Resultado do exame da Farbar Recovery Scan Tool (FRST) (x64) Versão: 15-01-2017
Executado por Glauber (administrador) em WIN8 (16-01-2017 10:53:40)
Executando a partir de C:\Users\Glauber Segalla\Desktop
Perfis Carregados: Glauber (Perfis Disponíveis: Glauber)
Platform: Windows 8.1 Single Language (Update) (X64) Idioma: Português (Brasil)
Internet Explorer Versão 11 (Navegador padrão: FF)
Modo da Inicialização: Normal
Tutorial da Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processos (Whitelisted) =================
(Se uma entrada for incluída na fixlist, o processo será fechado. O arquivo não será movido.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\tbaseprovisioning.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Microsoft Corporation) C:\Windows\System32\Locator.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Panda Security, S.L.) C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Microsoft Corporation) C:\Windows\System32\SppExtComObj.Exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIC.exe
==================== Registro (Whitelisted) ====================
(Se uma entrada for incluída na fixlist, o ítem no Registro será restaurado para o padrão ou removido. O arquivo não será movido.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7634288 2014-06-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1386712 2014-06-12] (Realtek Semiconductor)
HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-06-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [PSUAMain] => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe [109824 2016-08-05] (Panda Security, S.L.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKU\S-1-5-21-1751273365-4100181127-1669670999-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4015216 2016-12-15] (Tonec Inc.)
HKU\S-1-5-21-1751273365-4100181127-1669670999-1001\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-1751273365-4100181127-1669670999-1001\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-1751273365-4100181127-1669670999-1001\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-1751273365-4100181127-1669670999-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-1751273365-4100181127-1669670999-1001\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-1751273365-4100181127-1669670999-1001\...\Policies\Explorer: [NoResolveSearch] 1
HKU\S-1-5-21-1751273365-4100181127-1669670999-1001\...\Policies\Explorer: [NoInternetOpenWith] 1
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
Startup: C:\Users\Glauber Segalla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2016-04-08]
ShortcutTarget: MEGAsync.lnk -> C:\ProgramData\MEGAsync\MEGAsync.exe (Mega Limited)
BootExecute: autocheck autochk *
==================== Internet (Whitelisted) ====================
(Se um ítem for incluído na fixlist, sendo um ítem do Registro, será removido ou restaurado para o padrão.)
AutoConfigURL: [S-1-5-21-1751273365-4100181127-1669670999-1001] => hxxp://noblockweb.net/wpad.dat?75bf99f57d20c269bed3260f4914685723699845
Tcpip\Parameters: [DhcpNameServer] 200.189.80.122 200.189.80.108
Tcpip\..\Interfaces\{886A4B6C-67C0-46E8-8CA2-7C512AAD8465}: [DhcpNameServer] 200.189.80.122 200.189.80.108
ManualProxies: 0hxxp://noblockweb.net/wpad.dat?75bf99f57d20c269bed3260f4914685723699845
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCON14/17
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCON14/17
HKU\S-1-5-21-1751273365-4100181127-1669670999-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCON14/17
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1751273365-4100181127-1669670999-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://
www.google.com/search?q={searchTerms}
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2016-12-10] (Internet Download Manager, Tonec Inc.)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-02-01] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-02-01] (Microsoft Corporation)
BHO: Sem Nome -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> Nenhum Arquivo
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2016-12-10] (Internet Download Manager, Tonec Inc.)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-02-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-12-06] (Oracle Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-02-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-12-06] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
DPF: HKLM-x32 {55A2C0CD-3DE8-4264-9637-A0B40B05714E} hxxps://col430-sec.mail.live.com/mail/MailMigrationCabFileHolder.aspx?n=453342177
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-02-01] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-02-01] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-02-01] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-02-01] (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - Nenhum Arquivo
FireFox:
========
FF DefaultProfile: flk299ku.perfil
FF ProfilePath: C:\Users\Glauber Segalla\AppData\Roaming\Mozilla\Firefox\Profiles\flk299ku.perfil [2017-01-16]
FF Homepage: Mozilla\Firefox\Profiles\flk299ku.perfil -> hxxp://favoritosglauber.blogspot.com.br/
FF Extension: (QuickFox Notes) - C:\Users\Glauber Segalla\AppData\Roaming\Mozilla\Firefox\Profiles\flk299ku.perfil\Extensions\[email]amin.eft_bmnotes@gmail.com[/email] [2017-01-12]
FF Extension: (Classic Theme Restorer) - C:\Users\Glauber Segalla\AppData\Roaming\Mozilla\Firefox\Profiles\flk299ku.perfil\Extensions\[email]ClassicThemeRestorer@ArisT2Noia4dev.xpi[/email] [2017-01-12]
FF Extension: (YouTube mp3) - C:\Users\Glauber Segalla\AppData\Roaming\Mozilla\Firefox\Profiles\flk299ku.perfil\Extensions\[email]info@youtube-mp3.org.xpi[/email] [2017-01-13]
FF Extension: (Português (pt-BR) Language Pack) - C:\Users\Glauber Segalla\AppData\Roaming\Mozilla\Firefox\Profiles\flk299ku.perfil\Extensions\[email]langpack-pt-BR@firefox.mozilla.org.xpi[/email] [2017-01-12]
FF Extension: (Português Brasileiro (Nova Ortografia)) - C:\Users\Glauber Segalla\AppData\Roaming\Mozilla\Firefox\Profiles\flk299ku.perfil\Extensions\[email]pt-BR@dictionaries.addons.mozilla.org[/email] [2017-01-12]
FF Extension: (Google Translator for Firefox) - C:\Users\Glauber Segalla\AppData\Roaming\Mozilla\Firefox\Profiles\flk299ku.perfil\Extensions\[email]translator@zoli.bod.xpi[/email] [2017-01-12]
FF Extension: (Flagfox) - C:\Users\Glauber Segalla\AppData\Roaming\Mozilla\Firefox\Profiles\flk299ku.perfil\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2017-01-12]
FF Extension: (Speed Dial) - C:\Users\Glauber Segalla\AppData\Roaming\Mozilla\Firefox\Profiles\flk299ku.perfil\Extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi [2017-01-12]
FF Extension: (Open Profile Folder) - C:\Users\Glauber Segalla\AppData\Roaming\Mozilla\Firefox\Profiles\flk299ku.perfil\Extensions\{a756d17a-5a4c-4417-813c-c8cd0151e486}.xpi [2017-01-12]
FF Extension: (Tab Mix Plus) - C:\Users\Glauber Segalla\AppData\Roaming\Mozilla\Firefox\Profiles\flk299ku.perfil\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2017-01-12]
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2016-11-16]
FF ProfilePath: C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\6d5utyea.default [2017-01-16]
FF Homepage: Moonchild Productions\Pale Moon\Profiles\6d5utyea.default -> hxxp://favoritosglauber.blogspot.com.br/
FF Extension: (QuickFox Notes) - C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\6d5utyea.default\Extensions\[email]amin.eft_bmnotes@gmail.com[/email] [2017-01-08]
FF Extension: (YouTube mp3) - C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\6d5utyea.default\Extensions\[email]info@youtube-mp3.org.xpi[/email] [2017-01-08]
FF Extension: (Português Brasileiro Language Pack) - C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\6d5utyea.default\Extensions\[email]langpack-pt-BR@firefox.mozilla.org.xpi[/email] [2015-05-25] [não assinado]
FF Extension: (IDM CC) - C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\6d5utyea.default\Extensions\[email]mozilla_cc@internetdownloadmanager.com[/email] [2017-01-08] [não assinado]
FF Extension: (Português Brasileiro (Nova Ortografia)) - C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\6d5utyea.default\Extensions\[email]pt-BR@dictionaries.addons.mozilla.org[/email] [2017-01-08]
FF Extension: (Google Translator for Firefox) - C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\6d5utyea.default\Extensions\[email]translator@zoli.bod.xpi[/email] [2017-01-08]
FF Extension: (Flagfox) - C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\6d5utyea.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2017-01-08]
FF Extension: (Speed Dial) - C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\6d5utyea.default\Extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi [2015-09-13]
FF Extension: (Open Profile Folder) - C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\6d5utyea.default\Extensions\{a756d17a-5a4c-4417-813c-c8cd0151e486}.xpi [2017-01-08]
FF Extension: (Tab Mix Plus) - C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\6d5utyea.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2015-06-16]
FF SearchPlugin: C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions\Pale Moon\Profiles\6d5utyea.default\searchplugins\youtube.xml [2014-08-11]
FF HKU\S-1-5-21-1751273365-4100181127-1669670999-1001\...\Firefox\Extensions: [[email]mozilla_cc2@internetdownloadmanager.com[/email]] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF HKU\S-1-5-21-1751273365-4100181127-1669670999-1001\...\SeaMonkey\Extensions: [[email]mozilla_cc@internetdownloadmanager.com[/email]] - C:\Users\Glauber Segalla\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Glauber Segalla\AppData\Roaming\IDM\idmmzcc5 [2017-01-16] [não assinado]
FF HKU\S-1-5-21-1751273365-4100181127-1669670999-1001\...\SeaMonkey\Extensions: [[email]mozilla_cc2@internetdownloadmanager.com[/email]] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-11] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-11] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1225195.dll [2016-09-20] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-12-06] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-12-06] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-02-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-02-01] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxps://drive.google.com/drive/folders/0By4JBoB0i7ViRHVGb1lsRVROUWM
CHR StartupUrls: Default -> "hxxps://
www.facebook.com/","hxxps://app.hotmart.com/"
CHR Profile: C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default [2017-01-16]
CHR Extension: (Google Apresentações) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-01-03]
CHR Extension: (Sniply: Drive Conversion Through Content) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\aepeihpnlhiiipbchlidcipfpiaecpkd [2017-01-03]
CHR Extension: (Sudoku) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\agdhembpgcpfegeigidembjopfhghnpj [2017-01-03]
CHR Extension: (SEOquake) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\akdgnmcogleenhbclghghlkkdndkjdjc [2017-01-13]
CHR Extension: (Google Docs) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-01-03]
CHR Extension: (Google Drive) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-01-03]
CHR Extension: (Keeper Web App) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnglfciifmgnafcgkkngkeopldlialb [2017-01-03]
CHR Extension: (YouTube) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-01-03]
CHR Extension: (Paciência Online) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\cahbledjpnekmjeglfnelmnjfnmmemob [2017-01-03]
CHR Extension: (Dólar Hoje) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\eemaaomlfllldamnpoajaedaemnblgal [2017-01-03]
CHR Extension: (Planilhas do Google) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-01-03]
CHR Extension: (Documentos Google off-line) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-03]
CHR Extension: (HP Smart Print) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmpaiomihcebnclahoknbodeiaiohcdi [2017-01-03]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2017-01-12]
CHR Extension: (HP Network Check Launcher) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2017-01-03]
CHR Extension: (Paciência de Freecell) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnjgfflolfogjcejlkmkphkcohnmjdfd [2017-01-03]
CHR Extension: (Hootsuite) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\kneloppijbcidgidihgdjnooihjcdbij [2017-01-03]
CHR Extension: (TubeBuddy for YouTube) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhkhmbddkmdggbhaaaodilponhnccicb [2017-01-15]
CHR Extension: (IDM Integration Module) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2017-01-03]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-03]
CHR Extension: (Pingler) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\odgiehjnopebofbjkgdjenflakfaahnm [2017-01-03]
CHR Extension: (Gmail) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-01-03]
CHR Extension: (Chrome Media Router) - C:\Users\Glauber Segalla\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-01-03]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-12-15]
CHR HKLM-x32\...\Chrome\Extension: [jkfpchpiljkaemlpmpebnglgkomamfeo] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-12-15]
==================== Serviços (Whitelisted) ====================
(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2762936 2016-01-07] (Microsoft Corporation)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe [153096 2016-08-04] (Panda Security, S.L.)
R2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe [48584 2016-08-05] (Panda Security, S.L.)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] ()
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-08] (Realtek Semiconductor)
R2 tbaseprovisioning; C:\windows\SysWOW64\tbaseprovisioning.exe [51216 2016-07-08] (Advanced Micro Devices, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
S2 LiveUpdateSvc; não ImagePath
===================== Drivers (Whitelisted) ======================
(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)
S3 amdkmcsp; C:\windows\System32\drivers\amdkmcsp.sys [109488 2016-07-08] (Advanced Micro Devices, Inc. )
R0 amdkmpfd; C:\windows\System32\drivers\amdkmpfd.sys [36608 2013-12-14] (Advanced Micro Devices, Inc.)
R0 amdpsp; C:\windows\System32\drivers\amdpsp.sys [260528 2016-07-08] (Advanced Micro Devices, Inc. )
R3 athr; C:\windows\system32\DRIVERS\athwbx.sys [4316456 2016-05-03] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\windows\system32\drivers\AtihdWB6.sys [222720 2014-03-12] (Advanced Micro Devices)
R1 CLVirtualDrive; C:\windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
R1 HWiNFO32; C:\windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2016-01-23] (REALiX(tm))
R2 inpoutx64; C:\windows\System32\Drivers\inpoutx64.sys [15008 2016-11-10] (Highresolution Enterprises [
"]www.highrez.co.uk])
S4 IObitUnlocker; C:\Program Files (x86)\Outlook Express\IO\IObitUnlocker.sys [36568 2013-09-30] (IObit)
S3 ksapi64; C:\windows\system32\drivers\ksapi64.sys [56680 2016-02-10] (Kingsoft Corporation)
R1 NNSALPC; C:\windows\System32\DRIVERS\NNSAlpc.sys [94456 2015-12-04] (Panda Security, S.L.)
R1 NNSHTTP; C:\windows\System32\DRIVERS\NNSHttp.sys [201464 2015-12-04] (Panda Security, S.L.)
R1 NNSHTTPS; C:\windows\System32\DRIVERS\NNSHttps.sys [110840 2015-12-04] (Panda Security, S.L.)
R1 NNSIDS; C:\windows\System32\DRIVERS\NNSIds.sys [110840 2015-12-04] (Panda Security, S.L.)
R1 NNSNAHSL; C:\windows\system32\DRIVERS\NNSNAHSL.sys [58616 2015-06-19] (Panda Security, S.L.)
R1 NNSPICC; C:\windows\System32\DRIVERS\NNSPicc.sys [103160 2015-12-04] (Panda Security, S.L.)
R1 NNSPIHSW; C:\windows\System32\DRIVERS\NNSPihsw.sys [85712 2016-03-14] (Panda Security, S.L.)
R1 NNSPOP3; C:\windows\System32\DRIVERS\NNSPop3.sys [124152 2015-12-04] (Panda Security, S.L.)
R1 NNSPROT; C:\windows\System32\DRIVERS\NNSProt.sys [300280 2015-12-04] (Panda Security, S.L.)
R1 NNSPRV; C:\windows\System32\DRIVERS\NNSPrv.sys [177424 2016-02-17] (Panda Security, S.L.)
R1 NNSSMTP; C:\windows\System32\DRIVERS\NNSSmtp.sys [113400 2015-12-04] (Panda Security, S.L.)
R1 NNSSTRM; C:\windows\System32\DRIVERS\NNSStrm.sys [264976 2016-02-17] (Panda Security, S.L.)
R1 NNSTLSC; C:\windows\System32\DRIVERS\NNSTlsc.sys [106232 2015-12-04] (Panda Security, S.L.)
R2 PSINAflt; C:\windows\System32\DRIVERS\PSINAflt.sys [171792 2016-08-05] (Panda Security, S.L.)
R2 PSINFile; C:\windows\System32\DRIVERS\PSINFile.sys [127248 2016-08-05] (Panda Security, S.L.)
R1 PSINKNC; C:\windows\System32\DRIVERS\psinknc.sys [205072 2016-08-05] (Panda Security, S.L.)
R2 PSINProc; C:\windows\System32\DRIVERS\PSINProc.sys [131344 2016-08-05] (Panda Security, S.L.)
R2 PSINProt; C:\windows\System32\DRIVERS\PSINProt.sys [144656 2016-08-05] (Panda Security, S.L.)
R2 PSINReg; C:\windows\System32\DRIVERS\PSINReg.sys [114960 2016-08-05] (Panda Security, S.L.)
U3 PSKMAD; C:\windows\System32\DRIVERS\PSKMAD.sys [70360 2016-08-08] (Panda Security, S.L.)
R3 RSP2STOR; C:\windows\system32\DRIVERS\RtsP2Stor.sys [294104 2016-08-27] (Realtek Semiconductor Corp.)
R1 VBoxNetAdp; C:\windows\system32\DRIVERS\VBoxNetAdp6.sys [131096 2016-11-23] (Oracle Corporation)
R1 VBoxNetLwf; C:\windows\system32\DRIVERS\VBoxNetLwf.sys [203856 2016-11-23] (Oracle Corporation)
S3 VBoxUSB; C:\windows\System32\Drivers\VBoxUSB.sys [138896 2016-11-23] (Oracle Corporation)
S3 WdBoot; C:\windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\windows\System32\drivers\WirelessKeyboardFilter.sys [49896 2016-07-22] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(Se uma entrada for incluída na fixlist, será removida do Registro. O arquivo não será movido, a menos que seja colocado separadamente.)
==================== Três Meses Criados arquivos e pastas ========
(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)
2017-01-16 10:53 - 2017-01-16 10:55 - 00027524 _____ C:\Users\Glauber Segalla\Desktop\FRST.txt
2017-01-16 10:52 - 2017-01-16 10:53 - 00000000 ____D C:\FRST
2017-01-16 10:51 - 2017-01-16 10:51 - 02419200 _____ (Farbar) C:\Users\Glauber Segalla\Desktop\FRST64.exe
2017-01-16 02:47 - 2017-01-16 02:47 - 01861392 _____ (Installer ) C:\Users\Glauber Segalla\Desktop\Baixaki_classic-shell-for-windows-10.exe
2017-01-16 01:39 - 2017-01-16 01:40 - 10860931 _____ C:\Users\Glauber Segalla\Desktop\Como Colocar Menu Iniciar no Windows 8 (Sem Usar Programas).mp4
2017-01-15 20:47 - 2016-08-08 07:00 - 00070360 _____ (Panda Security, S.L.) C:\windows\system32\Drivers\PSKMAD.sys
2017-01-15 20:39 - 2017-01-15 20:39 - 00001316 _____ C:\Users\Glauber Segalla\Desktop\JRT.txt
2017-01-15 20:28 - 2017-01-15 20:28 - 01663040 _____ (Malwarebytes) C:\Users\Glauber Segalla\Desktop\JRT.exe
2017-01-15 17:49 - 2017-01-15 17:49 - 00001057 _____ C:\ProgramData\Microsoft\Windows\Start Menu\WinRAR.lnk
2017-01-15 16:28 - 2017-01-15 20:19 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Local\ESET
2017-01-15 16:21 - 2017-01-15 16:21 - 00030114 _____ C:\Users\Glauber Segalla\Desktop\relatório mbam arquivos enviados para quarentena 15-01-17.txt
2017-01-15 16:10 - 2017-01-15 16:10 - 00033326 _____ C:\Users\Glauber Segalla\Desktop\relatório mbam 15-01-17.txt
2017-01-15 02:56 - 2017-01-15 02:56 - 16769244 _____ C:\Users\Glauber Segalla\Desktop\How to remove browser redirects (browser hijackers)-.mp4
2017-01-15 00:56 - 2017-01-15 20:46 - 00000000 ____D C:\AdwCleaner
2017-01-13 01:13 - 2017-01-13 01:13 - 14691766 _____ C:\Users\Glauber Segalla\Desktop\Aula 2 - Analisando o Anúncio Nicho Emagrecimento.mp4
2017-01-11 17:03 - 2017-01-15 20:20 - 00000350 _____ C:\windows\Tasks\HPCeeScheduleForGlauber.job
2017-01-11 17:03 - 2017-01-15 17:08 - 00003168 _____ C:\windows\System32\Tasks\HPCeeScheduleForGlauber
2017-01-10 03:05 - 2017-01-10 03:05 - 00126976 _____ (Microsoft Corporation) C:\windows\system32\psbase.DLL
2017-01-10 03:05 - 2017-01-10 03:05 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\psbase.DLL
2017-01-10 03:05 - 2017-01-10 03:05 - 00049152 _____ (Microsoft Corporation) C:\windows\system32\pstorec.DLL
2017-01-10 03:05 - 2017-01-10 03:05 - 00045056 _____ (Microsoft Corporation) C:\windows\SysWOW64\pstorec.DLL
2017-01-10 03:05 - 2017-01-10 03:05 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\pstorsvc.DLL
2017-01-10 03:05 - 2017-01-10 03:05 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\pstorsvc.DLL
2017-01-10 03:05 - 2017-01-10 03:05 - 00000000 ____D C:\Users\Todos os Usuários\IObit
2017-01-10 03:05 - 2017-01-10 03:05 - 00000000 ____D C:\ProgramData\IObit
2017-01-10 03:04 - 2017-01-10 03:06 - 00000000 ____D C:\Program Files (x86)\Outlook Express
2017-01-10 03:04 - 2017-01-10 03:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook Express
2017-01-10 00:43 - 2017-01-10 00:44 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Local\CutePDF Writer
2017-01-08 01:39 - 2017-01-08 01:39 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Local\Moonchild Productions
2017-01-08 01:36 - 2017-01-08 01:36 - 00001108 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pale Moon.lnk
2017-01-08 01:36 - 2017-01-08 01:36 - 00000000 ____D C:\Program Files (x86)\Pale Moon
2017-01-05 19:51 - 2017-01-05 19:51 - 00000963 _____ C:\Users\Glauber Segalla\Desktop\Imagens - Atalho.lnk
2017-01-05 19:51 - 2017-01-05 19:51 - 00000953 _____ C:\Users\Glauber Segalla\Desktop\Vídeos - Atalho.lnk
2017-01-05 19:46 - 2017-01-05 19:46 - 00001006 _____ C:\Users\Glauber Segalla\Desktop\TABELAS DE CAMPEONATOS - Atalho.lnk
2017-01-05 19:44 - 2017-01-05 19:44 - 00000881 _____ C:\Users\Glauber Segalla\Desktop\SCANNER - Atalho.lnk
2017-01-05 18:17 - 2017-01-05 18:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CutePDF
2017-01-05 18:17 - 2016-01-22 17:57 - 00089008 _____ C:\windows\system32\cpwmon64.dll
2017-01-05 18:07 - 2017-01-05 18:07 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Local\Apps\2.0
2017-01-05 18:03 - 2017-01-05 18:03 - 00001917 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SumatraPDF.lnk
2017-01-05 18:03 - 2017-01-05 18:03 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Roaming\SumatraPDF
2017-01-05 18:03 - 2017-01-05 18:03 - 00000000 ____D C:\Program Files (x86)\SumatraPDF
2017-01-04 17:08 - 2017-01-15 17:08 - 00000382 _____ C:\windows\Tasks\HPCeeScheduleForGlauber Segalla.job
2017-01-04 17:08 - 2017-01-04 17:08 - 00003216 _____ C:\windows\System32\Tasks\HPCeeScheduleForGlauber Segalla
2017-01-02 02:10 - 2017-01-02 02:11 - 00007680 _____ C:\Users\Glauber Segalla\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-12-28 18:51 - 2017-01-05 18:17 - 00000000 ____D C:\Program Files (x86)\GPLGS
2016-12-27 19:52 - 2016-12-28 13:06 - 00000088 _____ C:\Users\Public\Nova mensagem.txt
2016-12-27 11:56 - 2016-12-28 19:25 - 00003598 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1751273365-4100181127-1669670999-1004
2016-12-26 20:05 - 2016-12-26 20:05 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Local\CEF
2016-12-26 20:02 - 2016-12-26 20:06 - 00000000 ____D C:\Users\Todos os Usuários\Adobe
2016-12-26 20:02 - 2016-12-26 20:06 - 00000000 ____D C:\ProgramData\Adobe
2016-12-26 01:06 - 2016-12-26 01:06 - 00001058 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2016-12-22 20:01 - 2017-01-01 01:33 - 00000000 ____D C:\Users\Glauber Segalla\Desktop\GUIA EXPRESS FACEADS
2016-12-22 00:16 - 2016-12-28 01:55 - 00000000 ____D C:\Users\Glauber Segalla\Desktop\Afiliado Macgyver
2016-12-19 18:20 - 2016-12-20 02:15 - 00080896 _____ C:\Users\Glauber Segalla\Desktop\Relação de Contadores do Guia Perito.doc
2016-12-17 12:08 - 2016-12-17 12:08 - 00001136 _____ C:\Users\Glauber Segalla\Desktop\TREINAMENTO GRATUITO MARCELO CALIXTO - Atalho.lnk
2016-12-16 19:34 - 2016-12-16 19:34 - 00003500 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-12-16 19:34 - 2016-12-16 19:34 - 00003372 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-12-16 11:25 - 2016-12-16 11:25 - 07619943 _____ C:\Users\Glauber Segalla\Desktop\Como criar mais um canal no Youtube com o mesmo e-mail - MiTutoriais.mp4
2016-12-15 09:51 - 2016-10-17 13:35 - 00223464 _____ (Tonec Inc.) C:\windows\system32\Drivers\idmwfp.sys
2016-12-06 20:39 - 2016-12-06 20:40 - 00004132 _____ C:\windows\System32\Tasks\eM Client Database Backup
2016-12-06 03:03 - 2016-12-06 03:03 - 00001102 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
2016-12-06 03:03 - 2016-12-06 03:03 - 00000000 ____D C:\windows\LastGood.Tmp
2016-12-06 03:03 - 2016-12-06 03:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2016-12-06 03:03 - 2016-11-23 14:57 - 00928416 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxDrv.sys
2016-12-06 03:03 - 2016-11-23 14:57 - 00149768 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxUSBMon.sys
2016-12-06 02:55 - 2016-12-06 02:55 - 00097856 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2016-12-06 02:55 - 2016-12-06 02:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-12-06 02:54 - 2016-12-06 02:54 - 00000000 ____D C:\Program Files (x86)\Java
2016-12-05 20:37 - 2016-12-14 10:59 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-12-05 20:37 - 2016-12-05 20:37 - 00001149 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-12-05 20:36 - 2017-01-15 16:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-12-05 13:37 - 2016-12-05 13:39 - 00524288 ___SH C:\windows\system32\config\drivers{52815b99-bb00-11e6-8661-9cb654a6fa79}.TMContainer00000000000000000002.regtrans-ms
2016-12-05 13:37 - 2016-12-05 13:39 - 00524288 ___SH C:\windows\system32\config\drivers{52815b99-bb00-11e6-8661-9cb654a6fa79}.TMContainer00000000000000000001.regtrans-ms
2016-12-05 13:37 - 2016-12-05 13:39 - 00065536 ___SH C:\windows\system32\config\drivers{52815b99-bb00-11e6-8661-9cb654a6fa79}.TM.blf
2016-12-05 13:35 - 2016-12-05 13:49 - 00524288 ___SH C:\Users\Glauber Segalla\ntuser.dat{6bf936b0-bafe-11e6-8648-9cb654a6fa79}.TMContainer00000000000000000002.regtrans-ms
2016-12-05 13:35 - 2016-12-05 13:49 - 00524288 ___SH C:\Users\Glauber Segalla\ntuser.dat{6bf936b0-bafe-11e6-8648-9cb654a6fa79}.TMContainer00000000000000000001.regtrans-ms
2016-12-05 13:35 - 2016-12-05 13:49 - 00065536 ___SH C:\Users\Glauber Segalla\ntuser.dat{6bf936b0-bafe-11e6-8648-9cb654a6fa79}.TM.blf
2016-12-05 13:02 - 2016-12-05 13:02 - 00524288 ___SH C:\windows\system32\config\drivers{86686238-bafb-11e6-8647-9cb654a6fa79}.TMContainer00000000000000000002.regtrans-ms
2016-12-05 13:02 - 2016-12-05 13:02 - 00524288 ___SH C:\windows\system32\config\drivers{86686238-bafb-11e6-8647-9cb654a6fa79}.TMContainer00000000000000000001.regtrans-ms
2016-12-05 13:02 - 2016-12-05 13:02 - 00065536 ___SH C:\windows\system32\config\drivers{86686238-bafb-11e6-8647-9cb654a6fa79}.TM.blf
2016-12-05 13:00 - 2016-12-05 13:02 - 00524288 ___SH C:\Users\Glauber Segalla\ntuser.dat{1072a140-baf7-11e6-8661-9cb654a6fa79}.TMContainer00000000000000000002.regtrans-ms
2016-12-05 13:00 - 2016-12-05 13:02 - 00524288 ___SH C:\Users\Glauber Segalla\ntuser.dat{1072a140-baf7-11e6-8661-9cb654a6fa79}.TMContainer00000000000000000001.regtrans-ms
2016-12-05 13:00 - 2016-12-05 13:02 - 00065536 ___SH C:\Users\Glauber Segalla\ntuser.dat{1072a140-baf7-11e6-8661-9cb654a6fa79}.TM.blf
2016-12-05 12:30 - 2016-12-05 12:33 - 00524288 ___SH C:\windows\system32\config\drivers{10729ff3-baf7-11e6-8661-9cb654a6fa79}.TMContainer00000000000000000002.regtrans-ms
2016-12-05 12:30 - 2016-12-05 12:33 - 00524288 ___SH C:\windows\system32\config\drivers{10729ff3-baf7-11e6-8661-9cb654a6fa79}.TMContainer00000000000000000001.regtrans-ms
2016-12-05 12:30 - 2016-12-05 12:33 - 00065536 ___SH C:\windows\system32\config\drivers{10729ff3-baf7-11e6-8661-9cb654a6fa79}.TM.blf
2016-12-05 12:28 - 2016-12-05 12:49 - 00524288 ___SH C:\Users\Glauber Segalla\ntuser.dat{0e5638a0-baea-11e6-8660-9cb654a6fa79}.TMContainer00000000000000000002.regtrans-ms
2016-12-05 12:28 - 2016-12-05 12:49 - 00524288 ___SH C:\Users\Glauber Segalla\ntuser.dat{0e5638a0-baea-11e6-8660-9cb654a6fa79}.TMContainer00000000000000000001.regtrans-ms
2016-12-05 12:28 - 2016-12-05 12:49 - 00065536 ___SH C:\Users\Glauber Segalla\ntuser.dat{0e5638a0-baea-11e6-8660-9cb654a6fa79}.TM.blf
2016-11-30 17:49 - 2017-01-11 17:02 - 00000052 _____ C:\windows\SysWOW64\DOErrors.log
2016-11-27 02:16 - 2017-01-08 01:39 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Roaming\Moonchild Productions
2016-11-25 11:44 - 2017-01-04 20:01 - 00000000 ____D C:\Users\Glauber Segalla\Desktop\CURSO GRATUITO DE BING ADS
2016-11-24 11:37 - 2016-11-24 11:37 - 00546912 _____ C:\windows\system32\FNTCACHE.DAT
2016-11-23 14:57 - 2016-11-23 14:57 - 00203856 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxNetLwf.sys
2016-11-23 14:57 - 2016-11-23 14:57 - 00138896 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxUSB.sys
2016-11-23 14:57 - 2016-11-23 14:57 - 00131096 _____ (Oracle Corporation) C:\windows\system32\Drivers\VBoxNetAdp6.sys
2016-11-22 02:10 - 2016-11-22 02:10 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Roaming\Geek Uninstaller
2016-11-21 00:51 - 2016-11-21 00:51 - 00000000 ____D C:\windows\System32\Tasks\R@1n-KMS
2016-11-21 00:51 - 2016-11-21 00:51 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Local\mpress
2016-11-21 00:46 - 2016-11-21 00:46 - 00000000 ____D C:\windows\LOG
2016-11-20 14:29 - 2017-01-16 10:53 - 00000000 ____D C:\Users\Glauber Segalla\AppData\LocalLow\Mozilla
2016-11-19 11:12 - 2016-09-29 11:13 - 00875712 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcr120_clr0400.dll
2016-11-19 11:12 - 2016-09-29 11:13 - 00869568 _____ (Microsoft Corporation) C:\windows\system32\msvcr120_clr0400.dll
2016-11-19 11:12 - 2016-09-29 11:13 - 00678600 _____ (Microsoft Corporation) C:\windows\system32\msvcp120_clr0400.dll
2016-11-19 11:12 - 2016-09-29 11:13 - 00536768 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvcp120_clr0400.dll
2016-11-19 11:10 - 2016-10-08 19:10 - 03547648 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2016-11-19 11:09 - 2016-11-05 18:46 - 00422744 ____C (Microsoft Corporation) C:\windows\system32\Drivers\spaceport.sys
2016-11-19 11:09 - 2016-10-12 19:49 - 00379224 _____ (Microsoft Corporation) C:\windows\system32\Drivers\storport.sys
2016-11-19 11:09 - 2016-10-12 19:11 - 00922968 _____ (Microsoft Corporation) C:\windows\system32\Drivers\refs.sys
2016-11-19 11:09 - 2016-10-11 14:45 - 00175104 _____ (Microsoft Corporation) C:\windows\system32\TpmTasks.dll
2016-11-19 11:09 - 2016-10-10 21:31 - 00990040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\http.sys
2016-11-19 11:09 - 2016-10-10 16:18 - 00069976 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2016-11-19 11:09 - 2016-10-10 16:18 - 00022360 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cmimcext.sys
2016-11-19 11:09 - 2016-10-09 12:17 - 00229888 _____ (Microsoft Corporation) C:\windows\system32\ActionQueue.dll
2016-11-19 11:09 - 2016-10-09 12:08 - 00116224 _____ (Microsoft Corporation) C:\windows\system32\shsetup.dll
2016-11-19 11:09 - 2016-10-09 12:08 - 00095232 _____ (Microsoft Corporation) C:\windows\SysWOW64\shsetup.dll
2016-11-19 11:09 - 2016-10-08 20:24 - 00658432 _____ (Microsoft Corporation) C:\windows\system32\dnsapi.dll
2016-11-19 11:09 - 2016-10-08 19:31 - 00498688 _____ (Microsoft Corporation) C:\windows\SysWOW64\dnsapi.dll
2016-11-19 11:09 - 2016-10-05 12:01 - 01200128 _____ (Microsoft Corporation) C:\windows\system32\Windows.Globalization.dll
2016-11-19 11:09 - 2016-10-05 12:00 - 00868864 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Globalization.dll
2016-11-19 11:09 - 2016-10-05 12:00 - 00323072 _____ (Microsoft Corporation) C:\windows\system32\GlobCollationHost.dll
2016-11-19 11:09 - 2016-10-05 11:52 - 00513456 _____ C:\windows\SysWOW64\locale.nls
2016-11-19 11:09 - 2016-10-05 11:52 - 00513456 _____ C:\windows\system32\locale.nls
2016-11-19 11:09 - 2016-10-05 02:15 - 01969944 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2016-11-19 11:09 - 2016-10-05 02:15 - 01613528 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
2016-11-19 11:09 - 2016-10-05 02:15 - 00324896 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
2016-11-19 11:09 - 2016-10-05 02:15 - 00245320 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
2016-11-19 11:09 - 2016-09-27 18:16 - 00445873 _____ C:\windows\system32\ApnDatabase.xml
2016-11-19 11:09 - 2016-09-20 20:30 - 02462040 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2016-11-14 13:33 - 2016-10-28 19:04 - 00828408 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-11-14 13:33 - 2016-10-28 19:04 - 00176632 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-11-14 13:01 - 2016-11-02 18:48 - 00372568 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2016-11-14 13:01 - 2016-11-02 18:48 - 00315224 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2016-11-14 13:01 - 2016-10-27 16:53 - 00576000 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2016-11-14 13:01 - 2016-10-27 16:51 - 02896384 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-11-14 13:01 - 2016-10-27 16:37 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2016-11-14 13:01 - 2016-10-27 16:28 - 25763328 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-11-14 13:01 - 2016-10-27 16:19 - 06047744 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-11-14 13:01 - 2016-10-27 16:08 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2016-11-14 13:01 - 2016-10-27 16:07 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2016-11-14 13:01 - 2016-10-27 16:05 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2016-11-14 13:01 - 2016-10-27 15:57 - 01033216 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2016-11-14 13:01 - 2016-10-27 15:49 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2016-11-14 13:01 - 2016-10-27 15:47 - 00378880 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2016-11-14 13:01 - 2016-10-27 15:46 - 00806912 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2016-11-14 13:01 - 2016-10-27 15:46 - 00725504 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2016-11-14 13:01 - 2016-10-27 15:44 - 02131456 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2016-11-14 13:01 - 2016-10-27 15:17 - 15257088 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-11-14 13:01 - 2016-10-27 15:16 - 02920448 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-11-14 13:01 - 2016-10-27 15:03 - 01543680 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-11-14 13:01 - 2016-10-27 13:05 - 20304896 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-11-14 13:01 - 2016-10-25 12:11 - 04169216 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2016-11-14 13:01 - 2016-10-22 15:34 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2016-11-14 13:01 - 2016-10-22 15:27 - 02287616 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-11-14 13:01 - 2016-10-22 15:21 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2016-11-14 13:01 - 2016-10-22 14:58 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2016-11-14 13:01 - 2016-10-22 14:57 - 00128000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2016-11-14 13:01 - 2016-10-22 14:56 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2016-11-14 13:01 - 2016-10-22 14:51 - 00880640 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2016-11-14 13:01 - 2016-10-22 14:46 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2016-11-14 13:01 - 2016-10-22 14:45 - 00693248 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2016-11-14 13:01 - 2016-10-22 14:45 - 00330752 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2016-11-14 13:01 - 2016-10-22 14:44 - 04608000 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-11-14 13:01 - 2016-10-22 14:43 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2016-11-14 13:01 - 2016-10-22 14:30 - 13654016 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-11-14 13:01 - 2016-10-22 14:12 - 02444800 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-11-14 13:01 - 2016-10-22 14:09 - 01312256 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-11-14 13:01 - 2016-10-13 17:06 - 01385280 _____ (Microsoft Corporation) C:\windows\system32\msctf.dll
2016-11-14 13:01 - 2016-10-13 17:06 - 01124376 _____ (Microsoft Corporation) C:\windows\SysWOW64\msctf.dll
2016-11-14 13:01 - 2016-10-12 06:01 - 00377176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\clfs.sys
2016-11-14 13:01 - 2016-10-11 18:21 - 00497448 _____ (Microsoft Corporation) C:\windows\system32\mfsvr.dll
2016-11-14 13:01 - 2016-10-11 18:21 - 00399776 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsvr.dll
2016-11-14 13:01 - 2016-10-11 16:34 - 00247296 _____ (Microsoft Corporation) C:\windows\system32\microsoft-windows-system-events.dll
2016-11-14 13:01 - 2016-10-11 15:47 - 00263680 _____ (Microsoft Corporation) C:\windows\system32\input.dll
2016-11-14 13:01 - 2016-10-11 14:55 - 00226816 _____ (Microsoft Corporation) C:\windows\SysWOW64\input.dll
2016-11-14 13:01 - 2016-10-10 19:17 - 00444248 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2016-11-14 13:01 - 2016-10-10 19:17 - 00333656 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2016-11-14 13:01 - 2016-10-09 20:59 - 00551256 ____C (Microsoft Corporation) C:\windows\system32\Drivers\vhdmp.sys
2016-11-14 13:01 - 2016-10-08 21:12 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2016-11-14 13:01 - 2016-10-08 20:53 - 03754496 _____ (Microsoft Corporation) C:\windows\system32\MSVidCtl.dll
2016-11-14 13:01 - 2016-10-08 20:21 - 01445376 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2016-11-14 13:01 - 2016-10-08 20:18 - 00840704 _____ (Microsoft Corporation) C:\windows\system32\netlogon.dll
2016-11-14 13:01 - 2016-10-08 20:07 - 00332288 _____ (Microsoft Corporation) C:\windows\system32\UIAnimation.dll
2016-11-14 13:01 - 2016-10-08 20:02 - 00324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2016-11-14 13:01 - 2016-10-08 19:49 - 02410496 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSVidCtl.dll
2016-11-14 13:01 - 2016-10-08 19:21 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\UIAnimation.dll
2016-11-14 13:01 - 2016-10-07 23:34 - 01660040 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2016-11-14 13:01 - 2016-10-07 23:34 - 01212248 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2016-11-14 13:01 - 2016-10-04 18:39 - 00101376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bowser.sys
2016-11-14 13:01 - 2016-10-04 18:23 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
2016-11-14 13:01 - 2016-10-04 18:08 - 00086016 _____ (Microsoft Corporation) C:\windows\SysWOW64\olepro32.dll
2016-11-14 13:01 - 2016-10-04 18:08 - 00077824 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
2016-11-14 13:00 - 2016-11-02 12:03 - 00044032 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2016-11-14 13:00 - 2016-11-02 12:00 - 00035840 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2016-11-14 13:00 - 2016-10-27 14:54 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2016-11-14 13:00 - 2016-10-22 15:35 - 00498688 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2016-11-14 13:00 - 2016-10-22 14:09 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2016-11-12 17:55 - 2016-11-19 11:29 - 00524288 ___SH C:\windows\system32\config\drivers{a38e0400-a911-11e6-860e-9cb654a6fa79}.TMContainer00000000000000000001.regtrans-ms
2016-11-12 17:55 - 2016-11-19 11:29 - 00065536 ___SH C:\windows\system32\config\drivers{a38e0400-a911-11e6-860e-9cb654a6fa79}.TM.blf
2016-11-12 17:55 - 2016-11-12 17:58 - 00524288 ___SH C:\windows\system32\config\drivers{a38e0400-a911-11e6-860e-9cb654a6fa79}.TMContainer00000000000000000002.regtrans-ms
2016-11-12 17:53 - 2016-11-12 18:00 - 00524288 ___SH C:\Users\Glauber Segalla\ntuser.dat{8fe0ae9e-a90d-11e6-8606-9cb654a6fa79}.TMContainer00000000000000000002.regtrans-ms
2016-11-12 17:53 - 2016-11-12 18:00 - 00524288 ___SH C:\Users\Glauber Segalla\ntuser.dat{8fe0ae9e-a90d-11e6-8606-9cb654a6fa79}.TMContainer00000000000000000001.regtrans-ms
2016-11-12 17:53 - 2016-11-12 18:00 - 00065536 ___SH C:\Users\Glauber Segalla\ntuser.dat{8fe0ae9e-a90d-11e6-8606-9cb654a6fa79}.TM.blf
2016-11-12 16:30 - 2016-11-12 16:32 - 00524288 ___SH C:\windows\system32\config\drivers{a090a661-a905-11e6-8605-9cb654a6fa79}.TMContainer00000000000000000002.regtrans-ms
2016-11-12 16:30 - 2016-11-12 16:32 - 00524288 ___SH C:\windows\system32\config\drivers{a090a661-a905-11e6-8605-9cb654a6fa79}.TMContainer00000000000000000001.regtrans-ms
2016-11-12 16:30 - 2016-11-12 16:32 - 00065536 ___SH C:\windows\system32\config\drivers{a090a661-a905-11e6-8605-9cb654a6fa79}.TM.blf
2016-11-12 16:28 - 2016-11-12 16:37 - 00524288 ___SH C:\Users\Glauber Segalla\ntuser.dat{4175fed8-a8fa-11e6-860d-9cb654a6fa79}.TMContainer00000000000000000002.regtrans-ms
2016-11-12 16:28 - 2016-11-12 16:37 - 00524288 ___SH C:\Users\Glauber Segalla\ntuser.dat{4175fed8-a8fa-11e6-860d-9cb654a6fa79}.TMContainer00000000000000000001.regtrans-ms
2016-11-12 16:28 - 2016-11-12 16:37 - 00065536 ___SH C:\Users\Glauber Segalla\ntuser.dat{4175fed8-a8fa-11e6-860d-9cb654a6fa79}.TM.blf
2016-11-10 12:22 - 2016-11-10 12:22 - 00015008 _____ (Highresolution Enterprises [
"]www.highrez.co.uk]) C:\windows\system32\Drivers\inpoutx64.sys
2016-11-10 12:22 - 2016-08-09 09:35 - 00059880 _____ (Kerish Products) C:\windows\system32\GPUTemp.dll
2016-11-10 12:22 - 2011-01-20 01:07 - 00098304 _____ (Highresolution Enterprises) C:\windows\SysWOW64\inpout32.dll
2016-11-09 12:51 - 2016-11-12 17:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Free Antivirus
2016-11-09 12:51 - 2016-11-09 12:52 - 00002180 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Free Antivirus.lnk
2016-11-09 11:37 - 2016-11-09 11:37 - 00000000 _____ C:\Autoexec.bat
2016-11-07 12:28 - 2016-11-12 17:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Player - Codec Pack
2016-11-07 12:27 - 2016-11-07 12:31 - 00000000 ____D C:\windows\SysWOW64\Codecs
2016-11-05 11:59 - 2016-11-05 12:57 - 00000000 ____D C:\Users\Glauber Segalla\Desktop\VENDEDOR OCULTO
2016-11-03 17:08 - 2017-01-15 20:21 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Local\CrashDumps
2016-11-03 17:06 - 2016-11-03 17:06 - 00000000 ___RD C:\Users\Glauber Segalla\Contacts
2016-11-02 18:39 - 2016-11-02 18:39 - 00001176 _____ C:\Users\Glauber Segalla\Desktop\Trabalhar pela Internet Agora 2.0 - Atalho.lnk
2016-11-02 18:11 - 2016-11-02 18:11 - 00001318 _____ C:\Users\Glauber Segalla\Desktop\Crie, Desenvolva e Venda Aplicativos em 5 MINUTOS - Atalho.lnk
2016-10-23 03:20 - 2016-12-12 18:32 - 00038912 _____ C:\Users\Glauber Segalla\Desktop\CARTOLA.xls
2016-10-22 19:57 - 2016-09-09 20:14 - 00275800 ____C (Microsoft Corporation) C:\windows\system32\Drivers\msiscsi.sys
2016-10-22 19:57 - 2016-09-09 12:15 - 00269824 _____ (Microsoft Corporation) C:\windows\system32\DafPrintProvider.dll
2016-10-22 19:57 - 2016-09-09 12:09 - 00203776 _____ (Microsoft Corporation) C:\windows\SysWOW64\DafPrintProvider.dll
2016-10-22 19:57 - 2016-09-09 12:04 - 00864256 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2016-10-22 19:57 - 2016-09-09 12:03 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\iscsiwmi.dll
2016-10-22 19:57 - 2016-09-09 12:02 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\iscsiwmi.dll
2016-10-22 19:57 - 2016-09-03 16:20 - 00075264 _____ (Microsoft Corporation) C:\windows\system32\iscsidsc.dll
2016-10-22 19:57 - 2016-09-03 16:06 - 00151040 _____ (Microsoft Corporation) C:\windows\system32\iscsiexe.dll
2016-10-22 19:57 - 2016-09-03 15:21 - 00055296 _____ (Microsoft Corporation) C:\windows\SysWOW64\iscsidsc.dll
2016-10-22 19:57 - 2016-09-03 14:12 - 00512512 _____ (Microsoft Corporation) C:\windows\system32\winspool.drv
2016-10-22 19:57 - 2016-09-03 14:05 - 01094656 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2016-10-22 19:57 - 2016-09-03 13:58 - 00397824 _____ (Microsoft Corporation) C:\windows\SysWOW64\winspool.drv
2016-10-22 19:57 - 2016-09-02 12:05 - 00306176 _____ (Microsoft Corporation) C:\windows\system32\pdh.dll
2016-10-22 19:57 - 2016-09-02 12:05 - 00262144 _____ (Microsoft Corporation) C:\windows\SysWOW64\pdh.dll
2016-10-22 19:57 - 2016-09-01 12:33 - 00377856 _____ (Microsoft Corporation) C:\windows\system32\vmrdvcore.dll
2016-10-22 19:57 - 2016-09-01 12:33 - 00342528 _____ (Microsoft Corporation) C:\windows\system32\SessEnv.dll
2016-10-22 19:57 - 2016-09-01 12:31 - 00296960 _____ (Microsoft Corporation) C:\windows\SysWOW64\SessEnv.dll
2016-10-22 19:57 - 2016-08-30 12:11 - 00092672 _____ (Microsoft Corporation) C:\windows\system32\dab.dll
2016-10-22 19:57 - 2016-08-30 00:45 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\xolehlp.dll
2016-10-22 19:57 - 2016-08-30 00:18 - 00871936 _____ (Microsoft Corporation) C:\windows\system32\msdtcprx.dll
2016-10-22 19:57 - 2016-08-30 00:18 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\xolehlp.dll
2016-10-22 19:57 - 2016-08-30 00:03 - 00721920 _____ (Microsoft Corporation) C:\windows\SysWOW64\msdtcprx.dll
2016-10-22 19:57 - 2016-08-22 11:34 - 01628672 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2016-10-22 12:54 - 2017-01-16 03:16 - 00142051 ____H C:\Users\Glauber Segalla\AppData\Local\IconCache.db
2016-10-22 01:36 - 2016-10-22 01:36 - 00000000 ____D C:\Users\Todos os Usuários\ATI
2016-10-22 01:36 - 2016-10-22 01:36 - 00000000 ____D C:\ProgramData\ATI
2016-10-22 01:35 - 2016-10-22 20:00 - 00524288 ___SH C:\windows\system32\config\drivers{52a5e0fb-9808-11e6-85bd-9cb654a6fa79}.TMContainer00000000000000000001.regtrans-ms
2016-10-22 01:35 - 2016-10-22 20:00 - 00065536 ___SH C:\windows\system32\config\drivers{52a5e0fb-9808-11e6-85bd-9cb654a6fa79}.TM.blf
2016-10-22 01:35 - 2016-10-22 01:38 - 00524288 ___SH C:\windows\system32\config\drivers{52a5e0fb-9808-11e6-85bd-9cb654a6fa79}.TMContainer00000000000000000002.regtrans-ms
2016-10-22 01:34 - 2016-10-22 03:07 - 00524288 ___SH C:\Users\Glauber Segalla\ntuser.dat{5fbcb0f2-97fc-11e6-85c3-9cb654a6fa79}.TMContainer00000000000000000002.regtrans-ms
2016-10-22 01:34 - 2016-10-22 03:07 - 00524288 ___SH C:\Users\Glauber Segalla\ntuser.dat{5fbcb0f2-97fc-11e6-85c3-9cb654a6fa79}.TMContainer00000000000000000001.regtrans-ms
2016-10-22 01:34 - 2016-10-22 03:07 - 00065536 ___SH C:\Users\Glauber Segalla\ntuser.dat{5fbcb0f2-97fc-11e6-85c3-9cb654a6fa79}.TM.blf
2016-10-22 00:35 - 2012-03-08 12:47 - 00108640 _____ (Andrea Electronics Corporation) C:\windows\system32\AERTAR64.dll
2016-10-22 00:23 - 2016-10-22 00:24 - 00000000 ____D C:\Program Files (x86)\WinRAR
2016-10-21 20:21 - 2016-10-22 00:46 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Local\AMD
2016-10-21 20:16 - 2016-10-21 20:16 - 00000000 ____D C:\Program Files (x86)\AMD
2016-10-21 20:13 - 2016-10-21 20:13 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-10-21 20:06 - 2016-10-22 01:20 - 00000000 ____D C:\AMD
2016-10-18 17:51 - 2016-12-15 01:07 - 00000842 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-10-18 17:51 - 2016-11-12 17:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-10-18 17:51 - 2016-10-18 17:51 - 00002802 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2016-10-18 17:51 - 2016-10-18 17:51 - 00000000 ____D C:\Program Files\CCleaner
2016-10-18 02:06 - 2016-10-18 02:06 - 00002489 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2016-10-18 02:06 - 2016-10-18 02:06 - 00002447 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
2016-10-18 02:06 - 2016-10-18 02:06 - 00002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2016-10-18 02:06 - 2016-10-18 02:06 - 00002401 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2016-10-18 02:06 - 2016-10-18 02:06 - 00002385 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2016-10-18 02:06 - 2016-10-18 02:06 - 00002382 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2016-10-18 02:06 - 2016-10-18 02:06 - 00002372 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2016-10-18 02:06 - 2016-10-18 02:06 - 00002368 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2016-10-18 02:06 - 2016-10-18 02:06 - 00002352 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2016-10-18 00:47 - 2016-10-18 00:47 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Local\Little_Apps
==================== Três Meses Modificados arquivos e pastas ========
(Se uma entrada for incluída na fixlist, o arquivo/pasta será movido.)
2017-01-16 10:55 - 2016-04-22 03:12 - 00000902 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2017-01-16 10:50 - 2016-09-16 03:27 - 00003598 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1751273365-4100181127-1669670999-1001
2017-01-16 03:16 - 2016-01-14 20:16 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Roaming\DMCache
2017-01-16 02:18 - 2016-08-04 12:25 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Roaming\eM Client
2017-01-16 00:13 - 2015-04-22 17:06 - 00785298 _____ C:\windows\system32\prfh0416.dat
2017-01-16 00:13 - 2015-04-22 17:06 - 00181786 _____ C:\windows\system32\prfc0416.dat
2017-01-16 00:13 - 2014-03-18 07:53 - 01860808 _____ C:\windows\system32\PerfStringBackup.INI
2017-01-16 00:13 - 2013-08-22 11:36 - 00000000 ____D C:\windows\Inf
2017-01-15 20:47 - 2013-08-22 12:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2017-01-15 20:46 - 2015-04-22 16:14 - 00065536 _____ C:\windows\system32\spu_storage.bin
2017-01-15 16:12 - 2016-01-05 15:06 - 00000000 ____D C:\Users\Glauber Segalla
2017-01-15 14:44 - 2016-05-19 20:09 - 00000000 ____D C:\windows\Minidump
2017-01-15 02:03 - 2016-01-07 20:25 - 00000000 ____D C:\Users\Glauber Segalla\.VirtualBox
2017-01-15 01:42 - 2016-01-11 22:43 - 00000000 ____D C:\Users\Glauber Segalla\Desktop\Compartilhada
2017-01-14 16:12 - 2016-03-14 03:31 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Roaming\IDM
2017-01-14 16:12 - 2016-01-19 18:37 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Roaming\uTorrent
2017-01-11 12:54 - 2013-08-22 11:25 - 00262144 ___SH C:\windows\system32\config\BBI
2017-01-11 02:55 - 2016-10-10 03:22 - 00003790 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2017-01-11 02:55 - 2013-08-22 13:36 - 00000000 ____D C:\windows\SysWOW64\Macromed
2017-01-11 02:55 - 2013-08-22 13:36 - 00000000 ____D C:\windows\system32\Macromed
2017-01-11 00:27 - 2016-01-11 15:05 - 00000000 ____D C:\Users\Glauber Segalla\VirtualBox VMs
2017-01-10 03:02 - 2013-08-22 13:36 - 00000000 ____D C:\windows\Help
2017-01-06 11:50 - 2016-01-17 19:11 - 00000000 ____D C:\SisAdm
2017-01-06 00:14 - 2016-01-22 20:00 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Local\ElevatedDiagnostics
2017-01-05 20:25 - 2016-01-05 15:06 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Roaming\Adobe
2017-01-05 20:18 - 2013-08-22 13:36 - 00000000 ____D C:\windows\AppReadiness
2017-01-05 18:17 - 2016-02-17 02:14 - 00000000 ____D C:\Program Files (x86)\Acro Software
2017-01-05 18:13 - 2016-01-20 16:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Limpeza
2017-01-04 02:09 - 2016-10-02 03:13 - 00000000 ____D C:\Users\Glauber Segalla\Desktop\BLOG NA HORA
2017-01-04 02:09 - 2016-01-05 15:06 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Local\Packages
2017-01-04 01:41 - 2016-05-14 11:33 - 00000000 ____D C:\Users\Glauber Segalla\Desktop\ANÚNCIOS MATADORES PARA FACEBOOK
2017-01-04 01:15 - 2016-02-21 02:36 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Roaming\Notepad++
2017-01-03 18:37 - 2016-08-01 12:31 - 00000000 ____D C:\Users\Glauber Segalla\Documents\eM Client
2017-01-03 03:05 - 2016-01-21 20:06 - 00000000 ____D C:\Users\Glauber Segalla\AppData\Local\Google
2017-01-01 02:34 - 2016-01-20 16:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Utilitários
2016-12-28 19:10 - 2013-08-22 13:36 - 00000000 ___HD C:\Program Files\WindowsApps
2016-12-28 17:54 - 2013-08-22 13:36 - 00000000 ____D C:\windows\debug
2016-12-28 17:13 - 2016-01-05 15:06 - 00000000 ___RD C:\Users\Glauber Segalla\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2016-12-27 19:52 - 2013-08-22 11:36 - 00000000 ___RD C:\Users\Public
2016-12-27 11:44 - 2016-05-25 03:35 - 00000000 __SHD C:\$RECYCLE.BIN
2016-12-26 01:06 - 2016-08-11 04:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-12-19 00:26 - 2013-08-22 13:36 - 00000000 __RSD C:\windows\assembly
2016-12-17 19:09 - 2016-10-17 01:36 - 00000000 ____D C:\Users\Glauber Segalla\Downloads\ATALHOS DE PROGRAMAS SALVOS NO DESKTOP
==================== Arquivos na raiz de alguns diretórios =======
2017-01-02 02:10 - 2017-01-02 02:11 - 0007680 _____ () C:\Users\Glauber Segalla\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2016-02-13 17:51 - 2016-02-13 17:51 - 0000017 _____ () C:\Users\Glauber Segalla\AppData\Local\resmon.resmoncfg
2016-01-16 02:29 - 2016-01-16 02:29 - 0000057 _____ () C:\ProgramData\Ament.ini
==================== Bamital & volsnap ======================
(Não há correção automática para arquivos que não passaram na verificação.)
C:\windows\system32\winlogon.exe => O arquivo é assinado digitalmente
C:\windows\system32\wininit.exe => O arquivo é assinado digitalmente
C:\windows\explorer.exe => O arquivo é assinado digitalmente
C:\windows\SysWOW64\explorer.exe => O arquivo é assinado digitalmente
C:\windows\system32\svchost.exe => O arquivo é assinado digitalmente
C:\windows\SysWOW64\svchost.exe => O arquivo é assinado digitalmente
C:\windows\system32\services.exe => O arquivo é assinado digitalmente
C:\windows\system32\User32.dll => O arquivo é assinado digitalmente
C:\windows\SysWOW64\User32.dll => O arquivo é assinado digitalmente
C:\windows\system32\userinit.exe => O arquivo é assinado digitalmente
C:\windows\SysWOW64\userinit.exe => O arquivo é assinado digitalmente
C:\windows\system32\rpcss.dll => O arquivo é assinado digitalmente
C:\windows\system32\dnsapi.dll => O arquivo é assinado digitalmente
C:\windows\SysWOW64\dnsapi.dll => O arquivo é assinado digitalmente
C:\windows\system32\Drivers\volsnap.sys => O arquivo é assinado digitalmente
LastRegBack: 2017-01-09 11:40
==================== Fim de FRST.txt ============================