Logo Hardware.com.br
Mcampos25
Mcampos25 Novo Membro Registrado
7 Mensagens 0 Curtidas

[Resolvido] Problema com vírus

#1 Por Mcampos25 18/09/2015 - 00:12
Boa noite, meu Avast tem acusado um vírus endereçado na pasta appdata.../autosetup.exe

Eu executei limpezas com o Adwcleaner, com o malwarebytes , e com o ZHP cleaner. Eles me apresentaram alguns relatórios, além do JTR e do Hijack This que usei também pra postar aqui. Queria saber se o que eu fiz foi suficiente para remoção dos vírus. Os relatórios estão aqui

"Log s"

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:42:07, on 17/09/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)
Boot mode: Normal

Running processes:
C:\PROGRA~2\GbPlugin\GbpSv.exe
C:\Users\mateu\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.seekmx.com/?bd=hp&oem=301br&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUK29370993709&version=2.3.0.10324&pid=414031160&tid=676
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seekmx.com/?bd=hp&oem=301br&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUK29370993709&version=2.3.0.10324&pid=414031160&tid=676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.seekmx.com/?bd=hp&oem=301br&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUK29370993709&version=2.3.0.10324&pid=414031160&tid=676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seekmx.com/?bd=hp&oem=301br&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUK29370993709&version=2.3.0.10324&pid=414031160&tid=676
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: G-Buster Browser Defense CEF - {C41A1C0E-EA6C-11D4-B1B8-444553540003} - C:\Program Files (x86)\GbPlugin\gbiehcef.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\mateu\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - Global Startup: Aplicativo de Download Automático do SolidWorks.lnk = ?
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: imagem.caixa.gov.br
O15 - Trusted Zone: internetbanking.caixa.gov.br
O15 - Trusted Zone: internetbankingpf.caixa.gov.br
O15 - Trusted Zone: www.caixa.gov.br
O15 - Trusted Zone: http://www.caixa.gov.br
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O20 - Winlogon Notify: GbPluginCef - C:\Program Files (x86)\GbPlugin\gbiehCef.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Gbp Service (GbpSv) - GAS Tecnologia - C:\PROGRA~2\GbPlugin\GbpSv.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Net.Tcp Service Handler (NetTcpHandler) - Unknown owner - C:\Users\mateu\AppData\Roaming\NetService\netservice.exe
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10129 bytes

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by mateu (administrator) on DESKTOP-8475GNN (17-09-2015 23:46:03)
Running from C:\Users\mateu\Downloads
Loaded Profiles: mateu (Available Profiles: mateu & manoe)
Platform: Windows 10 Home (X64) Language: Português (Brasil)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\gbpsv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(GAS Tecnologia) C:\Program Files (x86)\GbPlugin\gbpsv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
() C:\Users\mateu\AppData\Roaming\NetService\netservice.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.827.16340.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.9.9.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Farbar) C:\Users\mateu\Downloads\FRST64 (1).exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-08-23] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1795728 2015-08-24] (NVIDIA Corporation)
HKLM\...\Run: [PAC7302_Monitor] => C:\Windows\PixArt\PAC7302\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6111824 2015-08-26] (AVAST Software)
Winlogon\Notify\ GbPluginCef: C:\Program Files (x86)\GbPlugin\gbiehCef.dll [2015-07-08] (Caixa Economica Federal)
HKU\S-1-5-21-497741064-2335638771-2095936946-1001\...\Run: [Spotify Web Helper] => C:\Users\mateu\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2018360 2015-09-10] (Spotify Ltd)
HKU\S-1-5-21-497741064-2335638771-2095936946-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [55100016 2015-08-26] (Skype Technologies S.A.)
ShellExecuteHooks-x32: GbPluginObj Class - {E37CB5F0-51F5-4395-A808-5FA49E399003} - C:\Program Files (x86)\GbPlugin\gbiehcef.dll [1853256 2015-07-08] (Caixa Economica Federal)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-08-23] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Aplicativo de Download Automático do SolidWorks.lnk [2015-09-10]
ShortcutTarget: Aplicativo de Download Automático do SolidWorks.lnk -> C:\Program Files (x86)\Common Files\Gerenciador de Instalação do SolidWorks\BackgroundDownloading\sldBgDwld.exe (Dassault Systèmes SolidWorks Corp.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{bdfc8487-a4d6-4a3a-a387-a9a202cdad6f}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seekmx.com/?bd=hp&oem=301br&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUK29370993709&version=2.3.0.10324&pid=414031160&tid=676
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seekmx.com/?bd=hp&oem=301br&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUK29370993709&version=2.3.0.10324&pid=414031160&tid=676
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.seekmx.com/?bd=hp&oem=301br&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUK29370993709&version=2.3.0.10324&pid=414031160&tid=676
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.seekmx.com/?bd=hp&oem=301br&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUK29370993709&version=2.3.0.10324&pid=414031160&tid=676
HKU\S-1-5-21-497741064-2335638771-2095936946-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.seekmx.com/?bd=hp&oem=301br&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUK29370993709&version=2.3.0.10324&pid=414031160&tid=676
HKU\S-1-5-21-497741064-2335638771-2095936946-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.seekmx.com/?bd=hp&oem=301br&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUK29370993709&version=2.3.0.10324&pid=414031160&tid=676
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-08-23] (AVAST Software)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2015-09-13] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-08-23] (AVAST Software)
BHO-x32: GbIehObj Class -> {C41A1C0E-EA6C-11D4-B1B8-444553540003} -> C:\Program Files (x86)\GbPlugin\gbiehcef.dll [2015-07-08] (Caixa Economica Federal)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2015-09-13] (Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2015-09-13] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2015-09-13] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2015-09-13] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2015-09-13] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2015-09-13] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2015-09-13] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2015-09-13] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2015-09-13] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.seekmx.com/?bd=sc&oem=301br&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUK29370993709&version=2.3.0.10324&pid=414031160&tid=676

FireFox:
========
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2015-09-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2015-09-13] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-07-13] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-07-13] (NVIDIA Corporation)
FF HKLM-x32\...\Firefox\Extensions: [[email]wrc@avast.com[/email]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-08-23]

Chrome:
=======
CHR Profile: C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Apresentações) - C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-26]
CHR Extension: (Google Docs) - C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-26]
CHR Extension: (Google Drive) - C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-26]
CHR Extension: (YouTube) - C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-26]
CHR Extension: (Google Search) - C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-26]
CHR Extension: (Avast SafePrice) - C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-08-30]
CHR Extension: (Planilhas do Google) - C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-26]
CHR Extension: (Documentos Google off-line) - C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-03]
CHR Extension: (Avast Online Security) - C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-08-26]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-26]
CHR Extension: (Pagamentos da Chrome Web Store) - C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-26]
CHR Extension: (Gmail) - C:\Users\mateu\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-26]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-08-23]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-08-23]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-08-23] (AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2836056 2015-09-09] (Microsoft Corporation)
R2 GbpSv; C:\Program Files (x86)\GbPlugin\gbpsv.exe [579896 2015-04-29] (GAS Tecnologia)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NetTcpHandler; C:\Users\mateu\AppData\Roaming\NetService\netservice.exe [173088 2015-07-08] ()
S3 SolidWorks Licensing Service; C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2015-09-10] (SolidWorks) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-08-23] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-08-23] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-08-23] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-08-23] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048344 2015-08-23] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-08-23] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150672 2015-08-23] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-08-23] (AVAST Software)
R3 GBPRCM; C:\Program Files (x86)\GbPlugin\gbprcm64.sys [21720 2015-08-11] (GAS Tecnologia)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [193336 2015-08-23] (Intel Corporation)
R3 PAC7302; C:\Windows\system32\DRIVERS\PAC7302.SYS [527872 2007-11-08] (PixArt Imaging Inc.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek )
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
R3 Warsaw_PP; C:\Program Files (x86)\GbPlugin\wsftprp64.sys [24792 2014-11-03] (GAS Tecnologia LTDA)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S1 gbpddfac; system32\drivers\gbpddfac64.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-17 23:46 - 2015-09-17 23:46 - 00014834 _____ C:\Users\mateu\Downloads\FRST.txt
2015-09-17 23:46 - 2015-09-17 23:46 - 00000000 ____D C:\FRST
2015-09-17 23:42 - 2015-09-17 23:42 - 00010131 _____ C:\Users\mateu\Downloads\hijackthis.log
2015-09-17 23:42 - 2015-09-17 23:42 - 00010131 _____ C:\Users\mateu\Desktop\HJ.txt
2015-09-17 23:39 - 2015-09-17 23:39 - 00016148 _____ C:\Windows\system32\DESKTOP-8475GNN_mateu_HistoryPrediction.bin
2015-09-17 23:24 - 2015-09-17 23:24 - 00001056 _____ C:\Users\mateu\Desktop\JRT.txt
2015-09-17 23:17 - 2015-09-17 23:41 - 00388608 _____ (Trend Micro Inc.) C:\Users\mateu\Downloads\HijackThis.exe
2015-09-17 23:12 - 2015-09-17 23:12 - 01957888 _____ C:\Users\mateu\Downloads\ZHPCleaner-2015.9.16.348.exe
2015-09-17 23:04 - 2015-09-17 23:45 - 02191360 _____ (Farbar) C:\Users\mateu\Downloads\FRST64 (1).exe
2015-09-17 23:04 - 2015-09-17 23:04 - 02191360 _____ (Farbar) C:\Users\mateu\Downloads\FRST64.exe
2015-09-17 22:55 - 2015-09-17 22:58 - 01798976 _____ (Malwarebytes) C:\Users\mateu\Downloads\JRT.exe
2015-09-17 22:41 - 2015-09-17 22:41 - 00001181 _____ C:\AdwCleaner[S6].txt
2015-09-17 21:45 - 2015-09-17 21:50 - 00000000 ____D C:\Users\mateu\Downloads\Wxp
2015-09-17 21:18 - 2015-09-17 21:43 - 615755776 ____R C:\Users\mateu\Downloads\Windows XP Professional SP3 + Serial.iso
2015-09-17 21:12 - 2015-09-17 21:12 - 00011876 _____ C:\Users\mateu\Downloads\Windows XP Professional SP3 + Serial.iso.torrent
2015-09-17 20:27 - 2015-09-17 20:27 - 00001684 _____ C:\AdwCleaner[C3].txt
2015-09-17 20:25 - 2015-09-17 20:25 - 00001507 _____ C:\AdwCleaner[S5].txt
2015-09-17 20:08 - 2015-09-17 22:05 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-17 20:07 - 2015-09-17 20:07 - 00000000 ____D C:\Users\Todos os Usuários\Malwarebytes
2015-09-17 20:07 - 2015-09-17 20:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-17 20:07 - 2015-09-17 20:07 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-17 20:07 - 2015-09-17 20:07 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-17 20:07 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-17 20:07 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-09-17 20:07 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-17 20:01 - 2015-09-17 20:04 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\mateu\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-17 19:56 - 2015-09-17 21:51 - 00000000 ____D C:\Users\mateu\Documents\backups
2015-09-17 19:53 - 2015-09-17 21:54 - 00102402 _____ C:\Users\mateu\Documents\WinSetupFromUSB.log
2015-09-17 19:52 - 2015-09-17 20:30 - 00001546 _____ C:\Users\mateu\Desktop\WinSetupFromUSB.lnk
2015-09-17 19:52 - 2015-09-17 20:23 - 00000695 _____ C:\Users\mateu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinSetupFromUSB 0.1.1.lnk
2015-09-17 19:52 - 2015-09-17 19:52 - 00085890 _____ C:\Users\mateu\Documents\Uninstall.exe
2015-09-17 19:52 - 2015-09-17 19:52 - 00000000 ____D C:\Users\mateu\Documents\SourceCode
2015-09-17 19:52 - 2015-09-17 19:52 - 00000000 ____D C:\Users\mateu\Documents\files
2015-09-17 19:52 - 2015-09-17 19:52 - 00000000 ____D C:\Users\mateu\Documents\Docs
2015-09-17 19:45 - 2015-09-17 19:46 - 03159486 _____ () C:\Users\mateu\Downloads\WinSetupFromUSB-0.1.1.exe
2015-09-16 14:06 - 2015-09-16 14:06 - 00016148 _____ C:\Windows\system32\DESKTOP-8475GNN_manoe_HistoryPrediction.bin
2015-09-15 22:27 - 2015-09-15 22:30 - 00000000 ____D C:\Users\mateu\Desktop\Windows 10
2015-09-15 22:25 - 2015-09-15 22:25 - 00000000 ____D C:\Users\mateu\Downloads\WindowsXP
2015-09-13 16:50 - 2015-09-13 16:50 - 00000000 ____D C:\Users\mateu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Popcorn Time
2015-09-13 16:35 - 2015-09-13 16:35 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2015-09-13 16:34 - 2015-09-17 20:24 - 00002449 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project 2016.lnk
2015-09-13 16:34 - 2015-09-17 20:24 - 00002439 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2015-09-13 16:34 - 2015-09-17 20:24 - 00002438 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2015-09-13 16:34 - 2015-09-17 20:24 - 00002431 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visio 2016.lnk
2015-09-13 16:34 - 2015-09-17 20:24 - 00002402 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2015-09-13 16:34 - 2015-09-17 20:24 - 00002401 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2015-09-13 16:34 - 2015-09-17 20:24 - 00002395 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2015-09-13 16:34 - 2015-09-17 20:24 - 00002389 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2015-09-13 16:34 - 2015-09-17 20:24 - 00002381 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2015-09-13 16:34 - 2015-09-13 16:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2015-09-13 15:30 - 2015-09-13 15:32 - 17216290 _____ C:\Users\mateu\Downloads\AuoptCO7hx-MvmcdtlOBjtLp7h1DzsQJ9drvxoCV-VxX.mp4
2015-09-13 15:18 - 2015-09-13 15:18 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-09-13 15:09 - 2015-09-13 15:09 - 00001486 _____ C:\AdwCleaner[C2].txt
2015-09-13 15:06 - 2015-09-13 15:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-09-13 15:04 - 2015-09-13 15:05 - 00001315 _____ C:\AdwCleaner[S4].txt
2015-09-11 23:10 - 2015-09-14 12:39 - 00000000 ____D C:\Users\manoe\AppData\Roaming\SolidWorks
2015-09-10 20:36 - 2015-09-13 15:14 - 00000000 ____D C:\SolidWorks Data
2015-09-10 20:36 - 2015-09-10 20:36 - 00000000 ____D C:\Program Files\Common Files\Macrovision Shared
2015-09-10 20:35 - 2015-09-10 20:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gerenciador de Instalação do SolidWorks
2015-09-10 20:31 - 2011-03-23 22:53 - 00000000 ____D C:\Users\mateu\Downloads\SolidSQUAD
2015-09-10 20:30 - 2015-09-10 20:30 - 00000000 ____D C:\Users\mateu\AppData\Roaming\WinRAR
2015-09-10 20:29 - 2015-09-10 20:30 - 00000000 ____D C:\Program Files (x86)\WinRAR
2015-09-10 20:29 - 2015-09-10 20:29 - 00000000 ____D C:\Users\mateu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-09-10 20:29 - 2015-09-10 20:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-09-10 20:26 - 2015-09-10 20:27 - 03854096 _____ C:\Users\mateu\Downloads\wrar521br.exe
2015-09-10 20:15 - 2015-09-10 20:15 - 08741834 _____ C:\Users\mateu\Downloads\SolidSQUAD.rar
2015-09-10 19:35 - 2015-09-10 21:54 - 00000000 ____D C:\Users\mateu\Downloads\Microsoft Office Profissional Plus 2016 x32 x64 Portugues BR + Ativacao
2015-09-10 19:33 - 2015-09-10 19:33 - 00015105 _____ C:\Users\mateu\Downloads\2A891704301CA77AADA15BC7D9E7CC499FA8EEF2.torrent
2015-09-10 19:33 - 2015-09-10 19:33 - 00001658 _____ C:\Users\mateu\Downloads\Player_Setup.xml
2015-09-06 11:21 - 2015-09-16 13:31 - 00000000 ____D C:\Users\manoe\AppData\Local\CrashDumps
2015-09-03 22:09 - 2015-09-03 22:09 - 00921632 _____ C:\PA7302.DAT
2015-09-03 22:08 - 2015-09-03 22:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-03 22:08 - 2015-09-03 22:08 - 00000000 ____D C:\Windows\PixArt
2015-09-03 22:08 - 2015-09-03 22:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Camera
2015-09-03 22:08 - 2015-09-03 22:08 - 00000000 ____D C:\Program Files (x86)\PixArt
2015-09-03 22:08 - 2009-11-11 09:32 - 00000321 _____ C:\Windows\SysWOW64\Remover.ini
2015-09-03 22:08 - 2008-04-11 19:10 - 00000566 _____ C:\Windows\SysWOW64\SP7302.ini
2015-09-03 22:08 - 2007-11-20 17:58 - 00055296 _____ (PixArt Imaging Incorporation) C:\Windows\SysWOW64\Remove.exe
2015-09-03 22:08 - 2007-11-08 10:29 - 00527872 _____ (PixArt Imaging Inc.) C:\Windows\system32\Drivers\PAC7302.SYS
2015-09-03 22:08 - 2007-11-02 11:07 - 00008704 _____ (PixArt Imaging Inc.) C:\Windows\system32\CoInst_071029.dll
2015-09-03 22:08 - 2007-10-30 17:48 - 00129024 _____ (PixArt Imaging Incorporation) C:\Windows\SysWOW64\SP7302.ax
2015-09-03 22:08 - 2006-10-12 11:57 - 00014336 _____ (PixArt Imaging Inc.) C:\Windows\SysWOW64\P7302USD.dll
2015-09-03 22:07 - 2015-09-03 22:07 - 00000000 ____D C:\Users\mateu\Downloads\Câmera
2015-09-03 22:06 - 2015-09-03 22:07 - 07067675 _____ C:\Users\mateu\Downloads\drv_WC039.zip
2015-09-03 21:57 - 2015-09-03 21:57 - 00000000 ____D C:\Users\mateu\Tracing
2015-09-03 21:56 - 2015-09-17 20:24 - 00002636 _____ C:\Users\Public\Desktop\Skype.lnk
2015-09-03 21:56 - 2015-09-03 21:56 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-09-03 21:56 - 2015-09-03 21:56 - 00000000 ____D C:\Users\mateu\AppData\Local\Skype
2015-09-03 21:56 - 2015-09-03 21:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-09-03 21:51 - 2015-09-03 21:52 - 01494048 _____ (Skype Technologies S.A.) C:\Users\mateu\Downloads\SkypeSetup.exe
2015-08-30 18:54 - 2015-08-31 10:19 - 00000000 ____D C:\Windows\system32\MRT
2015-08-30 18:54 - 2015-07-28 10:59 - 132483416 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-30 15:29 - 2015-09-10 20:36 - 00000000 ____D C:\Windows\SolidWorks
2015-08-30 15:29 - 2015-08-30 15:29 - 00000000 ____D C:\Users\mateu\AppData\Roaming\SolidWorks
2015-08-30 12:29 - 2015-08-30 15:18 - 1442306048 _____ C:\Users\mateu\Downloads\SW2011-SP0-x64 (1).iso
2015-08-28 13:06 - 2015-08-30 12:16 - 00000000 ____D C:\Windows\AutoKMS
2015-08-28 12:58 - 2015-09-14 10:53 - 00000000 ____D C:\Program Files\Microsoft Office
2015-08-28 12:12 - 2015-09-17 22:45 - 00003540 _____ C:\Windows\System32\Tasks\AutoKMS
2015-08-27 22:37 - 2015-08-30 12:37 - 00005310 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-8475GNN-mateu DESKTOP-8475GNN
2015-08-27 22:09 - 2015-08-27 22:36 - 00000000 ____D C:\Users\mateu\AppData\Local\Microsoft Toolkit
2015-08-27 21:59 - 2015-08-30 12:32 - 00000000 ____D C:\Users\Todos os Usuários\Microsoft Help
2015-08-27 21:59 - 2015-08-30 12:32 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-27 21:59 - 2015-08-27 21:59 - 00000000 ____D C:\Users\mateu\AppData\Local\Microsoft Help
2015-08-27 21:38 - 2015-09-17 22:35 - 00000000 ____D C:\Program Files (x86)\GbPlugin
2015-08-27 21:38 - 2015-08-28 12:47 - 00000000 ____D C:\Users\Todos os Usuários\GbPlugin
2015-08-27 21:38 - 2015-08-28 12:47 - 00000000 ____D C:\ProgramData\GbPlugin
2015-08-27 21:38 - 2015-08-27 21:38 - 00000000 ____D C:\Users\Todos os Usuários\GAS Tecnologia
2015-08-27 21:38 - 2015-08-27 21:38 - 00000000 ____D C:\ProgramData\GAS Tecnologia
2015-08-27 21:33 - 2015-09-17 19:39 - 00004182 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{95B7A47F-7BAF-4A12-BB14-92B0C48809B8}
2015-08-27 21:24 - 2015-09-17 23:05 - 00000000 ____D C:\Users\mateu\AppData\Local\CrashDumps
2015-08-27 16:31 - 2015-08-27 21:31 - 00000000 ____D C:\Users\mateu\Downloads\Microsoft Office 2013 PT-BR X64 + crack - By baixetorrents.com
2015-08-27 16:12 - 2015-08-27 16:12 - 01685151 _____ C:\Users\mateu\Documents\Graphical Abstract - Alexandre 1.pfi
2015-08-27 15:55 - 2015-09-13 15:06 - 00000000 ____D C:\Program Files (x86)\MSECache
2015-08-27 15:35 - 2015-08-27 15:35 - 00000000 ____D C:\Users\mateu\Documents\Snagit
2015-08-27 15:34 - 2015-08-27 16:26 - 365881760 _____ (Microsoft Corporation) C:\Users\mateu\Downloads\office2007sp3-kb2526086-fullfile-pt-br.exe
2015-08-27 15:34 - 2015-08-27 15:55 - 39035640 _____ (Microsoft Corporation) C:\Users\mateu\Downloads\FileFormatConverters.exe
2015-08-27 15:33 - 2015-08-27 15:33 - 00003888 _____ C:\Windows\System32\Tasks\TechSmith Updater
2015-08-27 15:32 - 2015-08-27 15:32 - 00000000 ____D C:\Users\Todos os Usuários\TechSmith
2015-08-27 15:32 - 2015-08-27 15:32 - 00000000 ____D C:\Users\Todos os Usuários\regid.1995-08.com.techsmith
2015-08-27 15:32 - 2015-08-27 15:32 - 00000000 ____D C:\Users\mateu\AppData\Local\TechSmith
2015-08-27 15:32 - 2015-08-27 15:32 - 00000000 ____D C:\ProgramData\TechSmith
2015-08-27 15:32 - 2015-08-27 15:32 - 00000000 ____D C:\ProgramData\regid.1995-08.com.techsmith
2015-08-27 15:32 - 2015-08-27 15:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
2015-08-27 15:32 - 2015-08-27 15:32 - 00000000 ____D C:\Program Files (x86)\TechSmith
2015-08-27 15:31 - 2015-08-27 15:32 - 06297938 _____ C:\Users\mateu\Downloads\Alexandre Kwak - apresentacao proj final.pptx
2015-08-27 15:20 - 2015-08-27 15:20 - 00067816 _____ C:\Users\mateu\AppData\Local\GDIPFONTCACHEV1.DAT
2015-08-27 15:18 - 2015-08-27 15:19 - 13146016 _____ (Disc Soft Ltd) C:\Users\mateu\Downloads\DTLite501-0406.exe
2015-08-27 15:14 - 2015-08-27 16:41 - 00000000 ____D C:\Users\mateu\AppData\Roaming\PhotoFiltre Studio X
2015-08-27 15:14 - 2015-08-27 15:14 - 00000000 ____D C:\Users\mateu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Studio X
2015-08-27 15:14 - 2015-08-27 15:14 - 00000000 ____D C:\Program Files (x86)\PhotoFiltre Studio X
2015-08-27 15:12 - 2015-08-27 15:12 - 00000418 _____ C:\Windows\ODBC.INI
2015-08-27 15:09 - 2015-08-27 15:14 - 11154734 _____ C:\Users\mateu\Downloads\pfsx-setup-en-10-7-3.exe
2015-08-26 14:41 - 2015-09-11 23:11 - 00000000 ____D C:\Users\manoe\AppData\Local\Google
2015-08-26 10:47 - 2015-09-17 23:41 - 00000000 ____D C:\Program Files (x86)\Google
2015-08-26 10:47 - 2015-09-10 21:50 - 00000000 ____D C:\Users\mateu\AppData\Local\Google
2015-08-26 10:47 - 2015-08-26 10:47 - 00931408 _____ (Google Inc.) C:\Users\mateu\Downloads\ChromeSetup.exe
2015-08-26 10:32 - 2015-09-17 21:58 - 00000000 ____D C:\Users\mateu\AppData\Roaming\uTorrent
2015-08-26 10:30 - 2015-08-26 10:32 - 01696096 _____ (BitTorrent Inc.) C:\Users\mateu\Downloads\uTorrent.exe
2015-08-26 10:25 - 2015-08-26 10:25 - 00000000 ____D C:\Users\mateu\AppData\Local\NVIDIA
2015-08-25 11:14 - 2015-08-25 11:14 - 00000000 ____D C:\Windows\system32\SleepStudy
2015-08-25 10:50 - 2015-08-25 10:50 - 00000000 ____D C:\Users\manoe\AppData\Local\NVIDIA
2015-08-24 23:17 - 2015-09-17 22:35 - 00000000 ____D C:\Users\Todos os Usuários\NVIDIA
2015-08-24 23:17 - 2015-09-17 22:35 - 00000000 ____D C:\ProgramData\NVIDIA
2015-08-24 23:16 - 2015-08-24 23:17 - 00000000 ____D C:\Users\Todos os Usuários\NVIDIA Corporation
2015-08-24 23:16 - 2015-08-24 23:17 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-08-24 23:16 - 2015-08-24 23:15 - 00112784 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-08-24 23:16 - 2015-08-24 23:15 - 00105104 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-08-24 23:16 - 2015-07-13 14:37 - 06873744 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2015-08-24 23:16 - 2015-07-13 14:37 - 03493008 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2015-08-24 23:16 - 2015-07-13 14:37 - 02558792 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2015-08-24 23:16 - 2015-07-13 14:37 - 00937616 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2015-08-24 23:16 - 2015-07-13 14:37 - 00385168 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2015-08-24 23:16 - 2015-07-13 14:37 - 00062792 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2015-08-24 23:16 - 2015-07-13 14:17 - 00572048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2015-08-24 23:16 - 2015-07-13 13:28 - 05096627 _____ C:\Windows\system32\nvcoproc.bin
2015-08-24 23:15 - 2015-08-24 23:17 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-08-24 23:15 - 2015-08-24 23:17 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-08-24 23:15 - 2015-08-24 23:15 - 42730128 _____ C:\Windows\system32\nvcompiler.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 37748880 _____ C:\Windows\SysWOW64\nvcompiler.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 30518928 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 22972560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 18514616 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 16159608 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 16009800 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 15892904 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 14510584 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 13274560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 12972336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 11842680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 11139216 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-08-24 23:15 - 2015-08-24 23:15 - 03344672 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 02955832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 02360976 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 02163856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 01898312 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435354.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 01558848 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435354.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 01165192 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 01061192 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 01052488 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 00991336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 00983368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 00976528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 00195912 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2015-08-24 23:15 - 2015-08-24 23:15 - 00177088 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 00155280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 00128512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-08-24 23:15 - 2015-08-24 23:15 - 00031976 _____ C:\Windows\system32\nvinfo.pb
2015-08-24 23:15 - 2015-08-24 23:15 - 00031552 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2015-08-24 23:08 - 2015-08-13 01:33 - 24593408 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-24 23:08 - 2015-08-13 01:23 - 02178560 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2015-08-24 23:08 - 2015-08-13 01:22 - 02093056 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2015-08-24 23:08 - 2015-08-13 01:17 - 01795072 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2015-08-24 23:08 - 2015-08-13 01:07 - 19323392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-08-24 23:08 - 2015-08-11 07:04 - 04532304 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2015-08-24 23:08 - 2015-08-11 07:04 - 02462648 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2015-08-24 23:08 - 2015-08-11 07:04 - 01087296 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-08-24 23:08 - 2015-08-11 07:03 - 08021840 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-24 23:08 - 2015-08-11 07:02 - 00554744 _____ (Microsoft Corporation) C:\Windows\system32\directmanipulation.dll
2015-08-24 23:08 - 2015-08-11 07:02 - 00292856 _____ (Microsoft Corporation) C:\Windows\system32\LockAppHost.exe
2015-08-24 23:08 - 2015-08-11 06:57 - 03622256 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-24 23:08 - 2015-08-11 06:50 - 01643872 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-08-24 23:08 - 2015-08-11 06:40 - 04048808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2015-08-24 23:08 - 2015-08-11 06:40 - 02151208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2015-08-24 23:08 - 2015-08-11 06:40 - 00918320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2015-08-24 23:08 - 2015-08-11 06:38 - 00454000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\directmanipulation.dll
2015-08-24 23:08 - 2015-08-11 06:37 - 00243800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LockAppHost.exe
2015-08-24 23:08 - 2015-08-11 06:31 - 02880032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-08-24 23:08 - 2015-08-11 06:23 - 16706560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2015-08-24 23:08 - 2015-08-11 06:22 - 21875200 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2015-08-24 23:08 - 2015-08-11 06:20 - 02224640 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
2015-08-24 23:08 - 2015-08-11 06:16 - 02416640 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2015-08-24 23:08 - 2015-08-11 06:14 - 00404480 _____ C:\Windows\system32\diagtrack_wininternal.dll
2015-08-24 23:08 - 2015-08-11 06:13 - 00413184 _____ C:\Windows\system32\diagtrack_win.dll
2015-08-24 23:08 - 2015-08-11 06:11 - 02446336 _____ C:\Windows\system32\InputService.dll
2015-08-24 23:08 - 2015-08-11 06:10 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-08-24 23:08 - 2015-08-11 06:08 - 00893440 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
2015-08-24 23:08 - 2015-08-11 06:08 - 00563200 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApi.dll
2015-08-24 23:08 - 2015-08-11 06:07 - 01178112 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2015-08-24 23:08 - 2015-08-11 06:07 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2015-08-24 23:08 - 2015-08-11 06:06 - 07523328 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2015-08-24 23:08 - 2015-08-11 06:06 - 02662400 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2015-08-24 23:08 - 2015-08-11 06:05 - 03527168 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2015-08-24 23:08 - 2015-08-11 06:05 - 00996352 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll
2015-08-24 23:08 - 2015-08-11 06:05 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\LocationPermissions.dll
2015-08-24 23:08 - 2015-08-11 06:03 - 02558976 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2015-08-24 23:08 - 2015-08-11 06:02 - 03588096 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2015-08-24 23:08 - 2015-08-11 06:02 - 01890304 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-08-24 23:08 - 2015-08-11 06:01 - 01334784 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2015-08-24 23:08 - 2015-08-11 05:57 - 13024768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2015-08-24 23:08 - 2015-08-11 05:51 - 01916928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2015-08-24 23:08 - 2015-08-11 05:51 - 01823232 _____ C:\Windows\SysWOW64\InputService.dll
2015-08-24 23:08 - 2015-08-11 05:49 - 00586752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2015-08-24 23:08 - 2015-08-11 05:45 - 18805760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2015-08-24 23:08 - 2015-08-11 05:45 - 01820672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2015-08-24 23:08 - 2015-08-11 05:43 - 02748416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2015-08-24 23:08 - 2015-08-11 05:42 - 05454848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2015-08-24 23:08 - 2015-08-11 05:40 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2015-08-24 23:08 - 2015-08-11 05:40 - 01593856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-08-24 23:08 - 2015-08-11 05:40 - 01112064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2015-08-24 23:08 - 2015-08-08 04:29 - 01822280 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-24 23:08 - 2015-08-08 04:19 - 00608936 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2015-08-24 23:08 - 2015-08-08 04:01 - 01533496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-08-24 23:08 - 2015-08-08 03:48 - 00539728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2015-08-24 23:08 - 2015-08-08 03:40 - 00365056 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-24 23:08 - 2015-08-08 03:24 - 02415104 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-24 23:08 - 2015-08-08 03:24 - 01679360 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-24 23:08 - 2015-08-08 03:15 - 00303104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-08-24 23:08 - 2015-08-08 03:00 - 01985024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-08-24 23:08 - 2015-08-06 00:17 - 00237392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2015-08-24 23:08 - 2015-08-05 23:22 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdiWiFi.sys
2015-08-24 23:08 - 2015-08-05 01:49 - 00783112 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2015-08-24 23:08 - 2015-08-05 01:29 - 00644128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2015-08-24 23:08 - 2015-08-05 01:00 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenter.dll
2015-08-24 23:08 - 2015-08-05 00:54 - 01274880 _____ (Microsoft Corporation) C:\Windows\system32\wifinetworkmanager.dll
2015-08-24 23:08 - 2015-08-05 00:47 - 01383424 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2015-08-24 23:08 - 2015-08-05 00:39 - 00261632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActionCenter.dll
2015-08-24 23:08 - 2015-08-04 01:07 - 00102752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-24 23:08 - 2015-08-04 01:06 - 00583128 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-08-24 23:08 - 2015-08-03 23:59 - 01212416 _____ (Microsoft Corporation) C:\Windows\system32\RemoteNaturalLanguage.dll
2015-08-24 23:08 - 2015-08-03 23:47 - 00898560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RemoteNaturalLanguage.dll
2015-08-24 23:08 - 2015-08-02 23:32 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\NotificationObjFactory.dll
2015-08-24 23:08 - 2015-08-02 23:28 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NotificationObjFactory.dll
2015-08-24 23:08 - 2015-08-02 23:19 - 00505696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2015-08-24 23:08 - 2015-08-02 23:19 - 00393568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2015-08-24 23:08 - 2015-08-02 23:18 - 08613200 _____ (Microsoft Corp.) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2015-08-24 23:08 - 2015-08-02 23:18 - 01983840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2015-08-24 23:08 - 2015-08-02 23:18 - 00594472 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2015-08-24 23:08 - 2015-08-02 23:17 - 00516960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2015-08-24 23:08 - 2015-08-02 23:13 - 22322624 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-24 23:08 - 2015-08-02 23:12 - 00801632 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2015-08-24 23:08 - 2015-08-02 22:56 - 06878256 _____ (Microsoft Corp.) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-24 23:08 - 2015-08-02 22:50 - 20857848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-08-24 23:08 - 2015-08-02 22:49 - 00700256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2015-08-24 23:08 - 2015-08-02 22:31 - 00911360 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll
2015-08-24 23:08 - 2015-08-02 22:30 - 00253952 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_UserAccount.dll
2015-08-24 23:08 - 2015-08-02 22:24 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\tileobjserver.dll
2015-08-24 23:08 - 2015-08-02 22:24 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\VEEventDispatcher.dll
2015-08-24 23:08 - 2015-08-02 22:24 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModelShim.dll
2015-08-24 23:08 - 2015-08-02 22:23 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\VEDataLayerHelpers.dll
2015-08-24 23:08 - 2015-08-02 22:22 - 01601536 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Speech.dll
2015-08-24 23:08 - 2015-08-02 22:22 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-08-24 23:08 - 2015-08-02 22:18 - 12503552 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-24 23:08 - 2015-08-02 22:18 - 03780096 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2015-08-24 23:08 - 2015-08-02 22:18 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\SubscriptionMgr.dll
2015-08-24 23:08 - 2015-08-02 22:18 - 00120832 _____ (Microsoft Corporation) C:\Windows\system32\NetworkStatus.dll
2015-08-24 23:08 - 2015-08-02 22:15 - 01290752 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Shell.dll
2015-08-24 23:08 - 2015-08-02 22:15 - 00595456 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2015-08-24 23:08 - 2015-08-02 22:15 - 00573440 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.Desktop.dll
2015-08-24 23:08 - 2015-08-02 22:15 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\LockAppBroker.dll
2015-08-24 23:08 - 2015-08-02 22:15 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\WinBioDataModel.dll
2015-08-24 23:08 - 2015-08-02 22:14 - 00273920 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-24 23:08 - 2015-08-02 22:14 - 00247808 _____ C:\Windows\system32\facecredentialprovider.dll
2015-08-24 23:08 - 2015-08-02 22:12 - 00217088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VEEventDispatcher.dll
2015-08-24 23:08 - 2015-08-02 22:12 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VEDataLayerHelpers.dll
2015-08-24 23:08 - 2015-08-02 22:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\msctfuimanager.dll
2015-08-24 23:08 - 2015-08-02 22:10 - 01162240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Speech.dll
2015-08-24 23:08 - 2015-08-02 22:03 - 00494592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2015-08-24 23:08 - 2015-08-02 22:02 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LockAppBroker.dll
2015-08-24 23:08 - 2015-08-02 22:02 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-24 23:08 - 2015-08-02 22:01 - 11262464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-08-24 23:08 - 2015-08-02 21:59 - 00752640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctfuimanager.dll
2015-08-24 23:08 - 2015-07-30 03:24 - 01561872 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2015-08-24 23:08 - 2015-07-30 03:23 - 00527952 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-08-24 23:08 - 2015-07-30 03:21 - 00816576 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2015-08-24 23:08 - 2015-07-30 03:17 - 01200400 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-08-24 23:08 - 2015-07-30 03:17 - 01025840 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2015-08-24 23:08 - 2015-07-30 03:16 - 02147080 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2015-08-24 23:08 - 2015-07-30 03:14 - 00333168 _____ (Microsoft Corporation) C:\Windows\system32\MFPlay.dll
2015-08-24 23:08 - 2015-07-30 03:09 - 01562968 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2015-08-24 23:08 - 2015-07-30 03:06 - 01043872 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2015-08-24 23:08 - 2015-07-30 03:05 - 02498808 _____ C:\Windows\system32\CoreUIComponents.dll
2015-08-24 23:08 - 2015-07-30 03:05 - 00501008 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-08-24 23:08 - 2015-07-30 03:04 - 01396064 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2015-08-24 23:08 - 2015-07-30 03:03 - 02116448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2015-08-24 23:08 - 2015-07-30 02:24 - 00252768 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2015-08-24 23:08 - 2015-07-30 01:29 - 00705520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-08-24 23:08 - 2015-07-30 01:26 - 01867160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2015-08-24 23:08 - 2015-07-30 01:26 - 00877016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2015-08-24 23:08 - 2015-07-30 01:25 - 01356368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2015-08-24 23:08 - 2015-07-30 01:25 - 00713312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2015-08-24 23:08 - 2015-07-30 01:24 - 01769056 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
2015-08-24 23:08 - 2015-07-30 01:24 - 00445240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-08-24 23:08 - 2015-07-30 01:24 - 00285632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFPlay.dll
2015-08-24 23:08 - 2015-07-30 01:21 - 00962400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2015-08-24 23:08 - 2015-07-30 01:12 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\provhandlers.dll
2015-08-24 23:08 - 2015-07-30 01:12 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll
2015-08-24 23:08 - 2015-07-30 01:08 - 00494592 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2015-08-24 23:08 - 2015-07-30 01:08 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2015-08-24 23:08 - 2015-07-30 00:52 - 00859136 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2015-08-24 23:08 - 2015-07-30 00:52 - 00521216 _____ (Microsoft Corporation) C:\Windows\system32\PsmServiceExtHost.dll
2015-08-24 23:08 - 2015-07-30 00:52 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\ACPBackgroundManagerPolicy.dll
2015-08-24 23:08 - 2015-07-30 00:49 - 11557888 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2015-08-24 23:08 - 2015-07-30 00:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2015-08-24 23:08 - 2015-07-30 00:46 - 00487424 _____ (Microsoft Corporation) C:\Windows\system32\mfmkvsrcsnk.dll
2015-08-24 23:08 - 2015-07-30 00:46 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll
2015-08-24 23:08 - 2015-07-30 00:44 - 00280064 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2015-08-24 23:08 - 2015-07-30 00:44 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\SensorService.dll
2015-08-24 23:08 - 2015-07-30 00:42 - 00518144 _____ (Microsoft Corporation) C:\Windows\system32\NotificationController.dll
2015-08-24 23:08 - 2015-07-30 00:41 - 00407040 _____ (Microsoft Corporation) C:\Windows\system32\CredProvDataModel.dll
2015-08-24 23:08 - 2015-07-30 00:40 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2015-08-24 23:08 - 2015-07-30 00:38 - 01420288 _____ (Microsoft Corporation) C:\Windows\system32\UserDataService.dll
2015-08-24 23:08 - 2015-07-30 00:34 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2015-08-24 23:08 - 2015-07-30 00:29 - 00654848 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
2015-08-24 23:08 - 2015-07-30 00:15 - 09889792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2015-08-24 23:08 - 2015-07-30 00:06 - 00373248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll
2015-08-24 23:08 - 2015-07-30 00:04 - 01714176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2015-08-24 23:08 - 2015-07-30 00:04 - 00335360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
2015-08-24 23:08 - 2015-07-29 23:59 - 00473088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2015-08-24 23:08 - 2015-07-29 23:58 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
2015-08-24 23:08 - 2015-07-26 02:16 - 01018568 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-08-24 23:08 - 2015-07-26 02:16 - 00858408 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-08-24 23:08 - 2015-07-26 02:14 - 01294352 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-08-24 23:08 - 2015-07-26 02:14 - 01123400 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-08-24 23:08 - 2015-07-26 02:13 - 06488312 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2015-08-24 23:08 - 2015-07-26 02:06 - 00607008 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-08-24 23:08 - 2015-07-26 01:28 - 05118024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2015-08-24 23:08 - 2015-07-26 00:49 - 04760576 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2015-08-24 23:08 - 2015-07-26 00:49 - 00872448 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2015-08-24 23:08 - 2015-07-26 00:47 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
2015-08-24 23:08 - 2015-07-26 00:40 - 00850432 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2015-08-24 23:08 - 2015-07-26 00:40 - 00542720 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2015-08-24 23:08 - 2015-07-26 00:39 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2015-08-24 23:08 - 2015-07-26 00:39 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\sendmail.dll
2015-08-24 23:08 - 2015-07-26 00:38 - 04350464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2015-08-24 23:08 - 2015-07-26 00:35 - 00322048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll
2015-08-24 23:08 - 2015-07-26 00:34 - 00798208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2015-08-24 23:08 - 2015-07-26 00:30 - 00750592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2015-08-24 23:08 - 2015-07-26 00:30 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2015-08-24 23:08 - 2015-07-26 00:29 - 00104960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sendmail.dll
2015-08-24 23:08 - 2015-07-24 00:30 - 00498016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2015-08-24 23:08 - 2015-07-24 00:18 - 00980832 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2015-08-24 23:08 - 2015-07-24 00:17 - 00695136 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2015-08-24 23:08 - 2015-07-24 00:12 - 00584544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wimgapi.dll
2015-08-24 23:08 - 2015-07-23 23:55 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll
2015-08-24 23:08 - 2015-07-23 23:52 - 00680448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Connectivity.dll
2015-08-24 23:08 - 2015-07-23 23:46 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\MBMediaManager.dll
2015-08-24 23:08 - 2015-07-23 23:40 - 03248640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2015-08-24 23:08 - 2015-07-23 23:39 - 02646528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2015-08-24 23:08 - 2015-07-23 23:34 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2015-08-24 23:08 - 2015-07-23 23:25 - 01203200 _____ (Microsoft Corporation) C:\Windows\system32\Unistore.dll
2015-08-24 23:08 - 2015-07-23 23:24 - 01418240 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2015-08-24 23:08 - 2015-07-23 23:24 - 00925696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Unistore.dll
2015-08-24 23:08 - 2015-07-22 02:18 - 00808856 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2015-08-24 23:08 - 2015-07-22 02:02 - 00966424 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2015-08-24 23:08 - 2015-07-22 01:02 - 00589824 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2015-08-24 23:08 - 2015-07-22 01:00 - 02235904 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-08-24 23:08 - 2015-07-22 01:00 - 00783872 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-08-24 23:08 - 2015-07-22 00:59 - 01773056 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2015-08-24 23:08 - 2015-07-22 00:55 - 01203200 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Bluetooth.dll
2015-08-24 23:08 - 2015-07-22 00:54 - 14241792 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-08-24 23:08 - 2015-07-22 00:53 - 00762896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2015-08-24 23:08 - 2015-07-22 00:46 - 00856064 _____ (Microsoft Corporation) C:\Windows\system32\ContactApis.dll
2015-08-24 23:08 - 2015-07-22 00:13 - 01611264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2015-08-24 23:08 - 2015-07-22 00:13 - 00677888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-08-24 23:08 - 2015-07-22 00:11 - 12589056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-08-24 23:08 - 2015-07-22 00:10 - 00828416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
2015-08-24 23:08 - 2015-07-22 00:07 - 00458752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2015-08-24 23:08 - 2015-07-22 00:03 - 00623616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContactApis.dll
2015-08-24 23:08 - 2015-07-21 23:50 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2015-08-24 23:08 - 2015-07-19 01:04 - 00658568 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll
2015-08-24 23:08 - 2015-07-19 00:54 - 01168736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-08-24 23:08 - 2015-07-19 00:18 - 00430592 _____ (Microsoft Corporation) C:\Windows\system32\sppcomapi.dll
2015-08-24 23:08 - 2015-07-19 00:02 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\MessagingDataModel2.dll
2015-08-24 23:08 - 2015-07-18 23:39 - 00465920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MessagingDataModel2.dll
2015-08-24 23:08 - 2015-07-18 04:43 - 00575488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Import.dll
2015-08-24 23:08 - 2015-07-18 04:37 - 01043968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Editing.dll
2015-08-24 23:08 - 2015-07-18 04:29 - 03443200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
2015-08-24 23:08 - 2015-07-18 01:06 - 00841728 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Import.dll
2015-08-24 23:08 - 2015-07-18 00:59 - 01411072 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Editing.dll
2015-08-24 23:08 - 2015-07-18 00:59 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\DevicesFlowBroker.dll
2015-08-24 23:08 - 2015-07-18 00:52 - 04169728 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2015-08-24 23:08 - 2015-07-18 00:48 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2015-08-24 23:08 - 2015-07-17 01:23 - 00934752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refsv1.sys
2015-08-24 23:08 - 2015-07-17 01:07 - 00425824 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2015-08-24 23:08 - 2015-07-16 23:36 - 07569408 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
2015-08-24 23:08 - 2015-07-16 23:32 - 00329728 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2015-08-24 23:08 - 2015-07-16 23:31 - 01417216 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-08-24 23:08 - 2015-07-16 23:26 - 00584704 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Sensors.dll
2015-08-24 23:08 - 2015-07-16 23:24 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll
2015-08-24 23:08 - 2015-07-16 23:19 - 00869376 _____ (Microsoft Corporation) C:\Windows\system32\MapControlCore.dll
2015-08-24 23:08 - 2015-07-16 23:18 - 00902656 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2015-08-24 23:08 - 2015-07-16 22:53 - 00437248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll
2015-08-24 23:08 - 2015-07-16 22:50 - 00589312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efscore.dll
2015-08-24 23:08 - 2015-07-16 22:44 - 00712192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2015-08-24 23:08 - 2015-07-16 01:09 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2015-08-24 23:08 - 2015-07-16 01:04 - 01201664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Cred.dll
2015-08-24 23:08 - 2015-07-16 01:03 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.OneCore.dll
2015-08-24 23:08 - 2015-07-16 01:01 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-24 23:08 - 2015-07-16 00:47 - 00754688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Cred.dll
2015-08-24 23:08 - 2015-07-16 00:45 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2015-08-24 23:08 - 2015-07-16 00:44 - 02741760 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-24 23:08 - 2015-07-16 00:43 - 01602560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-24 23:08 - 2015-07-16 00:41 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\ConsoleLogon.dll
2015-08-24 23:08 - 2015-07-16 00:40 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\shutdownux.dll
2015-08-24 23:08 - 2015-07-16 00:35 - 01521664 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncProvider.dll
2015-08-24 23:08 - 2015-07-16 00:33 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\srumsvc.dll
2015-08-24 23:08 - 2015-07-16 00:32 - 00667136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2015-08-24 23:08 - 2015-07-16 00:29 - 01380864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-08-24 23:08 - 2015-07-16 00:27 - 02207744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-08-24 23:08 - 2015-07-16 00:19 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srumsvc.dll
2015-08-24 23:08 - 2015-07-15 00:21 - 01365072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-08-24 23:08 - 2015-07-14 23:49 - 01591856 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-08-24 23:08 - 2015-07-14 23:49 - 00325984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2015-08-24 23:08 - 2015-07-14 23:41 - 01135312 _____ (Microsoft Corporation) C:\Windows\system32\ClipUp.exe
2015-08-24 23:08 - 2015-07-14 23:22 - 02112512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2015-08-24 23:08 - 2015-07-14 23:16 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsApi.dll
2015-08-24 23:08 - 2015-07-14 22:57 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\OmaDmAgent.dll
2015-08-24 23:08 - 2015-07-14 22:47 - 04611584 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-08-24 23:08 - 2015-07-14 22:41 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\SensorsApi.dll
2015-08-24 23:08 - 2015-07-14 22:35 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\unenrollhook.dll
2015-08-24 23:08 - 2015-07-13 22:51 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2015-08-24 23:08 - 2015-07-13 22:49 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2015-08-24 23:08 - 2015-07-12 20:30 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcastdvr.exe
2015-08-24 23:08 - 2015-07-11 21:38 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2015-08-24 23:08 - 2015-07-11 21:25 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\SensorDataService.exe
2015-08-24 23:08 - 2015-07-11 21:18 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\AppContracts.dll
2015-08-24 23:08 - 2015-07-11 20:46 - 00441344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppContracts.dll
2015-08-24 23:08 - 2015-07-10 22:28 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BioFeedback.dll
2015-08-24 23:08 - 2015-07-10 22:17 - 06305792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2015-08-24 23:08 - 2015-07-10 22:07 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2015-08-24 23:08 - 2015-07-10 22:05 - 00263168 _____ (Microsoft Corporation) C:\Windows\system32\DisplayManager.dll
2015-08-24 23:08 - 2015-07-10 22:04 - 03362816 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-08-24 23:08 - 2015-07-10 22:03 - 03248128 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2015-08-24 23:08 - 2015-07-10 22:02 - 00283648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BioFeedback.dll
2015-08-24 23:08 - 2015-07-10 21:57 - 00670208 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll
2015-08-24 23:08 - 2015-07-10 21:51 - 04398080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2015-08-24 23:08 - 2015-07-10 21:43 - 00322048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll
2015-08-24 23:08 - 2015-07-10 21:42 - 00191488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DisplayManager.dll
2015-08-24 23:08 - 2015-07-10 21:41 - 03687936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-08-24 23:08 - 2015-07-10 21:40 - 02606080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2015-08-24 23:08 - 2015-07-10 21:34 - 00294912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll
2015-08-24 23:08 - 2015-07-10 12:51 - 00823336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2015-08-24 23:08 - 2015-07-10 12:47 - 00265480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-08-24 23:08 - 2015-07-10 12:00 - 01101792 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2015-08-24 23:08 - 2015-07-10 11:52 - 00335248 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-08-24 23:08 - 2015-07-10 07:05 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll
2015-08-24 23:08 - 2015-07-10 06:53 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2015-08-24 23:08 - 2015-07-10 06:35 - 00359936 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-08-24 23:08 - 2015-07-10 06:31 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-08-24 23:08 - 2015-07-10 06:29 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll
2015-08-24 23:07 - 2015-08-13 01:20 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2015-08-24 23:07 - 2015-08-13 00:53 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2015-08-24 23:07 - 2015-08-11 07:03 - 00442208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2015-08-24 23:07 - 2015-08-11 07:02 - 00080720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2015-08-24 23:07 - 2015-08-11 06:52 - 00993104 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2015-08-24 23:07 - 2015-08-11 06:26 - 00845664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2015-08-24 23:07 - 2015-08-11 06:21 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\tetheringservice.dll
2015-08-24 23:07 - 2015-08-11 06:21 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\tetheringclient.dll
2015-08-24 23:07 - 2015-08-11 06:20 - 00483328 _____ (Microsoft Corporation) C:\Windows\system32\OneDriveSettingSyncProvider.dll
2015-08-24 23:07 - 2015-08-11 06:19 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Notifications.dll
2015-08-24 23:07 - 2015-08-11 06:18 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\UserMgrProxy.dll
2015-08-24 23:07 - 2015-08-11 06:11 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe
2015-08-24 23:07 - 2015-08-11 06:10 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-24 23:07 - 2015-08-11 06:10 - 00293376 _____ C:\Windows\system32\TextInputFramework.dll
2015-08-24 23:07 - 2015-08-11 06:09 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\wuautoappupdate.dll
2015-08-24 23:07 - 2015-08-11 06:07 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe
2015-08-24 23:07 - 2015-08-11 06:05 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\LocationGeofences.dll
2015-08-24 23:07 - 2015-08-11 06:05 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\LocationFramework.dll
2015-08-24 23:07 - 2015-08-11 06:05 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\LocationFrameworkInternalPS.dll
2015-08-24 23:07 - 2015-08-11 06:02 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2015-08-24 23:07 - 2015-08-11 06:02 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\cloudAP.dll
2015-08-24 23:07 - 2015-08-11 06:00 - 00336384 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2015-08-24 23:07 - 2015-08-11 06:00 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\syncutil.dll
2015-08-24 23:07 - 2015-08-11 05:59 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-08-24 23:07 - 2015-08-11 05:59 - 00642560 _____ (Microsoft Corporation) C:\Windows\system32\rdbui.dll
2015-08-24 23:07 - 2015-08-11 05:59 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2015-08-24 23:07 - 2015-08-11 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tetheringclient.dll
2015-08-24 23:07 - 2015-08-11 05:58 - 00372224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll
2015-08-24 23:07 - 2015-08-11 05:57 - 00159744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
2015-08-24 23:07 - 2015-08-11 05:50 - 00420352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GamePanel.exe
2015-08-24 23:07 - 2015-08-11 05:50 - 00200704 _____ C:\Windows\SysWOW64\TextInputFramework.dll
2015-08-24 23:07 - 2015-08-11 05:50 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll
2015-08-24 23:07 - 2015-08-11 05:49 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-24 23:07 - 2015-08-11 05:48 - 00671232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
2015-08-24 23:07 - 2015-08-11 05:47 - 00448512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApi.dll
2015-08-24 23:07 - 2015-08-11 05:39 - 00280576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2015-08-24 23:07 - 2015-08-11 05:38 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReInfo.dll
2015-08-24 23:07 - 2015-08-06 00:17 - 00200528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wof.sys
2015-08-24 23:07 - 2015-08-04 01:06 - 00243248 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-08-24 23:07 - 2015-08-04 00:23 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\VPNv2CSP.dll
2015-08-24 23:07 - 2015-08-02 23:18 - 00046432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpiowin32.sys
2015-08-24 23:07 - 2015-08-02 23:17 - 00052264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wpcfltr.sys
2015-08-24 23:07 - 2015-08-02 22:22 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\configmanager2.dll
2015-08-24 23:07 - 2015-08-02 22:21 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\coredpus.dll
2015-08-24 23:07 - 2015-08-02 22:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-24 23:07 - 2015-08-02 22:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-24 23:07 - 2015-08-02 22:06 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
2015-08-24 23:07 - 2015-07-30 03:15 - 00632168 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2015-08-24 23:07 - 2015-07-30 01:24 - 00407616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-08-24 23:07 - 2015-07-30 01:22 - 00896144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2015-08-24 23:07 - 2015-07-30 01:22 - 00507696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2015-08-24 23:07 - 2015-07-30 01:09 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManagerShellext.exe
2015-08-24 23:07 - 2015-07-30 01:08 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2015-08-24 23:07 - 2015-07-30 00:59 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll
2015-08-24 23:07 - 2015-07-30 00:45 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\fwpolicyiomgr.dll
2015-08-24 23:07 - 2015-07-30 00:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
2015-08-24 23:07 - 2015-07-30 00:44 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SensorsNativeApi.V2.dll
2015-08-24 23:07 - 2015-07-30 00:44 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthhfenum.sys
2015-08-24 23:07 - 2015-07-30 00:44 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\VoiceActivationManager.dll
2015-08-24 23:07 - 2015-07-30 00:41 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\NotificationControllerPS.dll
2015-08-24 23:07 - 2015-07-30 00:38 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\AppxSysprep.dll
2015-08-24 23:07 - 2015-07-30 00:07 - 00163328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwpolicyiomgr.dll
2015-08-24 23:07 - 2015-07-30 00:06 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsNativeApi.V2.dll
2015-08-24 23:07 - 2015-07-30 00:06 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VoiceActivationManager.dll
2015-08-24 23:07 - 2015-07-24 00:17 - 00521568 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2015-08-24 23:07 - 2015-07-23 23:44 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Privacy.dll
2015-08-24 23:07 - 2015-07-23 23:30 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2015-08-24 23:07 - 2015-07-23 23:29 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys
2015-08-24 23:07 - 2015-07-23 23:24 - 01061888 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2015-08-24 23:07 - 2015-07-23 23:24 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\ReInfo.dll
2015-08-24 23:07 - 2015-07-22 02:15 - 00565088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2015-08-24 23:07 - 2015-07-22 01:13 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe
2015-08-24 23:07 - 2015-07-22 01:00 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2015-08-24 23:07 - 2015-07-22 00:55 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Bluetooth.dll
2015-08-24 23:07 - 2015-07-22 00:21 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\calc.exe
2015-08-24 23:07 - 2015-07-22 00:09 - 00296960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll
2015-08-24 23:07 - 2015-07-19 00:23 - 00505344 _____ C:\Windows\system32\EditionUpgradeManagerObj.dll
2015-08-24 23:07 - 2015-07-18 05:47 - 00082616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcd.dll
2015-08-24 23:07 - 2015-07-18 04:28 - 00584704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll
2015-08-24 23:07 - 2015-07-18 04:28 - 00037376 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-08-24 23:07 - 2015-07-18 04:26 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spbcd.dll
2015-08-24 23:07 - 2015-07-18 02:17 - 00097128 _____ (Microsoft Corporation) C:\Windows\system32\bcd.dll
2015-08-24 23:07 - 2015-07-18 02:02 - 00290312 _____ (Microsoft Corporation) C:\Windows\system32\wininit.exe
2015-08-24 23:07 - 2015-07-18 00:50 - 00584704 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2015-08-24 23:07 - 2015-07-18 00:50 - 00045568 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-24 23:07 - 2015-07-18 00:49 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2015-08-24 23:07 - 2015-07-18 00:49 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\BootMenuUX.dll
2015-08-24 23:07 - 2015-07-18 00:49 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\spbcd.dll
2015-08-24 23:07 - 2015-07-18 00:48 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\bcdboot.exe
2015-08-24 23:07 - 2015-07-18 00:47 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-08-24 23:07 - 2015-07-17 01:13 - 00601344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-08-24 23:07 - 2015-07-17 01:12 - 00630160 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2015-08-24 23:07 - 2015-07-16 23:39 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\MapConfiguration.dll
2015-08-24 23:07 - 2015-07-16 23:39 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-08-24 23:07 - 2015-07-16 23:33 - 00120832 _____ (Microsoft Corporation) C:\Windows\system32\omadmclient.exe
2015-08-24 23:07 - 2015-07-16 23:33 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\omadmprc.exe
2015-08-24 23:07 - 2015-07-16 23:26 - 07051264 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll
2015-08-24 23:07 - 2015-07-16 23:19 - 00832512 _____ (Microsoft Corporation) C:\Windows\system32\MapsStore.dll
2015-08-24 23:07 - 2015-07-16 23:05 - 00328704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapConfiguration.dll
2015-08-24 23:07 - 2015-07-16 23:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-08-24 23:07 - 2015-07-16 22:56 - 06101504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2015-08-24 23:07 - 2015-07-16 22:51 - 05076480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll
2015-08-24 23:07 - 2015-07-16 02:39 - 00061280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys
2015-08-24 23:07 - 2015-07-16 00:54 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\VEStoreEventHandlers.dll
2015-08-24 23:07 - 2015-07-16 00:36 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\ConhostV2.dll
2015-08-24 23:07 - 2015-07-14 23:04 - 00032768 _____ C:\Windows\system32\LicenseManagerApi.dll
2015-08-24 23:07 - 2015-07-14 22:37 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.ProxyStub.dll
2015-08-24 23:07 - 2015-07-14 22:27 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.PAL.Desktop.dll
2015-08-24 23:07 - 2015-07-14 00:00 - 00208736 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll
2015-08-24 23:07 - 2015-07-13 23:37 - 00181088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll
2015-08-24 23:07 - 2015-07-13 23:04 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UcmUcsi.sys
2015-08-24 23:07 - 2015-07-13 22:38 - 00291840 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll
2015-08-24 23:07 - 2015-07-13 22:20 - 00279552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\systemcpl.dll
2015-08-24 23:07 - 2015-07-12 21:01 - 00342528 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvr.exe
2015-08-24 23:07 - 2015-07-10 22:03 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-08-24 23:07 - 2015-07-10 22:01 - 04791296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-24 23:07 - 2015-07-10 21:40 - 03579904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-08-24 23:07 - 2015-07-10 21:40 - 00058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2015-08-24 23:07 - 2015-07-10 07:59 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_SignInOptions.dll
2015-08-24 23:07 - 2015-07-10 07:42 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hmkd.dll
2015-08-24 23:07 - 2015-07-10 07:10 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\hmkd.dll
2015-08-24 22:59 - 2015-08-24 22:59 - 00000000 ____D C:\Users\manoe\AppData\Roaming\Macromedia
2015-08-24 22:57 - 2015-08-24 22:58 - 00000000 ____D C:\Users\manoe\AppData\Local\MicrosoftEdge
2015-08-23 17:42 - 2015-08-23 19:07 - 40957775 _____ C:\Users\mateu\Downloads\SW2011-SP0-x64.iso.bw7kj3r.partial
2015-08-23 17:41 - 2015-09-17 19:53 - 00000000 ____D C:\Users\mateu\AppData\Local\Popcorn-Time
2015-08-23 17:39 - 2015-09-13 16:50 - 00000000 ____D C:\Users\mateu\AppData\Local\Popcorn Time
2015-08-23 17:37 - 2015-08-23 17:37 - 00000000 ____D C:\Users\mateu\Downloads\Autoruns
2015-08-23 17:34 - 2015-08-23 17:39 - 29144304 _____ (Popcorn Official) C:\Users\mateu\Downloads\Popcorn-Time-0.3.8-3-Setup.exe
2015-08-23 17:33 - 2015-08-23 17:33 - 00000870 _____ C:\AdwCleaner[S3].txt
2015-08-23 17:30 - 2015-08-23 17:30 - 00000000 ____H C:\Users\Todos os Usuários\DP45977C.lfl
2015-08-23 17:30 - 2015-08-23 17:30 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2015-08-23 17:30 - 2015-08-23 17:30 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2015-08-23 17:30 - 2015-08-23 17:30 - 00000000 ____D C:\Windows\system32\DAX2
2015-08-23 17:30 - 2015-08-23 17:30 - 00000000 ____D C:\Program Files\Realtek
2015-08-23 17:29 - 2015-08-23 17:29 - 72121872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2015-08-23 17:29 - 2015-08-23 17:29 - 14057256 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 13119736 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO3064.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 12956576 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO4064.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 07172920 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 07096192 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 06251328 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64AF3.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 05804772 _____ C:\Windows\system32\Drivers\rtvienna.dat
2015-08-23 17:29 - 2015-08-23 17:29 - 05767904 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV2apo.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 05289944 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 04504320 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2015-08-23 17:29 - 2015-08-23 17:29 - 03299824 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE2.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 03271912 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 03232448 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 03166128 _____ (Intel Corporation) C:\Windows\system32\IntelSSTAPO.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 03157796 _____ C:\Windows\system32\Drivers\rtkSSTsetting.dat
2015-08-23 17:29 - 2015-08-23 17:29 - 02926848 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 02882408 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 02823280 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO7064.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 02813457 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2015-08-23 17:29 - 2015-08-23 17:29 - 02710784 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2015-08-23 17:29 - 2015-08-23 17:29 - 02562704 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RltkAPO.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 02491640 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv211.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 02423480 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv201.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 02190992 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 02110600 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 02050184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01965816 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01959608 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64AF3.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01780624 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01756928 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01599792 _____ (Conexant Systems Inc.) C:\Windows\system32\CX64APO.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01591064 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01508936 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01435144 _____ (Synopsys, Inc.) C:\Windows\system32\SRRPTR64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01395760 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO6064.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01382240 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01336528 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01334384 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01211832 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO5064.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01164336 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO4064.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01122640 _____ (SRS Labs, Inc.) C:\Windows\system32\slcnt64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 01003864 _____ (Nahimic Inc) C:\Windows\system32\NahimicAPONSControl.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00998032 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO2064.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00965032 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00962176 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOProp.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00961016 _____ (DTS, Inc.) C:\Windows\system32\sl3apo64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00931624 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00923744 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00888472 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaeapo64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00874728 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDRA64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00873464 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00749776 _____ (DTS, Inc.) C:\Windows\system32\sltech64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00743968 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00737136 _____ (Intel Corporation) C:\Windows\system32\IntelSstCApoPropPage.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00727440 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00708312 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00699064 _____ (Sound Research, Corp.) C:\Windows\system32\SECOMN64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00678184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00677672 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00645456 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00618192 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00596120 _____ (TOSHIBA Corporation) C:\Windows\system32\tosasfapo64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00574248 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00569440 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SECOMN32.DLL
2015-08-23 17:29 - 2015-08-23 17:29 - 00532384 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00514528 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00504312 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00500560 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00467160 _____ (Synopsys, Inc.) C:\Windows\system32\SRAPO64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00448584 _____ (Sound Research, Corp.) C:\Windows\system32\SEAPO64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00447720 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00445400 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00441272 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00428232 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00387320 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00381416 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00358272 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2API.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00348088 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64AF3.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00343712 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00341152 _____ (Synopsys, Inc.) C:\Windows\SysWOW64\SRCOM.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00341152 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00340648 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00330568 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00327456 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00296496 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64F3.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00272720 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00259288 _____ (TODO: ) C:\Windows\system32\slprp64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00253904 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00253864 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00252880 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00231920 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00224256 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaemaxapo64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00221968 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00214832 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00209536 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00176968 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00172584 _____ (TOSHIBA Corporation) C:\Windows\system32\toseaeapo64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00166208 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00158704 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00151792 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00134200 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00122328 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00118600 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00118592 _____ C:\Windows\system32\AcpiServiceVnA64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00110984 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00105312 _____ C:\Windows\system32\audioLibVc.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00090920 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00088352 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00088328 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00084616 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00083632 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00075544 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll
2015-08-23 17:29 - 2015-08-23 17:29 - 00023696 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2015-08-23 17:24 - 2015-09-16 14:06 - 00000000 ____D C:\Users\manoe\OneDrive
2015-08-23 17:24 - 2015-09-16 13:30 - 00002340 _____ C:\Users\manoe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-08-23 17:22 - 2015-08-23 17:22 - 00000000 ____D C:\Users\manoe\AppData\Roaming\AVAST Software
2015-08-23 17:20 - 2015-08-23 17:20 - 00193336 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverW8x64.sys
2015-08-23 17:19 - 2015-08-23 17:19 - 00000000 ____D C:\Users\manoe\AppData\Local\Publishers
2015-08-23 17:18 - 2015-09-16 13:28 - 00000000 ____D C:\Users\manoe\AppData\Local\Packages
2015-08-23 17:18 - 2015-08-23 17:26 - 00000000 ____D C:\Users\manoe\AppData\Local\Comms
2015-08-23 17:18 - 2015-08-23 17:24 - 00000000 ____D C:\Users\manoe
2015-08-23 17:18 - 2015-08-23 17:18 - 00000020 ___SH C:\Users\manoe\ntuser.ini
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\Modelos
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\Meus Documentos
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\Menu Iniciar
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\Documents\Minhas Músicas
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\Documents\Minhas Imagens
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\Documents\Meus Vídeos
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\Dados de Aplicativos
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\Configurações Locais
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\AppData\Local\Histórico
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\AppData\Local\Dados de Aplicativos
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\Ambiente de Rede
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 _SHDL C:\Users\manoe\Ambiente de Impressão
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 ___RD C:\Users\manoe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 ____D C:\Users\manoe\AppData\Roaming\Adobe
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 ____D C:\Users\manoe\AppData\Local\VirtualStore
2015-08-23 17:18 - 2015-08-23 17:18 - 00000000 ____D C:\Users\manoe\AppData\Local\TileDataLayer
2015-08-23 17:18 - 2015-07-10 08:04 - 00000000 __RSD C:\Users\manoe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-08-23 17:18 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\manoe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-23 17:18 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\manoe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-23 17:18 - 2015-07-10 08:04 - 00000000 ____D C:\Users\manoe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-23 17:01 - 2015-08-23 17:01 - 00012034 _____ C:\AdwCleaner[C1].txt
2015-08-23 17:01 - 2015-08-23 17:01 - 00011025 _____ C:\AdwCleaner[S2].txt
2015-08-23 16:59 - 2015-09-17 19:49 - 00004280 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-08-23 16:59 - 2015-08-23 16:59 - 01048344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2015-08-23 16:59 - 2015-08-23 16:59 - 00447944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-08-23 16:59 - 2015-08-23 16:59 - 00378880 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-08-23 16:59 - 2015-08-23 16:59 - 00274808 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-08-23 16:59 - 2015-08-23 16:59 - 00150672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-08-23 16:59 - 2015-08-23 16:59 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-08-23 16:59 - 2015-08-23 16:59 - 00090968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-08-23 16:59 - 2015-08-23 16:59 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-08-23 16:59 - 2015-08-23 16:59 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-08-23 16:59 - 2015-08-23 16:59 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-08-23 16:59 - 2015-08-23 16:59 - 00000000 ____D C:\Users\mateu\AppData\Roaming\AVAST Software
2015-08-23 16:59 - 2015-08-23 16:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-08-23 16:54 - 2015-08-23 17:01 - 00000000 ____D C:\AdwCleaner
2015-08-23 16:54 - 2015-08-23 16:54 - 00011294 _____ C:\AdwCleaner[S1].txt
2015-08-23 16:54 - 2015-08-23 16:54 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-08-23 16:51 - 2015-08-23 16:54 - 01573888 _____ C:\Users\mateu\Downloads\adwcleaner-5-001-multi-win.exe
2015-08-23 16:46 - 2015-08-23 16:46 - 00000000 ____D C:\Program Files\AVAST Software
2015-08-23 16:46 - 2015-08-23 16:46 - 00000000 _____ C:\Windows\prleth.sys
2015-08-23 16:46 - 2015-08-23 16:46 - 00000000 _____ C:\Windows\hgfs.sys
2015-08-23 16:45 - 2015-08-23 16:49 - 00000000 ____D C:\Users\Todos os Usuários\update
2015-08-23 16:45 - 2015-08-23 16:49 - 00000000 ____D C:\ProgramData\update
2015-08-23 16:43 - 2015-08-23 16:43 - 00009927 _____ C:\Windows\unins000.dat
2015-08-23 16:43 - 2015-08-23 16:42 - 00717985 _____ C:\Windows\unins000.exe
2015-08-23 16:42 - 2015-09-17 19:52 - 00000000 ____D C:\Users\mateu\AppData\Roaming\RunDir
2015-08-23 16:42 - 2015-08-23 16:42 - 00000000 ____D C:\Users\mateu\AppData\Roaming\NetService
2015-08-23 16:40 - 2015-08-23 16:40 - 00000000 ____D C:\Users\Todos os Usuários\AVAST Software
2015-08-23 16:40 - 2015-08-23 16:40 - 00000000 ____D C:\ProgramData\AVAST Software
2015-08-23 16:34 - 2015-08-23 16:36 - 05500000 _____ (Avast Software s.r.o.) C:\Users\mateu\Downloads\avast_free_antivirus_setup_online (1).exe
2015-08-23 16:32 - 2015-08-23 16:40 - 05500000 _____ (Avast Software s.r.o.) C:\Users\mateu\Downloads\avast_free_antivirus_setup_online.exe
2015-08-23 16:23 - 2015-09-17 22:34 - 00000000 ____D C:\Users\mateu\AppData\Roaming\Skype
2015-08-23 16:22 - 2015-09-03 21:56 - 00000000 ____D C:\Users\Todos os Usuários\Skype
2015-08-23 16:22 - 2015-09-03 21:56 - 00000000 ____D C:\ProgramData\Skype
2015-08-23 16:21 - 2015-09-17 20:23 - 00001836 _____ C:\Users\mateu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-08-23 16:21 - 2015-09-10 22:55 - 00000000 ____D C:\Users\mateu\AppData\Local\Spotify
2015-08-23 16:21 - 2015-08-23 16:21 - 00000000 ____D C:\Users\mateu\AppData\Local\CEF
2015-08-23 16:19 - 2015-09-10 21:41 - 00000000 ____D C:\Users\mateu\AppData\Roaming\Spotify
2015-08-23 16:16 - 2015-08-23 16:16 - 00000000 ____D C:\Users\mateu\AppData\Local\PackageStaging
2015-08-23 14:44 - 2014-06-19 13:23 - 00022608 _____ C:\Users\mateu\Documents\Snagit v11.0.0.207.exe
2015-08-23 14:44 - 2013-12-09 19:59 - 00047332 _____ C:\Users\mateu\Documents\Repair welding influence on offshore pipelines residual.pptx
2015-08-23 14:44 - 2013-02-24 09:54 - 03234816 _____ C:\Users\mateu\Documents\Aves e mamíferos 4.ppt
2015-08-23 14:44 - 2013-02-16 10:22 - 29743720 _____ (Skype Technologies S.A.) C:\Users\mateu\Documents\SkypeSetupFull.exe
2015-08-23 14:43 - 2013-12-08 22:15 - 71288664 _____ C:\Users\mateu\Documents\829-snagit.exe
2015-08-23 14:40 - 2015-08-23 14:43 - 00000000 ____D C:\Users\mateu\Documents\UFF
2015-08-23 14:40 - 2015-08-23 14:40 - 00000000 ____D C:\Users\mateu\Documents\Solid peças
2015-08-23 14:39 - 2015-08-23 14:39 - 00000000 ____D C:\Users\mateu\AppData\Roaming\Macromedia
2015-08-23 14:38 - 2015-08-23 14:38 - 00000000 ____D C:\Users\mateu\AppData\Local\MicrosoftEdge
2015-08-23 14:37 - 2015-08-23 14:40 - 00000000 ____D C:\Users\mateu\Documents\office
2015-08-23 14:37 - 2015-08-23 14:37 - 00000000 ____D C:\Users\mateu\Documents\Músicas
2015-08-23 14:35 - 2015-08-23 14:35 - 00000000 ____D C:\Users\mateu\Documents\CEFET-RJ
2015-08-23 14:35 - 2015-02-20 11:04 - 00137888 _____ (Spotify Ltd) C:\Users\mateu\Documents\SpotifySetup.exe
2015-08-23 14:29 - 2015-09-17 20:23 - 00002340 _____ C:\Users\mateu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-08-23 14:29 - 2015-08-23 17:36 - 00000000 ____D C:\Users\mateu\OneDrive
2015-08-23 14:29 - 2015-08-23 16:22 - 00000000 ____D C:\Users\mateu\AppData\Local\Comms
2015-08-23 14:29 - 2015-08-23 14:29 - 00000000 ____D C:\Users\Todos os Usuários\Microsoft OneDrive
2015-08-23 14:29 - 2015-08-23 14:29 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-08-23 14:27 - 2015-09-15 22:07 - 00000000 ____D C:\Users\mateu\AppData\Local\Packages
2015-08-23 14:27 - 2015-09-03 22:10 - 00000000 ____D C:\Users\mateu\AppData\Local\VirtualStore
2015-08-23 14:27 - 2015-08-23 14:27 - 00016148 _____ C:\Windows\system32\DESKTOP-8475GNN_defaultuser0_HistoryPrediction.bin
2015-08-23 14:27 - 2015-08-23 14:27 - 00000000 ____D C:\Users\mateu\AppData\Roaming\Adobe
2015-08-23 14:27 - 2015-08-23 14:27 - 00000000 ____D C:\Users\mateu\AppData\Local\TileDataLayer
2015-08-23 14:27 - 2015-08-23 14:27 - 00000000 ____D C:\Users\mateu\AppData\Local\Publishers
2015-08-23 14:26 - 2015-09-17 22:42 - 01720508 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-23 14:25 - 2015-09-13 17:04 - 00000000 ____D C:\Users\mateu
2015-08-23 14:25 - 2015-08-23 17:01 - 00000000 ___RD C:\Users\mateu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-23 14:25 - 2015-08-23 14:25 - 00000020 ___SH C:\Users\mateu\ntuser.ini
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\Modelos
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\Meus Documentos
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\Menu Iniciar
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\Documents\Minhas Músicas
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\Documents\Minhas Imagens
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\Documents\Meus Vídeos
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\Dados de Aplicativos
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\Configurações Locais
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\AppData\Local\Histórico
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\AppData\Local\Dados de Aplicativos
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\Ambiente de Rede
2015-08-23 14:25 - 2015-08-23 14:25 - 00000000 _SHDL C:\Users\mateu\Ambiente de Impressão
2015-08-23 14:25 - 2015-07-10 08:04 - 00000000 __RSD C:\Users\mateu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-08-23 14:25 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\mateu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-23 14:25 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\mateu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-23 14:25 - 2015-07-10 08:04 - 00000000 ____D C:\Users\mateu\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas Músicas
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Minhas Imagens
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Usuário Padrão\Documents\Meus Vídeos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Histórico
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Usuário Padrão\AppData\Local\Dados de Aplicativos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Usuário Padrão
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Todos os Usuários\Modelos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Todos os Usuários\Menu Iniciar
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Todos os Usuários\Documentos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Todos os Usuários\Dados de Aplicativos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Todos os Usuários
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Public\Documents\Minhas Músicas
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Public\Documents\Minhas Imagens
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Public\Documents\Meus Vídeos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\Modelos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\Meus Documentos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\Menu Iniciar
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\Documents\Minhas Músicas
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\Documents\Minhas Imagens
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\Documents\Meus Vídeos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\Dados de Aplicativos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\Configurações Locais
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\AppData\Local\Histórico
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\AppData\Local\Dados de Aplicativos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\Ambiente de Rede
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default\Ambiente de Impressão
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default User\Documents\Minhas Músicas
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default User\Documents\Minhas Imagens
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default User\Documents\Meus Vídeos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programas
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Histórico
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Dados de Aplicativos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\ProgramData\Modelos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programas
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\ProgramData\Menu Iniciar
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\ProgramData\Documentos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\ProgramData\Dados de Aplicativos
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Program Files\Common Files\Sistema
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Program Files\Arquivos Comuns
2015-08-23 14:20 - 2015-08-23 14:20 - 00000000 _SHDL C:\Arquivos de Programas
2015-08-23 14:18 - 2015-08-30 12:12 - 00000000 __SHD C:\Recovery
2015-08-23 14:18 - 2015-07-10 07:59 - 02718208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2015-08-23 14:16 - 2015-08-23 14:16 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-08-23 14:15 - 2015-09-17 22:35 - 00040610 _____ C:\Windows\PFRO.log
2015-08-23 14:15 - 2015-08-23 14:24 - 00000000 ____D C:\Windows\Panther
2015-08-23 14:15 - 2015-08-23 14:15 - 00008192 __RSH C:\BOOTSECT.BAK

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-09-17 23:36 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\sru
2015-09-17 22:42 - 2015-07-10 13:36 - 00745002 _____ C:\Windows\system32\prfh0416.dat
2015-09-17 22:42 - 2015-07-10 13:36 - 00145032 _____ C:\Windows\system32\prfc0416.dat
2015-09-17 22:40 - 2015-07-10 09:22 - 00000275 _____ C:\Windows\WindowsUpdate.log
2015-09-17 22:35 - 2015-07-10 09:21 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-17 22:34 - 2015-07-10 06:05 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-09-17 21:06 - 2015-07-10 09:20 - 00011949 _____ C:\Windows\setupact.log
2015-09-17 21:06 - 2015-07-10 08:04 - 00000134 _____ C:\Windows\win.ini
2015-09-17 20:28 - 2015-07-10 13:37 - 00000000 ____D C:\Windows\SKB
2015-09-17 19:56 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\AppReadiness
2015-09-13 16:35 - 2015-07-10 08:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-09-13 15:37 - 2015-07-10 09:20 - 00340656 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-13 15:15 - 2015-07-10 07:55 - 00000000 ____D C:\Windows\CbsTemp
2015-09-13 14:49 - 2015-07-10 08:04 - 00000000 ___RD C:\Windows\PurchaseDialog
2015-09-13 14:49 - 2015-07-10 08:04 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2015-09-13 14:49 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\Usuário Padrão\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-13 14:49 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-13 14:49 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-13 14:49 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\SysWOW64\oobe
2015-09-13 14:49 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2015-09-13 14:49 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\SystemResetPlatform
2015-09-13 14:49 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\oobe
2015-09-13 14:49 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\appraiser
2015-09-13 14:49 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\Provisioning
2015-09-13 14:49 - 2015-07-10 06:05 - 00000000 ____D C:\Windows\SysWOW64\Dism
2015-09-13 14:49 - 2015-07-10 06:05 - 00000000 ____D C:\Windows\system32\Dism
2015-08-30 12:31 - 2015-07-10 13:48 - 00000000 ____D C:\Windows\ShellNew
2015-08-30 12:30 - 2015-07-10 08:04 - 00000000 ____D C:\Program Files\Common Files\System
2015-08-27 15:10 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\System
2015-08-24 23:16 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\Help
2015-08-24 22:56 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\appcompat
2015-08-23 14:27 - 2015-07-10 08:04 - 00000000 ___RD C:\Windows\PrintDialog
2015-08-23 14:27 - 2015-07-10 08:04 - 00000000 ___RD C:\Windows\MiracastView
2015-08-23 14:26 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\WinBioDatabase
2015-08-23 14:24 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\restore
2015-08-23 14:23 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\rescache
2015-08-23 14:22 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\spool
2015-08-23 14:20 - 2015-07-10 08:04 - 00000000 ____D C:\Program Files\Windows NT
2015-08-23 14:20 - 2015-07-10 06:05 - 00000000 __RHD C:\Users\Default
2015-08-23 14:18 - 2015-07-10 08:05 - 00002133 _____ C:\Windows\DtcInstall.log
2015-08-23 14:18 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\Recovery
2015-08-23 14:18 - 2015-07-10 08:04 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-08-23 14:18 - 2015-07-10 06:05 - 00000000 ____D C:\Windows\system32\Sysprep
2015-08-23 14:15 - 2015-07-10 08:04 - 00028672 _____ C:\Windows\system32\config\BCD-Template

==================== Files in the root of some directories =======

2015-08-23 17:30 - 2015-08-23 17:30 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\mateu\AppData\Local\Temp\sqlite3.dll
C:\Users\mateu\AppData\Local\Temp\update.exe
C:\Users\mateu\AppData\Local\Temp\vcredist_x86.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-09-17 20:57

==================== End of FRST.txt ============================

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.2 (09.14.2015:1)
OS: Windows 10 Home x64
Ran by mateu on 17/09/2015 at 22:58:43,68
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys



~~~ Files



~~~ Folders



~~~ Chrome


[C:\Users\mateu\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\mateu\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\mateu\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\mateu\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17/09/2015 at 23:24:49,95
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~ ZHPCleaner v2015.9.16.348 by Nicolas Coolman (2015/09/16)
~ Run by mateu (Administrator) (18/09/2015 00:09:57)
~ Site : http://www.nicolascoolman.fr
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : Version OK
~ Type : Reparo
~ Report : C:\Users\mateu\Desktop\ZHPCleaner.txt
~ Quarantine : C:\Users\mateu\AppData\Roaming\ZHP\ZHPCleaner_Quarantine.txt
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Home, 64-bit (Build 10240)


---\\ Serviços (0)
~ Nenhum ítem malicioso o desnecessários foi encontrado.


---\\ Navegadores de Internet (0)
~ Nenhum ítem malicioso o desnecessários foi encontrado.


---\\ Arquivo hosts (1)
~ O arquivo hosts é legítimo (21)


---\\ Tarefas automáticas agendadas. (0)
~ Nenhum ítem malicioso o desnecessários foi encontrado.


---\\ Explorer ( Arquivos, Pastas) (8)
MOVIDO pasta: C:\Windows\Prefetch\MOVIEDEA.EXE-A44C8D38.pf =>PUP.Optional.MovieDea
MOVIDO pasta: C:\Windows\Prefetch\OURSURFINGEIPC_18_08--E8ECAE9-944FFA34.pf =>PUP.Optional.OurSurfing
MOVIDO pasta: C:\Users\mateu\Downloads\Microsoft Office 2013 PT-BR X64 + crack - By baixetorrents.com\Crack\Microsoft Toolkit.exe [CODYQX4 - Microsoft Toolkit] =>HackTool.AutoKMS
MOVIDO pasta: C:\Users\mateu\AppData\Local\Microsoft\Windows\INetCache\IE\1CQ7TAXT\yet_another_cleaner_bxk[1].exe =>PUP.Optional.YetAnotherCleaner
MOVIDO pasta: C:\Windows\AutoKMS\AutoKMS.exe [CODYQX4 - AutoKMS] =>HackTool.AutoKMS
MOVIDO pasta: C:\Windows\AutoKMS\AutoKMS.log =>HackTool.AutoKMS
MOVIDO arquivo: C:\Windows\AutoKMS =>HackTool.AutoKMS
MOVIDO arquivo: C:\Users\mateu\AppData\Local\Microsoft Toolkit =>HackTool.AutoKMS


---\\ Registro ( Chaves, Valores, Dados ) (0)
~ Nenhum ítem malicioso o desnecessários foi encontrado.


---\\ Resultado de reparação
Reparação efectuada com sucesso
~ Este navegador está faltando ! (Mozilla Firefox)
~ Este navegador está faltando ! (Opera Software)


---\\ Estatísticas
~ Items scan : 541
~ Items encontrado : 0
~ items cancelados : 0
~ Items réparo : 8


~ End of clean in 0 minutes
===================
ZHPCleaner-[R]-17092015-23_59_58.txt
ZHPCleaner-[R]-18092015-00_10_07.txt
ZHPCleaner-[S]-17092015-23_56_08.txt
ZHPCleaner-[S]-18092015-00_05_42.txt

[/S][/S]
[S][S][/s][/s]
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#2 Por joram
18/09/2015 - 06:12
/!\ Bom Dia! Mcampos25 /!\

> Baixe: < Imagem > < Imagem > ( ... de Nicolas Coolman )

Imagem

> Estando na página,clique: Télécharge
> Salve-a ao desktop! ( ZHPDiag3 )

Imagem

> Execute ZHPDiag3.exe,como administrador,para instalar a ferramenta!

Imagem

Imagem

> Ao abri-la,clique Scanner.
> Aguarde a conclusão!

Imagem

> À seguir,clique Relatório.
> Poste o log de diagnóstico: ~ Modo: Scanner
> Ps: Como o log será extenso,envie-o à Pjjoint.malekal.

> Ou acesse: < Imagem >

> Clique no botão Parcourir...
> Busque o relatório ao desktop.
> Clique no botão Abrir.
> Clique no botão "Créer le lien Cjoint".
> Copie o link que está ao lado de "Le lien a été créé" e poste-o em sua resposta.

Imagem

> O link ao relatório,que é este assinalado,deverá ser colado em sua resposta.

Imagem

> Ou clique "Copier le lien (*)" e cole o link ao seu Post.

A+
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#4 Por joram
18/09/2015 - 12:34
/!\ Boa Tarde! Mcampos25 /!\

> Baixe: < Imagem > << Link!

> Estando na página,clique: "Télécharger"
> Salve-o no desktop!
> Instale-o,clicando em: Suivant >> Suivant >>...>> Suivant >> Suivant >> Installer >> Terminer
> Execute este script na ferramenta ZHPFix.
[spoiler]Script ZHPFix
sysrestore
EmptyFlash
EmptyTemp
SR - Auto [2015/07/08 22:26:02] [ 173088] Net.Tcp Service Handler (NetTcpHandler) . (...) - C:\Users\mateu\AppData\Roaming\NetService\netservice.exe
R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seekmx.com/
R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.seekmx.com/
R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.seekmx.com/
R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.seekmx.com/
R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.seekmx.com/
R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.seekmx.com/
[MD5.A271A66ABF8CAC3606FB114D7E8C517B] - (...) -- C:\Users\mateu\AppData\Roaming\NetService\netservice.exe [173088] [PID.5048]
[MD5.00000000000000000000000000000000] [APT] [AutoKMS] (...) -- C:\Windows\AutoKMS\AutoKMS.exe (.not file.) [0]
O23 - Service: Net.Tcp Service Handler (NetTcpHandler) . (...) - C:\Users\mateu\AppData\Roaming\NetService\netservice.exe
O39 - APT: AutoKMS - (...) -- C:\Windows\System32\Tasks\AutoKMS [3540]
O39 - APT: TechSmith Updater - (.TechSmith Corporation.) -- C:\Windows\System32\Tasks\TechSmith Updater [3888] ©
O43 - CFD: 2015/08/23 16:42:51 - [] D -- C:\Users\mateu\AppData\Roaming\NetService
O43 - CFD: 2015/09/17 19:52:52 - [] D -- C:\Users\mateu\AppData\Roaming\RunDir
O68 - StartMenuInternet: [HKLM\..\Shell\open\Command] (...) -- C:\Program Files\Internet Explorer\iexplore.ex http://www.seekmx.com/
O87 - FAEL: "TCP Query User{2EC02DBD-396B-484C-B229-A457FEBBA645}C:\users\mateu\appdata\local\popcorn time\nw.exe" [In-None-P6-TRUE] .(...) -- C:\users\mateu\appdata\local\popcorn time\nw.exe
O87 - FAEL: "UDP Query User{E1FAAFA6-C645-4124-A33D-8F2561DF635D}C:\users\mateu\appdata\local\popcorn time\nw.exe" [In-None-P17-TRUE] .(...) -- C:\users\mateu\appdata\local\popcorn time\nw.exe
C:\Users\mateu\AppData\Roaming\NetService\netservice.exe
C:\Windows\System32\Tasks\AutoKMS
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified
[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified
HKLM\SOFTWARE\Wow6432Node\NetTcpHandler
HKLM\SOFTWARE\Wow6432Node\NtIObits
HKLM\SOFTWARE\Wow6432Node\NtSvcHandler
HKLM\SOFTWARE\Wow6432Node\seekmx
HKCU\SOFTWARE\fbinstTool
ServiceStop:NetTcpHandler
EmptyPrefetch
FirewallRaz
ShortcutFix
HiddenFix
IfeoFix
[/spoiler]
> Selecione e copie estas informações que estão no Spoiler,para o Bloco de Notas.
> Com o Bloco de Notas aberto,faça: ctrl+a >> ctrl+c ( Selecionar e Copiar )
> À seguir,minimize o Bloco de Notas.

> Abra a ferramenta ZHPFix. < Imagem >

Imagem

> Clique IMPORTAÇÃO >> OK.
> Ps: Ao clicar "OK",verifique se o campo está limpo para que receba,somente,as informações do script.
> Clique "GO".

Imagem

> Ou,clique CONFIGURAR >> Personalizar.
> Cole as informações contidas no Bloco de Notas e clique "GO".
> Poste o relatório!

Imagem
< Peço aos visitantes que não utilizem este script em seus computadores,sob risco de danos aos mesmos! >

A+
Mcampos25
Mcampos25 Novo Membro Registrado
7 Mensagens 0 Curtidas
#5 Por Mcampos25
18/09/2015 - 16:28
Boa tarde, joram.

Só poderei executar essa etapa mais tarde, chegarei somente a noite em casa. Mas gostaria de entender o que exatamente aconteceu. Foi algum arquivo baixado que veio esse tipo de vírus junto? Porque quando aconteceu algo do tipo em outra ocasião era mais problema no navegador, redirecionando para outros sites e algo do tipo. Dessa vez, a única coisa que me fez reparar que havia algo errado, antes do meu antivírus acusar algo, foi que meu navegador edge fechava sozinho e determinados momentos, algumas janelas que eu utilizava, depois de minimizadas elas não maximizavam mais....
Bom, só queria entender um pouco do problema.

Obrigado desde já,
Mcampos25
Mcampos25 Novo Membro Registrado
7 Mensagens 0 Curtidas
#7 Por Mcampos25
18/09/2015 - 22:14
Boa noite, joram

Segue o relatório da última etapa realizada
"Relatório"

Rapport de ZHPFix 2015.8.24.7 par Nicolas Coolman, Update du 24/08/2015
Fichier d'export Registre :
Run by mateu at 18/09/2015 22:13:22
High Elevated Privileges : OK
Windows 8 Home Premium Edition, 64-bit Service Pack 1 (10240)

Reciclagem vazia (00mn 03s)
Prefetcher vazio
Reparação de atalhos do navegador

========== Processo memória ==========
ELIMINÉ: Memory Process: C:\Users\mateu\AppData\Roaming\NetService\netservice.exe

========== Estado dos serviços ==========
NetTcpHandler Parado

========== Chaves do Registo ==========
ELIMINÉ: Service: NetTcpHandler
ELIMINÉ: HKLM\SOFTWARE\Wow6432Node\NetTcpHandler
ELIMINÉ: HKLM\SOFTWARE\Wow6432Node\NtIObits
ELIMINÉ: HKLM\SOFTWARE\Wow6432Node\NtSvcHandler
ELIMINÉ: HKLM\SOFTWARE\Wow6432Node\seekmx
ELIMINÉ: HKCU\SOFTWARE\fbinstTool
Ramo Base de Registos IFEO não infetado !

========== Valores do Registo ==========
Ausente Valor Perfil Padrão: FirewallRaz :
Ausente Valor Perfil Domínio FirewallRaz :
ELIMINÉ: FirewallRaz (None) : MCX-Prov-Out-TCP
ELIMINÉ: FirewallRaz (None) : MCX-McrMgr-Out-TCP
ELIMINÉ: FirewallRaz (Public) : TCP Query User{0341C5E3-A75D-4F87-9AD2-D3F7D6BC28F2}C:\users\mateu\appdata\local\popcorn time\node-webkit\popcorn time.exe
ELIMINÉ: FirewallRaz (Public) : UDP Query User{EAAF3A2A-248B-459F-AA28-06A02145DCDB}C:\users\mateu\appdata\local\popcorn time\node-webkit\popcorn time.exe
ELIMINÉ: FirewallRaz (Public) : {219F0A95-7CAF-4352-B826-E197DBBE0E7F}
ELIMINÉ: FirewallRaz (Public) : {3361C7DA-103B-45E5-8539-6E1287D00713}

========== Elementos dos dados do Registo ==========
ELIMINÉ: R0 - Main,Start Page = KCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page
ELIMINÉ: R0 - Main,Start Page = KLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page
ELIMINÉ: R0 - Main,Start Page = KLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page
ELIMINÉ: R1 Search Page = http://www.seekmx.com/?bd=hp&oem=301br&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUK29370993709&version=2.3.0.10324&pid=414031160&tid=676
ELIMINÉ: StartMenuInternet: C:\Program Files\Internet Explorer\iexplore.ex http://www.seekmx.com/
SUBSTITUI Value CheckedValue : Good (1) - Bad (0)
SUBSTITUI Value NoActiveDesktopChanges : Good (0) - Bad (1)

========== Pastas ==========
ELIMINÉ Flash Cookies (0)
ELIMINÉ Temporários windows (0)
ELIMINÉ: C:\Users\mateu\AppData\Roaming\NetService
ELIMINÉ: C:\Users\mateu\AppData\Roaming\RunDir

========== Ficheiros ==========
ELIMINÉ Flash Cookies (0) (0 octets)
ELIMINÉ Temporários windows (0) (0 octets)
ELIMINÉ:** c:\users\mateu\appdata\roaming\netservice\netservice.exe
ELIMINA REINICIAR: c:\windows\system32\tasks\techsmith updater

========== Tarefa planificada ==========
ELIMINÉ: AutoKMS
ELIMINÉ: AutoKMS

========== Pastas/Ficheiros ocultos restaurados ==========
Mes images (My Pictures) : 42 restaurados com sucesso
Ma musique (My Music) : 1 restaurados com sucesso
Ma Video (My Video) : 2 restaurados com sucesso
Mes Favoris (My Favorites) : 2 restaurados com sucesso
Mes Documents (My Documents) : 28 restaurados com sucesso
Mon Bureau (My Desktop) : 2 restaurados com sucesso
Menu demarrer (Programs) : 10 restaurados com sucesso
Dossier utilisateur (AppData) : 12 restaurados com sucesso
Programmes (Program Files) : 6 restaurados com sucesso

========== Restauração Sistema ==========
Ponto de restauro do sistema criado com sucesso


========== Recapitulativo ==========
1 : Processo memória
7 : Chaves do Registo
8 : Valores do Registo
7 : Elementos dos dados do Registo
4 : Pastas
4 : Ficheiros
1 : Estado dos serviços
2 : Tarefa planificada
105 : Pastas/Ficheiros ocultos restaurados
1 : Restauração Sistema


End of clean in 00mn 32s

========== Caminho do ficheiro do relatório ==========
C:\Users\mateu\AppData\Roaming\ZHP\ZHPFix[R1].txt - 18/09/2015 22:13:26 [3809]
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#8 Por joram
18/09/2015 - 22:35
/!\ Boa Noite! Mcampos25 /!\

> Repita seu scan com a FRST e poste seu relatório,não esquecendo o Addition.txt <<

> Baixe: < Imagem > ( ... by Farbar )

> No banner àcima,é para sistemas 32bits!

< Farbar Recovery Scan Tool 64-Bit >

> No link àcima,é para sistemas 64bits!
> Salve-o no desktop! (Área de trabalho ...)
> Execute a ferramenta! Clique "Yes" >> "Scan".

Imagem

> Antes de clicar "Scan",verifique se as caixinhas em "Whitelist" estão assinaladas.
> Em "Optional Scan",deixe marcada a checkbox "Addition.txt".
> Ps: Será gerado,também,o relatório "Addition.txt" que estará disponibilizado na 1ª execução da ferramenta.
> Poste os relatórios! (FRST.txt + Addition.txt)

> Como o log será extenso,envie-o à Imagem >
Imagem
> Clique no botão Parcourir...
> Busque o relatório e clique no botão Abrir.
> Clique no botão "Créer le lien Cjoint".
> Copie o link que está ao lado de "Le lien a été créé" e poste-o em sua resposta.

Imagem

> O link ao relatório,que é este assinalado,deverá ser colado em sua resposta.

Imagem

> Ou clique "Copier le lien (*)" e cole o link ao seu Post.

A+
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#10 Por joram
19/09/2015 - 02:31
/!\ Bom Dia! Mcampos25 /!\

> Copie estas informações que estão em vermelho,para o Bloco de Notas.
> Salve-as com o nome fixlist. << Texto!
> Salve-as na pasta Downloads! -/- C:\Users\mateu\Downloads <<

start
CloseProcesses:
S3 catchme; \??\C:\Users\mateu\AppData\Local\Temp\catchmegnqc.sys [X]
S1 gbpddfac; system32\drivers\gbpddfac64.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
2015-09-18 22:13 - 2015-09-18 22:13 - 00003889 _____ C:\Users\mateu\Desktop\ZHPFixReport.txt
2015-09-18 22:11 - 2015-09-18 22:11 - 00001918 _____ C:\Users\Public\Desktop\ZHPFix.lnk
2015-09-18 22:11 - 2015-09-18 22:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
2015-09-18 22:11 - 2015-09-18 22:11 - 00000000 ____D C:\Program Files (x86)\ZHPFix
2015-09-18 22:10 - 2015-09-18 22:10 - 03521472 _____ (Nicolas Coolman ) C:\Users\mateu\Downloads\ZHPFix.exe
2015-09-18 10:11 - 2015-09-18 10:12 - 00059717 _____ C:\Users\mateu\Desktop\ZHPDiag.txt
2015-09-18 10:09 - 2015-09-18 10:09 - 01932800 _____ C:\Users\mateu\Downloads\ZHPDiag3.exe
2015-09-18 10:09 - 2015-09-18 10:09 - 00000865 _____ C:\Users\mateu\Desktop\ZHPDiag.lnk
2015-09-17 23:56 - 2015-09-18 00:17 - 00001582 _____ C:\Users\mateu\Desktop\ZHPCleaner.txt
2015-09-17 23:53 - 2015-09-18 22:13 - 00000000 ____D C:\Users\mateu\AppData\Roaming\ZHP
2015-09-17 23:53 - 2015-09-17 23:53 - 00000912 _____ C:\Users\mateu\Desktop\ZHPCleaner.lnk
2015-09-17 23:12 - 2015-09-17 23:53 - 01957888 _____ C:\Users\mateu\Downloads\ZHPCleaner-2015.9.16.348.exe
2015-09-17 22:55 - 2015-09-17 22:58 - 01798976 _____ (Malwarebytes) C:\Users\mateu\Downloads\JRT.exe
2015-09-17 22:41 - 2015-09-17 22:41 - 00001181 _____ C:\AdwCleaner[S6].txt
2015-09-17 20:27 - 2015-09-17 20:27 - 00001684 _____ C:\AdwCleaner[C3].txt
2015-09-17 20:25 - 2015-09-17 20:25 - 00001507 _____ C:\AdwCleaner[S5].txt
2015-09-13 15:09 - 2015-09-13 15:09 - 00001486 _____ C:\AdwCleaner[C2].txt
2015-09-13 15:04 - 2015-09-13 15:05 - 00001315 _____ C:\AdwCleaner[S4].txt
2015-08-23 17:33 - 2015-08-23 17:33 - 00000870 _____ C:\AdwCleaner[S3].txt
2015-08-23 17:01 - 2015-08-23 17:01 - 00012034 _____ C:\AdwCleaner[C1].txt
2015-08-23 17:01 - 2015-08-23 17:01 - 00011025 _____ C:\AdwCleaner[S2].txt
2015-08-23 16:54 - 2015-08-23 17:01 - 00000000 ____D C:\AdwCleaner
2015-08-23 16:54 - 2015-08-23 16:54 - 00011294 _____ C:\AdwCleaner[S1].txt
2015-08-23 16:54 - 2015-08-23 16:54 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
Folder: C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
CreateRestorePoint:
RemoveProxy:
EmptyTemp:
Reboot:
Hosts:
end


> Execute FRST/FRST64 >> Clique "Fix" << Aguarde!
> Na mensagem,clique Executar.
> Poste o relatório! (Fixlog.txt)

Imagem
< Peço aos visitantes que não utilizem este script em outros computadores,sob risco de danos aos mesmos! >

A+
Mcampos25
Mcampos25 Novo Membro Registrado
7 Mensagens 0 Curtidas
#11 Por Mcampos25
19/09/2015 - 13:22
Boa tarde, Joram

Segue o relatório
"Relatório"

Fix result of Farbar Recovery Scan Tool (x64) Version:15-09-2015
Ran by mateu (2015-09-19 13:17:20) Run:1
Running from C:\Users\mateu\Downloads
Loaded Profiles: mateu (Available Profiles: mateu & manoe)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CloseProcesses:
S3 catchme; \??\C:\Users\mateu\AppData\Local\Temp\catchmegnqc.sys [X]
S1 gbpddfac; system32\drivers\gbpddfac64.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
2015-09-18 22:13 - 2015-09-18 22:13 - 00003889 _____ C:\Users\mateu\Desktop\ZHPFixReport.txt
2015-09-18 22:11 - 2015-09-18 22:11 - 00001918 _____ C:\Users\Public\Desktop\ZHPFix.lnk
2015-09-18 22:11 - 2015-09-18 22:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
2015-09-18 22:11 - 2015-09-18 22:11 - 00000000 ____D C:\Program Files (x86)\ZHPFix
2015-09-18 22:10 - 2015-09-18 22:10 - 03521472 _____ (Nicolas Coolman ) C:\Users\mateu\Downloads\ZHPFix.exe
2015-09-18 10:11 - 2015-09-18 10:12 - 00059717 _____ C:\Users\mateu\Desktop\ZHPDiag.txt
2015-09-18 10:09 - 2015-09-18 10:09 - 01932800 _____ C:\Users\mateu\Downloads\ZHPDiag3.exe
2015-09-18 10:09 - 2015-09-18 10:09 - 00000865 _____ C:\Users\mateu\Desktop\ZHPDiag.lnk
2015-09-17 23:56 - 2015-09-18 00:17 - 00001582 _____ C:\Users\mateu\Desktop\ZHPCleaner.txt
2015-09-17 23:53 - 2015-09-18 22:13 - 00000000 ____D C:\Users\mateu\AppData\Roaming\ZHP
2015-09-17 23:53 - 2015-09-17 23:53 - 00000912 _____ C:\Users\mateu\Desktop\ZHPCleaner.lnk
2015-09-17 23:12 - 2015-09-17 23:53 - 01957888 _____ C:\Users\mateu\Downloads\ZHPCleaner-2015.9.16.348.exe
2015-09-17 22:55 - 2015-09-17 22:58 - 01798976 _____ (Malwarebytes) C:\Users\mateu\Downloads\JRT.exe
2015-09-17 22:41 - 2015-09-17 22:41 - 00001181 _____ C:\AdwCleaner[S6].txt
2015-09-17 20:27 - 2015-09-17 20:27 - 00001684 _____ C:\AdwCleaner[C3].txt
2015-09-17 20:25 - 2015-09-17 20:25 - 00001507 _____ C:\AdwCleaner[S5].txt
2015-09-13 15:09 - 2015-09-13 15:09 - 00001486 _____ C:\AdwCleaner[C2].txt
2015-09-13 15:04 - 2015-09-13 15:05 - 00001315 _____ C:\AdwCleaner[S4].txt
2015-08-23 17:33 - 2015-08-23 17:33 - 00000870 _____ C:\AdwCleaner[S3].txt
2015-08-23 17:01 - 2015-08-23 17:01 - 00012034 _____ C:\AdwCleaner[C1].txt
2015-08-23 17:01 - 2015-08-23 17:01 - 00011025 _____ C:\AdwCleaner[S2].txt
2015-08-23 16:54 - 2015-08-23 17:01 - 00000000 ____D C:\AdwCleaner
2015-08-23 16:54 - 2015-08-23 16:54 - 00011294 _____ C:\AdwCleaner[S1].txt
2015-08-23 16:54 - 2015-08-23 16:54 - 00000004 _____ C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
Folder: C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
CreateRestorePoint:
RemoveProxy:
EmptyTemp:
Reboot:
Hosts:
end

*****************

Processes closed successfully.
catchme => service removed successfully
gbpddfac => service removed successfully
wfpcapture => service removed successfully
C:\Users\mateu\Desktop\ZHPFixReport.txt => moved successfully
C:\Users\Public\Desktop\ZHPFix.lnk => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP => moved successfully
C:\Program Files (x86)\ZHPFix => moved successfully
C:\Users\mateu\Downloads\ZHPFix.exe => moved successfully
C:\Users\mateu\Desktop\ZHPDiag.txt => moved successfully
C:\Users\mateu\Downloads\ZHPDiag3.exe => moved successfully
C:\Users\mateu\Desktop\ZHPDiag.lnk => moved successfully
C:\Users\mateu\Desktop\ZHPCleaner.txt => moved successfully
C:\Users\mateu\AppData\Roaming\ZHP => moved successfully
C:\Users\mateu\Desktop\ZHPCleaner.lnk => moved successfully
C:\Users\mateu\Downloads\ZHPCleaner-2015.9.16.348.exe => moved successfully
C:\Users\mateu\Downloads\JRT.exe => moved successfully
C:\AdwCleaner[S6].txt => moved successfully
C:\AdwCleaner[C3].txt => moved successfully
C:\AdwCleaner[S5].txt => moved successfully
C:\AdwCleaner[C2].txt => moved successfully
C:\AdwCleaner[S4].txt => moved successfully
C:\AdwCleaner[S3].txt => moved successfully
C:\AdwCleaner[C1].txt => moved successfully
C:\AdwCleaner[S2].txt => moved successfully
C:\AdwCleaner => moved successfully
C:\AdwCleaner[S1].txt => moved successfully
C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 => moved successfully

========================= Folder: C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 ========================

not found.

====== End of Folder: ======

Restore point was successfully created.

========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-497741064-2335638771-2095936946-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-497741064-2335638771-2095936946-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully


========= End of RemoveProxy: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
EmptyTemp: => 55.3 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 13:17:55 ====
joram
joram Highlander Registrado
5.4K Mensagens 2.5K Curtidas
#12 Por joram
19/09/2015 - 13:28
/!\ Boa Tarde! Mcampos25 /!\

> O relatório da FRST,não mais indicou a infecção pelo hijacker.
> Tudo Ok?

> Não havendo mais problemas,remova as ferramentas que foram utilizadas na desinfecção e restabeleça backup,ao registro do Windows.

> Baixe: < Imagem > ( ... de Xplode )

> Link alternativo! < delfix_10.8.exe >

Imagem

> Estando na página,clique em Download Now.
> Salve-a em um local conveniente. ( desktop! )
> Feche aplicativos que estejam abertos.

Imagem

> Remover ferramentas de desinfecção
> Criar backup do registro
> Limpar pontos da restauração do sistema
> Redefinir as configurações do sistema

> Com estas caixinhas marcadas,clique Executar!
> Reinicie o computador ao concluir!
> Ps: Por fim,backup do Registro estará em: C:\WINDOWS\ERUNT\DelFix <<

Imagem

> Caso necessite acioná-lo,abra a pasta DelFix e execute ERDNT.exe.
> Clique OK na mensagem!

A+
© 1999-2024 Hardware.com.br. Todos os direitos reservados.
Imagem do Modal