows 10 Home Single Language Versão 1511 (X64) Idioma: Português (Brasil)
      Internet Explorer Versão 11 (Navegador padrão: Chrome)
      Modo da Inicialização: Normal
      Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processos (Whitelisted) ================= (Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
      (Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
      (Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
      (Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
      (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
      () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
      (LENOVO INCORPORATED.) C:\Program Files\Lenovo\iMController\SystemAgentService.exe
      (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
      (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
      () C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
      (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
      (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
      (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
      (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
      (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
      (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
      (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
      (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      (Intel Corporation) C:\Windows\System32\igfxEM.exe
      (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
      () C:\Windows\System32\igfxTray.exe
      () C:\Program Files (x86)\Lenovo\CCSDK\WinGather.exe
      (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
      (Realtek semiconductor) C:\Windows\RTFTrack.exe
      (Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
      (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
      () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
      (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
      (Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\Windows-KB890830-x64-V5.38-delta.exe
      (Microsoft Corporation) C:\Windows\System32\MRT.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
      ==================== Registro (Whitelisted) =========================== (Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.) HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [4060376 2014-10-23] (Realtek semiconductor)
      HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [323312 2015-01-27] (Intel Corporation)
      HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
      HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
      HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [919768 2014-11-20] (Conexant Systems, Inc.)
      HKLM\...\Run: [LenovoUtility] => C:\Program Files\Lenovo\LenovoUtility\utility.exe [791368 2015-06-04] ()
      HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3945672 2015-07-27] (Synaptics Incorporated)
      HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
      HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
      HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [493960 2014-12-04] (Autodesk Inc.)
      HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
      HKU\S-1-5-21-1883175002-3615411677-2762873912-1001\...\Run: [Dropbox Update] => C:\Users\Geicy\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-05-03] (Dropbox, Inc.)
      HKU\S-1-5-21-1883175002-3615411677-2762873912-1001\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1310088 2015-01-27] (Autodesk, Inc.)
      HKU\S-1-5-21-1883175002-3615411677-2762873912-1001\...\Policies\Explorer: [] 
      HKU\S-1-5-18\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1310088 2015-01-27] (Autodesk, Inc.)
      ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  Nenhum Arquivo
      ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc.)
      Startup: C:\Users\Geicy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-07-11]
      ShortcutTarget: Dropbox.lnk -> C:\Users\Geicy\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
      Tcpip\..\Interfaces\{4866c1ee-6903-4bd6-b1c3-675d9ff2ac93}: [DhcpNameServer] 192.168.0.1
      Tcpip\..\Interfaces\{750707c0-341b-4f1e-9e74-1b2294b45987}: [DhcpNameServer] 9.9.9.100 9.9.9.100 Internet Explorer:
      ==================
      HKU\S-1-5-21-1883175002-3615411677-2762873912-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo13.msn.com/?PC=LCJB
      HKU\S-1-5-21-1883175002-3615411677-2762873912-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?PC=LCJB
      HKU\S-1-5-21-1883175002-3615411677-2762873912-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
      HKU\S-1-5-21-1883175002-3615411677-2762873912-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
      SearchScopes: HKU\S-1-5-21-1883175002-3615411677-2762873912-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
      BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
      BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
      BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
      BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation) FireFox:
      ========
      FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
      FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-09-03] (Intel Corporation)
      FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-09-03] (Intel Corporation)
      FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
      FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
      FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
      FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-10] (Google Inc.)
      FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.) Chrome: 
      =======
      CHR Profile: C:\Users\Geicy\AppData\Local\Google\Chrome\User Data\Default
      CHR Extension: (Google Apresentações) - C:\Users\Geicy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-04-25]
      CHR Extension: (Google Docs) - C:\Users\Geicy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-25]
      CHR Extension: (Google Drive) - C:\Users\Geicy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-25]
      CHR Extension: (YouTube) - C:\Users\Geicy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-25]
      CHR Extension: (Planilhas do Google) - C:\Users\Geicy\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-04-25]
      CHR Extension: (Documentos Google off-line) - C:\Users\Geicy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-25]
      CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Geicy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-25]
      CHR Extension: (Gmail) - C:\Users\Geicy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-25] ==================== Serviços (Whitelisted) ======================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [599944 2014-12-04] (Autodesk Inc.)
      S2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc.)
      R2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [644080 2014-10-22] ()
      R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19184 2015-01-27] (Intel Corporation)
      R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373160 2015-12-19] (Intel Corporation)
      S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887256 2014-05-13] (Intel(R) Corporation)
      R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2014-09-03] (Intel Corporation)
      S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
      R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-09-03] (Intel Corporation)
      R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584664 2015-12-14] (LENOVO INCORPORATED.)
      R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
      R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-07-27] (Synaptics Incorporated)
      R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
      R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
      R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2014-09-11] (Atheros) [Arquivo não assinado] ===================== Drivers (Whitelisted) ========================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.) S3 KMDFVirtualMouse; C:\Windows\System32\drivers\KMDFVirtualMouse.sys [21240 2014-08-04] ()
      R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation)
      S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [80920 2015-07-02] (McAfee, Inc.)
      R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [2584280 2014-10-23] (Realtek Semiconductor Corp.)
      R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-07-27] (Synaptics Incorporated)
      S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
      R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
      R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
      S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink) ==================== NetSvcs (Whitelisted) =================== (Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)
      ==================== Três Meses Criados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-07-22 18:00 - 2016-07-22 18:02 - 00013941 _____ C:\Users\Geicy\Desktop\FRST.txt
      2016-07-22 17:58 - 2016-07-22 18:00 - 00000000 ____D C:\FRST
      2016-07-22 17:45 - 2016-07-22 17:58 - 02393600 _____ (Farbar) C:\Users\Geicy\Desktop\FRST64.exe
      2016-07-22 10:46 - 2016-07-22 10:46 - 00000000 ____D C:\Users\Geicy\Downloads\9061741203859586
      2016-07-22 10:45 - 2016-07-22 10:45 - 00001772 _____ C:\Users\Geicy\Downloads\9061741203859586.zip
      2016-07-21 16:51 - 2016-07-21 16:51 - 00002015 _____ C:\Users\Geicy\Desktop\Windows Defender.lnk
      2016-07-11 17:00 - 2016-07-11 17:00 - 00000000 ____D C:\Users\Geicy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
      2016-07-07 13:00 - 2016-07-07 13:10 - 00000000 ____D C:\Users\Geicy\AppData\Roaming\ZHP
      2016-06-29 11:55 - 2016-06-29 11:55 - 00025674 _____ C:\Users\Geicy\Downloads\geraBoletoBancario_3_916782_6__2016_1.pdf
      2016-06-28 12:38 - 2016-06-28 12:50 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
      2016-06-28 12:37 - 2016-06-28 12:37 - 00000000 ____D C:\WINDOWS\pss
      2016-06-20 14:30 - 2016-06-20 14:30 - 00000000 ____D C:\Users\Geicy\Downloads\Instagram
      2016-06-14 21:05 - 2016-05-28 01:19 - 24605696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
      2016-06-14 21:05 - 2016-05-28 01:17 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
      2016-06-14 21:04 - 2016-05-28 03:13 - 01401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
      2016-06-14 21:04 - 2016-05-28 03:13 - 00290496 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
      2016-06-14 21:04 - 2016-05-28 03:13 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
      2016-06-14 21:04 - 2016-05-28 03:13 - 00046784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
      2016-06-14 21:04 - 2016-05-28 02:25 - 04268880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupapi.dll
      2016-06-14 21:04 - 2016-05-28 02:23 - 00388384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll
      2016-06-14 21:04 - 2016-05-28 02:22 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
      2016-06-14 21:04 - 2016-05-28 02:22 - 04387680 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupapi.dll
      2016-06-14 21:04 - 2016-05-28 02:20 - 00430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
      2016-06-14 21:04 - 2016-05-28 02:09 - 00501600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
      2016-06-14 21:04 - 2016-05-28 02:08 - 00693600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
      2016-06-14 21:04 - 2016-05-28 02:07 - 03675512 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
      2016-06-14 21:04 - 2016-05-28 02:07 - 02921880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
      2016-06-14 21:04 - 2016-05-28 02:07 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
      2016-06-14 21:04 - 2016-05-28 02:07 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
      2016-06-14 21:04 - 2016-05-28 02:07 - 00808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
      2016-06-14 21:04 - 2016-05-28 02:07 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
      2016-06-14 21:04 - 2016-05-28 02:07 - 00331616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
      2016-06-14 21:04 - 2016-05-28 02:06 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
      2016-06-14 21:04 - 2016-05-28 02:06 - 04074160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
      2016-06-14 21:04 - 2016-05-28 02:06 - 00730344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
      2016-06-14 21:04 - 2016-05-28 02:06 - 00303216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
      2016-06-14 21:04 - 2016-05-28 02:06 - 00254656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
      2016-06-14 21:04 - 2016-05-28 02:05 - 04515264 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
      2016-06-14 21:04 - 2016-05-28 02:04 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
      2016-06-14 21:04 - 2016-05-28 02:04 - 00431296 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
      2016-06-14 21:04 - 2016-05-28 02:04 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
      2016-06-14 21:04 - 2016-05-28 01:58 - 01996640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
      2016-06-14 21:04 - 2016-05-28 01:58 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
      2016-06-14 21:04 - 2016-05-28 01:57 - 02548944 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
      2016-06-14 21:04 - 2016-05-28 01:57 - 02195632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
      2016-06-14 21:04 - 2016-05-28 01:57 - 01594416 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
      2016-06-14 21:04 - 2016-05-28 01:57 - 01372312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
      2016-06-14 21:04 - 2016-05-28 01:57 - 00649792 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
      2016-06-14 21:04 - 2016-05-28 01:57 - 00636304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
      2016-06-14 21:04 - 2016-05-28 01:57 - 00546456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
      2016-06-14 21:04 - 2016-05-28 01:57 - 00521664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
      2016-06-14 21:04 - 2016-05-28 01:57 - 00316256 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
      2016-06-14 21:04 - 2016-05-28 01:35 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdlrecover.exe
      2016-06-14 21:04 - 2016-05-28 01:35 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsdport.sys
      2016-06-14 21:04 - 2016-05-28 01:31 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdlrecover.exe
      2016-06-14 21:04 - 2016-05-28 01:31 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
      2016-06-14 21:04 - 2016-05-28 01:29 - 22379008 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
      2016-06-14 21:04 - 2016-05-28 01:26 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
      2016-06-14 21:04 - 2016-05-28 01:24 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
      2016-06-14 21:04 - 2016-05-28 01:22 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
      2016-06-14 21:04 - 2016-05-28 01:22 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
      2016-06-14 21:04 - 2016-05-28 01:22 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
      2016-06-14 21:04 - 2016-05-28 01:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
      2016-06-14 21:04 - 2016-05-28 01:21 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrokerLib.dll
      2016-06-14 21:04 - 2016-05-28 01:21 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
      2016-06-14 21:04 - 2016-05-28 01:20 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
      2016-06-14 21:04 - 2016-05-28 01:19 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
      2016-06-14 21:04 - 2016-05-28 01:18 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
      2016-06-14 21:04 - 2016-05-28 01:18 - 07977472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
      2016-06-14 21:04 - 2016-05-28 01:18 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
      2016-06-14 21:04 - 2016-05-28 01:18 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
      2016-06-14 21:04 - 2016-05-28 01:18 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
      2016-06-14 21:04 - 2016-05-28 01:18 - 00380416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
      2016-06-14 21:04 - 2016-05-28 01:18 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
      2016-06-14 21:04 - 2016-05-28 01:17 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
      2016-06-14 21:04 - 2016-05-28 01:17 - 00963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
      2016-06-14 21:04 - 2016-05-28 01:17 - 00173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
      2016-06-14 21:04 - 2016-05-28 01:16 - 19344384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
      2016-06-14 21:04 - 2016-05-28 01:16 - 00690176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
      2016-06-14 21:04 - 2016-05-28 01:16 - 00684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StructuredQuery.dll
      2016-06-14 21:04 - 2016-05-28 01:16 - 00592896 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
      2016-06-14 21:04 - 2016-05-28 01:16 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
      2016-06-14 21:04 - 2016-05-28 01:16 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
      2016-06-14 21:04 - 2016-05-28 01:15 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
      2016-06-14 21:04 - 2016-05-28 01:15 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
      2016-06-14 21:04 - 2016-05-28 01:15 - 00794624 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
      2016-06-14 21:04 - 2016-05-28 01:15 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
      2016-06-14 21:04 - 2016-05-28 01:15 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
      2016-06-14 21:04 - 2016-05-28 01:14 - 18674176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
      2016-06-14 21:04 - 2016-05-28 01:14 - 01716736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
      2016-06-14 21:04 - 2016-05-28 01:14 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
      2016-06-14 21:04 - 2016-05-28 01:14 - 00965632 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
      2016-06-14 21:04 - 2016-05-28 01:14 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
      2016-06-14 21:04 - 2016-05-28 01:14 - 00606208 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
      2016-06-14 21:04 - 2016-05-28 01:14 - 00499712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
      2016-06-14 21:04 - 2016-05-28 01:13 - 00990208 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
      2016-06-14 21:04 - 2016-05-28 01:13 - 00939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
      2016-06-14 21:04 - 2016-05-28 01:13 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
      2016-06-14 21:04 - 2016-05-28 01:13 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
      2016-06-14 21:04 - 2016-05-28 01:12 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
      2016-06-14 21:04 - 2016-05-28 01:12 - 00614400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
      2016-06-14 21:04 - 2016-05-28 01:12 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StructuredQuery.dll
      2016-06-14 21:04 - 2016-05-28 01:11 - 01445888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
      2016-06-14 21:04 - 2016-05-28 01:11 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
      2016-06-14 21:04 - 2016-05-28 01:11 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
      2016-06-14 21:04 - 2016-05-28 01:11 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
      2016-06-14 21:04 - 2016-05-28 01:11 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
      2016-06-14 21:04 - 2016-05-28 01:09 - 01073152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
      2016-06-14 21:04 - 2016-05-28 01:08 - 13385728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
      2016-06-14 21:04 - 2016-05-28 01:08 - 06295552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
      2016-06-14 21:04 - 2016-05-28 01:06 - 12128256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
      2016-06-14 21:04 - 2016-05-28 01:06 - 07200256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
      2016-06-14 21:04 - 2016-05-28 01:06 - 01339904 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
      2016-06-14 21:04 - 2016-05-28 01:05 - 03994624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
      2016-06-14 21:04 - 2016-05-28 01:05 - 03664896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
      2016-06-14 21:04 - 2016-05-28 01:05 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
      2016-06-14 21:04 - 2016-05-28 01:05 - 01797120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
      2016-06-14 21:04 - 2016-05-28 01:04 - 06973952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
      2016-06-14 21:04 - 2016-05-28 01:03 - 05323776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
      2016-06-14 21:04 - 2016-05-28 01:03 - 05205504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
      2016-06-14 21:04 - 2016-05-28 01:03 - 02609664 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
      2016-06-14 21:04 - 2016-05-28 01:03 - 01185280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationFramework.dll
      2016-06-14 21:04 - 2016-05-28 01:02 - 03590144 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
      2016-06-14 21:04 - 2016-05-28 01:02 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
      2016-06-14 21:04 - 2016-05-28 01:02 - 01534464 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
      2016-06-14 21:04 - 2016-05-28 01:01 - 01799680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
      2016-06-14 21:04 - 2016-05-28 01:01 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
      2016-06-14 21:04 - 2016-05-28 01:01 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
      2016-06-14 21:04 - 2016-05-28 01:00 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
      2016-06-14 21:04 - 2016-05-28 01:00 - 03585536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
      2016-06-14 21:04 - 2016-05-28 01:00 - 02635776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
      2016-06-14 21:04 - 2016-05-28 01:00 - 02168320 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
      2016-06-14 21:04 - 2016-05-28 01:00 - 01730560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
      2016-06-14 21:04 - 2016-05-28 01:00 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
      2016-06-14 21:04 - 2016-05-28 01:00 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
      2016-06-14 21:04 - 2016-05-28 00:58 - 07832576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
      2016-06-14 21:04 - 2016-05-28 00:58 - 04896256 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
      2016-06-14 21:04 - 2016-05-28 00:58 - 02066432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
      2016-06-14 21:04 - 2016-05-28 00:58 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
      2016-06-14 21:04 - 2016-05-28 00:57 - 02281472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
      2016-06-14 21:04 - 2016-05-28 00:55 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
      2016-06-14 21:03 - 2016-05-28 03:13 - 01184960 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
      2016-06-14 21:03 - 2016-05-28 03:13 - 00514752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
      2016-06-14 21:03 - 2016-05-28 02:23 - 00312160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswsock.dll
      2016-06-14 21:03 - 2016-05-28 02:22 - 00428896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
      2016-06-14 21:03 - 2016-05-28 02:22 - 00211296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
      2016-06-14 21:03 - 2016-05-28 02:22 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
      2016-06-14 21:03 - 2016-05-28 02:18 - 00357216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mswsock.dll
      2016-06-14 21:03 - 2016-05-28 02:16 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
      2016-06-14 21:03 - 2016-05-28 02:09 - 00170848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkUXBroker.exe
      2016-06-14 21:03 - 2016-05-28 02:09 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
      2016-06-14 21:03 - 2016-05-28 02:08 - 00258912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufx01000.sys
      2016-06-14 21:03 - 2016-05-28 02:08 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
      2016-06-14 21:03 - 2016-05-28 02:04 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
      2016-06-14 21:03 - 2016-05-28 02:04 - 00111064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptsslp.dll
      2016-06-14 21:03 - 2016-05-28 02:04 - 00097096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptsslp.dll
      2016-06-14 21:03 - 2016-05-28 02:03 - 00131248 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpapi.dll
      2016-06-14 21:03 - 2016-05-28 01:57 - 00577376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
      2016-06-14 21:03 - 2016-05-28 01:35 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
      2016-06-14 21:03 - 2016-05-28 01:31 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
      2016-06-14 21:03 - 2016-05-28 01:29 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\adhsvc.dll
      2016-06-14 21:03 - 2016-05-28 01:29 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
      2016-06-14 21:03 - 2016-05-28 01:29 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxp.dll
      2016-06-14 21:03 - 2016-05-28 01:28 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
      2016-06-14 21:03 - 2016-05-28 01:28 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
      2016-06-14 21:03 - 2016-05-28 01:28 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\FwRemoteSvr.dll
      2016-06-14 21:03 - 2016-05-28 01:27 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
      2016-06-14 21:03 - 2016-05-28 01:27 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
      2016-06-14 21:03 - 2016-05-28 01:26 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
      2016-06-14 21:03 - 2016-05-28 01:26 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
      2016-06-14 21:03 - 2016-05-28 01:26 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
      2016-06-14 21:03 - 2016-05-28 01:26 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
      2016-06-14 21:03 - 2016-05-28 01:25 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
      2016-06-14 21:03 - 2016-05-28 01:25 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
      2016-06-14 21:03 - 2016-05-28 01:24 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
      2016-06-14 21:03 - 2016-05-28 01:24 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ndu.sys
      2016-06-14 21:03 - 2016-05-28 01:24 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
      2016-06-14 21:03 - 2016-05-28 01:24 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
      2016-06-14 21:03 - 2016-05-28 01:24 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
      2016-06-14 21:03 - 2016-05-28 01:24 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll
      2016-06-14 21:03 - 2016-05-28 01:24 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FwRemoteSvr.dll
      2016-06-14 21:03 - 2016-05-28 01:23 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
      2016-06-14 21:03 - 2016-05-28 01:23 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll
      2016-06-14 21:03 - 2016-05-28 01:22 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
      2016-06-14 21:03 - 2016-05-28 01:22 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
      2016-06-14 21:03 - 2016-05-28 01:22 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
      2016-06-14 21:03 - 2016-05-28 01:22 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptsvc.dll
      2016-06-14 21:03 - 2016-05-28 01:22 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
      2016-06-14 21:03 - 2016-05-28 01:21 - 00550912 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
      2016-06-14 21:03 - 2016-05-28 01:21 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
      2016-06-14 21:03 - 2016-05-28 01:20 - 00511488 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.dll
      2016-06-14 21:03 - 2016-05-28 01:20 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\system32\polstore.dll
      2016-06-14 21:03 - 2016-05-28 01:20 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
      2016-06-14 21:03 - 2016-05-28 01:20 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\GnssAdapter.dll
      2016-06-14 21:03 - 2016-05-28 01:20 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll
      2016-06-14 21:03 - 2016-05-28 01:20 - 00057344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll
      2016-06-14 21:03 - 2016-05-28 01:19 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
      2016-06-14 21:03 - 2016-05-28 01:19 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
      2016-06-14 21:03 - 2016-05-28 01:19 - 00355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
      2016-06-14 21:03 - 2016-05-28 01:19 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll
      2016-06-14 21:03 - 2016-05-28 01:18 - 00392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\IPSECSVC.DLL
      2016-06-14 21:03 - 2016-05-28 01:17 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.dll
      2016-06-14 21:03 - 2016-05-28 01:17 - 00415232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
      2016-06-14 21:03 - 2016-05-28 01:17 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
      2016-06-14 21:03 - 2016-05-28 01:17 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
      2016-06-14 21:03 - 2016-05-28 01:16 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\polstore.dll
      2016-06-14 21:03 - 2016-05-28 01:16 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
      2016-06-14 21:03 - 2016-05-28 01:15 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
      2016-06-14 21:03 - 2016-05-28 01:15 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
      2016-06-14 21:03 - 2016-05-28 01:14 - 00219136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
      2016-06-14 21:03 - 2016-05-28 01:14 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
      2016-06-14 21:03 - 2016-05-28 01:13 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
      2016-06-14 21:03 - 2016-05-28 01:13 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
      2016-06-14 21:03 - 2016-05-28 01:13 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
      2016-06-14 21:03 - 2016-05-28 01:13 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
      2016-06-14 21:03 - 2016-05-28 01:11 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
      2016-06-14 21:03 - 2016-05-28 01:11 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
      2016-06-14 21:03 - 2016-05-28 01:11 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\httpprxm.dll
      2016-06-14 21:03 - 2016-05-28 01:04 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
      2016-06-14 21:03 - 2016-05-28 01:04 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
      2016-06-14 21:03 - 2016-05-28 01:03 - 00693760 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
      2016-06-14 21:03 - 2016-05-28 01:03 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
      2016-06-14 21:03 - 2016-05-28 01:02 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
      2016-06-14 21:03 - 2016-05-28 01:01 - 00111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
      2016-06-14 21:03 - 2016-05-28 01:00 - 02230272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
      2016-06-14 21:03 - 2016-05-28 01:00 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
      2016-06-14 21:03 - 2016-05-28 01:00 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
      2016-06-14 21:03 - 2016-05-28 00:59 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
      2016-06-14 21:03 - 2016-05-28 00:58 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
      2016-06-14 21:03 - 2016-05-28 00:53 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
      2016-06-14 10:10 - 2016-06-20 14:50 - 00000000 ____D C:\Users\Geicy\Documents\PDF COM NOVO FORMATO
      2016-06-14 09:26 - 2016-06-20 14:27 - 00000000 ____D C:\Users\Geicy\Documents\PRANCHAS CARIMBO
      2016-05-31 17:52 - 2016-05-31 17:52 - 00236776 _____ C:\Users\Geicy\Downloads\DETRAN_SE - Portal de Serviços.pdf
      2016-05-31 17:12 - 2016-05-31 17:12 - 00002087 _____ C:\Users\Public\Desktop\A360 Desktop.lnk
      2016-05-31 17:10 - 2016-05-31 17:10 - 00002168 _____ C:\Users\Public\Desktop\Autodesk ReCap 2016.lnk
      2016-05-31 17:10 - 2016-05-31 17:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk ReCap 2016
      2016-05-31 17:07 - 2016-05-31 17:07 - 00002182 _____ C:\Users\Public\Desktop\AutoCAD 2016 - English.lnk
      2016-05-31 17:07 - 2016-05-31 17:07 - 00000000 ____D C:\Users\Public\Documents\Autodesk
      2016-05-31 17:06 - 2016-05-31 17:06 - 00000000 ____D C:\Users\Geicy\Documents\Inventor Server SDK ACAD 2016
      2016-05-28 10:58 - 2016-05-28 11:21 - 00047584 _____ C:\Users\Geicy\Downloads\Sinalizacao tatil de alerta e diecional.dwg
      2016-05-26 11:30 - 2016-05-26 11:30 - 00000000 ____D C:\Users\Geicy\Downloads\Certificados
      2016-05-26 11:22 - 2016-05-26 11:23 - 00000000 ____D C:\Users\Geicy\Downloads\Filarmônica
      2016-05-12 07:31 - 2016-07-18 21:30 - 00000000 ____D C:\Users\Geicy\Documents\Revit
      2016-05-11 09:40 - 2016-04-23 02:28 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
      2016-05-11 09:40 - 2016-04-23 02:24 - 01819208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
      2016-05-11 09:40 - 2016-04-23 02:09 - 21123320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
      2016-05-11 09:40 - 2016-04-23 02:09 - 05240960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
      2016-05-11 09:40 - 2016-04-23 02:08 - 06605504 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
      2016-05-11 09:40 - 2016-04-23 01:31 - 13018112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
      2016-05-11 09:40 - 2016-04-23 01:28 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
      2016-05-11 09:40 - 2016-04-23 01:19 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
      2016-05-11 09:40 - 2016-04-23 01:15 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
      2016-05-11 09:40 - 2016-04-23 01:05 - 05502976 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
      2016-05-11 09:40 - 2016-04-23 01:05 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
      2016-05-11 09:40 - 2016-04-23 01:04 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
      2016-05-11 09:40 - 2016-04-23 01:03 - 02000896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
      2016-05-11 09:40 - 2016-04-23 01:02 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
      2016-05-11 09:39 - 2016-05-06 01:53 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdport.sys
      2016-05-11 09:39 - 2016-05-06 01:05 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
      2016-05-11 09:39 - 2016-05-06 01:03 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
      2016-05-11 09:39 - 2016-05-06 00:53 - 00351232 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
      2016-05-11 09:39 - 2016-05-06 00:49 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
      2016-05-11 09:39 - 2016-05-06 00:44 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
      2016-05-11 09:39 - 2016-05-06 00:43 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
      2016-05-11 09:39 - 2016-04-23 03:12 - 00713920 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
      2016-05-11 09:39 - 2016-04-23 03:12 - 00190144 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
      2016-05-11 09:39 - 2016-04-23 02:28 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
      2016-05-11 09:39 - 2016-04-23 02:26 - 00707608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
      2016-05-11 09:39 - 2016-04-23 02:24 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
      2016-05-11 09:39 - 2016-04-23 02:24 - 00754664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
      2016-05-11 09:39 - 2016-04-23 02:24 - 00638816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
      2016-05-11 09:39 - 2016-04-23 02:24 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
      2016-05-11 09:39 - 2016-04-23 02:24 - 00099680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
      2016-05-11 09:39 - 2016-04-23 02:22 - 01161120 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
      2016-05-11 09:39 - 2016-04-23 02:13 - 00306832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
      2016-05-11 09:39 - 2016-04-23 02:12 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
      2016-05-11 09:39 - 2016-04-23 02:12 - 00451928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
      2016-05-11 09:39 - 2016-04-23 02:12 - 00413536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
      2016-05-11 09:39 - 2016-04-23 02:11 - 01092464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
      2016-05-11 09:39 - 2016-04-23 02:11 - 00498960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
      2016-05-11 09:39 - 2016-04-23 02:11 - 00390496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
      2016-05-11 09:39 - 2016-04-23 02:11 - 00131424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufxsynopsys.sys
      2016-05-11 09:39 - 2016-04-23 02:09 - 00569744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
      2016-05-11 09:39 - 2016-04-23 02:09 - 00565600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
      2016-05-11 09:39 - 2016-04-23 02:09 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
      2016-05-11 09:39 - 2016-04-23 02:08 - 00725776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
      2016-05-11 09:39 - 2016-04-23 02:07 - 01848072 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
      2016-05-11 09:39 - 2016-04-23 02:07 - 01536088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
      2016-05-11 09:39 - 2016-04-23 02:07 - 00204048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll
      2016-05-11 09:39 - 2016-04-23 02:07 - 00183904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll
      2016-05-11 09:39 - 2016-04-23 02:06 - 00291360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
      2016-05-11 09:39 - 2016-04-23 02:02 - 00188256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
      2016-05-11 09:39 - 2016-04-23 02:01 - 00619296 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll
      2016-05-11 09:39 - 2016-04-23 02:01 - 00513368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll
      2016-05-11 09:39 - 2016-04-23 02:01 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
      2016-05-11 09:39 - 2016-04-23 02:01 - 00217440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
      2016-05-11 09:39 - 2016-04-23 02:00 - 01776768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
      2016-05-11 09:39 - 2016-04-23 02:00 - 01522152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
      2016-05-11 09:39 - 2016-04-23 02:00 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
      2016-05-11 09:39 - 2016-04-23 02:00 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
      2016-05-11 09:39 - 2016-04-23 02:00 - 00550656 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
      2016-05-11 09:39 - 2016-04-23 02:00 - 00453472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
      2016-05-11 09:39 - 2016-04-23 02:00 - 00058208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwminit.dll
      2016-05-11 09:39 - 2016-04-23 01:56 - 00534872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
      2016-05-11 09:39 - 2016-04-23 01:34 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
      2016-05-11 09:39 - 2016-04-23 01:34 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
      2016-05-11 09:39 - 2016-04-23 01:34 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
      2016-05-11 09:39 - 2016-04-23 01:33 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
      2016-05-11 09:39 - 2016-04-23 01:33 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshbth.dll
      2016-05-11 09:39 - 2016-04-23 01:33 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmCx.sys
      2016-05-11 09:39 - 2016-04-23 01:33 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ByteCodeGenerator.exe
      2016-05-11 09:39 - 2016-04-23 01:32 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
      2016-05-11 09:39 - 2016-04-23 01:32 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
      2016-05-11 09:39 - 2016-04-23 01:29 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
      2016-05-11 09:39 - 2016-04-23 01:29 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
      2016-05-11 09:39 - 2016-04-23 01:29 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\filecrypt.sys
      2016-05-11 09:39 - 2016-04-23 01:29 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
      2016-05-11 09:39 - 2016-04-23 01:29 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
      2016-05-11 09:39 - 2016-04-23 01:29 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe
      2016-05-11 09:39 - 2016-04-23 01:29 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
      2016-05-11 09:39 - 2016-04-23 01:28 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
      2016-05-11 09:39 - 2016-04-23 01:28 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
      2016-05-11 09:39 - 2016-04-23 01:28 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
      2016-05-11 09:39 - 2016-04-23 01:28 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshbth.dll
      2016-05-11 09:39 - 2016-04-23 01:27 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
      2016-05-11 09:39 - 2016-04-23 01:26 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
      2016-05-11 09:39 - 2016-04-23 01:25 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
      2016-05-11 09:39 - 2016-04-23 01:25 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
      2016-05-11 09:39 - 2016-04-23 01:25 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
      2016-05-11 09:39 - 2016-04-23 01:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
      2016-05-11 09:39 - 2016-04-23 01:24 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
      2016-05-11 09:39 - 2016-04-23 01:24 - 00287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
      2016-05-11 09:39 - 2016-04-23 01:24 - 00181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
      2016-05-11 09:39 - 2016-04-23 01:24 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
      2016-05-11 09:39 - 2016-04-23 01:24 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
      2016-05-11 09:39 - 2016-04-23 01:23 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
      2016-05-11 09:39 - 2016-04-23 01:23 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrowserSettingSync.dll
      2016-05-11 09:39 - 2016-04-23 01:23 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
      2016-05-11 09:39 - 2016-04-23 01:21 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
      2016-05-11 09:39 - 2016-04-23 01:20 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
      2016-05-11 09:39 - 2016-04-23 01:20 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
      2016-05-11 09:39 - 2016-04-23 01:20 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
      2016-05-11 09:39 - 2016-04-23 01:20 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
      2016-05-11 09:39 - 2016-04-23 01:20 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
      2016-05-11 09:39 - 2016-04-23 01:19 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
      2016-05-11 09:39 - 2016-04-23 01:19 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlansec.dll
      2016-05-11 09:39 - 2016-04-23 01:19 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BrowserSettingSync.dll
      2016-05-11 09:39 - 2016-04-23 01:18 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
      2016-05-11 09:39 - 2016-04-23 01:18 - 00804352 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
      2016-05-11 09:39 - 2016-04-23 01:18 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
      2016-05-11 09:39 - 2016-04-23 01:18 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
      2016-05-11 09:39 - 2016-04-23 01:18 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
      2016-05-11 09:39 - 2016-04-23 01:18 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
      2016-05-11 09:39 - 2016-04-23 01:17 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
      2016-05-11 09:39 - 2016-04-23 01:17 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
      2016-05-11 09:39 - 2016-04-23 01:17 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
      2016-05-11 09:39 - 2016-04-23 01:17 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll
      2016-05-11 09:39 - 2016-04-23 01:16 - 01319424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
      2016-05-11 09:39 - 2016-04-23 01:16 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
      2016-05-11 09:39 - 2016-04-23 01:15 - 00865792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
      2016-05-11 09:39 - 2016-04-23 01:15 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
      2016-05-11 09:39 - 2016-04-23 01:15 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
      2016-05-11 09:39 - 2016-04-23 01:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
      2016-05-11 09:39 - 2016-04-23 01:14 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
      2016-05-11 09:39 - 2016-04-23 01:14 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
      2016-05-11 09:39 - 2016-04-23 01:14 - 00647680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
      2016-05-11 09:39 - 2016-04-23 01:14 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
      2016-05-11 09:39 - 2016-04-23 01:14 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
      2016-05-11 09:39 - 2016-04-23 01:13 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
      2016-05-11 09:39 - 2016-04-23 01:13 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
      2016-05-11 09:39 - 2016-04-23 01:13 - 00434688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
      2016-05-11 09:39 - 2016-04-23 01:12 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
      2016-05-11 09:39 - 2016-04-23 01:10 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
      2016-05-11 09:39 - 2016-04-23 01:07 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
      2016-05-11 09:39 - 2016-04-23 01:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
      2016-05-11 09:39 - 2016-04-23 01:05 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
      2016-05-11 09:39 - 2016-04-23 01:03 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
      2016-05-11 09:39 - 2016-04-23 01:03 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
      2016-05-11 09:39 - 2016-04-23 01:03 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
      2016-05-11 09:39 - 2016-04-23 01:01 - 04775424 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
      2016-05-11 09:39 - 2016-04-23 01:00 - 00984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
      2016-05-11 09:39 - 2016-04-23 00:45 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
      2016-05-11 09:39 - 2016-04-22 23:10 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
      2016-05-11 09:39 - 2016-04-22 23:10 - 00002186 _____ C:\WINDOWS\system32\AppxProvisioning.xml
      2016-05-11 09:39 - 2016-04-18 19:30 - 00002186 _____ C:\WINDOWS\SysWOW64\AppxProvisioning.xml
      2016-05-08 11:41 - 2016-05-08 11:42 - 12237952 _____ C:\Users\Geicy\Downloads\VID-20160507-WA0014.mp4
      2016-05-06 10:42 - 2016-07-13 13:44 - 00130760 _____ C:\Users\Geicy\AppData\Local\GDIPFONTCACHEV1.DAT
      2016-05-06 10:31 - 2016-05-06 10:31 - 00000000 ____D C:\Users\Geicy\Documents\Autodesk Application Manager
      2016-05-06 10:27 - 2016-05-06 10:27 - 00002059 _____ C:\Users\Public\Desktop\Revit 2016.lnk
      2016-05-06 08:53 - 2016-05-06 08:53 - 00002123 _____ C:\Users\Public\Desktop\Autodesk ReCap.lnk
      2016-05-06 08:53 - 2016-05-06 08:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk ReCap
      2016-05-06 08:43 - 2016-05-31 17:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
      2016-05-06 08:43 - 2016-05-31 17:12 - 00000000 ____D C:\Program Files (x86)\Autodesk
      2016-05-06 07:50 - 2016-05-31 16:29 - 00000000 ____D C:\Users\Geicy\Downloads\Instaladores CAD e Revit
      2016-05-05 23:55 - 2016-05-06 00:11 - 00388608 _____ (Trend Micro Inc.) C:\HijackThis.exe
      2016-05-05 22:41 - 2016-05-05 23:05 - 22851472 _____ (Malwarebytes ) C:\Users\Geicy\Downloads\mbam-setup-cnet.35891-2.2.1.1043.exe
      2016-05-05 22:20 - 2016-06-27 16:17 - 00473592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys.146705510676502
      2016-05-05 22:03 - 2016-07-21 16:43 - 00000000 ____D C:\Users\Todos os Usuários\AVAST Software
      2016-05-05 22:03 - 2016-07-21 16:43 - 00000000 ____D C:\ProgramData\AVAST Software
      2016-05-05 22:02 - 2016-05-05 22:03 - 05168776 _____ (AVAST Software) C:\Users\Geicy\Downloads\avast_free_antivirus_setup_online.exe
      2016-05-04 13:09 - 2016-05-04 13:09 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
      2016-05-04 13:00 - 2016-05-06 10:31 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache
      2016-05-04 13:00 - 2016-05-06 10:31 - 00000000 ____D C:\ProgramData\Package Cache
      2016-05-04 12:50 - 2016-05-31 16:41 - 00000000 ____D C:\Autodesk
      2016-05-03 09:23 - 2016-07-21 16:05 - 00000000 ___RD C:\Users\Geicy\Dropbox
      2016-05-03 09:23 - 2016-05-03 09:23 - 00001225 _____ C:\Users\Geicy\Desktop\Dropbox.lnk
      2016-05-03 09:20 - 2016-07-11 17:00 - 00000000 ____D C:\Users\Geicy\AppData\Roaming\Dropbox
      2016-05-03 08:58 - 2016-07-22 18:03 - 00001050 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1883175002-3615411677-2762873912-1001UA.job
      2016-05-03 08:58 - 2016-06-15 09:03 - 00000998 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-1883175002-3615411677-2762873912-1001Core.job
      2016-05-03 08:58 - 2016-05-13 09:27 - 00000000 ____D C:\Users\Geicy\AppData\Local\Dropbox
      2016-05-03 08:58 - 2016-05-03 08:58 - 00004170 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1883175002-3615411677-2762873912-1001UA
      2016-05-03 08:58 - 2016-05-03 08:58 - 00003794 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1883175002-3615411677-2762873912-1001Core
      2016-05-03 08:58 - 2016-05-03 08:58 - 00000000 ____D C:\Users\Todos os Usuários\Dropbox
      2016-05-03 08:58 - 2016-05-03 08:58 - 00000000 ____D C:\ProgramData\Dropbox
      2016-05-03 08:57 - 2016-05-03 08:58 - 00690072 _____ (Dropbox, Inc.) C:\Users\Geicy\Downloads\DropboxInstaller.exe
      2016-05-02 09:45 - 2016-04-02 00:25 - 00278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
      2016-05-02 09:45 - 2016-04-02 00:25 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
      2016-05-02 09:45 - 2016-03-29 07:15 - 00100232 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
      2016-05-02 09:45 - 2016-03-29 07:11 - 00686976 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
      2016-05-02 09:45 - 2016-03-29 06:28 - 00535080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
      2016-05-02 09:45 - 2016-03-29 06:25 - 00058400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
      2016-05-02 09:45 - 2016-03-29 05:41 - 00051128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.dll
      2016-05-02 09:45 - 2016-03-29 05:16 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
      2016-05-02 09:45 - 2016-03-29 05:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
      2016-05-02 09:45 - 2016-03-29 05:07 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsdchngr.dll
      2016-05-02 09:45 - 2016-03-29 05:06 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacchooks.dll
      2016-05-02 09:45 - 2016-03-29 05:00 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
      2016-05-02 09:45 - 2016-03-29 05:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveskybackup.dll
      2016-05-02 09:45 - 2016-03-29 04:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
      2016-05-02 09:45 - 2016-03-29 04:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
      2016-05-02 09:45 - 2016-03-29 04:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
      2016-05-02 09:45 - 2016-03-29 04:55 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
      2016-05-02 09:45 - 2016-03-29 04:53 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\FontProvider.dll
      2016-05-02 09:45 - 2016-03-29 04:52 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
      2016-05-02 09:45 - 2016-03-29 04:51 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
      2016-05-02 09:45 - 2016-03-29 04:51 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
      2016-05-02 09:45 - 2016-03-29 04:50 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeHdCfgLib.dll
      2016-05-02 09:45 - 2016-03-29 04:50 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OnDemandConnRouteHelper.dll
      2016-05-02 09:45 - 2016-03-29 04:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
      2016-05-02 09:45 - 2016-03-29 04:49 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthLEEnum.sys
      2016-05-02 09:45 - 2016-03-29 04:44 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFWSD.dll
      2016-05-02 09:45 - 2016-03-29 04:36 - 00530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
      2016-05-02 09:45 - 2016-03-29 04:35 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
      2016-05-02 09:45 - 2016-03-29 04:34 - 00333824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
      2016-05-02 09:45 - 2016-03-29 04:34 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
      2016-05-02 09:45 - 2016-03-29 04:30 - 00328192 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
      2016-05-02 09:45 - 2016-03-29 04:27 - 00339968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
      2016-05-02 09:45 - 2016-03-29 04:22 - 00438784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AccountsRt.dll
      2016-05-02 09:45 - 2016-03-29 04:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
      2016-05-02 09:45 - 2016-03-29 04:20 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
      2016-05-02 09:45 - 2016-03-29 04:20 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
      2016-05-02 09:45 - 2016-03-29 04:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsdchngr.dll
      2016-05-02 09:45 - 2016-03-29 04:19 - 00556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
      2016-05-02 09:45 - 2016-03-29 04:18 - 00676352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
      2016-05-02 09:45 - 2016-03-29 04:11 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
      2016-05-02 09:45 - 2016-03-29 04:06 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
      2016-05-02 09:45 - 2016-03-29 04:05 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OnDemandConnRouteHelper.dll
      2016-05-02 09:45 - 2016-03-29 04:03 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
      2016-05-02 09:45 - 2016-03-29 04:00 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
      2016-05-02 09:45 - 2016-03-29 04:00 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
      2016-05-02 09:45 - 2016-03-29 03:59 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
      2016-05-02 09:45 - 2016-03-29 03:59 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
      2016-05-02 09:45 - 2016-03-29 03:53 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
      2016-05-02 09:45 - 2016-03-29 03:43 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AccountsRt.dll
      2016-05-02 09:45 - 2016-03-29 03:39 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
      2016-05-02 09:45 - 2016-03-29 03:32 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
      2016-05-02 09:45 - 2016-03-29 03:27 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
      2016-05-02 09:45 - 2016-03-29 03:27 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
      2016-05-02 09:45 - 2016-03-29 03:17 - 00765952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
      2016-05-02 09:45 - 2016-03-29 03:05 - 00361472 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
      2016-05-02 09:45 - 2016-02-24 04:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
      2016-05-02 09:45 - 2016-02-24 04:39 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
      2016-05-02 09:45 - 2016-02-24 04:38 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
      2016-05-02 09:45 - 2016-02-24 04:37 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
      2016-05-02 09:45 - 2016-02-24 04:36 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll
      2016-05-02 09:45 - 2016-02-24 04:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
      2016-05-02 09:45 - 2016-02-24 04:28 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
      2016-05-02 09:45 - 2016-02-24 04:23 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
      2016-05-02 09:45 - 2016-02-24 04:19 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
      2016-05-02 09:45 - 2016-02-24 04:19 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
      2016-05-02 09:45 - 2016-02-24 04:09 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll
      2016-05-02 09:45 - 2016-02-24 04:07 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
      2016-05-02 09:45 - 2016-02-24 04:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
      2016-05-02 09:45 - 2016-02-24 04:01 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
      2016-05-02 09:45 - 2016-02-24 04:01 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
      2016-05-02 09:45 - 2016-02-24 03:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
      2016-05-02 09:45 - 2016-02-24 03:55 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
      2016-05-02 09:45 - 2016-02-24 03:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
      2016-05-02 09:45 - 2016-02-24 03:54 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
      2016-05-02 09:45 - 2016-02-24 03:54 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
      2016-05-02 09:45 - 2016-02-24 03:53 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
      2016-05-02 09:45 - 2016-02-24 03:53 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
      2016-05-02 09:45 - 2016-02-24 03:52 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll
      2016-05-02 09:45 - 2016-02-24 03:40 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
      2016-05-02 09:45 - 2016-02-24 03:28 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll
      2016-05-02 09:45 - 2016-02-24 03:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
      2016-05-02 09:45 - 2016-02-24 03:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
      2016-05-02 09:45 - 2016-02-23 08:25 - 00563552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
      2016-05-02 09:45 - 2016-02-23 07:31 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
      2016-05-02 09:45 - 2016-02-23 06:20 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
      2016-05-02 09:45 - 2016-02-23 06:10 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
      2016-05-02 09:45 - 2016-02-23 06:07 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
      2016-05-02 09:45 - 2016-02-23 06:00 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
      2016-05-02 09:45 - 2016-02-23 05:55 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
      2016-05-02 09:45 - 2016-02-23 05:48 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerClient.dll
      2016-05-02 09:45 - 2016-02-23 05:40 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
      2016-05-02 09:45 - 2016-02-23 05:39 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
      2016-05-02 09:45 - 2016-02-23 05:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
      2016-05-02 09:45 - 2016-02-23 05:04 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
      2016-05-02 09:45 - 2016-02-23 04:57 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TimeBrokerClient.dll
      2016-05-02 09:45 - 2016-02-23 04:48 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
      2016-05-02 09:45 - 2016-02-09 00:18 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
      2016-05-02 09:45 - 2016-02-09 00:18 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
      2016-05-02 09:44 - 2016-04-02 01:13 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
      2016-05-02 09:44 - 2016-04-02 01:10 - 00770640 _____ (Microsoft Corporation) C:\WINDOWS\system32\iuilp.dll
      2016-05-02 09:44 - 2016-04-02 01:10 - 00374008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
      2016-05-02 09:44 - 2016-04-02 00:19 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
      2016-05-02 09:44 - 2016-03-29 07:22 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
      2016-05-02 09:44 - 2016-03-29 07:22 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
      2016-05-02 09:44 - 2016-03-29 07:20 - 02656952 _____ C:\WINDOWS\system32\CoreUIComponents.dll
      2016-05-02 09:44 - 2016-03-29 07:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
      2016-05-02 09:44 - 2016-03-29 07:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
      2016-05-02 09:44 - 2016-03-29 07:05 - 01152864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
      2016-05-02 09:44 - 2016-03-29 07:02 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
      2016-05-02 09:44 - 2016-03-29 07:02 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
      2016-05-02 09:44 - 2016-03-29 06:56 - 01297752 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
      2016-05-02 09:44 - 2016-03-29 06:37 - 01862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
      2016-05-02 09:44 - 2016-03-29 06:19 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
      2016-05-02 09:44 - 2016-03-29 06:13 - 00986976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
      2016-05-02 09:44 - 2016-03-29 06:11 - 00074424 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
      2016-05-02 09:44 - 2016-03-29 06:10 - 00110584 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvcli.dll
      2016-05-02 09:44 - 2016-03-29 06:09 - 00078040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkscli.dll
      2016-05-02 09:44 - 2016-03-29 06:08 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
      2016-05-02 09:44 - 2016-03-29 06:08 - 00261376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
      2016-05-02 09:44 - 2016-03-29 06:07 - 00081144 _____ (Microsoft Corporation) C:\WINDOWS\system32\netapi32.dll
      2016-05-02 09:44 - 2016-03-29 05:26 - 01089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
      2016-05-02 09:44 - 2016-03-29 05:26 - 00073872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srvcli.dll
      2016-05-02 09:44 - 2016-03-29 05:25 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wkscli.dll
      2016-05-02 09:44 - 2016-03-29 05:24 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
      2016-05-02 09:44 - 2016-03-29 05:23 - 00069744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netapi32.dll
      2016-05-02 09:44 - 2016-03-29 05:21 - 00378208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
      2016-05-02 09:44 - 2016-03-29 05:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
      2016-05-02 09:44 - 2016-03-29 05:07 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
      2016-05-02 09:44 - 2016-03-29 04:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
      2016-05-02 09:44 - 2016-03-29 04:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\browcli.dll
      2016-05-02 09:44 - 2016-03-29 04:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
      2016-05-02 09:44 - 2016-03-29 04:54 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
      2016-05-02 09:44 - 2016-03-29 04:51 - 00181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rfcomm.sys
      2016-05-02 09:44 - 2016-03-29 04:50 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
      2016-05-02 09:44 - 2016-03-29 04:48 - 00144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Devices.dll
      2016-05-02 09:44 - 2016-03-29 04:46 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
      2016-05-02 09:44 - 2016-03-29 04:36 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
      2016-05-02 09:44 - 2016-03-29 04:35 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovhost.dll
      2016-05-02 09:44 - 2016-03-29 04:33 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
      2016-05-02 09:44 - 2016-03-29 04:30 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
      2016-05-02 09:44 - 2016-03-29 04:23 - 00694784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
      2016-05-02 09:44 - 2016-03-29 04:21 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
      2016-05-02 09:44 - 2016-03-29 04:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacchooks.dll
      2016-05-02 09:44 - 2016-03-29 04:17 - 00708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
      2016-05-02 09:44 - 2016-03-29 04:14 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
      2016-05-02 09:44 - 2016-03-29 04:12 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
      2016-05-02 09:44 - 2016-03-29 04:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
      2016-05-02 09:44 - 2016-03-29 04:11 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\browcli.dll
      2016-05-02 09:44 - 2016-03-29 04:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
      2016-05-02 09:44 - 2016-03-29 04:08 - 00888320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
      2016-05-02 09:44 - 2016-03-29 04:08 - 00841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
      2016-05-02 09:44 - 2016-03-29 04:08 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
      2016-05-02 09:44 - 2016-03-29 04:07 - 01902592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
      2016-05-02 09:44 - 2016-03-29 04:05 - 01395712 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
      2016-05-02 09:44 - 2016-03-29 04:02 - 01211904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
      2016-05-02 09:44 - 2016-03-29 04:00 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
      2016-05-02 09:44 - 2016-03-29 04:00 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
      2016-05-02 09:44 - 2016-03-29 03:59 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
      2016-05-02 09:44 - 2016-03-29 03:55 - 01052160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.dll
      2016-05-02 09:44 - 2016-03-29 03:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
      2016-05-02 09:44 - 2016-03-29 03:52 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\easwrt.dll
      2016-05-02 09:44 - 2016-03-29 03:49 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
      2016-05-02 09:44 - 2016-03-29 03:42 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
      2016-05-02 09:44 - 2016-03-29 03:41 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
      2016-05-02 09:44 - 2016-03-29 03:36 - 00649728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
      2016-05-02 09:44 - 2016-03-29 03:32 - 01588224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
      2016-05-02 09:44 - 2016-03-29 03:32 - 01098240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
      2016-05-02 09:44 - 2016-03-29 03:32 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
      2016-05-02 09:44 - 2016-03-29 03:30 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
      2016-05-02 09:44 - 2016-03-29 03:29 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
      2016-05-02 09:44 - 2016-03-29 03:27 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
      2016-05-02 09:44 - 2016-03-29 03:23 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MsSpellCheckingFacility.dll
      2016-05-02 09:44 - 2016-03-29 03:05 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
      2016-05-02 09:44 - 2016-03-29 03:04 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
      2016-05-02 09:44 - 2016-03-29 03:01 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
      2016-05-02 09:44 - 2016-03-29 02:45 - 03078144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
      2016-05-02 09:44 - 2016-03-29 02:45 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncbservice.dll
      2016-05-02 09:44 - 2016-03-29 02:43 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
      2016-05-02 09:44 - 2016-03-29 02:36 - 02722816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
      2016-05-02 09:44 - 2016-03-29 02:35 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
      2016-05-02 09:44 - 2016-03-29 02:28 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
      2016-05-02 09:44 - 2016-03-29 02:27 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
      2016-05-02 09:44 - 2016-03-29 02:26 - 00958976 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
      2016-05-02 09:44 - 2016-03-29 02:26 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
      2016-05-02 09:44 - 2016-03-29 02:25 - 00712704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
      2016-05-02 09:44 - 2016-03-29 02:25 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
      2016-05-02 09:44 - 2016-03-29 02:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\basesrv.dll
      2016-05-02 09:44 - 2016-03-01 02:31 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
      2016-05-02 09:44 - 2016-03-01 02:22 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
      2016-05-02 09:44 - 2016-02-24 06:34 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
      2016-05-02 09:44 - 2016-02-24 06:28 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
      2016-05-02 09:44 - 2016-02-24 05:58 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
      2016-05-02 09:44 - 2016-02-24 05:43 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
      2016-05-02 09:44 - 2016-02-24 05:39 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe
      2016-05-02 09:44 - 2016-02-24 05:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
      2016-05-02 09:44 - 2016-02-24 05:11 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
      2016-05-02 09:44 - 2016-02-24 05:09 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
      2016-05-02 09:44 - 2016-02-24 05:09 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
      2016-05-02 09:44 - 2016-02-24 04:35 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
      2016-05-02 09:44 - 2016-02-24 04:33 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
      2016-05-02 09:44 - 2016-02-24 04:33 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
      2016-05-02 09:44 - 2016-02-24 04:23 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
      2016-05-02 09:44 - 2016-02-24 04:22 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
      2016-05-02 09:44 - 2016-02-24 04:20 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
      2016-05-02 09:44 - 2016-02-24 04:14 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
      2016-05-02 09:44 - 2016-02-24 04:13 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
      2016-05-02 09:44 - 2016-02-24 04:12 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll
      2016-05-02 09:44 - 2016-02-24 04:12 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
      2016-05-02 09:44 - 2016-02-24 04:10 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
      2016-05-02 09:44 - 2016-02-24 04:09 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
      2016-05-02 09:44 - 2016-02-24 04:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
      2016-05-02 09:44 - 2016-02-24 03:59 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
      2016-05-02 09:44 - 2016-02-24 03:59 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
      2016-05-02 09:44 - 2016-02-24 03:55 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
      2016-05-02 09:44 - 2016-02-24 03:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
      2016-05-02 09:44 - 2016-02-24 03:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
      2016-05-02 09:44 - 2016-02-24 03:52 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
      2016-05-02 09:44 - 2016-02-24 03:49 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
      2016-05-02 09:44 - 2016-02-24 03:46 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
      2016-05-02 09:44 - 2016-02-24 03:44 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
      2016-05-02 09:44 - 2016-02-24 03:44 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
      2016-05-02 09:44 - 2016-02-24 03:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
      2016-05-02 09:44 - 2016-02-24 03:40 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
      2016-05-02 09:44 - 2016-02-24 03:40 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
      2016-05-02 09:44 - 2016-02-24 03:39 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
      2016-05-02 09:44 - 2016-02-24 03:38 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
      2016-05-02 09:44 - 2016-02-24 03:34 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
      2016-05-02 09:44 - 2016-02-24 03:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
      2016-05-02 09:44 - 2016-02-24 03:32 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
      2016-05-02 09:44 - 2016-02-24 03:31 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll
      2016-05-02 09:44 - 2016-02-24 03:31 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
      2016-05-02 09:44 - 2016-02-24 03:28 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
      2016-05-02 09:44 - 2016-02-24 03:25 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
      2016-05-02 09:44 - 2016-02-24 03:23 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
      2016-05-02 09:44 - 2016-02-24 03:21 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
      2016-05-02 09:44 - 2016-02-24 03:21 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
      2016-05-02 09:44 - 2016-02-24 03:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
      2016-05-02 09:44 - 2016-02-24 03:17 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
      2016-05-02 09:44 - 2016-02-24 03:16 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
      2016-05-02 09:44 - 2016-02-24 03:09 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
      2016-05-02 09:44 - 2016-02-24 03:07 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
      2016-05-02 09:44 - 2016-02-24 02:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
      2016-05-02 09:44 - 2016-02-24 02:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll
      2016-05-02 09:44 - 2016-02-23 07:31 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
      2016-05-02 09:44 - 2016-02-23 07:31 - 00476728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
      2016-05-02 09:44 - 2016-02-23 07:17 - 00146272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
      2016-05-02 09:44 - 2016-02-23 06:40 - 00430944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
      2016-05-02 09:44 - 2016-02-23 06:38 - 00420928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
      2016-05-02 09:44 - 2016-02-23 06:27 - 00376536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
      2016-05-02 09:44 - 2016-02-23 06:20 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSave.dll
      2016-05-02 09:44 - 2016-02-23 06:12 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll
      2016-05-02 09:44 - 2016-02-23 06:07 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
      2016-05-02 09:44 - 2016-02-23 06:06 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
      2016-05-02 09:44 - 2016-02-23 06:01 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
      2016-05-02 09:44 - 2016-02-23 05:58 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\irmon.dll
      2016-05-02 09:44 - 2016-02-23 05:53 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
      2016-05-02 09:44 - 2016-02-23 05:53 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
      2016-05-02 09:44 - 2016-02-23 05:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
      2016-05-02 09:44 - 2016-02-23 05:36 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll
      2016-05-02 09:44 - 2016-02-23 05:34 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
      2016-05-02 09:44 - 2016-02-23 05:31 - 00463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
      2016-05-02 09:44 - 2016-02-23 05:29 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
      2016-05-02 09:44 - 2016-02-23 05:28 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
      2016-05-02 09:44 - 2016-02-23 05:27 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
      2016-05-02 09:44 - 2016-02-23 05:26 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
      2016-05-02 09:44 - 2016-02-23 05:23 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
      2016-05-02 09:44 - 2016-02-23 05:22 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
      2016-05-02 09:44 - 2016-02-23 05:20 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
      2016-05-02 09:44 - 2016-02-23 05:20 - 00493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
      2016-05-02 09:44 - 2016-02-23 05:19 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
      2016-05-02 09:44 - 2016-02-23 05:02 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
      2016-05-02 09:44 - 2016-02-23 05:02 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
      2016-05-02 09:44 - 2016-02-23 04:58 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerServer.dll
      2016-05-02 09:44 - 2016-02-23 04:52 - 00456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
      2016-05-02 09:44 - 2016-02-23 04:50 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
      2016-05-02 09:44 - 2016-02-23 04:47 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
      2016-05-02 09:44 - 2016-02-23 04:37 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
      2016-05-02 09:44 - 2016-02-23 04:36 - 00713728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
      2016-05-02 09:44 - 2016-02-23 04:36 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
      2016-05-02 09:44 - 2016-02-23 04:35 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
      2016-05-02 09:43 - 2016-03-29 07:23 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
      2016-05-02 09:43 - 2016-03-29 07:18 - 02152280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
      2016-05-02 09:43 - 2016-03-29 06:18 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
      2016-05-02 09:43 - 2016-03-29 05:26 - 02403680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
      2016-05-02 09:43 - 2016-03-29 04:11 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
      2016-05-02 09:43 - 2016-03-29 04:09 - 01239552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
      2016-05-02 09:43 - 2016-03-29 04:06 - 01575936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
      2016-05-02 09:43 - 2016-03-29 04:04 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Devices.dll
      2016-05-02 09:43 - 2016-03-29 04:02 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
      2016-05-02 09:43 - 2016-03-29 03:42 - 01410560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
      2016-05-02 09:43 - 2016-03-29 03:40 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
      2016-05-02 09:43 - 2016-03-29 03:39 - 00496128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
      2016-05-02 09:43 - 2016-03-29 03:36 - 03351040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
      2016-05-02 09:43 - 2016-03-29 03:34 - 00682496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
      2016-05-02 09:43 - 2016-03-29 03:32 - 00854528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
      2016-05-02 09:43 - 2016-03-29 03:31 - 01117184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
      2016-05-02 09:43 - 2016-03-29 03:28 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
      2016-05-02 09:43 - 2016-03-29 03:28 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
      2016-05-02 09:43 - 2016-03-29 03:27 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
      2016-05-02 09:43 - 2016-03-29 03:14 - 01072128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Http.dll
      2016-05-02 09:43 - 2016-03-29 03:13 - 00592384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
      2016-05-02 09:43 - 2016-03-29 03:10 - 03671040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
      2016-05-02 09:43 - 2016-03-29 02:43 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
      2016-05-02 09:43 - 2016-03-29 02:38 - 02798080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
      2016-05-02 09:43 - 2016-02-24 05:54 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
      2016-05-02 09:43 - 2016-02-24 03:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
      2016-05-02 09:43 - 2016-02-24 03:44 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
      2016-05-02 09:43 - 2016-02-24 03:36 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
      2016-05-02 09:43 - 2016-02-24 03:18 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
      2016-05-02 09:43 - 2016-02-24 03:13 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
      2016-05-02 09:43 - 2016-02-24 03:09 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
      2016-05-02 09:43 - 2016-02-24 03:04 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
      2016-05-02 09:43 - 2016-02-24 03:03 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
      2016-05-02 09:43 - 2016-02-24 02:05 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
      2016-05-02 09:43 - 2016-02-24 02:03 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
      2016-05-02 09:43 - 2016-02-23 08:15 - 00779384 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
      2016-05-02 09:43 - 2016-02-23 07:32 - 08705672 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
      2016-05-02 09:43 - 2016-02-23 07:32 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
      2016-05-02 09:43 - 2016-02-23 07:32 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
      2016-05-02 09:43 - 2016-02-23 07:32 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
      2016-05-02 09:43 - 2016-02-23 07:31 - 01017032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
      2016-05-02 09:43 - 2016-02-23 07:31 - 00819648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
      2016-05-02 09:43 - 2016-02-23 07:22 - 00572272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
      2016-05-02 09:43 - 2016-02-23 06:45 - 02773096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
      2016-05-02 09:43 - 2016-02-23 06:38 - 06952088 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
      2016-05-02 09:43 - 2016-02-23 06:38 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
      2016-05-02 09:43 - 2016-02-23 06:38 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
      2016-05-02 09:43 - 2016-02-23 06:38 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
      2016-05-02 09:43 - 2016-02-23 06:38 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
      2016-05-02 09:43 - 2016-02-23 06:37 - 00713824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
      2016-05-02 09:43 - 2016-02-23 05:56 - 02186864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
      2016-05-02 09:43 - 2016-02-23 05:38 - 00287712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
      2016-05-02 09:43 - 2016-02-23 05:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
      2016-05-02 09:43 - 2016-02-23 05:34 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
      2016-05-02 09:43 - 2016-02-23 05:14 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
      2016-05-02 09:43 - 2016-02-23 05:10 - 00997376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
      2016-05-02 09:43 - 2016-02-23 05:04 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
      2016-05-02 09:43 - 2016-02-23 04:49 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
      2016-05-02 09:43 - 2016-02-23 04:38 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
      2016-05-02 09:43 - 2016-02-23 04:31 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
      2016-05-02 09:43 - 2016-02-23 04:24 - 04827136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
      2016-05-02 09:43 - 2016-02-23 04:24 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
      2016-05-02 09:43 - 2016-02-23 04:01 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
      2016-05-02 09:43 - 2016-02-23 03:56 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
      2016-05-02 09:43 - 2016-02-23 03:41 - 02912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
      2016-05-02 09:43 - 2016-02-23 03:35 - 07533568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
      2016-05-02 09:43 - 2016-02-23 03:33 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
      2016-05-02 09:43 - 2016-02-23 03:28 - 06740992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
      2016-05-02 07:14 - 2016-05-02 07:14 - 00000000 ____D C:\Users\Geicy\AppData\Local\NetworkTiles
      2016-04-29 21:02 - 2016-05-05 17:51 - 00000000 ____D C:\Users\Geicy\AppData\Local\MicrosoftEdge
      2016-04-29 21:00 - 2016-04-29 21:00 - 00002395 _____ C:\Users\Geicy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
      2016-04-29 20:58 - 2016-04-29 20:58 - 00000000 ____D C:\Users\Geicy\AppData\Local\ActiveSync
      2016-04-29 20:57 - 2016-04-29 20:57 - 00000000 ____D C:\Users\Geicy\AppData\Local\Publishers
      2016-04-29 20:56 - 2016-05-02 07:28 - 00000000 ____D C:\Users\Geicy\AppData\Local\Comms
      2016-04-29 20:56 - 2016-04-29 20:56 - 00000020 ___SH C:\Users\Geicy\ntuser.ini
      2016-04-29 20:56 - 2016-04-29 20:56 - 00000000 ____D C:\Users\Geicy\AppData\Local\TileDataLayer
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas Músicas
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas Imagens
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Meus Vídeos
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Histórico
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Dados de Aplicativos
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\Modelos
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\Meus Documentos
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\Menu Iniciar
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\Documents\Minhas Músicas
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\Documents\Minhas Imagens
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\Documents\Meus Vídeos
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\Dados de Aplicativos
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\Configurações Locais
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\AppData\Local\Histórico
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dados de Aplicativos
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\Ambiente de Rede
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default\Ambiente de Impressão
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default User\Documents\Minhas Músicas
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default User\Documents\Minhas Imagens
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default User\Documents\Meus Vídeos
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Histórico
      2016-04-29 20:53 - 2016-04-29 20:53 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Dados de Aplicativos
      2016-04-29 20:52 - 2016-07-04 12:14 - 01822696 _____ C:\WINDOWS\system32\PerfStringBackup.INI
      2016-04-29 20:48 - 2016-04-29 20:48 - 00022956 _____ C:\WINDOWS\system32\emptyregdb.dat
      2016-04-29 20:42 - 2016-04-29 20:42 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
      2016-04-29 20:42 - 2016-04-29 20:42 - 00000000 ____D C:\Users\Usuário Padrão\AppData\Roaming\Macromedia
      2016-04-29 20:42 - 2016-04-29 20:42 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
      2016-04-29 20:42 - 2016-04-29 20:42 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
      2016-04-29 20:37 - 2016-04-29 20:43 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
      2016-04-29 20:35 - 2016-05-05 21:10 - 00000000 ____D C:\Users\Geicy
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\Modelos
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\Meus Documentos
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\Menu Iniciar
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\Documents\Minhas Músicas
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\Documents\Minhas Imagens
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\Documents\Meus Vídeos
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\Dados de Aplicativos
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\Configurações Locais
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\AppData\Local\Histórico
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\AppData\Local\Dados de Aplicativos
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\Ambiente de Rede
      2016-04-29 20:35 - 2016-04-29 20:35 - 00000000 _SHDL C:\Users\Geicy\Ambiente de Impressão
      2016-04-29 20:32 - 2016-07-22 17:24 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
      2016-04-29 20:32 - 2016-04-29 20:38 - 00000000 ____D C:\Users\Todos os Usuários\Conexant
      2016-04-29 20:32 - 2016-04-29 20:38 - 00000000 ____D C:\ProgramData\Conexant
      2016-04-29 20:32 - 2016-04-29 20:37 - 00000000 ____D C:\Program Files\CONEXANT
      2016-04-29 20:32 - 2016-04-29 20:32 - 00000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
      2016-04-29 20:32 - 2016-04-29 20:32 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
      2016-04-29 20:32 - 2016-04-29 20:32 - 00000000 ____H C:\Users\Todos os Usuários\DP45977C.lfl
      2016-04-29 20:32 - 2016-04-29 20:32 - 00000000 ____H C:\ProgramData\DP45977C.lfl
      2016-04-29 20:32 - 2016-04-29 20:32 - 00000000 ____D C:\Program Files\Common Files\Atheros
      2016-04-29 20:32 - 2015-12-19 01:08 - 00103944 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
      2016-04-29 20:32 - 2015-12-19 01:08 - 00099848 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
      2016-04-29 20:31 - 2016-04-29 20:37 - 00000000 ____D C:\Program Files\Intel
      2016-04-29 20:31 - 2016-04-29 20:31 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
      2016-04-29 20:31 - 2016-04-29 20:31 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
      2016-04-29 20:31 - 2016-04-29 20:31 - 00000000 ____D C:\Program Files\Synaptics
      2016-04-29 20:29 - 2016-05-05 22:34 - 00000000 ___DC C:\WINDOWS\Panther
      2016-04-29 20:25 - 2016-04-29 20:25 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
      2016-04-29 20:23 - 2016-04-29 20:43 - 00000000 ____D C:\Program Files (x86)\MSBuild
      2016-04-29 20:23 - 2016-04-29 20:23 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
      2016-04-29 20:23 - 2016-04-29 20:23 - 00000000 ____D C:\Program Files\Reference Assemblies
      2016-04-29 20:23 - 2016-04-29 20:23 - 00000000 ____D C:\Program Files\MSBuild
      2016-04-29 20:23 - 2016-04-29 20:23 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
      2016-04-29 20:23 - 2015-10-23 17:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
      2016-04-29 20:23 - 2015-10-23 17:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
      2016-04-29 20:23 - 2015-10-23 17:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
      2016-04-29 20:22 - 2016-04-29 20:22 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
      2016-04-29 20:22 - 2016-04-29 20:22 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
      2016-04-29 20:22 - 2015-10-23 17:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
      2016-04-29 20:22 - 2015-10-23 17:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
      2016-04-29 20:22 - 2015-10-23 17:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
      2016-04-29 20:08 - 2016-04-29 20:52 - 00009528 _____ C:\WINDOWS\diagwrn.xml
      2016-04-29 20:08 - 2016-04-29 20:52 - 00009528 _____ C:\WINDOWS\diagerr.xml
      2016-04-26 09:10 - 2016-04-26 09:10 - 00000000 ____D C:\Users\Geicy\AppData\Local\cache
      2016-04-25 17:36 - 2016-04-25 17:36 - 00000000 ____D C:\Users\Geicy\AppData\Local\VirtualStore
      2016-04-25 17:34 - 2016-04-25 17:08 - 00024064 _____ C:\WINDOWS\zoek-delete.exe ==================== Três Meses Modificados arquivos e pastas ======== (Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.) 2016-07-22 18:01 - 2016-03-27 16:00 - 00000000 ____D C:\WINDOWS\system32\MRT
      2016-07-22 18:01 - 2015-10-30 04:11 - 00000000 ____D C:\WINDOWS\CbsTemp
      2016-07-22 17:52 - 2016-03-27 16:00 - 144749672 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
      2016-07-22 17:50 - 2015-10-30 04:24 - 00000000 ___HD C:\Program Files\WindowsApps
      2016-07-22 17:50 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\AppReadiness
      2016-07-22 17:39 - 2015-08-21 14:49 - 00001096 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
      2016-07-22 17:24 - 2015-08-21 14:49 - 00001092 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
      2016-07-22 17:24 - 2015-08-21 13:14 - 00000000 __SHD C:\Users\Geicy\IntelGraphicsProfiles
      2016-07-21 16:43 - 2016-02-13 14:55 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
      2016-07-21 16:43 - 2015-10-30 03:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
      2016-07-21 15:01 - 2015-08-21 14:47 - 00004172 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{250C93A8-23FA-4344-B921-D70E600FD1A6}
      2016-07-20 10:17 - 2016-03-08 10:38 - 00000000 ____D C:\Users\Geicy\Documents\AutoCAD
      2016-07-13 16:22 - 2015-11-22 15:41 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
      2016-07-13 16:21 - 2015-11-22 15:40 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
      2016-07-13 16:01 - 2016-02-24 15:34 - 00000000 ____D C:\AdwCleaner
      2016-07-10 10:54 - 2015-11-14 08:42 - 00000000 ____D C:\Users\Geicy\Downloads\plantas baixas
      2016-07-09 19:45 - 2015-10-30 04:21 - 00000000 ____D C:\WINDOWS\INF
      2016-07-06 21:39 - 2015-09-19 10:19 - 00485032 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
      2016-07-04 12:14 - 2016-02-13 14:31 - 00786498 _____ C:\WINDOWS\system32\prfh0416.dat
      2016-07-04 12:14 - 2016-02-13 14:31 - 00154782 _____ C:\WINDOWS\system32\prfc0416.dat
      2016-06-27 20:54 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\rescache ==================== Arquivos na raiz de alguns diretórios ======= 2016-04-29 20:32 - 2016-04-29 20:32 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Alguns arquivos em TEMP:
      ====================
      C:\Users\Geicy\AppData\Local\Temp\libeay32.dll
      C:\Users\Geicy\AppData\Local\Temp\msvcr120.dll
      C:\Users\Geicy\AppData\Local\Temp\sqlite3.dll
      C:\Users\Geicy\AppData\Local\Temp\{3D3CEC53-4033-4FDD-B612-300705C329D7}-DropboxClient_5.4.24.exe
      C:\Users\Geicy\AppData\Local\Temp\{3E97EDD8-813F-42E6-8C8D-D849CAD322B9}-DropboxClient_5.4.24.exe
      C:\Users\Geicy\AppData\Local\Temp\{7E059758-C237-4B67-BDC2-F6B0B829BE92}-DropboxClient_5.4.24.exe
      C:\Users\Geicy\AppData\Local\Temp\{9C1221FE-3ECE-4019-BE46-E1E82EB1AA8C}-DropboxClient_5.4.24.exe
      ==================== Bamital & volsnap ================= (Não há correção automática para arquivos que não passaram na verificação.) C:\WINDOWS\system32\winlogon.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\wininit.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\explorer.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\svchost.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\services.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\User32.dll => O arquivo é assinado digitalmente
      C:\WINDOWS\SysWOW64\User32.dll => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\userinit.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\rpcss.dll => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\dnsapi.dll => O arquivo é assinado digitalmente
      C:\WINDOWS\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
      C:\WINDOWS\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente
      LastRegBack: 2016-06-27 17:15 ==================== Fim de FRST.txt ============================ -->