cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

Resultado do exame da Farbar Recovery Scan Tool (FRST) (x86) Versão: 07-12-2016
Executado por fff (administrador) em FFF-PC (09-12-2016 11:24:37)
Executando a partir de C:\Users\fff\Desktop
Perfis Carregados: fff (Perfis Disponíveis: fff)
Platform: Microsoft Windows 7 Professional (X86) Idioma: Português (Brasil)
Internet Explorer Versão 8 (Navegador padrão: IE)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processos (Whitelisted) =================

(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Byte Technologies LLC) C:\Program Files\ByteFence\ByteFenceService.exe
() C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
() C:\Program Files\ByteFence\rtop\bin\rtop_bg.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(The Chromium Authors) C:\Users\fff\AppData\Local\chromium\Application\chrome.exe
(The Chromium Authors) C:\Users\fff\AppData\Local\chromium\Application\chrome.exe
(Byte Technologies LLC) C:\Program Files\ByteFence\ByteFence.exe
(The Chromium Authors) C:\Users\fff\AppData\Local\chromium\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\osk.exe

==================== Registro (Whitelisted) ====================

(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-12-06] (AVAST Software)
HKLM\...\RunOnce: [Cokucehocus] => C:\Windows\system32\wscript.exe /E:vbscript /B "C:\Users\fff\AppData\Roaming\Nofilo"
HKLM\...\RunOnce: [Mededofafame] => C:\Windows\system32\wscript.exe /E:vbscript /B "C:\Users\fff\AppData\Roaming\Locilomaged"
HKU\S-1-5-21-1992992304-2174605327-656110796-1000\...\Run: [Chromium] => c:\users\fff\appdata\local\chromium\application\chrome.exe [1068544 2016-03-18] (The Chromium Authors)
HKU\S-1-5-21-1992992304-2174605327-656110796-1000\...\Run: [GoogleChromeAutoLaunch_6A87FA6847E526EC1FB30C134F4AA50C] => C:\Users\fff\AppData\Local\chromium\Application\chrome.exe [1068544 2016-03-18] (The Chromium Authors)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-12-06] (AVAST Software)
GroupPolicy: Restrição ? <======= ATENÇÃO
CHR HKLM\SOFTWARE\Policies\Google: Restrição <======= ATENÇÃO

==================== Internet (Whitelisted) ====================

(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)

Hosts: Há mais de uma entrada no Hosts. Veja a seção Hosts do Addition.txt
Tcpip\Parameters: [DhcpNameServer] 167.250.136.1 167.250.136.38 8.8.8.8
Tcpip\..\Interfaces\{CDFAFF61-FBA4-4156-87BE-F977FDECB9CD}: [DhcpNameServer] 167.250.136.1 167.250.136.38 8.8.8.8

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://br.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_bxinw_16_49¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dbr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0BzzzyyByD0A0BtAtA0CtD0AyCzz0AzytN0D0Tzu0StCzztDtBtN1L2XzutAtFtByDtFtCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StC0EyC0D0A0Fzz0AtGyBtDyD0BtGyD0EyEtCtGtDyCzytBtGtAzz0A0CtB0FyBzztD0DyD0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtC0A0DyE0DyB0CtGtD0C0CtAtGyEyByD0FtG0ByCyEyBtGzz0AyEtCtC0B0CyCtA0EyEzy2QtN0A0LzuyE%26cr%3D245767769%26a%3Dwbf_bxinw_16_49%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional
HKU\S-1-5-21-1992992304-2174605327-656110796-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://br.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_bxinw_16_49¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dbr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0BzzzyyByD0A0BtAtA0CtD0AyCzz0AzytN0D0Tzu0StCzztDtBtN1L2XzutAtFtByDtFtCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StC0EyC0D0A0Fzz0AtGyBtDyD0BtGyD0EyEtCtGtDyCzytBtGtAzz0A0CtB0FyBzztD0DyD0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtC0A0DyE0DyB0CtGtD0C0CtAtGyEyByD0FtG0ByCyEyBtGzz0AyEtCtC0B0CyCtA0EyEzy2QtN0A0LzuyE%26cr%3D245767769%26a%3Dwbf_bxinw_16_49%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_bxinw_16_49¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0BzzzyyByD0A0BtAtA0CtD0AyCzz0AzytN0D0Tzu0StCzztDtBtN1L2XzutAtFtByDtFtCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StC0EyC0D0A0Fzz0AtGyBtDyD0BtGyD0EyEtCtGtDyCzytBtGtAzz0A0CtB0FyBzztD0DyD0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtC0A0DyE0DyB0CtGtD0C0CtAtGyEyByD0FtG0ByCyEyBtGzz0AyEtCtC0B0CyCtA0EyEzy2QtN0A0LzuyE%26cr%3D245767769%26a%3Dwbf_bxinw_16_49%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_bxinw_16_49¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0BzzzyyByD0A0BtAtA0CtD0AyCzz0AzytN0D0Tzu0StCzztDtBtN1L2XzutAtFtByDtFtCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StC0EyC0D0A0Fzz0AtGyBtDyD0BtGyD0EyEtCtGtDyCzytBtGtAzz0A0CtB0FyBzztD0DyD0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtC0A0DyE0DyB0CtGtD0C0CtAtGyEyByD0FtG0ByCyEyBtGzz0AyEtCtC0B0CyCtA0EyEzy2QtN0A0LzuyE%26cr%3D245767769%26a%3Dwbf_bxinw_16_49%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1992992304-2174605327-656110796-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_bxinw_16_49¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0BzzzyyByD0A0BtAtA0CtD0AyCzz0AzytN0D0Tzu0StCzztDtBtN1L2XzutAtFtByDtFtCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StC0EyC0D0A0Fzz0AtGyBtDyD0BtGyD0EyEtCtGtDyCzytBtGtAzz0A0CtB0FyBzztD0DyD0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtC0A0DyE0DyB0CtGtD0C0CtAtGyEyByD0FtG0ByCyEyBtGzz0AyEtCtC0B0CyCtA0EyEzy2QtN0A0LzuyE%26cr%3D245767769%26a%3Dwbf_bxinw_16_49%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1992992304-2174605327-656110796-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://br.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_bxinw_16_49¶m1=1¶m2=f%3D4%26b%3DIE%26cc%3Dbr%26pa%3Dwincy%26cd%3D2XzuyEtN2Y1L1Qzu0BzzzyyByD0A0BtAtA0CtD0AyCzz0AzytN0D0Tzu0StCzztDtBtN1L2XzutAtFtByDtFtCtFyDtBtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2StC0EyC0D0A0Fzz0AtGyBtDyD0BtGyD0EyEtCtGtDyCzytBtGtAzz0A0CtB0FyBzztD0DyD0E2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0CtC0A0DyE0DyB0CtGtD0C0CtAtGyEyByD0FtG0ByCyEyBtGzz0AyEtCtC0B0CyCtA0EyEzy2QtN0A0LzuyE%26cr%3D245767769%26a%3Dwbf_bxinw_16_49%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional&p={searchTerms}
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-12-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-12-06] (Google Inc.)

Chrome:
=======
CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
CHR Profile: C:\Users\fff\AppData\Local\Google\Chrome\User Data\Default [2016-12-09]
CHR Extension: (Google Docs) - C:\Users\fff\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-06]
CHR Extension: (Google Drive) - C:\Users\fff\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-06]
CHR Extension: (YouTube) - C:\Users\fff\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-06]
CHR Extension: (Documentos Google off-line) - C:\Users\fff\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-06]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\fff\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-06]
CHR Extension: (Search Manager) - C:\Users\fff\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej [2016-12-06]
CHR Extension: (Gmail) - C:\Users\fff\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-06]
CHR Extension: (Chrome Media Router) - C:\Users\fff\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-06]
CHR HKLM\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1992992304-2174605327-656110796-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pilplloabdedfmialnfchjomjmpjcoej] - hxxps://clients2.google.com/service/update2/crx

==================== Serviços (Whitelisted) ====================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-12-06] (AVAST Software)
R2 ByteFenceService; C:\Program Files\ByteFence\ByteFenceService.exe [146912 2016-11-01] (Byte Technologies LLC)
R2 rtop; C:\Program Files\ByteFence\rtop\bin\rtop_svc.exe [254280 2016-12-07] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-13] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)

S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [34008 2016-12-06] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [92256 2016-12-06] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [91232 2016-12-06] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [60424 2016-12-06] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [735488 2016-12-06] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [433768 2016-12-06] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [118664 2016-12-06] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [224752 2016-12-06] (AVAST Software)
S3 gdrv; C:\Windows\gdrv.sys [17488 2016-12-06] (Windows (R) 2000 DDK provider)

==================== NetSvcs (Whitelisted) ===================

(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)


==================== Três Meses Criados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-12-09 11:24 - 2016-12-09 11:25 - 00011595 _____ C:\Users\fff\Desktop\FRST.txt
2016-12-09 11:22 - 2016-12-09 11:24 - 00000000 ____D C:\FRST
2016-12-09 11:21 - 2016-12-09 11:21 - 01761792 _____ (Farbar) C:\Users\fff\Downloads\FRST (1).exe
2016-12-09 11:21 - 2016-12-09 11:21 - 01761792 _____ (Farbar) C:\Users\fff\Desktop\FRST.exe
2016-12-09 11:21 - 2016-12-09 11:21 - 01761792 _____ (Farbar) C:\Users\fff\Desktop\FRST (1).exe
2016-12-09 10:58 - 2016-12-09 10:59 - 00016224 _____ (Microsoft Corporation) C:\Users\fff\Downloads\api-ms-win-crt-runtime-l1-1-0.dll
2016-12-09 10:52 - 2016-10-12 10:09 - 00001983 _____ C:\Users\fff\Downloads\README.txt
2016-12-09 10:38 - 2016-12-09 10:42 - 00000000 ____D C:\Windows\system32\MRT
2016-12-09 10:37 - 2016-12-09 10:37 - 138444440 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-12-09 10:36 - 2011-04-09 04:13 - 03957632 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2016-12-09 10:36 - 2011-04-09 04:13 - 03901824 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-12-09 10:36 - 2011-04-09 03:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2016-12-09 10:35 - 2016-06-25 13:43 - 00301056 _____ (Microsoft Corporation) C:\Windows\system32\EOSNotify.exe
2016-12-09 10:35 - 2010-12-18 03:29 - 00541184 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-12-09 10:32 - 2012-06-02 20:19 - 01933848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-12-09 10:32 - 2012-06-02 20:19 - 00577048 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2016-12-09 10:32 - 2012-06-02 20:19 - 00053784 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2016-12-09 10:32 - 2012-06-02 20:19 - 00045080 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2016-12-09 10:32 - 2012-06-02 20:19 - 00035864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2016-12-09 10:32 - 2012-06-02 20:12 - 02422272 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2016-12-09 10:32 - 2012-06-02 20:12 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2016-12-09 10:32 - 2012-06-02 15:19 - 00171904 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2016-12-09 10:32 - 2012-06-02 15:12 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2016-12-09 10:26 - 2016-12-09 10:28 - 00000000 ____D C:\Program Files\PCSX2 1.4.0
2016-12-09 10:26 - 2016-12-09 10:26 - 00001885 _____ C:\Users\Public\Desktop\PCSX2 1.4.0.lnk
2016-12-09 10:26 - 2016-12-09 10:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2
2016-12-09 00:17 - 2016-12-09 00:17 - 14230000 _____ (Microsoft Corporation) C:\Users\fff\Downloads\vc_redist.x86 (1).exe
2016-12-08 21:46 - 2016-12-08 21:46 - 13969576 _____ (Microsoft Corporation) C:\Users\fff\Downloads\vc_redist.x86.exe
2016-12-08 21:38 - 2016-12-09 11:00 - 00000000 ____D C:\Users\Todos os Usuários\Package Cache
2016-12-08 21:38 - 2016-12-09 11:00 - 00000000 ____D C:\ProgramData\Package Cache
2016-12-08 21:33 - 2016-12-08 21:35 - 17837152 _____ C:\Users\fff\Downloads\pcsx2-1.4.0-setup.exe
2016-12-07 11:50 - 2016-12-07 11:51 - 24410691 _____ C:\Users\fff\Downloads\WinXP32.zip
2016-12-07 11:45 - 2016-12-07 11:45 - 00000000 ____D C:\Users\fff\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence
2016-12-07 11:08 - 2016-12-07 11:08 - 00002201 _____ C:\Users\fff\Desktop\Chromium.lnk
2016-12-07 11:08 - 2016-12-07 11:08 - 00000000 ____D C:\Users\fff\AppData\Roaming\PlutoTV
2016-12-07 11:06 - 2016-12-07 11:07 - 00000000 ____D C:\Users\fff\AppData\Roaming\3B816DA3-DE56-6895-3DA8-76A330788BF4
2016-12-07 11:06 - 2016-12-07 11:06 - 00020277 _____ C:\Users\fff\AppData\Roaming\Locilomaged
2016-12-07 10:48 - 2016-12-07 10:48 - 00000000 ____D C:\Users\Todos os Usuários\ByteFence
2016-12-07 10:48 - 2016-12-07 10:48 - 00000000 ____D C:\ProgramData\ByteFence
2016-12-07 10:45 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2016-12-07 10:45 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2016-12-07 10:45 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2016-12-07 10:45 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2016-12-07 10:45 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2016-12-07 10:45 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2016-12-07 10:45 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2016-12-07 10:45 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2016-12-07 10:45 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2016-12-07 10:45 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2016-12-07 10:45 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2016-12-07 10:45 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2016-12-07 10:45 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2016-12-07 10:45 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2016-12-07 10:45 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2016-12-07 10:45 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2016-12-07 10:45 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2016-12-07 10:45 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2016-12-07 10:45 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2016-12-07 10:45 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2016-12-07 10:45 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2016-12-07 10:45 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2016-12-07 10:45 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2016-12-07 10:45 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2016-12-07 10:45 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2016-12-07 10:45 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2016-12-07 10:45 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2016-12-07 10:45 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2016-12-07 10:45 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2016-12-07 10:45 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2016-12-07 10:45 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2016-12-07 10:45 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2016-12-07 10:45 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2016-12-07 10:45 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2016-12-07 10:45 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2016-12-07 10:45 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2016-12-07 10:45 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2016-12-07 10:45 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2016-12-07 10:45 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2016-12-07 10:45 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2016-12-07 10:45 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2016-12-07 10:45 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2016-12-07 10:45 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2016-12-07 10:45 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2016-12-07 10:45 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2016-12-07 10:45 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2016-12-07 10:45 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2016-12-07 10:45 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2016-12-07 10:45 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2016-12-07 10:45 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2016-12-07 10:45 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2016-12-07 10:45 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2016-12-07 10:45 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2016-12-07 10:45 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2016-12-07 10:45 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2016-12-07 10:45 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2016-12-07 10:45 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2016-12-07 10:45 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2016-12-07 10:45 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2016-12-07 10:45 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2016-12-07 10:45 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2016-12-07 10:45 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2016-12-07 10:45 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2016-12-07 10:45 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2016-12-07 10:45 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2016-12-07 10:45 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2016-12-07 10:45 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2016-12-07 10:45 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2016-12-07 10:45 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2016-12-07 10:45 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2016-12-07 10:45 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2016-12-07 10:45 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2016-12-07 10:45 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2016-12-07 10:45 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2016-12-07 10:45 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2016-12-07 10:45 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2016-12-07 10:45 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2016-12-07 10:45 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2016-12-07 10:45 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2016-12-07 10:45 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2016-12-07 10:45 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2016-12-07 10:45 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2016-12-07 10:45 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2016-12-07 10:45 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2016-12-07 10:45 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2016-12-07 10:45 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2016-12-07 10:45 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2016-12-07 10:45 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2016-12-07 10:45 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2016-12-07 10:45 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2016-12-07 10:45 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2016-12-07 10:44 - 2016-12-07 11:08 - 00002209 _____ C:\Users\fff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromium.lnk
2016-12-07 10:43 - 2016-12-07 16:48 - 00000000 ____D C:\Users\fff\AppData\Local\chromium
2016-12-07 10:41 - 2016-12-09 10:52 - 00000000 ____D C:\Program Files\ByteFence
2016-12-07 10:41 - 2016-12-09 10:28 - 00000000 ____D C:\Windows\system32\directx
2016-12-07 10:41 - 2016-12-07 10:47 - 00000000 ____D C:\Users\fff\AppData\Local\{3603005F-12AB-6CE7-7F33-490F5B5BB597}
2016-12-06 23:58 - 2016-12-06 23:58 - 00002020 _____ C:\Users\Public\Desktop\Conquest Online.lnk
2016-12-06 23:58 - 2016-12-06 23:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetDragon
2016-12-06 22:36 - 2016-12-06 23:38 - 902233424 _____ (TQ Digital Entertainment Inc. ) C:\Users\fff\Downloads\Conquest_v6351.exe
2016-12-06 21:06 - 2016-12-06 21:06 - 00000000 ___SD C:\Users\fff\AppData\LocalLow\Temp
2016-12-06 20:16 - 2016-12-06 20:16 - 00000000 ____D C:\Users\fff\AppData\Local\CEF
2016-12-06 20:06 - 2016-12-06 20:06 - 00002075 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-12-06 20:06 - 2016-12-06 20:06 - 00000000 ____D C:\Users\fff\AppData\Roaming\AVAST Software
2016-12-06 20:06 - 2016-12-06 20:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-12-06 20:05 - 2016-12-06 20:06 - 00224752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-12-06 20:05 - 2016-12-06 20:05 - 00735488 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2016-12-06 20:05 - 2016-12-06 20:05 - 00433768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2016-12-06 20:05 - 2016-12-06 20:05 - 00000000 ____D C:\Program Files\Common Files\AV
2016-12-06 20:05 - 2016-12-06 20:04 - 00118664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-12-06 20:05 - 2016-12-06 20:04 - 00092256 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-12-06 20:05 - 2016-12-06 20:04 - 00091232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-12-06 20:05 - 2016-12-06 20:04 - 00060424 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-12-06 20:05 - 2016-12-06 20:04 - 00034008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-12-06 20:04 - 2016-12-06 20:04 - 00921280 _____ (Microsoft Corporation) C:\Windows\ucrtbase.dll
2016-12-06 20:04 - 2016-12-06 20:04 - 00319760 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-12-06 20:04 - 2016-12-06 20:04 - 00053208 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-12-06 20:04 - 2016-12-06 20:04 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2016-12-06 20:04 - 2016-12-06 20:04 - 00000000 ____D C:\Users\fff\AppData\Roaming\WinRAR
2016-12-06 20:04 - 2016-12-06 20:04 - 00000000 ____D C:\Program Files\Realtek
2016-12-06 20:04 - 2016-09-20 02:44 - 00775688 _____ (Realtek ) C:\Windows\system32\Drivers\Rt86win7.sys
2016-12-06 20:04 - 2016-09-20 02:44 - 00109648 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst32.dll
2016-12-06 20:04 - 2016-09-20 02:44 - 00085616 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp32.dll
2016-12-06 20:03 - 2016-12-06 20:03 - 00000000 ____D C:\Users\fff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-12-06 20:03 - 2016-12-06 20:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-12-06 20:03 - 2016-12-06 20:03 - 00000000 ____D C:\Program Files\WinRAR
2016-12-06 20:02 - 2016-12-06 21:02 - 00000000 ____D C:\Program Files\Common Files\33379CF4-7958-0B43-0432-2B306E72B8FA
2016-12-06 20:02 - 2016-12-06 20:02 - 00057560 _____ C:\Users\fff\AppData\Local\GDIPFONTCACHEV1.DAT
2016-12-06 20:02 - 2016-12-06 20:02 - 00018656 _____ C:\Users\fff\AppData\Roaming\Nofilo
2016-12-06 20:02 - 2016-12-06 20:02 - 00000000 ____D C:\Users\Todos os Usuários\AVAST Software
2016-12-06 20:02 - 2016-12-06 20:02 - 00000000 ____D C:\ProgramData\AVAST Software
2016-12-06 20:02 - 2016-12-06 20:02 - 00000000 ____D C:\Program Files\AVAST Software
2016-12-06 20:01 - 2016-12-09 00:07 - 00000000 ____D C:\Users\Todos os Usuários\{5F419A22-D503-10E4-53C5-8EA6C9870568}
2016-12-06 20:01 - 2016-12-09 00:07 - 00000000 ____D C:\ProgramData\{5F419A22-D503-10E4-53C5-8EA6C9870568}
2016-12-06 20:01 - 2016-12-07 11:05 - 00000372 __RSH C:\Users\Todos os Usuários\ntuser.pol
2016-12-06 20:01 - 2016-12-07 11:05 - 00000372 __RSH C:\ProgramData\ntuser.pol
2016-12-06 20:01 - 2016-12-07 10:41 - 00001436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk
2016-12-06 20:01 - 2016-12-06 20:01 - 00000000 ____D C:\Users\fff\AppData\Local\Setup7432480
2016-12-06 20:00 - 2016-12-06 22:28 - 00000964 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-12-06 20:00 - 2016-12-06 20:00 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-12-06 20:00 - 2016-12-06 20:00 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-12-06 19:59 - 2016-12-06 19:59 - 00000000 ____D C:\Users\fff\AppData\Local\Adobe
2016-12-06 19:39 - 2016-12-06 20:00 - 00000000 ____D C:\Windows\system32\Macromed
2016-12-06 19:39 - 2007-07-11 17:15 - 00917504 _____ (Macromedia, Inc.) C:\Windows\system32\Flash.ocx
2016-12-06 19:30 - 2016-12-06 23:42 - 00000000 ____D C:\Program Files\NetDragon
2016-12-06 19:29 - 2016-12-06 19:29 - 00002211 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-12-06 19:29 - 2016-12-06 19:29 - 00002199 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-12-06 19:28 - 2016-12-09 10:45 - 00001054 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-12-06 19:28 - 2016-12-09 10:40 - 00001058 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-12-06 19:28 - 2016-12-06 19:29 - 00000000 ____D C:\Program Files\Google
2016-12-06 19:27 - 2016-12-06 19:51 - 00000000 ____D C:\Users\fff\AppData\Local\Google
2016-12-06 18:48 - 2016-12-06 18:48 - 00000000 ____D C:\Users\fff\AppData\Roaming\DRPSu
2016-12-06 18:44 - 2016-12-06 18:45 - 00017488 _____ (Windows (R) 2000 DDK provider) C:\Windows\gdrv.sys
2016-12-06 18:44 - 2016-12-06 18:45 - 00000010 _____ C:\Windows\GSetup.ini
2016-12-06 18:31 - 2016-12-06 18:19 - 00000000 ____D C:\Windows\Panther
2016-12-06 18:24 - 2016-12-09 10:50 - 01491932 _____ C:\Windows\system32\PerfStringBackup.INI
2016-12-06 18:21 - 2016-12-06 18:21 - 00000000 ____D C:\Windows.old
2016-12-06 18:20 - 2016-12-06 18:20 - 00001389 _____ C:\Users\fff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-12-06 18:20 - 2016-12-06 18:20 - 00000020 ___SH C:\Users\fff\ntuser.ini
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\Modelos
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\Meus documentos
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\Menu Iniciar
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\Documents\Minhas músicas
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\Documents\Minhas imagens
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\Documents\Meus vídeos
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\Dados de aplicativos
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\Configurações locais
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\AppData\Local\Histórico
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\AppData\Local\Dados de aplicativos
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\Ambiente de rede
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 _SHDL C:\Users\fff\Ambiente de impressão
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 ____D C:\Users\fff\AppData\Local\VirtualStore
2016-12-06 18:20 - 2016-12-06 18:20 - 00000000 ____D C:\Users\fff
2016-12-06 18:20 - 2009-07-14 06:53 - 00000000 ____D C:\Users\fff\AppData\Roaming\Media Center Programs
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas músicas
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas imagens
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Meus vídeos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Histórico
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Dados de aplicativos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Usuário Padrão
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Todos os Usuários\Modelos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Todos os Usuários\Menu Iniciar
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Todos os Usuários\Favoritos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Todos os Usuários\Documentos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Todos os Usuários\Dados de aplicativos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Todos os Usuários
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Public\Documents\Minhas músicas
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Public\Documents\Minhas imagens
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Public\Documents\Meus vídeos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\Modelos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\Meus documentos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\Menu Iniciar
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\Documents\Minhas músicas
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\Documents\Minhas imagens
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\Documents\Meus vídeos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\Dados de aplicativos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\Configurações locais
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Histórico
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dados de aplicativos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\Ambiente de rede
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default\Ambiente de impressão
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default User\Documents\Minhas músicas
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default User\Documents\Minhas imagens
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default User\Documents\Meus vídeos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Histórico
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Dados de aplicativos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\ProgramData\Modelos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programas
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\ProgramData\Menu Iniciar
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\ProgramData\Favoritos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\ProgramData\Documentos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\ProgramData\Dados de aplicativos
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Program Files\Common Files\Sistema
2016-12-06 18:19 - 2016-12-06 18:19 - 00000000 _SHDL C:\Program Files\Arquivos Comuns
2016-12-06 17:37 - 2016-12-06 17:37 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-12-06 17:37 - 2016-12-06 17:37 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-11-22 01:56 - 2016-11-24 12:28 - 00000002 _____ C:\END

==================== Três Meses Modificados arquivos e pastas ========

(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)

2016-12-09 10:50 - 2009-07-14 06:31 - 00654272 _____ C:\Windows\system32\prfh0416.dat
2016-12-09 10:50 - 2009-07-14 06:31 - 00124724 _____ C:\Windows\system32\prfc0416.dat
2016-12-09 10:50 - 2009-07-14 00:37 - 00000000 ____D C:\Windows\inf
2016-12-09 10:46 - 2009-07-14 02:34 - 00009600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-12-09 10:46 - 2009-07-14 02:34 - 00009600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-12-09 10:44 - 2009-07-14 02:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-12-06 20:01 - 2009-07-14 00:37 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2016-12-06 19:16 - 2009-07-14 00:37 - 00000000 ____D C:\Windows\system32\NDF
2016-12-06 18:31 - 2009-07-14 02:52 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2016-12-06 18:21 - 2009-07-14 00:37 - 00000000 ____D C:\Windows\rescache
2016-12-06 18:19 - 2009-07-14 00:37 - 00000000 ____D C:\Program Files\Windows NT
2016-12-06 17:48 - 2009-07-14 02:33 - 00265944 _____ C:\Windows\system32\FNTCACHE.DAT
2016-12-06 17:37 - 2009-07-14 00:37 - 00000000 ____D C:\Windows\system32\sysprep
2016-12-06 17:33 - 2009-07-14 06:53 - 00000000 ____D C:\Windows\CSC

==================== Arquivos na raiz de alguns diretórios =======

2016-12-07 11:06 - 2016-12-07 11:06 - 0020277 _____ () C:\Users\fff\AppData\Roaming\Locilomaged
2016-12-06 20:02 - 2016-12-06 20:02 - 0018656 _____ () C:\Users\fff\AppData\Roaming\Nofilo

Alguns arquivos em TEMP:
====================
C:\Users\fff\AppData\Local\Temp\ICReinstall_Baixaki_nvidia-cuda-driver.exe
C:\Users\fff\AppData\Local\Temp\vcredist_2015_Update_1_x86.exe


==================== Bamital & volsnap ======================

(Não há correção automática para arquivos que não passaram na verificação.)

C:\Windows\explorer.exe => O arquivo é assinado digitalmente
C:\Windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\Windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\Windows\system32\services.exe => O arquivo é assinado digitalmente
C:\Windows\system32\User32.dll => O arquivo é assinado digitalmente
C:\Windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\Windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\Windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\Windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente

Publicité


Signaler le contenu de ce document

Publicité